3 ms·
I was trying to make the case that you can give perks for natural reporting to IT (passive and active) + ensure that a user that has acted on a phishing email t
by wstuartcl 7y ago
I was trying to make the case that you can give perks for natural reporting to IT (passive and active) + ensure that a user that has acted on a phishing email that reports it in a timely manor is treated as a non-fail (at least at some level).
Both of these things together leave a system in place where:
users are highly penalized for failing a phish test (or real life phishing attempts)
User's that fail the test (or real phishing attempt), but follow it with a timely notice have less pain.
Users that notify on apparent phishing attempts get small rewards.
That does not seem like a joke to me.