Earlier quoted context omitted.
You politely say swipe your badge. If they refuse you walk over and get physical security. No need to physically challenge anyone.
Swiping on an already-unlocked door is meaningless.
Should Failing Phish Tests Be a Fireable Offense?
271–280 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#272I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
If tailgating is that big of a deal, especially for the defense industry, then they need to install man traps at the entrances. Make tailgating physically impossible. It's unreasonable to expect, say, a smaller female employee to stop a larger male who she only realizes is tailgating her after she's already swiped her badge. If physical employee is that important, install physical security or have guards. Plenty of i…
Re: Should Failing Phish Tests Be a Fireable Offense?
#273The fortune 50 company I work for sends out what I must consider the stupidest phishing test emails I've seen. They are blatantly simplistic and transparent. I have had this fantasy of trying to see if I could trick the IT people who send them with a phishing attempt. It would involve perhaps reporting that my virus scanner had reported something suspicious in an email to get them to open something. Or maybe register…
Re: Should Failing Phish Tests Be a Fireable Offense?
#274Earlier quoted context omitted.
If tailgating is that big of a deal, especially for the defense industry, then they need to install man traps at the entrances. Make tailgating physically impossible. It's unreasonable to expect, say, a smaller female employee to stop a larger male who she only realizes is tailgating her after she's already swiped her badge. If physical employee is that important, install physical security or have guards. Plenty of i…
I don't think any company's policy requires every employee to physically stop the tailgater. It would be enough that she e.g. alert security to the situation.
Re: Should Failing Phish Tests Be a Fireable Offense?
#275Earlier quoted context omitted.
The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.
"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.
Re: Should Failing Phish Tests Be a Fireable Offense?
#276Earlier quoted context omitted.
There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?
Curiosity killed the cat. But you can't stop curiosity. I wonder how many such phishing e-mails a company gets a day. If the volume is not that high and it's something manageable by the (proper) security team, I wonder if a company could implement a policy where the employee can report a phishing e-mail to the security team and get to sit with them to watch them investigate. If that's not possible, maybe have the sec…
from: jim.bob.sales@bigcompony.com
"hey cindy it's bob your bosses boss boss. I forgot my password and have a MAJOR presentation coming up. Can you give me yours for login so i can see our powerpoint?"
Re: Should Failing Phish Tests Be a Fireable Offense?
#277Earlier quoted context omitted.
Since you are making the more extraordinary claim, you need to provide evidence that your computer usage practices are 100% infallible to sophisticated attacks against you by people who know a lot about you.
No I don't have to do that. The onus isn't on me. I don't know where you came up with such a silly idea.
There's a con out there for everyone just like there's a lid for every pot.
Re: Should Failing Phish Tests Be a Fireable Offense?
#278Earlier quoted context omitted.
Should it be expunged though? They've indicated they were aware it was quite clearly a phishing attempt, but they still accessed the link. If the test was to see if a user would try accessing the link, then this user failed the test. Why should that be expunged? Curiosity shouldn't preclude security, and intent shouldn't preclude policy if the operator operated knowingly. This isn't to attack maxk42, but to engage th…
> intent shouldn't preclude policy Oh boy, I hope I never work in this kind of organization.
Re: Should Failing Phish Tests Be a Fireable Offense?
#279Earlier quoted context omitted.
90 days? Our security team forces us to change every personal password every month!
Point them to NIST's new guidance on mandatory password changes.
... by George W. Bush...
... in 2004 (Homeland Security Presidential Directive 12, HSPD-12).
Even Google has recently given up on passwords.
Re: Should Failing Phish Tests Be a Fireable Offense?
#280Earlier quoted context omitted.
> b) Does the phishing test service detect if the link is accessed via a sandboxed env? In any company likely to be doing phishing testing internally, there are two kinds of people who might try this. One is the infosec group, which isn't going to do this because they're running the test. The other is engineers who think they're clever and are equipped to fsck around with things. The former are professionals. The lat…
I wouldn't classify the majority of "Blue teams" I've worked with as professional. I'm currently dealing with a new Infosec group at my company that thinks the CEH is a high quality cert, that doesn't understand how open relays can be a problem, and believe that everything Qualys spits out is the word of God. I feel sorry for the CSO we just hired, but he's not much better, and a classic example of why "CSO" often st…
A good infosec group is a wonderful thing. It's unfortunate that you don't have one.