Should Failing Phish Tests Be a Fireable Offense?
221–230 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#222In one way, it's pretty easy to answer: if firing offenders results in real costs from successful phishing efforts decreasing more than the cost of hiring and training people and any side effects from worse morale... then yes.
But unless you're working with state/military secrets where lives could be at risk, or on the security teams of financial institutions where a mistake could lose tens of millions of dollars...
...then probably not.
Re: Should Failing Phish Tests Be a Fireable Offense?
#223Re: Should Failing Phish Tests Be a Fireable Offense?
#224I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
"No tailgating" can be supported through decent vetted entrances and exits.
"No phishing" could have mailserver and mail client support to properly flag the origin of emails and/or enforce "no remote loading" or "restrict html" or "check attachments" sorts of things
Re: Should Failing Phish Tests Be a Fireable Offense?
#225However, if there are staff that repeatedly fail these tests and receive constant training, then that's a question for the business in how willing they are to accept the risk.
Given that there are tools that can quite often successfully block these types of emails before they get to the end user. Most often when we are crafting these emails we need to ask the IT teams to unblock the domain.
In my opinion I think in most cases no, however depending on the industry and the strike rate you might have a case for it at some point.
Re: Should Failing Phish Tests Be a Fireable Offense?
#226Earlier quoted context omitted.
Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…
After the incident, he was contacted by the building management, who asked him what happened and warned him not to do it again.
This seems like a reasonable policy since many people would not have thought in advance what to do if a potentially threatening person tries to tailgate.
Re: Should Failing Phish Tests Be a Fireable Offense?
#227Earlier quoted context omitted.
Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…
Re: Should Failing Phish Tests Be a Fireable Offense?
#228Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script kiddie can take a real email from a mainstream brand, "Save As HTML...", change one link, and resend... and snare even sophisticated victims. This BlackHat talk ( https://www.youtube.com/watch?v=Z20XNp-luNA ) shows just how easy it is to phish even users who…
Claiming that a complicated problem involving a lot of humans, that is very much not solved at the moment, can expect to be fully "solved" in 3-5 years stretches my credulity.
I fully expect the next decade to look much like the past several decades, with both sides of the security arms race making incremental adjustments and improvements.
Re: Should Failing Phish Tests Be a Fireable Offense?
#229Earlier quoted context omitted.
If you got my email address from a third party, then I do not want to be marketed to. If you got my email address because I applied for a job, then I do not want to be marketed to. If you got my email address because I signed up for a service, then I do not want to be marketed to. If you got my email address because I purchased something, then I do not want to be marketed to. If you got my email address because someo…
Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.
You are incorrect and interpreting my comments very narrowly.
Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if businesses don't like that: tough shit. My world doesn't revolve around your business. If that means that the business relationship ends right there, then I'm better off for it.
Re: Should Failing Phish Tests Be a Fireable Offense?
#230Earlier quoted context omitted.
You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.
It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."