Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

31–40 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#31
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Did you alter the URL at all? Every phishing test campaign I've seen has a URL in the form of like http://totallylegit.your-company.com/somePath/login?id=12345.... I'd change the id= to some other value before testing to mess with their tracking.

Re: Should Failing Phish Tests Be a Fireable Offense?

#32
post #21

A few years ago I received one of these at work, before I even knew they were a thing. I would have been very annoyed if they'd taken any action against me for following the link in it. The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them. So I did the obvious thing of opening the link in a fr…

Often the phishing training says "do not investigate yourself" but maybe your company missed that part.

Re: Should Failing Phish Tests Be a Fireable Offense?

#33
Honest question: why do so many workplace penalties come with only two levels of punishment?: words ("reprimand") and getting fired. This would be like only having speeding tickets and the death penalty in normal law. Losing part of your bonus for the year would certainly sting enough to provide a disincentive without having to fire anyone.

Re: Should Failing Phish Tests Be a Fireable Offense?

#34
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

That's only true if you have a shitty enterprise email system. On a proper system such spear phishing attempts are blocked before reaching end users, or at least immediately obvious to anyone paying attention.

Re: Should Failing Phish Tests Be a Fireable Offense?

#35

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

I agree that a very strict version of this is too draconian for most workplaces, but depending on the person's role and how many times they've failed a phish test I think it's reasonable to have consequences. For positions where getting phished would be disastrous, something along the lines of a warning or training after the first and second strikes then firing after the third doesn't strike me as exceptionally draconian.

Re: Should Failing Phish Tests Be a Fireable Offense?

#36
post #16

Earlier quoted context omitted.

> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?

From and reply-to looks just like your company unless you catch the misspelling. "l" and "I" in the domain name go to different companies, but when everything else in the email looks just like any other email from IT you aren't going to notice that small difference - you probably won't even read the from/reply lines.

Re: Should Failing Phish Tests Be a Fireable Offense?

#37
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Presumably you were able to explain your case and have the reprimand expunged from your record. As long as they are reasonable in that way I don't think occasionally testing the people handling sensitive data is a bad idea.

Re: Should Failing Phish Tests Be a Fireable Offense?

#39

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

I do not agree. This should also be implemented in financial institutions and any company that has access to overly sensitive information, especially that which you can not easily change or that would put your family at risk of harm.

I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.

Re: Should Failing Phish Tests Be a Fireable Offense?

#40

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.
Post reply on HN