5 ms·
Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative conseque
by Trisell 7y ago
Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team.
This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days. Just wait until their “games” are the reason for people getting fired. This is a guaranteed way to get your users to not only not want to help you. But actively work against you. And if enough people scream the C ring will eventually listen. And I don’t think the security team will win.
- Consultant32452 7y agoWhen a new phishing test goes out everyone in my department announces to everyone else to watch out for it. So it's a bonding experience of the non-security people against the security people.
- smelendez 7y agoThat seems okay though, since it's also behavior you'd want if real phishing emails were coming in.
- btilly 7y agoNo. Because the department that has advance warning of internal tests will be unlikely to be the first targeted by real phishing emails.
- Benjammer 7y agoThis doesn't seem like much of a reason to try and dissuade employees from discussing these things though. I think there are probably a great many sysadmins, security analysts, and ciso's who can only dream of a day when run-of-the-mill employees are having casual conversations about phishing and identity security at the office.
- 4ntonius8lock 7y agoIt's silly to do it inhouse. It creates distrust. That is why you pay consultants. They send out the phishing test, and hopefully regular people bond with the security people in an effort to pass it. I mean, after all, security and regular people in the company should want the same thing (company success... which implies not giving away things to phishing probes)
- pbhjpbhj 7y agoYes, you don't want to create an environment in which people don't want to ask IT/opsec people for help for fear they will be getting themselves in trouble.
- freehunter 7y agoOn the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines. Not destroying the company through your own negligence should be basic standard practice. Repeatedly failing a phishing test even when given proper security education (like PhishMe provides) is negligence that can destroy an entire company. I worked in security at a company where the IT security department didn't report up the IT chain but was under HR alongside the Internal Audit department. Enforcing policy and holding people accountable were fundamental expectations of our managers all the way up, no different than someone repeatedly harassing a coworker or watching porn at work.
- Benjammer 7y ago>all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing A problem here is that a company whose leadership is receptive to your argument would probably already have mandated some form of security/phishing training. The ones who are likely to fall victim to these problems are the same types who do not plan for this stuff to begin with, and also would not be receptive to your hypothetical argument, imo. (e.g. "I don't have time for thought exercises, how many performance bugs have you fixed this week!?") The path to victory is far more often along the lines of teaching your leadership to care for themselves about security, rather than trying to beat them over the head with heavy-handed hypotheticals of doom and gloom if they don't listen to you and do what you say. They need to feel it in their bones themselves. Otherwise you're never going to get cultural buy-in from the rest of the organization.
- perl4ever 7y ago"Not destroying the company through your own negligence should be basic standard practice. Repeatedly failing a phishing test even when given proper security education (like PhishMe provides) is negligence that can destroy an entire company." The issue is that people are trained and required to ignore warning signs most of the time, so it is impossible to crack down too harshly. Employees by definition do not really care about destroying the company, because they do not own it and can walk away if they like. So the company does not have unlimited leverage over them.
- orthoxerox 7y ago90 days? Our security team forces us to change every personal password every month!
- Shivetya 7y agoWell lest we forget that some companies only pursue those who management at some level wants out. Many times negative consequence campaigns are just used to hide real intent. then throw in all the people excluded from being judged and it can affect morale to where people get ambivalent about other security issues.
- c3534l 7y agoI'm capable of not clicking on random links in email. I'm not cognitively capable of remembering dozens of passwords and then "forgetting" them (i.e. memorizing that the password you previously memorized is not the password any more). And then throw in the fact that schemes like that also don't work.