Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

101–110 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#101

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I had to take a security training class because I failed to report a phishing attempt. Didn’t click the link and likely ignored the email altogether. My boss was confused why they contacted him. I don’t work there anymore.

Re: Should Failing Phish Tests Be a Fireable Offense?

#102
post #83

Earlier quoted context omitted.

The risk of hitting an exploit on the command line, especially with something like wget, is enough orders of magnitude lower that I think it falls under acceptable. The standard cannot be zero risk because that's impossible. Even shutting off the internet link doesn't get you all the way to zero.

The issue isn't how much risk there is in opening it. The problem is that regardless of how much or little risk there is in opening the link, it wasn't op's job to examine it. It was unnecessary risk to open the link.

It's unnecessary to look at something on imgur, too, but that doesn't mean you should get reprimanded if that causes a hack somehow.

Re: Should Failing Phish Tests Be a Fireable Offense?

#103
I was just talking to a coworker yesterday and at his previous job part of his security was to go out to the employee parking lot and dump thumbdrives, if they were plugged into the corporate network they would send a message to the security department on the terminal and user account. I actually said to him, no one would be stupid enough to do that, he told me they did this monthly and at least 2 to 3 people would get caught.

He said employees had training and still failed. No one got fired for it though.

Re: Should Failing Phish Tests Be a Fireable Offense?

#104
post #94
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

Re: Should Failing Phish Tests Be a Fireable Offense?

#105
post #29

Repeat after me: Everyone can be spearphished. I mean it. Everyone.

No I can't be spearphished. Prove me wrong.

Since you are making the more extraordinary claim, you need to provide evidence that your computer usage practices are 100% infallible to sophisticated attacks against you by people who know a lot about you.

Re: Should Failing Phish Tests Be a Fireable Offense?

#106
post #82

Earlier quoted context omitted.

> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...

I'm sure this [reporting spam rather than unsubscribing] happens all the time but it's sort of obnoxious if the email is legit and, especially, if it's a list you requested to get put on at some point.

If you got my email address from a third party, then I do not want to be marketed to.

If you got my email address because I applied for a job, then I do not want to be marketed to.

If you got my email address because I signed up for a service, then I do not want to be marketed to.

If you got my email address because I purchased something, then I do not want to be marketed to.

If you got my email address because someone else "legitimately" entered my email address into your field, then I do not want to be marketed to.

In short: your definition of "legit" likely does not meet my definition of legit. The only email that I deem to be legit is an email that:

1) is @from a domain name that I recognize (walk like a junk, talk like a junk, it's junk) 2) is @from the same domain name as the correspondent (no third party bulk email or proxies; eg mailchimp et al) 3) does not have a no-reply@ as the reply-to address (I must be able to talk to a human) 4) does not hyperlink to third party domains (from@domain must match hyperlinked domain text)

Any legitimate email outside of those parameters are specially treated with liberal amounts of filtering.

Re: Should Failing Phish Tests Be a Fireable Offense?

#107
post #90

Earlier quoted context omitted.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

I nearly fell for a real fishing link once recently, due to changes that have been made by our IT department. Firstly all external senders have the mail reformatted with a red bar at the top and some text, and secondly all hyperlinks are forced through a proxy, which makes it effectively impossible to know what the URL is from the email. I'd received a (rare to my work account) fishing email and I was about to click…

I hate the mimecast URL-hiding. I think it makes me less secure (but may make the totally not paying attention more secure).

Re: Should Failing Phish Tests Be a Fireable Offense?

#108
Depends on what you're doing, but if your employees are dangerously gullible, of course firing them should be on the table if they (especially repeatedly) exercise that gullibility, and it is not feasible to give them tools to mitigate that risk (like PGP, though that's not perfect either).

My general approach is to create computing environments which make it generally impossible to send/receive general communications, and access sensitive information (or the web), at the same time on the same machine. The communication channels available to an agent while accessing a customer file are heavily sanitized, and the environment does not allow for opening links; images are transcoded in fresh containers on a remote machine with no general access to the database or the internet.

The real question is: do many businesses understand the risks well enough to make that determination well?

Re: Should Failing Phish Tests Be a Fireable Offense?

#109
My company uses similar tests - you get a random email and if you click on the link you're required to take some training. One of the things they emphasize is to ensure the actual URL seems legitimate, or is pointing to a company domain if the email claims to be from within the company. Ditto for the From field.

Recently there were reports of an active shooter on site. Everyone got email alerts about it. Many (most?) employees ignored the alert because the From address was an unknown external domain. Fortunately there wasn't an active shooter (although the person who was arrested was armed).

And then the company sent out an email asking us not to ignore those types of emails even if it appears to be a phishing attempt.

I think from now on, just for the heck of it, I'll click on the links but modify some of the characters in the URL. Hopefully someone else in my/some company will be notified that they need training.

Re: Should Failing Phish Tests Be a Fireable Offense?

#110
post #101

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I had to take a security training class because I failed to report a phishing attempt. Didn’t click the link and likely ignored the email altogether. My boss was confused why they contacted him. I don’t work there anymore.

They failed you for a negative result to such a test?

I agree, this should only be for 'positive' results (getting hooked).

Post reply on HN