Write Up:
Statewide, MoDOT maintains thousands of computer devices. Keeping those computers safe from outside threats is a 24-hour responsibility using the latest security measures.
For the first quarter of fiscal year 2025, MoDOT received a total of 3,897 emails containing malicious content (links and/or attachments) that were delivered to user inboxes. Of those 3,897 delivered emails, 15 recipients clicked on the links or attachments. Among those 15 clicks, six were blocked at the time of the click while the remaining nine were permitted. Of the nine permitted clicks, six were identified as false positives, the remaining three links were re-written to launch in an isolated browser protecting the end user.
First quarter FY 2025 saw the largest number of malicious emails delivered to user inboxes since this measure began in FY 2017. The previous high was 2,288 malicious emails delivered in the last quarter of FY 2024. Out of the 91 days in this quarter, there were only 23 days when MoDOT did not receive a malicious email directly to the user's inbox. The majority of these emails came from two large campaigns with a scattering of smaller campaigns, just five threat actors were involved.
MoDOT continues to emphasize cybersecurity and provide training for all department computer users. The cybersecurity oversight team works to define areas of vulnerability and deploy solutions to address risk. In addition, MoDOT utilizes the Office of Administration’s network firewall services, endpoint cybersecurity detection and remediation services to provide increased cyber protection.
Purpose of the Measure:
This measure reports MoDOT's average click rate on malicious email links and attachments. Using this measure, MoDOT can compare performance to previous quarters and make adjustments in the security training program to reflect the observed trend.
Measurement and Data Collection:
The incident data for this measure is captured from MoDOT's e-mail security platform.
The target for this measure is zero clicks.
Result Driver
Todd Grosvenor
Title
Financial Services Director
Department
Financial Services
Contact Info
Email: Todd.Grosvenor@modot.mo.gov
Phone: (573) 751-4626
Email: Todd.Grosvenor@modot.mo.gov
Phone: (573) 751-4626
Measurement Driver
Isaac Lee
Title
Lead Information Systems Technologist
Department
Information Systems
Contact Info
Email: Isaac.Lee@modot.mo.gov
Phone: 573-751-2158
Email: Isaac.Lee@modot.mo.gov
Phone: 573-751-2158