Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

221–230 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#222
> Should Failing Phish Tests Be a Fireable Offense?

In one way, it's pretty easy to answer: if firing offenders results in real costs from successful phishing efforts decreasing more than the cost of hiring and training people and any side effects from worse morale... then yes.

But unless you're working with state/military secrets where lives could be at risk, or on the security teams of financial institutions where a mistake could lose tens of millions of dollars...

...then probably not.

Re: Should Failing Phish Tests Be a Fireable Offense?

#224

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I think it's reasonable, but there should also be reasonable common-sense support for these policies.

"No tailgating" can be supported through decent vetted entrances and exits.

"No phishing" could have mailserver and mail client support to properly flag the origin of emails and/or enforce "no remote loading" or "restrict html" or "check attachments" sorts of things

Re: Should Failing Phish Tests Be a Fireable Offense?

#225
I work at a firm that creates and sends these phishing tests for our clients. Prior to doing this type of work we always assess the "tone at the top" regarding the culture of the workplace, to assess the suitability of doing these tests.

However, if there are staff that repeatedly fail these tests and receive constant training, then that's a question for the business in how willing they are to accept the risk.

Given that there are tools that can quite often successfully block these types of emails before they get to the end user. Most often when we are crafting these emails we need to ask the IT teams to unblock the domain.

In my opinion I think in most cases no, however depending on the industry and the strike rate you might have a case for it at some point.

Re: Should Failing Phish Tests Be a Fireable Offense?

#226
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

Good point. My brother was radiated into his condo building in D.C. one night. They robbed the office after he went up to his condo. He didn't feel safe refusing then entry, and knew this was a risk of letting them in.

After the incident, he was contacted by the building management, who asked him what happened and warned him not to do it again.

This seems like a reasonable policy since many people would not have thought in advance what to do if a potentially threatening person tries to tailgate.

Re: Should Failing Phish Tests Be a Fireable Offense?

#227
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

For the guy that has to clock in at 8:30 and is trying to enter the door at 8:29 it is a huge deal.

Re: Should Failing Phish Tests Be a Fireable Offense?

#228

Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script kiddie can take a real email from a mainstream brand, "Save As HTML...", change one link, and resend... and snare even sophisticated victims. This BlackHat talk ( https://www.youtube.com/watch?v=Z20XNp-luNA ) shows just how easy it is to phish even users who…

> The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector...

Claiming that a complicated problem involving a lot of humans, that is very much not solved at the moment, can expect to be fully "solved" in 3-5 years stretches my credulity.

I fully expect the next decade to look much like the past several decades, with both sides of the security arms race making incremental adjustments and improvements.

Re: Should Failing Phish Tests Be a Fireable Offense?

#229

Earlier quoted context omitted.

If you got my email address from a third party, then I do not want to be marketed to. If you got my email address because I applied for a job, then I do not want to be marketed to. If you got my email address because I signed up for a service, then I do not want to be marketed to. If you got my email address because I purchased something, then I do not want to be marketed to. If you got my email address because someo…

Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.

> Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails.

You are incorrect and interpreting my comments very narrowly.

Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if businesses don't like that: tough shit. My world doesn't revolve around your business. If that means that the business relationship ends right there, then I'm better off for it.

Re: Should Failing Phish Tests Be a Fireable Offense?

#230

Earlier quoted context omitted.

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

There’s no need to confront anybody. Just notify security immediately if you see someone go through a security gate without swiping their access card, or if they tailgate you.
Post reply on HN