Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

11–20 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#11
post #6

Yes, the security team should be fired since they failed in the educational aspects of their job.

We still issue speeding tickets instead of firing everyone at the DMV.

Educate all you want; no consequences, no behavior change. Incentives matter. Employee opsec metrics should be a part of corporate cybersecurity insurance pricing IMHO.

Re: Should Failing Phish Tests Be a Fireable Offense?

#13

I have a client in the banking industry who performed these tests. Everyone failed. I'm not sure if they ran them again but there's a point where you need to sit someone down and explain how serious the situation is. If they still don't get it, you should probably fire them or transfer them to a department that isn't vulnerable.

It's possible to both get it and still be fooled.

Re: Should Failing Phish Tests Be a Fireable Offense?

#14
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> Are people really so gullible & trusting?

Yes, and it is not a “bad” thing outside the niche of security I think. We should all hope to live a life where we can implicitly trust other human beings.

Re: Should Failing Phish Tests Be a Fireable Offense?

#15
post #6

Yes, the security team should be fired since they failed in the educational aspects of their job.

This is a good point, and I think there are parallels to other areas of the industry.

For instance, let's say I'm a junior developer and I'm told that merging code that fails a suite of unit tests is a serious offense.

If I one day forget to run the test suite and merge code that breaks stuff ... it might be my fault at an acute level.

But at an organizational level, someone should be saying, "If it's that important to not merge code that breaks tests ... then we should change our process so you _cannot_ merge code until all tests have passed."

And if nobody gets faulted at the organizational level, then the junior dev is really just a scapegoat.

Re: Should Failing Phish Tests Be a Fireable Offense?

#16
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?

Re: Should Failing Phish Tests Be a Fireable Offense?

#17
I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in other industries don't have to give many fucks about, like security. If you don't care enough about security that you click on obvious phishing emails then you're not doing your job. Don't do your job and get fired.

They also did have a reporting system. Presumably you wouldn't get a strike if you clicked and reported. People who reported "legitimate" phishing attempts were rewarded. Spear phishing is a totally different game and nobody in their right mind would fail people for clicking on a (well crafted) spear phishing email.

Re: Should Failing Phish Tests Be a Fireable Offense?

#18
I think it's very case by case. On first fail of a phishing test, absolutely not. They should have phishing explained to them again, maybe in a more personal setting (instead of educational video/talk).

It's definitely true that anyone can be spearphished or can fall for a sophisticated enough phishing scheme, but if someone is continually failing the most basic phishing tests (responding to random emails asking for your password for example) I think that's grounds for firing.

It's akin to locking up after you leave. Is it a fireable offence to fail to lock up the office when you leave? Probably not the first time. But if you never lock the door, at some point it becomes a liability. Sure a professional could break in even if you lock the front door, but it's not like locking up is pointless.

Re: Should Failing Phish Tests Be a Fireable Offense?

#19
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

The tests I have seen are more like a macro enabled office document attatched to an email that says it is from an address actually on the corporate email server. And it has a line like "review my schedule update, a week less for test creation is fine right?". Except I don't work with the sender and the corporate firewall as marked as having actually been sent from outside.

Re: Should Failing Phish Tests Be a Fireable Offense?

#20
Proportional to the degree of damage that can be done by the employee in question... yes, absolutely. If you have the responsibility and authority to disburse millions of dollars to a random bank account number, then you've got a high degree of responsibility not to be spear-phished, and it would be a disqualification if you are unable to resist it.

On the other hand, firing a front-line call center employee because they failed the spear-phishing tests is fairly pointless and more damaging than helpful.

Where exactly the line falls would be up to the business and like so many things, involves too many factors to be reasonable to discuss here. With the typical concentrations of power and authority in a business, it's only going to be the minority of employees that would be faced with termination for this problem, because only a minority will have the power to do significant damage to the business in general.

I think it's not too difficult to think that the article is mostly talking about the situations where it isn't proportional to the degree of damage that can be done by the employee.

Post reply on HN