5 ms·
I agree with what you are saying, but calling it a people problem makes it harder to solve. If you organization is large enough than your users will always clic
by syoc 5y ago
I agree with what you are saying, but calling it a people problem makes it harder to solve. If you organization is large enough than your users will always click on phishing links and download sketchy malware toolbars.
You should also expect to an lesser extent that your internet facing infrastructure will have vulnerabilities that will be exploited before you are aware of them.
These are facts of life and need to be expected. Not saying that security training is wasted money, but it is in no way a solution to for example phishing. Accept that you will have compromised clients and internet facing servers and start making a strategy with that scenario in mind.