3 ms·
> If you fail, the last page is corporate training on the topic. In my work, the policy is 3 strikes and you are gone. First two fails are trainings with tests
by blntechie 6y ago
> If you fail, the last page is corporate training on the topic.
In my work, the policy is 3 strikes and you are gone. First two fails are trainings with tests and third fail is an instant fireable event. As we work with clients and and their data, this is strictly enforced too.
- Igelau 6y agoSounds like a hellhole. That policy is perfectly tailored for corruption and paranoia.
- gruez 6y ago> That policy is perfectly tailored for corruption Elaborate?
- fargle 6y agoconcur. I do hope that the "well meaning" security team that thought this up is diligent in investigating and accounting for false positives. "Oh, I clicked the link in the fishing email IN A VM to see what the F* it was" and "I entered 'fakeceo' and 'mrpassword123'". People have different methods of exploring and learning to decide if something is legit or not. Nor should any "security policy" should be a 3 strikes zero tolerance policy. Everything needs context. P.S. I'm pretty sure that the mental and behavioral damage done by this 3 strikes policy can easily be weaponized. Shame.
- blntechie 6y agoThat’s the cost of client enforced security policy. I have not known or heard anyone personally fired for this but definitely getting warnings and or getting reassigned their roles.
- perl4ever 6y agoI've never gotten in trouble for missing a phishing test, but everywhere I've worked there are real emails that have all the hallmarks of a phishing one. Like, misspellings, weird domains, etc. So I don't think it's reasonable to punish people, nor it is sufficient to raise awareness. The security people don't address the issue of real emails that look fake that condition people to click on similar things, because obviously it's outside of their area of responsibility and control. Also, what do you do if you have a draconian policy and someone important clicks on one?
- eertami 6y agoI guess that depends if failure is visiting the unique URL they've sent you or actually inputting credentials. I got curious about an obvious internal phishing test and decided copy the link to another machine and see how convincing it was... I hadn't clicked, it wasn't my work machine, and I didn't enter any details - but instantly received an email informing me I'd failed. Yeah right, I obviously haven't done the associated failure training and I will forever refuse to do so out of principle.
- renewiltord 6y agoChrist, what a nightmare.