Le Lézard
Classified in: Science and technology
Subjects: NPT, EXE, FVT

All Federal Agencies Have Less Than 90 Days To Secure .Gov Email


WASHINGTON, July 16, 2018 /PRNewswire-USNewswire/ -- U.S. federal government agencies have less than 90 days to meet a U.S. Department of Homeland Security (DHS) Binding Operational Directive (BOD) focused on bolstering email and website security for all federal agencies that operate .gov email and website domains. The federal government has made good progress toward fulfilling the directive, with 74% of the domains tested having implemented a DMARC policy, however, less than half of the domains (47%) are at the highest policy level of "reject" ? the setting that prevents spoofed email from being delivered to people. Agencies have three more months to meet the requirements of the directive.

By October 16, 2018, all agencies are required to deploy the email security protocol DMARC (Domain-based Message Authentication, Reporting & Conformance) at the policy level of "reject" to prevent spammers and phishers from using an organization's name to conduct cyberattacks.

Since the BOD was issued on October 16, 2017, GCA research has found that more than 600 agency email domains have moved to the most secure "reject" setting for DMARC. In total, 605 domains are set to "reject" and 26 are set at the second-highest security level, "quarantine". However, half of all federal government email domains (319) have only deployed DMARC at its least secure setting or have not deployed DMARC at all (334). 

"DHS has shown tremendous leadership in requiring the deployment of advanced email and web security tools that will protect consumers, government workers and our nation's critical infrastructure," said Philip Reitinger, president and CEO of the Global Cyber Alliance. "Even with difficulties, agencies should at least have implemented DMARC at its most simple level. It takes little time, does not risk disruption of service, and provides insight on operations and threats."

GCA has helped organizations implement DMARC with a collection of free resources that include the GCA DMARC Setup Guide, instructional videos, and webinars. Agencies can take advantage of these resources online at www.dmarc.globalcyberalliance.org.

DMARC weeds out fake emails (known as direct domain spoofing) deployed by spammers and phishers targeting the inboxes of any person with an email address.  According to the 2018 Symantec ISTR report, 1 in 131 emails contained malware, the highest rate in 5 years. Without DMARC protection, hackers can create emails that appear to be from a trusted source but instead contain malicious links or ask for additional personal information that could be provided by unsuspecting consumers.

About the Global Cyber Alliance

The Global Cyber Alliance (GCA) is an international, cross-sector effort dedicated to eradicating cyber risk and improving our connected world. We achieve our mission by uniting global communities, implementing concrete solutions, and measuring the effect.  Learn more at www.globalcyberalliance.org.

CONTACT: Josh Zecher, 202-463-0045, [email protected]

SOURCE Global Cyber Alliance


These press releases may also interest you

at 22:30
Today, a decision was issued by the Court of Appeals Division I in the State of Washington in Erickson v. Monsanto, ruling in Monsanto's favor on multiple grounds. This decision reverses the initial verdict of $185 million in its entirety and...

at 21:51
BTQ Technologies Corp. (the "Company") (CBOE CA: BTQ) is providing this bi-weekly update on the status of the management cease trade order issued on April 3, 2024 (the "MCTO"), by its principal regulator, the British Columbia Securities Commission...

at 21:45
Pangea Entertainment Productions (Venice, Ca.) and Big Bang Mediaverse (Mumbai, India) announce a partnership to create and produce innovative multiplatform content aimed at younger and connected audiences globally and in India. The first program in...

at 21:30
Astellas Pharma Inc. (TSE: 4503, President and CEO: Naoki Okamura, "Astellas") and Poseida Therapeutics, Inc.  today announced that Xyphos Biosciences, Inc., (a wholly owned subsidiary of Astellas, "Xyphos") and Poseida have entered into a...

at 21:25
RiskOpsAItm, the Award Winning Pioneer in AI Driven Integrated Risk Modeling & Decision Supremacy, hosts Ethical Dimensions of AI: A Deep Dive into Data Privacy and Security. "We are delighted...

at 21:00
Landlord Studio, the leading property management accounting software for self-managing landlords announced its new free listing syndication feature in partnership with Zillow and Zumper. Charles Chan, CEO of Landlord Studio said, "We're delighted to...



News published on and distributed by: