Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

241–250 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#241

Earlier quoted context omitted.

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

If the company handles this correctly, the intern should feel empowered to tell the CEO to get a visitor badge.

It’s also a safety issue. In a building evacuation, you should be able to account for every employee or visitor.

Re: Should Failing Phish Tests Be a Fireable Offense?

#242
post #134

Earlier quoted context omitted.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. This seems pretty minor by comparison. I wouldn’t expect any physical force to be used. If asking politely doesn’t work, call security. If they threaten you into letting them in, comply, then call security.

> We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting.

We don't actually. All sane employers have them record and report the incident and not engage, because petty shoplifting isn't worth somebody getting shot and it's built into the margins anyway. If the store is big enough, they may have "loss prevention", who are people who are very much not tiny and will verbally engage the shoplifter and pretend to be scary, but they are also not allowed to engage physically, because again, it's not worth somebody getting shot, and liability is going to be a nightmare even if they were stealing.

Re: Should Failing Phish Tests Be a Fireable Offense?

#243
post #193
post #56

Earlier quoted context omitted.

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

> b) Does the phishing test service detect if the link is accessed via a sandboxed env? In any company likely to be doing phishing testing internally, there are two kinds of people who might try this. One is the infosec group, which isn't going to do this because they're running the test. The other is engineers who think they're clever and are equipped to fsck around with things. The former are professionals. The lat…

I wouldn't classify the majority of "Blue teams" I've worked with as professional. I'm currently dealing with a new Infosec group at my company that thinks the CEH is a high quality cert, that doesn't understand how open relays can be a problem, and believe that everything Qualys spits out is the word of God. I feel sorry for the CSO we just hired, but he's not much better, and a classic example of why "CSO" often stands for Chief Sacrificial Officer.

Re: Should Failing Phish Tests Be a Fireable Offense?

#244
post #233

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

It might be easier to try detection (and embarrassing alarms) instead of physical prevention. For example, floor sensors could detect when multiple sets of feet are enter on the same activation. Granted, they might not know the difference between one person and a handcart versus two people where one is in a wheelchair, but I doubt many would-be infiltrators would draw attention to themselves that way.

[deleted]

Re: Should Failing Phish Tests Be a Fireable Offense?

#245
As the article implies, absolutely not, and obviously so. Do not make enemies of your own staff, a hostile workplace is exploitable, not to mention unpleasant and demotivating.

My god are people bad at security. Security people especially so. Actual security is not bound to the mechanics of securing things. It is bound entirely to risk. Did you just fire the best accountant your company has because they were too focused on solving your huge tax liability to notice a phishing attempt. Risk.

Everyone is fallible including your IT security group. If phishing attacks are actually causing appreciable damage to your company, it's the security group who needs replacing. Can they report quantitatively how much more value your organization has captured with it's 90 day password replacement policy, and does it account for all the passwords written on post-it notes laying round, and the productivity impact of constant forgotten passwords?

The purpose of security is to mitigate the risk of loss, but so is insurance. Don't fixate on the machinery of security, and don't fire people for poor email filtering who's value is not to filter emails.

Re: Should Failing Phish Tests Be a Fireable Offense?

#246
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

On the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines. Not destroying the company through your own neglig…

>all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing

A problem here is that a company whose leadership is receptive to your argument would probably already have mandated some form of security/phishing training. The ones who are likely to fall victim to these problems are the same types who do not plan for this stuff to begin with, and also would not be receptive to your hypothetical argument, imo. (e.g. "I don't have time for thought exercises, how many performance bugs have you fixed this week!?")

The path to victory is far more often along the lines of teaching your leadership to care for themselves about security, rather than trying to beat them over the head with heavy-handed hypotheticals of doom and gloom if they don't listen to you and do what you say. They need to feel it in their bones themselves. Otherwise you're never going to get cultural buy-in from the rest of the organization.

Re: Should Failing Phish Tests Be a Fireable Offense?

#247
post #68

Earlier quoted context omitted.

Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.

Considering that from what I recall Lynx doesn't execute javascript, it would have to be one esoteric zero-day

Lynx has still had remote code execution CVEs in the past. It's probably a smaller attack surface than a regular browser, but far from nonexistent.

Re: Should Failing Phish Tests Be a Fireable Offense?

#248
In my experience, gullibility has little to do with innate intelligence and is rather correlated with how much trait neuroticism you have (ie distrust of other people/the world). So in a sense if you were to fire the most gullible employees you might be inadvertently be selecting for neuroticism, which you may not want (unless you're in a very security oriented business where that could be a useful trait)

Re: Should Failing Phish Tests Be a Fireable Offense?

#249
post #75

Earlier quoted context omitted.

That seems okay though, since it's also behavior you'd want if real phishing emails were coming in.

No. Because the department that has advance warning of internal tests will be unlikely to be the first targeted by real phishing emails.

This doesn't seem like much of a reason to try and dissuade employees from discussing these things though.

I think there are probably a great many sysadmins, security analysts, and ciso's who can only dream of a day when run-of-the-mill employees are having casual conversations about phishing and identity security at the office.

Re: Should Failing Phish Tests Be a Fireable Offense?

#250

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.
Post reply on HN