// BRIEFING

Email security. Four ways it breaks. E-mailbeveiliging. Vier manieren waarop het misgaat.

Interception, manipulation, domain impersonation and man-in-the-middle — in plain language: what each one costs us, and the single control that stops it. Afluisteren, manipulatie, domeinnabootsing en man-in-the-middle — in gewone taal: wat elk risico ons kost, en welke maatregel het stopt.

// RISK 01RISICO 01

Someone is listening in. Iemand luistert mee.

“afgeluisterd worden” / eavesdropping / interception afgeluisterd worden / interceptie
IN TRANSITONDERWEG
🏢
Our mail serverOnze mailserver
🏦
Their mail serverHun mailserver
🕵️READING EVERYTHINGLEEST ALLES MEE

An email is not one hop — it crosses several networks and relays before it lands. If any hop negotiates plaintext instead of TLS, everything in that message is readable by whoever sits on that path: a transit provider, a compromised router, a hostile Wi-Fi, a nation-state tap. Nothing breaks, no alert fires, and the recipient still receives the mail. That is exactly why it goes unnoticed for years.

What is exposed: M&A and contract negotiations, HR and medical data, invoices and bank details, password-reset links, board material. Under GDPR this is a personal-data breach with a 72-hour notification clock.

Een e-mail maakt niet één sprong — hij passeert meerdere netwerken en relays voordat hij aankomt. Onderhandelt één van die hops platte tekst in plaats van TLS, dan is de volledige inhoud leesbaar voor iedereen op dat pad: een transitprovider, een gehackte router, een vijandig wifinetwerk, een statelijke tap. Er gaat niets stuk, er komt geen alarm, en de ontvanger krijgt de mail gewoon. Precies daarom blijft dit jarenlang onopgemerkt.

Wat er op straat ligt: overname- en contractonderhandelingen, HR- en medische gegevens, facturen en bankrekeningnummers, wachtwoord-resetlinks, bestuursstukken. Onder de AVG is dit een datalek met een meldtermijn van 72 uur.

SILENT · UNDETECTABLE · RETROACTIVESTIL · ONOPGEMERKT · TERUGWERKEND FIX: ENFORCED TLS + MTA-STS + DANEOPLOSSING: AFGEDWONGEN TLS + MTA-STS + DANE
// RISK 02RISICO 02

Someone rewrites the message. Iemand verandert het bericht.

“verkeer gemanipuleerd worden” / tampering / integrity loss verkeer gemanipuleerd worden / integriteitsverlies
INVOICE FLOWFACTUURSTROOM
🧾
SupplierLeverancier
💳
FinanceFinance
IBAN …4417 · € 84.200
IBAN …9902 · € 84.200
✍️EDITS IN TRANSITPAST ONDERWEG AAN

Reading is passive. Changing is active — and far more expensive. An attacker positioned on an unprotected path can alter the message body, swap an attached invoice, or rewrite a single IBAN, then forward the mail onward. Both sender and recipient see a normal conversation thread. The mismatch only surfaces weeks later, when the real supplier asks where their money is.

Business impact: direct financial loss (invoice-redirection fraud averages six figures per incident), contract disputes over “what was actually agreed”, and no reliable evidence trail — because without a cryptographic signature you cannot prove the message you hold is the message that was sent.

Meelezen is passief. Wijzigen is actief — en veel duurder. Een aanvaller op een onbeschermd pad kan de tekst aanpassen, een bijgevoegde factuur vervangen of één IBAN herschrijven, en de mail daarna gewoon doorsturen. Zowel afzender als ontvanger ziet een normale gespreksdraad. Het verschil komt pas weken later boven water, als de echte leverancier vraagt waar zijn geld blijft.

Bedrijfsimpact: direct financieel verlies (factuurfraude loopt gemiddeld in de zes cijfers per incident), contractdiscussies over “wat er nu écht is afgesproken”, en geen betrouwbaar bewijsspoor — zonder cryptografische handtekening kun je niet aantonen dat het bericht dat je hebt, het bericht is dat is verstuurd.

DIRECT FINANCIAL LOSS · NO EVIDENCE TRAILDIRECT GELDVERLIES · GEEN BEWIJSSPOOR FIX: DKIM SIGNING + S/MIME ON KEY FLOWSOPLOSSING: DKIM + S/MIME OP KRITIEKE STROMEN
// RISK 03RISICO 03

Someone pretends to be us. Iemand doet zich voor als ons.

“het domein kan nagebootst worden” / domain spoofing het domein kan nagebootst worden / spoofing
INBOX VIEWINBOX-BEELD
REALECHT
CFO
cfo@ons-bedrijf.nl
SPF ✓ DKIM ✓ DMARC ✓
VS
FAKENEP
CFO
cfo@ons-bedrijf.nl
sent from an attacker's servervanaf server van aanvaller

Nothing in the email protocol stops a stranger from typing our domain into the “From:” field. Without SPF, DKIM and an enforcing DMARC policy, anyone on the internet can send mail that is — for every practical purpose the recipient can check — from our CFO. Their mail client shows our name, our domain, our branding.

Business impact: CEO fraud and payment-instruction fraud aimed at our own staff; phishing of our customers under our brand; our domain's sending reputation destroyed, which means our legitimate mail starts landing in spam. And this risk exists whether or not we are otherwise “secure” — the attacker never has to touch our infrastructure.

Niets in het e-mailprotocol verhindert een vreemde om ons domein in het “Van:”-veld te typen. Zonder SPF, DKIM en een handhavend DMARC-beleid kan iedereen op internet mail versturen die — voor alles wat de ontvanger kan controleren — van onze CFO ís. In hun mailprogramma staat onze naam, ons domein, onze huisstijl.

Bedrijfsimpact: CEO-fraude en betaalinstructiefraude richting onze eigen medewerkers; phishing van onze klanten onder onze merknaam; vernietiging van de verzendreputatie van ons domein, waardoor onze legitieme post in de spamfolder belandt. Dit risico bestaat los van hoe “veilig” wij verder zijn — de aanvaller hoeft onze infrastructuur nooit aan te raken.

CEO FRAUD · BRAND ABUSE · DELIVERABILITYCEO-FRAUDE · MERKMISBRUIK · BEZORGBAARHEID FIX: SPF + DKIM + DMARC AT P=REJECTOPLOSSING: SPF + DKIM + DMARC OP P=REJECT
// RISK 04RISICO 04

Someone sits in the middle. Iemand zit ertussen.

man-in-the-middle attack / TLS downgrade man-in-the-middle-aanval / TLS-downgrade
TLS HANDSHAKETLS-HANDSHAKE
🏢
UsWij
🤝
PartnerPartner
🔒
🎭RELAYS BOTH SIDESSPEELT BEIDE KANTEN
TLS STRIPPED → PLAINTEXTTLS VERWIJDERD → PLATTE TEKST

This is risks 01 and 02 combined and weaponised. The attacker inserts themselves between the two mail servers and impersonates each side to the other. Because STARTTLS is opportunistic by default, they simply strip the encryption offer during the handshake — both servers then fall back to plaintext and neither complains. From that position the attacker reads everything, changes anything, and can hold the conversation open for months.

Why this is the board-level one: it defeats the assumption that “we have encryption”. Opportunistic TLS is encryption that silently turns itself off when asked nicely. MTA-STS and DANE remove the “opportunistic” part — they make encryption mandatory, so a stripped connection fails instead of quietly downgrading.

Dit is risico 01 en 02 gecombineerd en tot wapen gemaakt. De aanvaller plaatst zich tussen beide mailservers en doet zich naar elke kant voor als de ander. Omdat STARTTLS standaard opportunistisch is, verwijdert hij simpelweg het versleutelingsaanbod tijdens de handshake — beide servers vallen terug op platte tekst en geen van beide klaagt. Vanuit die positie leest de aanvaller alles, wijzigt hij wat hij wil, en kan hij de conversatie maandenlang openhouden.

Waarom dit een directiethema is: het ondergraaft de aanname dat “wij versleuteling hebben”. Opportunistische TLS is versleuteling die zichzelf stilletjes uitschakelt zodra er vriendelijk om wordt gevraagd. MTA-STS en DANE halen het “opportunistische” eruit — zij maken versleuteling verplicht, zodat een gestripte verbinding faalt in plaats van stil te degraderen.

READ + REWRITE + IMPERSONATE, AT ONCEMEELEZEN + WIJZIGEN + NABOOTSEN TEGELIJK FIX: MTA-STS ENFORCE + DANE + TLS-RPTOPLOSSING: MTA-STS ENFORCE + DANE + TLS-RPT
// CONTROLSMAATREGELEN

What actually stops this. Wat dit daadwerkelijk stopt.

DNS records and mail-server settings — no new product, no licence DNS-records en mailserverinstellingen — geen nieuw product, geen licentie
DEFENCE STACKVERDEDIGINGSLAGEN
SPF DKIM DMARC MTA-STS DANE / TLS-RPT
ControlStopsIn one line
SPFSpoofing (03)A DNS list of the servers allowed to send mail as our domain.
DKIMManipulation (02)A cryptographic signature over the message — any edit in transit breaks it.
DMARCSpoofing (03)Tells receivers what to do when SPF/DKIM fail. Only p=reject actually blocks; it also gives us reports on who is abusing our domain.
MTA-STSInterception (01), MITM (04)Declares “encryption is mandatory for my domain” — a stripped connection fails instead of downgrading.
DANEMITM (04)Pins the expected certificate in DNSSEC-signed DNS, so a forged certificate is rejected.
TLS-RPTBlind spotsDaily reports on failed TLS connections — how we find out that an attack or misconfiguration is happening.
S/MIME · PGP01 + 02, end-to-endEncrypts and signs the message itself, not just the transport. For the small set of genuinely high-value flows.
MaatregelStoptIn één zin
SPFSpoofing (03)Een DNS-lijst van servers die namens ons domein mogen versturen.
DKIMManipulatie (02)Een cryptografische handtekening over het bericht — elke wijziging onderweg breekt hem.
DMARCSpoofing (03)Vertelt ontvangers wat te doen als SPF/DKIM falen. Alleen p=reject blokkeert echt; daarnaast krijgen we rapportages over wie ons domein misbruikt.
MTA-STSAfluisteren (01), MITM (04)Verklaart “versleuteling is verplicht voor mijn domein” — een gestripte verbinding faalt in plaats van te degraderen.
DANEMITM (04)Legt het verwachte certificaat vast in DNSSEC-ondertekende DNS, zodat een vervalst certificaat wordt geweigerd.
TLS-RPTBlinde vlekkenDagelijkse rapportage over mislukte TLS-verbindingen — zo merken we dat er een aanval of misconfiguratie speelt.
S/MIME · PGP01 + 02, end-to-endVersleutelt en ondertekent het bericht zelf, niet alleen het transport. Voor de kleine set echt kritieke stromen.
The board-level point: all of the above are DNS records and mail-server configuration. Cost is engineering hours, not licences. The real decision is whether we are willing to move DMARC to p=reject and MTA-STS to enforce — the monitoring-only modes cost the same effort and stop nothing. De kern voor de directie: dit zijn allemaal DNS-records en mailserverconfiguratie. De kosten zijn engineeringuren, geen licenties. De echte beslissing is of we DMARC naar p=reject en MTA-STS naar enforce durven te zetten — de monitoring-standen kosten evenveel werk en stoppen niets.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Spoofing needs no access to our systems. Anyone on the internet can try it today, and many do.Spoofing vraagt geen toegang tot onze systemen. Iedereen op internet kan het vandaag proberen, en velen doen dat.

ImpactImpactHighHoog

Invoice and CEO fraud, phishing of customers under our brand, exposure of confidential mail, and legitimate mail landing in spam.Factuur- en CEO-fraude, phishing van klanten onder onze naam, blootstelling van vertrouwelijke mail, en legitieme mail die in de spam belandt.

Residual after controlsRestrisico na maatregelenLowLaag

With DMARC on reject and MTA-STS enforced, spoofing and downgrade are blocked. What remains is a compromised mailbox, which is an identity problem.Met DMARC op reject en MTA-STS op enforce zijn spoofing en downgrade geblokkeerd. Wat overblijft is een gehackte mailbox, en dat is een identiteitsprobleem.

Risk ownerRisico-eigenaarCIO / CFOCIO / CFO

IT owns the DNS records. Finance owns payment verification, which catches what the technology misses.IT is eigenaar van de DNS-records. Finance is eigenaar van de betaalverificatie, die opvangt wat de techniek mist.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

DMARC policy level (none / quarantine / reject) · % of outbound mail passing DMARC · MTA-STS mode (testing / enforce) · TLS-RPT failures per week.DMARC-beleidsniveau (none / quarantine / reject) · % uitgaande mail dat DMARC doorstaat · MTA-STS-modus (testing / enforce) · TLS-RPT-fouten per week.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Spoofing or interception of company email causes payment fraud, phishing of customers under our name and disclosure of confidential correspondence.”“Spoofing of onderschepping van bedrijfsmail veroorzaakt betaalfraude, phishing van klanten onder onze naam en het uitlekken van vertrouwelijke correspondentie.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Basic cyber hygiene, encryption of communication where appropriate, and measures against phishing and impersonation are part of the required risk management measures.Ask suppliers for their DMARC policy. It is public in DNS and takes one lookup to verify, unlike most claims in a questionnaire.A large fraud or a spoofing campaign against customers can be a significant incident with the 24-hour early warning. Intercepted personal data is a GDPR notification within 72 hours.
DORASecure communication and protection of data in transit are part of the ICT risk framework. Email is a channel with clients and with the supervisor.Providers whose email carries your instructions should themselves enforce DMARC. Check before trusting instructions that arrive from them.Payment fraud through spoofed mail may qualify as a major ICT incident with notification to the supervisor. Document detection and response times.
SOC 2Email authentication and transport encryption fall under logical access and communication controls. Auditors expect DMARC and TLS enforcement as evidence.A SOC 2 report rarely tests email authentication explicitly. Check the DNS yourself; it takes a minute.A fraud through spoofed mail is tested as an incident, and weak payment controls can appear as an exception in the report.
ISAE 3402Relevant where email carries payment or financial instructions. The auditor looks at how instructions are authorised, not at the protocol.Look for controls on how instructions are verified, not on how email is sent. The report will not tell you whether their domain can be spoofed.A fraud through spoofed instructions becomes a control failure in the report period and must be disclosed to the user auditors.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Basale cyberhygiëne, versleuteling van communicatie waar passend, en maatregelen tegen phishing en nabootsing vallen onder de verplichte risicobeheersmaatregelen.Vraag leveranciers naar hun DMARC-beleid. Het staat openbaar in DNS en is met één opzoekactie te controleren, anders dan de meeste antwoorden in een vragenlijst.Een grote fraude of een spoofingcampagne richting klanten kan een significant incident zijn met de 24-uurs vroegtijdige waarschuwing. Onderschepte persoonsgegevens zijn een AVG-melding binnen 72 uur.
DORAVeilige communicatie en bescherming van gegevens onderweg maken deel uit van het ICT-risicokader. E-mail is een kanaal met klanten en met de toezichthouder.Leveranciers wier e-mail uw instructies vervoert, moeten zelf DMARC afdwingen. Controleer dat voordat u instructies van hen vertrouwt.Betaalfraude via nagebootste mail kan een ernstig ICT-incident zijn met melding aan de toezichthouder. Documenteer detectie- en reactietijden.
SOC 2E-mailauthenticatie en transportversleuteling vallen onder logische toegang en communicatiebeheersing. Auditors verwachten DMARC en afgedwongen TLS als bewijs.Een SOC 2-rapport test e-mailauthenticatie zelden expliciet. Controleer de DNS zelf; dat kost een minuut.Een fraude via nagebootste mail wordt als incident getest, en zwakke betaalcontroles kunnen als afwijking in het rapport verschijnen.
ISAE 3402Relevant waar e-mail betaal- of financiële instructies vervoert. De auditor kijkt naar hoe instructies worden geautoriseerd, niet naar het protocol.Zoek naar maatregelen voor het verifiëren van instructies, niet voor het verzenden van e-mail. Het rapport vertelt u niet of hun domein na te bootsen is.Een fraude via nagebootste instructies wordt een tekortkoming in de rapportperiode en moet aan de auditors van de klanten worden gemeld.