Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

151–160 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#151
post #44

Earlier quoted context omitted.

There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?

Worry about CSS-based exfil. https://www.mike-gualtieri.com/posts/stealing-data-with-css-... The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).

Okay, but if I'm not supposed to click on unknown links, why do I even have a web browser installed on my work machine? 99% of the time I'm using it to access unknown and untrusted external websites.

Re: Should Failing Phish Tests Be a Fireable Offense?

#152

Earlier quoted context omitted.

If I’m curious I’ll open the link off the company network. Easiest way I can think of is just opening with a browser on my private iPhone while on a 4G connection.

It would still trigger the fail. Typically the link contains an identifier and the landing page is hosted on a public facing web server.

Yeah - I’d be wary of doing it without changing the parameters for that reason. But obviously you can’t check a link without checking a link.

It would also be interesting to hear whether someone actually considers me to have failed anything when visiting a (faux) attacker’s link on my own device off the company network and entering no credentials.

Re: Should Failing Phish Tests Be a Fireable Offense?

#153
post #116

Earlier quoted context omitted.

Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.

My job is not investigating phishing but security is everyone's job. Reporting what was obviously a targeted phishing attack to the people who do investigate phishing is a basic expectation. Now before you try to tell me "well you should've forwarded the email and been done with it" those guys are going to be pissed as fuck if I pass along every spam link trying to sell me boner pills, so I've got a duty to make sure…

"Now before you try to tell me "well you should've forwarded the email and been done with it" those guys are going to be pissed as fuck if I pass along every spam link trying to sell me boner pills"

I know you say the team would be pissed, but it's actually the exact opposite! Firstly, most sophisticated companies have automated the abuse inbox management process, but even when it's not automated, I'd rather 100 easily ignorable reports about boner pills than one person not send an actual spear-phishing email. Plus we can use the generic spam reports to better train our spam filters so please do keep sending them, even the Nigerian prince stuff.

Re: Should Failing Phish Tests Be a Fireable Offense?

#154
post #105
post #29

Earlier quoted context omitted.

No I can't be spearphished. Prove me wrong.

Since you are making the more extraordinary claim, you need to provide evidence that your computer usage practices are 100% infallible to sophisticated attacks against you by people who know a lot about you.

How do you prove this though? It's the classic "you can't prove a negative" scenario. I have no particular desire to associate this account with my real name or I would post my work email here just to let people try.

Re: Should Failing Phish Tests Be a Fireable Offense?

#155
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

90 days? Our security team forces us to change every personal password every month!

Re: Should Failing Phish Tests Be a Fireable Offense?

#156
Definitely don't bother looking into what you're doing (or not doing) on a structural/organizational level that is causing your employees to fall for potential scams. Just fire them, it's a lot easier that way.

BUT, if you INSIST on thinking about things at that level instead of just firing your employees who surely must be stupid idiots who hate security: one small thing my company did was to make a browser extension that shows emails from internal addresses in a different color than emails from outside the company.

Re: Should Failing Phish Tests Be a Fireable Offense?

#157
post #134

Earlier quoted context omitted.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's also a very tiny edge case that someone is trying to gain improper or unlawful entry to a workplace. It's not my job to put myself at risk in order to stop an intruder. It's not my job to play policy police with my co-workers, either.

My employer recognizes this and uses mantraps to physically prevent tailgating at unguarded entries.

Re: Should Failing Phish Tests Be a Fireable Offense?

#158

Earlier quoted context omitted.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

If that’s the bar, the org should just strip out all external links. Voilà.

That way they’ll also protect themselves against an external vendor that gets used to spearphish you.

Re: Should Failing Phish Tests Be a Fireable Offense?

#159

Earlier quoted context omitted.

Many people don't get a bonus. If you have no benefits, an hourly wage, and no path for advancement, the only thing they can do is whine or fire you.

Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.

I'm a reasonably well paid software engineer in Silicon Valley, but I don't get a bonus or options of any kind. I suppose my employer to could take vacation days from me or not give me a raise next year, but if they did either of those things because I "failed" a phishing test (where "fail" doesn't even involve giving up any credentials) I would probably be looking for a new job anyway so they might as well fire me.

Re: Should Failing Phish Tests Be a Fireable Offense?

#160
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

Well lest we forget that some companies only pursue those who management at some level wants out. Many times negative consequence campaigns are just used to hide real intent.

then throw in all the people excluded from being judged and it can affect morale to where people get ambivalent about other security issues.

Post reply on HN