Master'sOpen Access

Evaluation and classification of e-mail security methods used by institutions in the digital transformation process

2024
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Emre Baysan

Abstract (EN)

Digital transformation is defined as the process in which organizations transfer their operations to digital platforms, thereby increasing operational efficiency in the modern business world. In this process, email has become one of the most critical tools of digital communication. Email emerges as an indispensable tool for organizations during the digital transformation process due to its role in both internal and external communication. During digital transformation, email security is of great importance in the face of the increasing complexity and variety of cyber threats. While email plays a crucial role in digital communication, it has also become one of the most common attack vectors. Organizations are particularly vulnerable to phishing and malware attacks conducted via email, which can lead to not only financial losses but also reputational damage, data loss, and unauthorized access to sensitive information. Email attacks are one of the most frequently used methods by cybercriminals, posing a significant threat to organizations undergoing digital transformation. Therefore, developing effective email security strategies is vital for preventing potential losses. Organizations must develop effective strategies to ensure email security throughout this process. Failure to secure emails can result in both financial and reputational damage. This research aims to evaluate and classify the email security methods used by organizations during the digital transformation process. The research is important in identifying the email security issues faced by organizations during digital transformation, determining the methods they use to address these issues, introducing new methods to the literature, assisting in the development of email security strategies, and raising awareness about email security. In this research, the case study method, a qualitative research model, was used. In the first stage of the study, expert interviews were conducted as a qualitative data collection method. Participants were asked questions such as "What are the main issues faced by organizations during the digital transformation process concerning email security?" and "What methods and solutions are used by organizations for email security?" In the second stage, a phishing email attack method was employed to investigate "Are the email security methods and tools sufficient against a phishing attack?" Participants were selected using a non-random purposive sampling method, and interviews were conducted with experts in email security from five volunteer companies and one institution, including the organization's owner or authorized personnel. Subsequently, phishing emails were sent to the participants' corporate email accounts to collect data on their security levels. According to the findings, the primary issues encountered in email security were listed as "phishing," "email password compromise," "bulk acquisition of email addresses," "man-in-the-middle attacks," "malware," "system updates and patches," "spam emails," "email-borne viruses," "data theft," "lack of email security awareness," "failure to allocate resources for email security," "lack of email security training," and "zero-day attacks." The methods used for email security, as stated by the participants, included "spam filters," "keeping SPF records," "mandatory strong passwords," "mail gateways," "antivirus programs," "penetration tests," "email bounce," "hard-to-guess email addresses," "ransomware software," "key lists," "Pegasus software," "penetration tests," "blacklists," "web filters," "Bitdefender," "multi-factor authentication," and "content filtering." The phishing attacks revealed that the email security methods and tools of 2 out of 6 participants were sufficient, while 4 were found to be insufficient. It is crucial for organizations to continually update their email security strategies and take proactive measures against evolving threats.

Author

Celalettin İrdem

How to Cite

Celalettin İrdem (Master Thesis). Evaluation and classification of e-mail security methods used by institutions in the digital transformation process, 2024, Afyon Kocatepe University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Afyon Kocatepe University