Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

1–10 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#3
I have a client in the banking industry who performed these tests. Everyone failed. I'm not sure if they ran them again but there's a point where you need to sit someone down and explain how serious the situation is. If they still don't get it, you should probably fire them or transfer them to a department that isn't vulnerable.

Re: Should Failing Phish Tests Be a Fireable Offense?

#4
How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question.

Are people really so gullible & trusting?

Re: Should Failing Phish Tests Be a Fireable Offense?

#5
Nope. Of course not. These opportunistic campaigns use inherent human weaknesses to lure and snare suspecting and unsuspecting users.

Now, if someone is told that official policy states you must only use approved devices and services and you violate that and that introduces additional weaknesses, then yes. But that’s different.

I mean phishing experts in active campaigns get phished. So, regular Jane and Joe? ‘Course not.

Re: Should Failing Phish Tests Be a Fireable Offense?

#7
Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team.

This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days. Just wait until their “games” are the reason for people getting fired. This is a guaranteed way to get your users to not only not want to help you. But actively work against you. And if enough people scream the C ring will eventually listen. And I don’t think the security team will win.

Re: Should Failing Phish Tests Be a Fireable Offense?

#9
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> If you're being asked for data by someone you don't know

That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

Re: Should Failing Phish Tests Be a Fireable Offense?

#10
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

What about an email from someone you know (coworker, relative) via a spoofed or compromised account?
Post reply on HN