











<p>It also is important for your employees. Many employees may know security is important, but they do not know the extent of the damage that is possible. </p><p>Many orgs try to educate their employees, but many do not get the message. Most people don't think of the consequences of being compromised - either because they don't know how the org is set up in terms of IT or they do not care. And why should they, it's not their job to know about security. </p><p>You can see that the types of training we currently deliver either backfire or just do not show any measurable improvement in security behaviour past 3 weeks or so.<br />Even worse for "embedded training", that landing page that opens after you click on a simulated phishing link. Most people I've talked to receiving these (granted, anecdotal evidence) think of it as a neat little game. Never have I heard "oh I learned from this". It's usually something along "Oh I clicked it again, yikes". </p><p>That's not good. </p><p>So yeah, scams are bad, but they hurt way less than losing your org. And your people usually can imagine the damage of scams, but they cannot imagine the damage phishing can do. </p><p>Don't conflate scams and <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="tag">#<span>phishing</span></a>.</p><p>3/3</p>
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。