Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

121–130 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#121
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

I rather like my buildings' set up for this—

We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through.

So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

Re: Should Failing Phish Tests Be a Fireable Offense?

#123

Earlier quoted context omitted.

Many people don't get a bonus. If you have no benefits, an hourly wage, and no path for advancement, the only thing they can do is whine or fire you.

Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.

I'm pretty sure something like phone banks (in or out-bound) are filled with low-skill workers whose credentials would be valuable to data thieves.

I've worked low wage jobs for the Government and Private Industry where we were hit with ransomware and phishing attacks. I think you are underestimating how many workers are really in that position. I'm not sure if you're American, but it's very common in America.

Re: Should Failing Phish Tests Be a Fireable Offense?

#124
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

On the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines.

Not destroying the company through your own negligence should be basic standard practice. Repeatedly failing a phishing test even when given proper security education (like PhishMe provides) is negligence that can destroy an entire company.

I worked in security at a company where the IT security department didn't report up the IT chain but was under HR alongside the Internal Audit department. Enforcing policy and holding people accountable were fundamental expectations of our managers all the way up, no different than someone repeatedly harassing a coworker or watching porn at work.

Re: Should Failing Phish Tests Be a Fireable Offense?

#126
post #56

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

>Does the phishing test service detect if the link is accessed via a sandboxed env?

Does it really matter? I used to play these games with my org's absurdly obvious phishing trainers, but the truth is it's not my job to determine whether an apparent phishing email is genuine or not. If you know that getting phished is a fireable offense, then just don't access the links, obvious fake or not.

Re: Should Failing Phish Tests Be a Fireable Offense?

#127
post #104
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

I would think such a building is not (or should not be) considered high security.

Re: Should Failing Phish Tests Be a Fireable Offense?

#128
I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable.

I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close to indistinguishable from a legit email as you want.

In my experience these "phish-your-employees" programs have 2 side effects, both possibly unwanted:

1. Reluctance to even look in Outlook for fear of getting a drive-by. I know these haven't shown up in a while, but Outlook is a strange beast. That is, I'm just not going to look for, or even open, emails. 2. Enthusiastic reporting of false positives. After getting burned by a decent phish, I reported a few legit emails, including one that had a salutation of "Dear Joe User:" or something equally generic and stupid, but was a genuine email. There's sort of a Poe's Law in the relationship between phish and real emails. This wastes security staff's time. Or maybe you want that. They tend to be a bit weird and annoying.

Re: Should Failing Phish Tests Be a Fireable Offense?

#129
post #80

Earlier quoted context omitted.

That's not very fair. Browser exploits are a lot rarer than phishing.

I don't think background noise of broad, low-effort phishing emails can be directly compared to a more focused attack. If you work somewhere with interesting data the odds of a good phishing attack leading to an exploit could be much higher because you're being specifically targeted and they're not going to send the message until they have a current exploit ready (probably hoping to get it in before your IT departmen…

If someone had a working browser exploit, wouldn't they just deliver it to their targets via an ad network?

AFAIK most enterprises don't mandate ad blocking or noscript.

Re: Should Failing Phish Tests Be a Fireable Offense?

#130
post #74

I see this a lot as a security guy. There has to be a healthy medium. Users can be fired, sure, but this should be a last resort. It's not really fair to say "you're fired" when you don't have DKIM/SPF/DMARC, you haven't tagged external emails as such, you haven't provided here awareness training, you have provided training but not in a gradual form (ie. From Nigerian prince emails right the way through to sophistica…

Your organization becomes more secure if people aren't afraid of revealing their mistakes. Seriously, you should give people who fail phishing tests cupcakes and additional future phishing tests. If there is a continued failure or inability to learn then there is a problem to be fixed perhaps with firing. Cultures of fear breed disaster.

>give people who fail phishing tests... additional future phishing tests

This usually happens, especially if they're using something like PhishMe. If you fail the phishing test, you're immediately told you were tricked, and scheduled for mandatory training within a few days. After you complete the training you're put on a re-targeting list.

What we're talking about isn't firing someone for making a mistake. It's firing someone for gross negligence over and over again even when given proper training and incentives. At some point it becomes clear that the employee is a danger to the company. If they're that careless with their emails even after getting caught and going through training, what else are they neglecting to do? And who might be injured/killed because they don't care?

Post reply on HN