Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

231–240 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#231

I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable. I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close…

> 2. Enthusiastic reporting of false positives

I used to work in a casino that sent out a notice to all employees urging them to report more suspicious activity. There was no information or training given on what specifically to look for.

After some time the initiative was deemed a great success. Although there had been zero improvement in the rate of dangerous activity stopped or prevented, there had been a giant increase in the amount of reports that turned out to be false.

Re: Should Failing Phish Tests Be a Fireable Offense?

#232
post #157

Earlier quoted context omitted.

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's also a very tiny edge case that someone is trying to gain improper or unlawful entry to a workplace. It's not my job to put myself at risk in order to stop an intruder. It's not my job to play policy police with my co-workers, either. My employer recognizes this and uses mantraps to physically prevent tailgating at unguarded entries.

You don’t have to put yourself at any risk, but if you work in a secure facility, you are usually explicitly required by contract to “play policy police”. That is, report any security violation like someone jumping the turnstile, or not having a badge.

Re: Should Failing Phish Tests Be a Fireable Offense?

#233
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

It might be easier to try detection (and embarrassing alarms) instead of physical prevention. For example, floor sensors could detect when multiple sets of feet are enter on the same activation.

Granted, they might not know the difference between one person and a handcart versus two people where one is in a wheelchair, but I doubt many would-be infiltrators would draw attention to themselves that way.

Re: Should Failing Phish Tests Be a Fireable Offense?

#234

Earlier quoted context omitted.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

Good point. My brother was radiated into his condo building in D.C. one night. They robbed the office after he went up to his condo. He didn't feel safe refusing then entry, and knew this was a risk of letting them in. After the incident, he was contacted by the building management, who asked him what happened and warned him not to do it again. This seems like a reasonable policy since many people would not have thou…

[deleted]

Re: Should Failing Phish Tests Be a Fireable Offense?

#235

Earlier quoted context omitted.

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

I guy I worked with fell for one when he was selling his car online, he got an email from an interested buyer (car thief) the linked to a very good replication of the site he was selling it on. The car thief turns up and scouts the location but the give away was that he showed little interest in the car, at which point he went back and checked the email to discover the phishing.

Even trained intelligent people have momentary lapses of concentration. Imagine opening a link from email on your phone then looking away for a second while it loads, but then the address bar has disappeared and you've missed the ssl indicator.

Re: Should Failing Phish Tests Be a Fireable Offense?

#236

Earlier quoted context omitted.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

For the guy that has to clock in at 8:30 and is trying to enter the door at 8:29 it is a huge deal.

Well, there would be need to also be an understanding that tardiness is acceptible if (!) it’s because you were being tailed.

Re: Should Failing Phish Tests Be a Fireable Offense?

#237

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

If tailgating is that big of a deal, especially for the defense industry, then they need to install man traps at the entrances. Make tailgating physically impossible. It's unreasonable to expect, say, a smaller female employee to stop a larger male who she only realizes is tailgating her after she's already swiped her badge. If physical employee is that important, install physical security or have guards. Plenty of important facilities have both.

Re: Should Failing Phish Tests Be a Fireable Offense?

#238

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

If tailgating is that big of a deal, especially for the defense industry, then they need to install man traps at the entrances. Make tailgating physically impossible. It's unreasonable to expect, say, a smaller female employee to stop a larger male who she only realizes is tailgating her after she's already swiped her badge. If physical employee is that important, install physical security or have guards. Plenty of i…

I don't think any company's policy requires every employee to physically stop the tailgater. It would be enough that she e.g. alert security to the situation.

Re: Should Failing Phish Tests Be a Fireable Offense?

#239
post #94
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

You have a duty to at least report what is happening if you are threatened.

Re: Should Failing Phish Tests Be a Fireable Offense?

#240

Earlier quoted context omitted.

Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.

> Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. You are incorrect and interpreting my comments very narrowly. Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if busine…

And, assuming there are clear and reasonable ways to inform them that you don't wish further communications (as there should be with any professional marketing), you should take that route. Otherwise anything is fair game. But I attended an event and got a follow-up email? Calling that spam is mostly being an asshole.
Post reply on HN