I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…
Should Failing Phish Tests Be a Fireable Offense?
31–40 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#32A few years ago I received one of these at work, before I even knew they were a thing. I would have been very annoyed if they'd taken any action against me for following the link in it. The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them. So I did the obvious thing of opening the link in a fr…
Re: Should Failing Phish Tests Be a Fireable Offense?
#33Re: Should Failing Phish Tests Be a Fireable Offense?
#34How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?
> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.
Re: Should Failing Phish Tests Be a Fireable Offense?
#35I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.
Re: Should Failing Phish Tests Be a Fireable Offense?
#36Earlier quoted context omitted.
> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.
What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?
Re: Should Failing Phish Tests Be a Fireable Offense?
#37I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…
Re: Should Failing Phish Tests Be a Fireable Offense?
#38Repeat after me: Everyone can be spearphished. I mean it. Everyone.
Re: Should Failing Phish Tests Be a Fireable Offense?
#39I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…
This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.
I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.
Re: Should Failing Phish Tests Be a Fireable Offense?
#40I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…