4 ms·
In all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a g
by skeaker 3mo ago
In all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a genuine attack is not pretty. Of course a simulated attack will be indecent and discourteous in nature, that is how attacks are.
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- deepsun 3mo agoNot necessarily WILL. I've seen awesome attackers who were mostly checkbox spreadsheet clerks. Friendly, methodical, boring, expert.
- wjnc 3mo agoYeah, this is a part about itsec I don’t understand in my firm. They run social engineering tests, but never notify management when individuals fail, only in general terms. While being psyopped needs to be activelly discussed among coworkers imho.
- garbagewoman 3mo agoAssigning individual blame is missing the point of improving the security culture in general
- hypfer 3mo agoYes and no. Yes in general, because usually it's culture and not an individual failing. No in specific situations, because it's not just culture but also some people are just the weakest link. Only focusing on either of these while ignoring the other is going to lead to bad results.
- quantummagic 3mo agoDo you hold that same opinion for the training and testing of pilots and surgeons? Do you want to step on a plane with a pilot who is only there because we are too nice to assign individual blame for his inability to do the job properly? Do you want to be going into open heart surgery in a system that dismisses the idea of individual blame when analyzing the outcomes associated with each surgeon? Having no idea if the man cutting into you, has previously had great outcomes or poor outcomes?
- scratcheee 3mo agoYou’re both imagining different scenarios. Scenario 1: 20% of staff tested failed. Individual targeting is pointless because the issue is systemic. This has happened in aviation, it’s common for accident investigators to conclude that the entire company culture (or even the entire industry) has failed to handle a problem. They don’t waste time in cases like this pointing at individuals. Scenario 2: you test very regularly and nobody fails the tests. Except Bob, he fails the tests. In this scenario, your threat analysis document will recommend retraining, firing, or restricting Bob specifically. Scenario 2 almost never happens because nobody has data that good. If your sampling frequency or ability to conduct tests are limited, no specific sample is enough to cover the entire problem. If you focus on a punishing (or just re-educating) the 20% who failed then your next test will fail for (potentially) 20% of the 80% who weren’t retrained, and thus didn’t learn anything. TLDR: you need to choose the approach based on the situation, but we collectively tend to treat security poorly enough that we’re almost never in the fortunate situation where scenario 2 fits.
- dmos62 3mo agoThat's because susceptibility to attacks is a question of training. What would the goal of placing individual blame be? Shame? Drive them to seek training outside work? Further, if you periodically single out people, the organization will hate you.
- vasco 3mo agoShame works for me. If I was ever the one that got sniped and my colleagues saw it I'd forever be paranoid about it. Like when my dad sat me down and told me that I couldn't keep losing hats all the time when I was a kid and that I wasn't a baby anymore and it was expensive, and that shame made me look behind me when I leave somewhere until today and stop losing stuff. Specially for security, yes, shame the personal in a small setting, shame them in a positive way, as in lets all learn from this, but shame is very powerful. Much more powerful than saying "someone in this team failed this" and everyone thinks it was the other guy.
- hypfer 3mo agoI think people saw that old culture and thought "man, that's horrible. We must never do that". And the assessment was right, but also wrong. Previously, shame (and other pressure) was just applied without first empathically inspecting why the node was acting in the way it did, thinking that just enough force will surely solve the problem. It kinda did, but with lots of collateral. Essentially, the security consultants (and everyone else involved) were just being lazy and not doing their job correctly. But now we have this overcorrection, because people are still lazy and do not want to do their job correctly, which leads to the systems failing in a different way. ___ The solution would be to understand the individual node and apply the correct corrective measure. This can be shame, but it might also not be. And the level of it is also highly dependent on the situation. This is a hard problem to solve, but it needs to be solved for good results. The problem here being that scaling that up is hard, but everything needed to hyperscale. With either the individual nodes or the system integrity picking up the slack.
- stymaar 3mo ago
- cucumber3732842 3mo agoBecause 99.99% of the industry is not about improving the end state. It's about covering ass. Same as accounting, safety, environmental, and every other compliance industry.
- cindyllm 3mo ago[dead]
- thrownthatway 3mo ago[dead]