Earlier quoted context omitted.
From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.
If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.
Should Failing Phish Tests Be a Fireable Offense?
131–140 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#132Earlier quoted context omitted.
I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.
From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.
Re: Should Failing Phish Tests Be a Fireable Offense?
#133Earlier quoted context omitted.
I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.
...and now we see why such policies are bad, and it's even covered in the article: while people falling for phishing are bad, what's even worse is when they fall for it and don't report. Creating a culture where the security is the enemy is _not_ good. I mean, sure, if it's 20 times, we're getting into outrageous territory and you have reasons to suspect employee is trolling you. But other than that, the reality is t…
Re: Should Failing Phish Tests Be a Fireable Offense?
#134Earlier quoted context omitted.
Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.
It's one thing to say "don't let people tailgate", it's quite another to actually enforce a policy that says that unless you provide proper physical security onsite. During security awareness training I always stress that people know who to notify onsite as well as telling them that they can choose to challenge them directly if they encounter someone tailgating.
Re: Should Failing Phish Tests Be a Fireable Offense?
#135Earlier quoted context omitted.
I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.
Did the link take you to a site that auto-ran malware? Or did it take you to some kind of page that said "login to unsubscribe"? The latter is why password managers can be so valuable. I never type my passwords in so if my auto-fill doesn't activate I immediately become suspicious. If it's the former, it seems like your company must be using an insecure browser or the site was running some kind of 0-day? I never thin…
Re: Should Failing Phish Tests Be a Fireable Offense?
#136Earlier quoted context omitted.
Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.
I'm pretty sure something like phone banks (in or out-bound) are filled with low-skill workers whose credentials would be valuable to data thieves. I've worked low wage jobs for the Government and Private Industry where we were hit with ransomware and phishing attacks. I think you are underestimating how many workers are really in that position. I'm not sure if you're American, but it's very common in America.
Re: Should Failing Phish Tests Be a Fireable Offense?
#137Earlier quoted context omitted.
There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?
Worry about CSS-based exfil. https://www.mike-gualtieri.com/posts/stealing-data-with-css-... The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).
Re: Should Failing Phish Tests Be a Fireable Offense?
#138Earlier quoted context omitted.
I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…
Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
If you’re just trying to ensure only employees are on-site, tailgating is less of an issue (unless somebody got fired but their colleagues were never told).
Re: Should Failing Phish Tests Be a Fireable Offense?
#139I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…
Re: Should Failing Phish Tests Be a Fireable Offense?
#140Earlier quoted context omitted.
I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…
I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.
And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.