The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. The perpetra…
> Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. One bank I interned at sent people an email about the weather or something to that extent and each link had a unique identifier. Shaming each individual user is the best way for them to learn.
It's the best way for them to stop trusting the security team and never come in with any issue, even if it could be used as an early signal preventing bigger attack. Many people's jobs rely on them receiving emails from unknown sources and receiving files from them. Shaming them for "you should've known this specific link is bad" is counterproductive. That's even before we get to whether they would actually put in any credentials.
Phishing tests have value. Running them to shame people into compliance is a waste of time.
For better takes, there's a good thread https://twitter.com/hacks4pancakes/status/133487573995560550...