Love it when someone falls for phishing, gives away their login, and just… says nothing. Really helpful.
I’ve been told off for reporting phishing attempts:
- Real: “Why did you receive it?!” Dunno mate. Woke up this morning and decided that I wanted it. We all have total control over what email we get sent, right?
- Fake: “This Isn’t a phishing attempt! What’s wrong with you?!” The From domain, the link domain both look suspicious, and the SMTP headers are dodgy AF. Should I have FAFO and then reported it after the fact?
- Test: “Why are you reporting this? It’s the test phish we commissioned!” You do realise that you’re meant to do some work, right? Sure, you paid someone to safely phish staff, but that also means following up on it’s effects.
Damned if you do, damned if you don’t. And manglement gaze at their navels wondering why incidents don’t get reported… 😬
When the reward for reporting an incident is more work then people won’t report
Remember that many know nothing about security and might not realize that pop up is a real problem
True. Additionally, some might be embarrassed or too afraid to report an incident.
True but I believe that ignorance is a much more common problem.
Source: not an IT person and ignorant of stuff
On don’t give a shit bc they are external employees and have no interest in the company… why bother?
“External Employees” sounds like a term that was invented purely to avoid paying people adequate wages or benefits.
Contractors tend to get way higher pay in exchange for a lack of benefits like guaranteed employment. I’d be surprised if security gives them the same level of trust as normal employees though.
Depends I guess. Some are definitely not hurting. Others are starving. But none are giving a shit for sure.
I don’t think it’s helpful at all! 😳🙃🫠