3 ms·
This is how I approach it at work (a non-profit where we deal with sensitive data). Every new employee and volunteer goes through a 30-minute training webinar o
by cmg 7y ago
This is how I approach it at work (a non-profit where we deal with sensitive data). Every new employee and volunteer goes through a 30-minute training webinar on security when they start: spotting phishing emails, choosing good passwords, 2FA etc.
At the end, I tell them that if something just feels off, even if they can't figure out why, I'd rather they call or message me on Slack than ignore it. It absolutely never bothers me when they do it - in fact, it makes me feel better. Maybe 1% of reports are actual issues, but I'd rather deal with 99% false positives than miss even one thing.
- bradknowles 7y agoI’ve seen the kind of videos that FAANGs require their new employees to watch. Not good. Even scarily bad. If you are at a FAANG, then the phish success rate against your company is probably in the mid single digit percentages. If you’re at a Fortune 50 company, then the phish success rate against your company is most likely in the high single digit percentage range — if you’re lucky. If you’re at a company not big enough to be in the Fortune 50, then the phish success rate at your company is most likely in the double digit percentage range. That’s right, over 10% of all phishing messages sent to people in your company will end up hooking their targets. And the sad thing is that we techies are the ones that are supposed to be most aware of these things and most likely to be able to protect against them.