Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

351–357 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#351

Earlier quoted context omitted.

This can be equalized by having a perk or bonus on reporting phishing attacks to IT. Anything from casual Friday (for offices that are not relaxed wear) to a Starbucks card or whatever. IMHO the act of timely reporting the click on a phishing email should negate the email click penalty. The idea is make the wanted behavior pleasurable and the unwanted ones painful.

> This can be equalized by having a perk or bonus on reporting phishing attacks to IT. ...there is no way you can equalise "you're going to lose your job" with anything less than "we're going to give you enough money that you won't really need the job anymore." And with a Starbucks card or casual Friday? I'm not even sure if you're being serious, because that sounds like a joke.

I was trying to make the case that you can give perks for natural reporting to IT (passive and active) + ensure that a user that has acted on a phishing email that reports it in a timely manor is treated as a non-fail (at least at some level).

Both of these things together leave a system in place where:

users are highly penalized for failing a phish test (or real life phishing attempts)

User's that fail the test (or real phishing attempt), but follow it with a timely notice have less pain.

Users that notify on apparent phishing attempts get small rewards.

That does not seem like a joke to me.

Re: Should Failing Phish Tests Be a Fireable Offense?

#352
post #343

Earlier quoted context omitted.

This definitely needs to be considered. I open WSL and use curl on suspicious looking email links. I've been logged as doing so before. I'd hate for that log to actually go somewhere significant.

It might be worth considering carefully how safe the practice of opening essentially random email links might be. Are you opening the links with a full suite of forensic measures in place, or are you dropping curl $URL into your terminal on your workstation? It looks like WSL isn't exactly a sandbox. It does seem to already be used by some malware: https://research.checkpoint.com/beware-bashware-new-method-m... In a…

One of the best policies I ever witnessed: There was a second guest network with internet and nothing else for guests/consultants and facebook/twitter/porn (the company just paid for internet twice). Employees had a second crappy machine connected to the isolated guest network for this purpose.

Re: Should Failing Phish Tests Be a Fireable Offense?

#353

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

Very arguably, transit (literally) free-ridership isn't a problem.

Nuisance riders are: disturbing peace, damaging proprty, assaulting passengers or staff.

Police behaviour, not fares.

(And have social and justice systems which can effectively deal with individuals in need of help or discipline / isolation.)

Re: Should Failing Phish Tests Be a Fireable Offense?

#354
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

You can wave any object at the sensor. Maybe an unauthorized tag will yield a different beep or make the light flash a different color. Maybe the person in front of you will be in a position to see the light on the reader, maybe they'll notice, and maybe they'll consider it odd. Getting that far, and then actually deciding to challenge you or report it, is a vanishingly small chance. There is no point in badging an u…

That´s exactly what I have at work, and it does deter tailgating.

Some people do ask for the owner of a badge to do a second pass but security always appears at that point.

Re: Should Failing Phish Tests Be a Fireable Offense?

#355

Earlier quoted context omitted.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

If the company handles this correctly, the intern should feel empowered to tell the CEO to get a visitor badge. It’s also a safety issue. In a building evacuation, you should be able to account for every employee or visitor.

Reminds me of Roger Federer being denied entry:

https://www.msn.com/en-us/sports/tennis/not-so-fast-roger-fe...

Rules are rules in Australia, even if you are a 20-times Grand Slam champion and one of the most recognizable people on the planet.

Roger Federer found that out this week when he was blocked access to a locker room at the Australian Open by a security guard who took his job very seriously.

A video circulating Twitter on Saturday showed the Swiss double defending champion stalled at the entrance for lacking his tournament accreditation.

Re: Should Failing Phish Tests Be a Fireable Offense?

#356

Earlier quoted context omitted.

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

I do not agree. This should also be implemented in financial institutions and any company that has access to overly sensitive information, especially that which you can not easily change or that would put your family at risk of harm. I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.

At a financial institution I worked for, they had a separate entrance with separate badges and alarms for the really sensitive stuff.

I only entered that area once, as I was a low-level programmer.

It was also the only company where I never ever made a query on the production server :) (I worked for another financial institution on a more senior role and I did have scary access to the production DB).

Re: Should Failing Phish Tests Be a Fireable Offense?

#357
post #149

Earlier quoted context omitted.

A company I worked for just had revolving doors for all entrances

Some revolving door systems (not the ones you mean, probably) actually improve a lot on the classic turnstiles or gates. They allow one authorized person to pass from one side through but sensors on both sides can easily detect if another person is trying to piggy back from the other side of the door. And there's no way over or around them. In higher security environments where unauthorized persons getting on the oth…

That's exactly the ones that I mean :)
Post reply on HN