I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
Should Failing Phish Tests Be a Fireable Offense?
101–110 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#102Earlier quoted context omitted.
The risk of hitting an exploit on the command line, especially with something like wget, is enough orders of magnitude lower that I think it falls under acceptable. The standard cannot be zero risk because that's impossible. Even shutting off the internet link doesn't get you all the way to zero.
The issue isn't how much risk there is in opening it. The problem is that regardless of how much or little risk there is in opening the link, it wasn't op's job to examine it. It was unnecessary risk to open the link.
Re: Should Failing Phish Tests Be a Fireable Offense?
#103He said employees had training and still failed. No one got fired for it though.
Re: Should Failing Phish Tests Be a Fireable Offense?
#104Earlier quoted context omitted.
I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…
Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
Re: Should Failing Phish Tests Be a Fireable Offense?
#105Repeat after me: Everyone can be spearphished. I mean it. Everyone.
No I can't be spearphished. Prove me wrong.
Re: Should Failing Phish Tests Be a Fireable Offense?
#106Earlier quoted context omitted.
> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...
I'm sure this [reporting spam rather than unsubscribing] happens all the time but it's sort of obnoxious if the email is legit and, especially, if it's a list you requested to get put on at some point.
If you got my email address because I applied for a job, then I do not want to be marketed to.
If you got my email address because I signed up for a service, then I do not want to be marketed to.
If you got my email address because I purchased something, then I do not want to be marketed to.
If you got my email address because someone else "legitimately" entered my email address into your field, then I do not want to be marketed to.
In short: your definition of "legit" likely does not meet my definition of legit. The only email that I deem to be legit is an email that:
1) is @from a domain name that I recognize (walk like a junk, talk like a junk, it's junk) 2) is @from the same domain name as the correspondent (no third party bulk email or proxies; eg mailchimp et al) 3) does not have a no-reply@ as the reply-to address (I must be able to talk to a human) 4) does not hyperlink to third party domains (from@domain must match hyperlinked domain text)
Any legitimate email outside of those parameters are specially treated with liberal amounts of filtering.
Re: Should Failing Phish Tests Be a Fireable Offense?
#107Earlier quoted context omitted.
> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.
I nearly fell for a real fishing link once recently, due to changes that have been made by our IT department. Firstly all external senders have the mail reformatted with a red bar at the top and some text, and secondly all hyperlinks are forced through a proxy, which makes it effectively impossible to know what the URL is from the email. I'd received a (rare to my work account) fishing email and I was about to click…
Re: Should Failing Phish Tests Be a Fireable Offense?
#108My general approach is to create computing environments which make it generally impossible to send/receive general communications, and access sensitive information (or the web), at the same time on the same machine. The communication channels available to an agent while accessing a customer file are heavily sanitized, and the environment does not allow for opening links; images are transcoded in fresh containers on a remote machine with no general access to the database or the internet.
The real question is: do many businesses understand the risks well enough to make that determination well?
Re: Should Failing Phish Tests Be a Fireable Offense?
#109Recently there were reports of an active shooter on site. Everyone got email alerts about it. Many (most?) employees ignored the alert because the From address was an unknown external domain. Fortunately there wasn't an active shooter (although the person who was arrested was armed).
And then the company sent out an email asking us not to ignore those types of emails even if it appears to be a phishing attempt.
I think from now on, just for the heck of it, I'll click on the links but modify some of the characters in the URL. Hopefully someone else in my/some company will be notified that they need training.
Re: Should Failing Phish Tests Be a Fireable Offense?
#110I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
I had to take a security training class because I failed to report a phishing attempt. Didn’t click the link and likely ignored the email altogether. My boss was confused why they contacted him. I don’t work there anymore.
I agree, this should only be for 'positive' results (getting hooked).