Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

291–300 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#291

Earlier quoted context omitted.

It is absolutely unreasonable to get fired by putting your life in danger to stop trailgaters. There are essentially three types of tailgaters, people who belong there, tourists, and nefarious across. People who belong there are just getting lazy, but it is OK. Tourists you can stop (these are people who might be guests, or are just curious) but these people aren't bad people, and most lonely wing do any harm. Then t…

>The ones who are there for a bad reason, and I'm supposed to stop them? You can contact security, presumably a company with such a policy has 24/7 on site security.

Yeah, I'm sure the policy is more or less "confront if you wish, otherwise contact security immediately."

Re: Should Failing Phish Tests Be a Fireable Offense?

#292

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

> Nobody thought this was unreasonable.

How could you ever possibly know that?

Re: Should Failing Phish Tests Be a Fireable Offense?

#293

Earlier quoted context omitted.

I do not agree. This should also be implemented in financial institutions and any company that has access to overly sensitive information, especially that which you can not easily change or that would put your family at risk of harm. I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.

Like the sibling comment, I think it all should depend on the roles of the people as well. You need strict access controls in place to ensure that access rights are well defined such as no/read-only access for certain data in certain environments, physical access control, etc. Someone who does client-facing retail at a financial institution should not have access to production data. As such, them getting phished won'…

In practice there's often a way to escalate privilege. Defense in depth requires that one be good at each layer. Being good against phishing attacks is important even when the victim has apparently-inconsequential access.

Re: Should Failing Phish Tests Be a Fireable Offense?

#294
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

On the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines. Not destroying the company through your own neglig…

So, do the security guys get fired when they misconfigure a firewall or give the wrong settings for a database?

Re: Should Failing Phish Tests Be a Fireable Offense?

#295
One thing to understand about phishing is that it isn't necessarily from outside.

Our (large) company recently had a sort of big (we think) leak of internal source code from a GitHub Enterprise server - done by an internal person who DL'ed a bunch of code and put it outside.

Basically no security system in the world would have stopped that, as long as we think the idea of sharing source code internally is a good idea.

So yea - the guns all point out, and if anyone inside your organization ever tries to phish you, there's a good chance you'll never see it coming.

Re: Should Failing Phish Tests Be a Fireable Offense?

#296

Earlier quoted context omitted.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.

For public transport it makes perfect sense. You don't care about people getting on for free, you care about ticket profits falling because of people getting on for free. If the fine is high enough that they totally cover all the lost profit from people not paying the you are doing well.

Re: Should Failing Phish Tests Be a Fireable Offense?

#297
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

I'm capable of not clicking on random links in email. I'm not cognitively capable of remembering dozens of passwords and then "forgetting" them (i.e. memorizing that the password you previously memorized is not the password any more). And then throw in the fact that schemes like that also don't work.

Re: Should Failing Phish Tests Be a Fireable Offense?

#298
It makes no sense to blame users for doing perfectly normal things like clicking on web links, reading email, opening attachments, reading a memory card, connecting to a wireless network, etc. rather than blaming hardware and software developers for designing systems where perfectly normal actions result in criminals taking over your computer.

It also makes no sense to blame users for thinking an email message is from their bank when there is no obvious, visible difference between messages from their bank and messages from criminals.

Re: Should Failing Phish Tests Be a Fireable Offense?

#299
post #56

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

The env it was accessed in shouldn't matter too much. Simply clicking on a link is a fairly small risk. Not zero risk but unlikely to be an issue. The real issue is when the link you clicked on asks you for a password and you type it in. You should only fail the test for giving a password.

Re: Should Failing Phish Tests Be a Fireable Offense?

#300
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Yes, it does. You should have been let go.
Post reply on HN