Earlier quoted context omitted.
It is absolutely unreasonable to get fired by putting your life in danger to stop trailgaters. There are essentially three types of tailgaters, people who belong there, tourists, and nefarious across. People who belong there are just getting lazy, but it is OK. Tourists you can stop (these are people who might be guests, or are just curious) but these people aren't bad people, and most lonely wing do any harm. Then t…
>The ones who are there for a bad reason, and I'm supposed to stop them? You can contact security, presumably a company with such a policy has 24/7 on site security.
Should Failing Phish Tests Be a Fireable Offense?
291–300 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#292I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
How could you ever possibly know that?
Re: Should Failing Phish Tests Be a Fireable Offense?
#293Earlier quoted context omitted.
I do not agree. This should also be implemented in financial institutions and any company that has access to overly sensitive information, especially that which you can not easily change or that would put your family at risk of harm. I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.
Like the sibling comment, I think it all should depend on the roles of the people as well. You need strict access controls in place to ensure that access rights are well defined such as no/read-only access for certain data in certain environments, physical access control, etc. Someone who does client-facing retail at a financial institution should not have access to production data. As such, them getting phished won'…
Re: Should Failing Phish Tests Be a Fireable Offense?
#294Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…
On the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines. Not destroying the company through your own neglig…
Re: Should Failing Phish Tests Be a Fireable Offense?
#295Our (large) company recently had a sort of big (we think) leak of internal source code from a GitHub Enterprise server - done by an internal person who DL'ed a bunch of code and put it outside.
Basically no security system in the world would have stopped that, as long as we think the idea of sharing source code internally is a good idea.
So yea - the guns all point out, and if anyone inside your organization ever tries to phish you, there's a good chance you'll never see it coming.
Re: Should Failing Phish Tests Be a Fireable Offense?
#296Earlier quoted context omitted.
The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.
"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.
Re: Should Failing Phish Tests Be a Fireable Offense?
#297Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…
Re: Should Failing Phish Tests Be a Fireable Offense?
#298It also makes no sense to blame users for thinking an email message is from their bank when there is no obvious, visible difference between messages from their bank and messages from criminals.
Re: Should Failing Phish Tests Be a Fireable Offense?
#299I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?
Re: Should Failing Phish Tests Be a Fireable Offense?
#300I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…