# Four Corporate Email Oversights That Put Your Organization at Risk
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-03-14
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Risks of Using Work Email: A Security Concern
Meta Description: Learn from CTO Morey Haber about the potential security implications of using your work email for personal communications and transactions, and find out how to
URL: https://financedigest.com/four-corporate-email-oversights-that-put-your-organization-at-riskhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/beyond-trust-1736839092812-compressed.jpg)

_Author:_ **_Morey Haber,_** _CTO, BeyondTrust_

As part of onboarding,new hires typically sign an employee handbook which includes policies and guidelines for acceptable information technology usage. Within the details, are often policy restrictions regarding unacceptable usage for email. Typically, these policies state that email should only be used for official [company business](https://www.financedigest.com/5-saas-tools-to-help-your-company-business-save-money-in-2022.html "5 SaaS Tools To Help Your Company/Business Save Money in 2022") correspondence,and not for personal communications.

![Morey Haber, CTO, BeyondTrust](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/morey-450x450-1736839092840-compressed.jpg)

Morey Haber, CTO, BeyondTrust

If you travel frequently for work, or are responsible for purchasing merchandise or services for your employer, is it acceptable to use your work email address, or should you use your personal email to complete the transaction?

This question, and the aftermath of your departure from an organization, can create a complicated [situation and security](https://www.financedigest.com/factors-contributing-to-negligent-security-situations.html "Factors Contributing To Negligent Security Situations") risk that most employers are completely ignoring. And, unfortunately, theyhave no way to manage or [mitigate the potential risk](https://www.financedigest.com/mitigating-operational-risk-through-centralising-reconciliation.html "MITIGATING OPERATIONAL RISK THROUGH CENTRALISING RECONCILIATION").Consider these real-life [scenarios that organizations are facing](https://www.financedigest.com/factbox-possible-scenarios-as-italys-government-faces-collapse.html "Factbox-Possible scenarios as Italy’s government faces collapse") today:

**Using corporate email accounts as login for travel services**

An employee [creates an account on an airline’s website using the corporate email address](https://www.financedigest.com/how-to-create-a-professional-email-address.html "How to Create a Professional Email Address"). This address is used for authentication into the service and to book [flights or other travel](https://www.financedigest.com/chinas-international-flight-suspensions-leave-travellers-stranded-hurt-businesses.html "China’s international flight suspensions leave travellers stranded, hurt businesses") arrangements.

_Potential security implications_

After their employment is finished, any notifications or [future bookings for flights are tied to the suspended business](https://www.financedigest.com/surgical-equipment-market-high-trend-opportunities-offers-future-business-growth-by-2030.html "Surgical Equipment Market High Trend Opportunities Offers Future Business Growth by 2030") email account. If your [organization auto-forwards the email to a peer](https://www.financedigest.com/six-reasons-why-digital-world-classtm-finance-organizations-outperform-peers.html "Six Reasons Why Digital World ClassTM Finance Organizations Outperform Peers") or a manager, then an identity theft threat vector has now been created. A co-worker now receiving the former employee’s emails can simply select “Forgot password” and own the former employee’s account. This is especially true if the account is not further [protected by security questions or additional](https://www.financedigest.com/antimicrobial-protection-additives-for-adhesives-market-incredible-possibilities-growth-analysis-and-forecast-to-2028.html "Antimicrobial Protection Additives for Adhesives Market Incredible Possibilities, Growth Analysis And Forecast To 2028") two factor authentication. If verification is tied back to the same email address, then it is game over once they have a confirmation link.

_Recommendation_

The most security-conscious [way to handle this scenario is for an organization](https://www.financedigest.com/the-medical-tourism-market-is-estimated-to-substantiate-i-e-grow-at-a-handsome-rate-in-upcoming-years-the-present-day-scenario-implies-the-adoption-of-smarter-ways-to-do-business-as-such-digital.html "The Medical Tourism Market to get filtered through organic digitized growth") to enforce the use of an approved corporate travel service for booking flights, hotels, cars, etc. in lieu of allowing employees to book travel on their own and using a corporate email account. If the [business permits bookings outside of a corporate service](https://www.financedigest.com/philanthropy-is-an-underrated-tool-for-growing-financial-services-businesses.html "Philanthropy Is an Underrated Tool for Growing Financial Services Businesses"), allow and recommend individuals to use their personal email accounts for booking travel—even if they pay with a corporate credit card. After all, it is their account.

**Email address formats**

Most organizations have an email address schema. Typical formats include first initial last name or first name dot last name.

_Potential security implications_

What happens when an employee leaves the organization and a new employee starts with the same name or initial combination? The new employee potentially receives all email of the former employee even if it not slated for them. Depending on the new employee’s role, the email may not be remotely appropriate (such as when PII and financials are involved) for them to receive. [Organizations that continue to grow](https://www.financedigest.com/jewelry-organizer-market-is-expected-to-grow-at-a-cagr-of-approximately-over-2022-2030.html "Jewelry Organizer Market is expected to grow at a CAGR of Approximately Over 2022-2030") will have a higher statistical likelihood of overlap for names and initials.

_Recommendation_

Organizations should never reuse email addresses from former employees for new personnel. Consider adding numbers like “01” to the end of new email addresses to avoid this problem in the future.

**Using corporate email accounts for** [payment gateways](https://www.financedigest.com/online-payment-gateway-market-to-witness-a-cagr-of-10-3.html "Online Payment Gateway Market to witness a CAGR of 10.3%")

Some organizations allow for the purchase of merchandise and [services through common payment platforms](https://www.financedigest.com/choosing-the-best-digital-experience-platform-dxp-in-financial-services.html "Choosing the best Digital Experience Platform (DXP) in financial services"), like PayPal or Apple Pay. These are necessary for some employees (such as [marketing team](https://www.financedigest.com/frameplay-announces-new-attention-metric-in-video-game-environments-validated-in-partnership-with-dentsus-attention-economy-team-by-first-to-market-studies.html "Frameplay Announces New Attention Metric in Video Game Environments, Validated in Partnership with dentsu’s Attention Economy Team by First-to-Market Studies") members) to perform their job functions.  However, none of these platforms should be setup with a user’s corporate email address. If they [need to use a business](https://www.financedigest.com/pstn-isdn-switch-off-what-businesses-need-to-know.html "PSTN/ISDN switch-off: what businesses need to know ") email address, create a group or alias for these services.

_Potential security implications_

Just as with the air travel example in the first scenario, a [personal account used for services](https://www.financedigest.com/personalizing-the-workforce-experience-in-financial-services.html "Personalizing the Workforce Experience in Financial Services") can be leveraged against the individual if they leave and have no access to change their email address.

_Recommendation_

For these types of situations, it is recommended to use a dedicated account name for authentication, as opposed to an email address. This option allows the account owner to [change the email address,but does present additional risk if the account is shared](https://www.financedigest.com/entrepreneur-investor-dale-w-wood-shares-how-he-is-using-his-funds-to-create-change.html "Entrepreneur & Investor Dale W Wood Shares How He Is Using His Funds to Create Change"). Former employees using shared accounts for payment [services underscore the ongoing](https://www.financedigest.com/how-can-financial-services-strike-back-in-the-ongoing-skills-crisis.html "How can financial services strike back in the ongoing skills crisis?") risk of inadequate privileged access controls and the threats of shared accounts.

**Using corporate accounts for personal email**

Some employees use personal email for group-based personal correspondence, such as for their [children’s school](https://www.financedigest.com/mobile-school-offers-hope-to-nomad-children-in-chad.html "Mobile school offers hope to nomad children in Chad").

_Potential security implications_

Once an employee departs the organization, the receiver of forwarded email is now potentially exposed to highly personal information, and potentially in violation of some local regulations.

_Recommendation_

Corporate email addresses should always remain strictly delegated to [business usage—and never for personal communications](https://www.financedigest.com/business-texting-an-essential-communication-tool.html "Business Texting: An Essential Communication Tool"). The results can present some interesting legal ramifications, especially if removal of the address from a group is not trivial.

Today, the boundaries of work and personal spheres continue to blend and blur—providing benefits (work flexibility, higher productivity, etc.) for both employers and employees—but not without [cyber risks](https://www.financedigest.com/automated-cyber-risk-quantification-saving-the-insurance-industry.html "Automated Cyber Risk Quantification: Saving the Insurance Industry"). [Completely strict policies of corporate](https://www.financedigest.com/verasity-completes-major-corporate-rebrand-and-releases-new-website.html "Verasity Completes Major Corporate Rebrand and Releases New Website") email usage will only introduce more risk as employee turnover occurs and our dependence on electronic communication continues.

[Organizations have embraced policies like Bring Your Own Device](https://www.financedigest.com/the-medical-device-technologies-market-to-stick-around-based-on-organic-expansion.html "The Medical Device Technologies Market to stick around based on organic expansion") (BYOD) for mobile device support and should consider allowing personal emails addresses for exactly the same reasons. Acceptable email usage policies [need](https://www.financedigest.com/why-ev-charging-stations-need-to-accept-open-cashless-payments.html "Why EV Charging Stations Need to Accept Open Cashless Payments ") to clearly state when personal usage is acceptable, should be implemented, and when it creates unnecessary risk due to employee termination.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

