Earlier quoted context omitted.
There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?
Worry about CSS-based exfil. https://www.mike-gualtieri.com/posts/stealing-data-with-css-... The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).
Should Failing Phish Tests Be a Fireable Offense?
151–160 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#152Earlier quoted context omitted.
If I’m curious I’ll open the link off the company network. Easiest way I can think of is just opening with a browser on my private iPhone while on a 4G connection.
It would still trigger the fail. Typically the link contains an identifier and the landing page is hosted on a public facing web server.
It would also be interesting to hear whether someone actually considers me to have failed anything when visiting a (faux) attacker’s link on my own device off the company network and entering no credentials.
Re: Should Failing Phish Tests Be a Fireable Offense?
#153Earlier quoted context omitted.
Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.
My job is not investigating phishing but security is everyone's job. Reporting what was obviously a targeted phishing attack to the people who do investigate phishing is a basic expectation. Now before you try to tell me "well you should've forwarded the email and been done with it" those guys are going to be pissed as fuck if I pass along every spam link trying to sell me boner pills, so I've got a duty to make sure…
I know you say the team would be pissed, but it's actually the exact opposite! Firstly, most sophisticated companies have automated the abuse inbox management process, but even when it's not automated, I'd rather 100 easily ignorable reports about boner pills than one person not send an actual spear-phishing email. Plus we can use the generic spam reports to better train our spam filters so please do keep sending them, even the Nigerian prince stuff.
Re: Should Failing Phish Tests Be a Fireable Offense?
#154Earlier quoted context omitted.
No I can't be spearphished. Prove me wrong.
Since you are making the more extraordinary claim, you need to provide evidence that your computer usage practices are 100% infallible to sophisticated attacks against you by people who know a lot about you.
Re: Should Failing Phish Tests Be a Fireable Offense?
#155Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…
Re: Should Failing Phish Tests Be a Fireable Offense?
#156BUT, if you INSIST on thinking about things at that level instead of just firing your employees who surely must be stupid idiots who hate security: one small thing my company did was to make a browser extension that shows emails from internal addresses in a different color than emails from outside the company.
Re: Should Failing Phish Tests Be a Fireable Offense?
#157Earlier quoted context omitted.
That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…
You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.
My employer recognizes this and uses mantraps to physically prevent tailgating at unguarded entries.
Re: Should Failing Phish Tests Be a Fireable Offense?
#158Earlier quoted context omitted.
> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.
I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.
That way they’ll also protect themselves against an external vendor that gets used to spearphish you.
Re: Should Failing Phish Tests Be a Fireable Offense?
#159Earlier quoted context omitted.
Many people don't get a bonus. If you have no benefits, an hourly wage, and no path for advancement, the only thing they can do is whine or fire you.
Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.
Re: Should Failing Phish Tests Be a Fireable Offense?
#160Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…
then throw in all the people excluded from being judged and it can affect morale to where people get ambivalent about other security issues.