Live data from Hacker News

Launch HN: Riot (YC W20) – Phishing training for your team

news.ycombinator.com

41–50 of 93 posts

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#42

How do you differentiate yourself with places like https://www.knowbe4.com/ which offer free services against phishing.

I tried Knowbe4, I think it's a horrible product. I heard once you try the "free service" they call you daily to sign you up for the paid plan.

i used knowbe4 before and I found their product to be very good and easy to use. also i like that they had training videos and assessment tests as part of their packages. i didn't see anything on your site pertaining to this.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#43
post #24

Earlier quoted context omitted.

Definitely worth trying! Just want to help you set expectations. :)

Did you try punitive disincentives?

The company sends out fake phishing emails. The same people keep falling for it... I suppose the outlined punishments are not strictly enforced.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#44
One that is happening in nearly every parish is that scammers are using church bulletins to get the personal info and then sending a "message" from the priest to those people. So while not CEO fraud it is very similar. A great setup and one that you could find a way that you charge when teams are doing the right thing... have the test be free and the training have a cost

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#45
post #24

Earlier quoted context omitted.

Definitely worth trying! Just want to help you set expectations. :)

Did you try punitive disincentives?

A better approach is to turn it into a game: reward those who report suspected phishing emails, security breaches, tailgating into secure areas, USB devices left around, etc. and have red teams doing this stuff periodically. Punitive measures don't really work. Friendly competition with rewards does work, though.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#46
My company uses Knowbe4, and I'm constantly frustrated how it considers it a fail if I only click a link vs entering in credentials. Sometimes it's tough to tell if something is phishing when your checking email on your phone. Does Riot work the same way? Or do you test to see if users notice issues once they've actually opened something in the browser?

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#47
post #41

Seems to be a hot topic recently. I first discovered https://www.hoxhunt.com/ , there are probably some other competitors as well, what makes you different?

I would be interesting in this answer as well. There is actually quite heave competition in this space: PhishMe, PhishLabs, IronScales, MediaPro, KnowBe4, Wombat (acquired by ProofPoint).

What convinced YC to invest in your company?

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#48
I wonder if you can comment on the weirdly pro-phishing behavior of many US banks who, if I didn't know better, appear to be trying hard to make their customers vulnerable to phishing attacks ...

- TIAA Bank redirects customers, after login, to "cibng.ibanking-services.com".

- US Bank, depending on which account you log into will redirect you to "loansphereservicingdigital.bkiconnect.com".

- Union Bank will redirect you to "unionbank.customercarenet.com" if you look at a mortgage account.

These are big, serious US Banks and these domain jumpings (to domains that almost look like parodies of an actual bank domain) occur to every online banking customer.

They are training their customers to be phished.

FWIW, I have never seen Wells Fargo do this ...

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#49
post #2

This is a hot area, but there are already huge competitors. How do you differentiate?

Great question! 1. From Gophish: you need to be technical and you need at least a week off to prepare the attacks. With Riot, you can be sending attacks in a matter of minutes. 2. From Knowbe4, …: those are products made for enterprise companies, that are trying somehow to adapt to smaller companies. Riot is doing the opposite: it was built with smaller companies in mind. Overall, I think there's a huge need today fo…

> Overall, I think there's a huge need today for product-centric cybersecurity companies, where most of the big players are sales-centric companies.

Totally agreed, and I love this. High five from a Techstars 2020 company doing a similar product-first approach to cyber security program planning and implementation for small businesses. We use Webroot as a vendor to supply phishing right now but would love to talk. brian@havocshield.com

Post reply on HN