5 ms·
Very interesting read, can't emphasise enough how important _practicing_ for security is as opposed to mere education. A couple of folks I went to Uni with laun
by jrudolph 8y ago
Very interesting read, can't emphasise enough how important _practicing_ for security is as opposed to mere education. A couple of folks I went to Uni with launched a startup that helps companies conduct automated phishing awareness training and continuous employee sensibilisation by sending "white-hat" phishing emails: IT-Seal https://www.it-seal.de/en.html https://www.it-seal.de/en.html
I can highly recommend giving it a try. The first few levels of difficulty are easy to spot, but it's been eye opening for me how sophisticated phishing emails can get.
- gukov 8y agoKevin Mitnick's KnowBe4 does it too.
- wpietri 8y agoI worked at one place that sent a fake phishing email in the employee's first month, and I loved it. I wish they had kept it going, though, doing random re-tests. It reminds me of the luggage-scanner technology Threat Image Projection: https://www.rapiscansystems.com/en/products/rapiscan-threat-image-projection https://www.rapiscansystems.com/en/products/rapiscan-threat-... Basically I think there's an optimum frequency window for humans detecting and responding to problems. Once real occurrences drop below that frequency, we need to supplement with simulations. Fire drills are the obvious example, but I think we could use a lot more of it.
- CaptainZapp 8y ago"It reminds me of the luggage-scanner technology Threat Image Projection" Yeah, thanks to those I once was asked what that huge hypodermic needle is doing in my hand luggage. I didn't really have a clue and it disappeared, when they scanned it for the second time. It was an European airport with reasonable security scanners so overall it was a quite funny experience.
- wpietri 8y agoHah! As I understand it, machines with TIP have a button they're supposed to press as soon as they see a threat. Then any fake threats go away. Weird that they didn't do that in your case.
- CaptainZapp 8y agoMaybe there was such a button and they rescan it anyway? After all they have to ensure that there's no other dodgy stuff in there, which may have been obscured by the imposed image.
- andai 8y agoI hide my real gun behind the fake one.
- jedberg 8y ago> by sending "white-hat" phishing emails I hate those tests. I've been doing anti-phishing work since before the term was coined, and I fail every one of those tests. Why? Because I load up a virtual env and click on every link in them to see how good of a phish it is. I suspect this is a problem limited to a very small set of people, but none the less, it's annoying when our head of security comes over and says, "shouldn't you know better?"
- ericpauley 8y agoIn my experience (at a large institution) these phishing tests haven't flagged a user until personal info was actually entered, or some other vulnerable action was taken. Seems like there would be so many false positives otherwise.
- jedberg 8y agoMaybe they’ve gotten better since I started ignoring them. But back in the day they flagged you the moment you clicked.
- holdmywaffles 8y agoAs a security goon, you get pretty detailed reporting on who did what with the email... but you have to decide what to do with it. Punishing and mocking people doesn't work. A good head of security should be _excited_ for someone who's interested in digging deeper. There's a lot of talk in our field about outreach for security-minded devs and sysadmins (usually called a security champion program).
- fjsolwmv 8y agoHow many times in your life has that happened? Why don't you enjoy the opportunity to show off your cleverness to head of security?
- zw123456 8y agoThe company I am currently working for is doing those and they are making it fun for the employees keeping score and doing prizes, people are actually having fun with it. Kind of a cool approach I think, and it seems to be working too.