Earlier quoted context omitted.
Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…
> I'm the only person in the entire world with the encryption keys to provision the product The chaos that surrounds you, the facts that astound you, at last your number has found you, your bus number is one.
Should Failing Phish Tests Be a Fireable Offense?
251–260 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#252In my office we can get into trouble for this. However, they always send a magic header in the email to get through the firewall. My solution: filter out emails with the header.
What if a spearphisher is watching out for the test emails on one account and we lose the magic headers that bypass the firewall? What then???
Re: Should Failing Phish Tests Be a Fireable Offense?
#253Earlier quoted context omitted.
I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.
It might be easier to try detection (and embarrassing alarms) instead of physical prevention. For example, floor sensors could detect when multiple sets of feet are enter on the same activation. Granted, they might not know the difference between one person and a handcart versus two people where one is in a wheelchair, but I doubt many would-be infiltrators would draw attention to themselves that way.
Re: Should Failing Phish Tests Be a Fireable Offense?
#254Earlier quoted context omitted.
Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…
Maybe that's how it is at your big organization. I'm sure glad my big organization is different.
But when your big org is hiring, let me know :)
Re: Should Failing Phish Tests Be a Fireable Offense?
#255I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…
There is no point in badging an unlocked door, or in expecting people to do so. You have to actually close it between entries. This is a physically and socially ridiculous thing to do with traditional doors; if it's what you want, you need a turnstile.
Re: Should Failing Phish Tests Be a Fireable Offense?
#256Earlier quoted context omitted.
The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.
The City does not want to be sued by the estate of someone cut in half by a turnstile gate. This limits the available force and material strength. The specifications for those gates almost certainly include a requirement that they allow a sufficiently determined person through without breaking themselves, and probably sound an audible alert.
Re: Should Failing Phish Tests Be a Fireable Offense?
#257Earlier quoted context omitted.
It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."
If the company handles this correctly, the intern should feel empowered to tell the CEO to get a visitor badge. It’s also a safety issue. In a building evacuation, you should be able to account for every employee or visitor.
Re: Should Failing Phish Tests Be a Fireable Offense?
#258Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…
90 days? Our security team forces us to change every personal password every month!
Re: Should Failing Phish Tests Be a Fireable Offense?
#259Earlier quoted context omitted.
That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…
You politely say swipe your badge. If they refuse you walk over and get physical security. No need to physically challenge anyone.
Re: Should Failing Phish Tests Be a Fireable Offense?
#260Earlier quoted context omitted.
We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. This seems pretty minor by comparison. I wouldn’t expect any physical force to be used. If asking politely doesn’t work, call security. If they threaten you into letting them in, comply, then call security.
> We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. We don't actually. All sane employers have them record and report the incident and not engage , because petty shoplifting isn't worth somebody getting shot and it's built into the margins anyway. If the store is big enough, they may have "loss prevention", who are people who are very much not tiny and will verbally e…