Should Failing Phish Tests Be a Fireable Offense?(krebsonsecurity.com)
krebsonsecurity.com
Should Failing Phish Tests Be a Fireable Offense?
https://krebsonsecurity.com/2019/05/should-failing-phish-tests-be-a-fireable-offense/
345 comments
Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team.
This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days. Just wait until their “games” are the reason for people getting fired. This is a guaranteed way to get your users to not only not want to help you. But actively work against you. And if enough people scream the C ring will eventually listen. And I don’t think the security team will win.
This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days. Just wait until their “games” are the reason for people getting fired. This is a guaranteed way to get your users to not only not want to help you. But actively work against you. And if enough people scream the C ring will eventually listen. And I don’t think the security team will win.
Phish tests need to be fair to people who actually understand something about security.
"Opening an email" is not actually an issue (spearphishers that sit on drive-by 0-days in current browsers or email programs are not a threat model that most orgs can possibly defend against). Opening attachements is hard to measure and again needs context: What kind of software and sandbox was the attachement opened with? Attackers using some ancient forever-day word processor exploit is realistic. Attackers sitting on fully patched VM outbreaks is unrealistic. If the used VM has unimpeded network access, then the attacker needs no VM outbreak. If the target opens a phish link in a current browser, but then refuses to enter valid credentials (because user is wary), then the user can be argued to have passed the phish test.
If you make failure fireable, then you need to demonstrate that the victim was actually successfully phished.
If failure requires remedial training, then you can afford a high false positive rate: Clueless victims learn not to click on links, and sophisticated "victims" get to talk with a security person about why their action was dangerous or harmless, and in accordance or in violation of policy.
"Opening an email" is not actually an issue (spearphishers that sit on drive-by 0-days in current browsers or email programs are not a threat model that most orgs can possibly defend against). Opening attachements is hard to measure and again needs context: What kind of software and sandbox was the attachement opened with? Attackers using some ancient forever-day word processor exploit is realistic. Attackers sitting on fully patched VM outbreaks is unrealistic. If the used VM has unimpeded network access, then the attacker needs no VM outbreak. If the target opens a phish link in a current browser, but then refuses to enter valid credentials (because user is wary), then the user can be argued to have passed the phish test.
If you make failure fireable, then you need to demonstrate that the victim was actually successfully phished.
If failure requires remedial training, then you can afford a high false positive rate: Clueless victims learn not to click on links, and sophisticated "victims" get to talk with a security person about why their action was dangerous or harmless, and in accordance or in violation of policy.
I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line.
I was promptly informed that I had failed the test and I would be receiving a formal reprimand.
Did that make the company more secure?
I was promptly informed that I had failed the test and I would be receiving a formal reprimand.
Did that make the company more secure?
I see this a lot as a security guy. There has to be a healthy medium. Users can be fired, sure, but this should be a last resort. It's not really fair to say "you're fired" when you don't have DKIM/SPF/DMARC, you haven't tagged external emails as such, you haven't provided here awareness training, you have provided training but not in a gradual form (ie. From Nigerian prince emails right the way through to sophisticated attacks), you're not providing outbound filtering, educational resources or a reporting tool, you've not registered similar domain names or <my company>. otherTLD, sandboxing, AV...
Users know what phishing is, even the most naive of them. You need to do your darndest to make sure nothing gets in to your network first off. If people are repeat offenders then you have to chat with them first off and figure out what's going on . If they're being intentionally obtuse - clicking emails to see what happens even if they know it is phishing - then look into firing them, otherwise just act like you're on the same team, provide them with education but not overwhelming amounts, and it s eems to work has been my experience anyway
Users know what phishing is, even the most naive of them. You need to do your darndest to make sure nothing gets in to your network first off. If people are repeat offenders then you have to chat with them first off and figure out what's going on . If they're being intentionally obtuse - clicking emails to see what happens even if they know it is phishing - then look into firing them, otherwise just act like you're on the same team, provide them with education but not overwhelming amounts, and it s eems to work has been my experience anyway
I think it's very case by case. On first fail of a phishing test, absolutely not. They should have phishing explained to them again, maybe in a more personal setting (instead of educational video/talk).
It's definitely true that anyone can be spearphished or can fall for a sophisticated enough phishing scheme, but if someone is continually failing the most basic phishing tests (responding to random emails asking for your password for example) I think that's grounds for firing.
It's akin to locking up after you leave. Is it a fireable offence to fail to lock up the office when you leave? Probably not the first time. But if you never lock the door, at some point it becomes a liability. Sure a professional could break in even if you lock the front door, but it's not like locking up is pointless.
It's definitely true that anyone can be spearphished or can fall for a sophisticated enough phishing scheme, but if someone is continually failing the most basic phishing tests (responding to random emails asking for your password for example) I think that's grounds for firing.
It's akin to locking up after you leave. Is it a fireable offence to fail to lock up the office when you leave? Probably not the first time. But if you never lock the door, at some point it becomes a liability. Sure a professional could break in even if you lock the front door, but it's not like locking up is pointless.
Proportional to the degree of damage that can be done by the employee in question... yes, absolutely. If you have the responsibility and authority to disburse millions of dollars to a random bank account number, then you've got a high degree of responsibility not to be spear-phished, and it would be a disqualification if you are unable to resist it.
On the other hand, firing a front-line call center employee because they failed the spear-phishing tests is fairly pointless and more damaging than helpful.
Where exactly the line falls would be up to the business and like so many things, involves too many factors to be reasonable to discuss here. With the typical concentrations of power and authority in a business, it's only going to be the minority of employees that would be faced with termination for this problem, because only a minority will have the power to do significant damage to the business in general.
I think it's not too difficult to think that the article is mostly talking about the situations where it isn't proportional to the degree of damage that can be done by the employee.
On the other hand, firing a front-line call center employee because they failed the spear-phishing tests is fairly pointless and more damaging than helpful.
Where exactly the line falls would be up to the business and like so many things, involves too many factors to be reasonable to discuss here. With the typical concentrations of power and authority in a business, it's only going to be the minority of employees that would be faced with termination for this problem, because only a minority will have the power to do significant damage to the business in general.
I think it's not too difficult to think that the article is mostly talking about the situations where it isn't proportional to the degree of damage that can be done by the employee.
A few years ago I received one of these at work, before I even knew they were a thing. I would have been very annoyed if they'd taken any action against me for following the link in it.
The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them.
So I did the obvious thing of opening the link in a fresh, zero data, locked-down VM just to see where it would take me.
I got the message that I was an idiot, and my company also was notified that I'm clueless about information security.
I can only imagine how difficult it might be to explain to someone what I had done, and why I probably shouldn't have to go on some tedious training course let alone be fired. Luckily all I saw was an increase in the number of these emails I received.
The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them.
So I did the obvious thing of opening the link in a fresh, zero data, locked-down VM just to see where it would take me.
I got the message that I was an idiot, and my company also was notified that I'm clueless about information security.
I can only imagine how difficult it might be to explain to someone what I had done, and why I probably shouldn't have to go on some tedious training course let alone be fired. Luckily all I saw was an increase in the number of these emails I received.
Repeat after me:
Everyone can be spearphished.
I mean it. Everyone.
Everyone can be spearphished.
I mean it. Everyone.
I have a client in the banking industry who performed these tests. Everyone failed. I'm not sure if they ran them again but there's a point where you need to sit someone down and explain how serious the situation is. If they still don't get it, you should probably fire them or transfer them to a department that isn't vulnerable.
Nope. Of course not. These opportunistic campaigns use inherent human weaknesses to lure and snare suspecting and unsuspecting users.
Now, if someone is told that official policy states you must only use approved devices and services and you violate that and that introduces additional weaknesses, then yes. But that’s different.
I mean phishing experts in active campaigns get phished. So, regular Jane and Joe? ‘Course not.
Now, if someone is told that official policy states you must only use approved devices and services and you violate that and that introduces additional weaknesses, then yes. But that’s different.
I mean phishing experts in active campaigns get phished. So, regular Jane and Joe? ‘Course not.
Honest question: why do so many workplace penalties come with only two levels of punishment?: words ("reprimand") and getting fired. This would be like only having speeding tickets and the death penalty in normal law. Losing part of your bonus for the year would certainly sting enough to provide a disincentive without having to fire anyone.
Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script kiddie can take a real email from a mainstream brand, "Save As HTML...", change one link, and resend... and snare even sophisticated victims. This BlackHat talk (https://www.youtube.com/watch?v=Z20XNp-luNA) shows just how easy it is to phish even users who think they are too good to be fooled.
At Inky (https://inky.com) we're using a combination of computer vision, anomaly detection, and domain-specific hacks to identify zero-day phishing emails "from first principles" (as I like to say). And it works! But the pushback from the security establishment is impressive. I like to say that there are two widely-held but false beliefs about phishing: 1) phishing is solved; 2) phishing is unsolvable.
The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... but you'd never know it listening to "Security Thought Leaders."
At Inky (https://inky.com) we're using a combination of computer vision, anomaly detection, and domain-specific hacks to identify zero-day phishing emails "from first principles" (as I like to say). And it works! But the pushback from the security establishment is impressive. I like to say that there are two widely-held but false beliefs about phishing: 1) phishing is solved; 2) phishing is unsolvable.
The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... but you'd never know it listening to "Security Thought Leaders."
I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable.
I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close to indistinguishable from a legit email as you want.
In my experience these "phish-your-employees" programs have 2 side effects, both possibly unwanted:
1. Reluctance to even look in Outlook for fear of getting a drive-by. I know these haven't shown up in a while, but Outlook is a strange beast. That is, I'm just not going to look for, or even open, emails. 2. Enthusiastic reporting of false positives. After getting burned by a decent phish, I reported a few legit emails, including one that had a salutation of "Dear Joe User:" or something equally generic and stupid, but was a genuine email. There's sort of a Poe's Law in the relationship between phish and real emails. This wastes security staff's time. Or maybe you want that. They tend to be a bit weird and annoying.
I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close to indistinguishable from a legit email as you want.
In my experience these "phish-your-employees" programs have 2 side effects, both possibly unwanted:
1. Reluctance to even look in Outlook for fear of getting a drive-by. I know these haven't shown up in a while, but Outlook is a strange beast. That is, I'm just not going to look for, or even open, emails. 2. Enthusiastic reporting of false positives. After getting burned by a decent phish, I reported a few legit emails, including one that had a salutation of "Dear Joe User:" or something equally generic and stupid, but was a genuine email. There's sort of a Poe's Law in the relationship between phish and real emails. This wastes security staff's time. Or maybe you want that. They tend to be a bit weird and annoying.
Yes, the security team should be fired since they failed in the educational aspects of their job.
The fortune 50 company I work for sends out what I must consider the stupidest phishing test emails I've seen. They are blatantly simplistic and transparent.
I have had this fantasy of trying to see if I could trick the IT people who send them with a phishing attempt. It would involve perhaps reporting that my virus scanner had reported something suspicious in an email to get them to open something.
Or maybe register mimecastprotection.com, then send out a fake email to IT as if it was a big marketing announcement from Mimecast that "We've changed our name! We are now Mimecast Protection as part of our commitment to serving you!"
My theory is that a really well crafted phishing email is going to be very hard to avoid.
I have had this fantasy of trying to see if I could trick the IT people who send them with a phishing attempt. It would involve perhaps reporting that my virus scanner had reported something suspicious in an email to get them to open something.
Or maybe register mimecastprotection.com, then send out a fake email to IT as if it was a big marketing announcement from Mimecast that "We've changed our name! We are now Mimecast Protection as part of our commitment to serving you!"
My theory is that a really well crafted phishing email is going to be very hard to avoid.
MFA as provided FIDO/U2F seems like a much more sensible approach, that doesn't break down on even a momentary lapse in vigilance.
It makes no sense to blame users for doing perfectly normal things like clicking on web links, reading email, opening attachments, reading a memory card, connecting to a wireless network, etc. rather than blaming hardware and software developers for designing systems where perfectly normal actions result in criminals taking over your computer.
It also makes no sense to blame users for thinking an email message is from their bank when there is no obvious, visible difference between messages from their bank and messages from criminals.
It also makes no sense to blame users for thinking an email message is from their bank when there is no obvious, visible difference between messages from their bank and messages from criminals.
I was just talking to a coworker yesterday and at his previous job part of his security was to go out to the employee parking lot and dump thumbdrives, if they were plugged into the corporate network they would send a message to the security department on the terminal and user account. I actually said to him, no one would be stupid enough to do that, he told me they did this monthly and at least 2 to 3 people would get caught.
He said employees had training and still failed. No one got fired for it though.
He said employees had training and still failed. No one got fired for it though.
Is someone trying to apply AI and Deep Learning to phishing attacks? One of the things which PG noted in "A Plan for Spam" back in the day, was that the Bayes classifier found markers of Spam he never would have thought of.
http://www.paulgraham.com/spam.html
If Phishers are concentrating on fooling human beings in the same way that spammers were back in the day, they might be vulnerable to such techniques.
http://www.paulgraham.com/spam.html
If Phishers are concentrating on fooling human beings in the same way that spammers were back in the day, they might be vulnerable to such techniques.
Firing people for this would leave the entire company in a state of fear. Have you seen those sci-fi dystopias where a script or AI unfairly decides the fate of people...?
As the article implies, absolutely not, and obviously so. Do not make enemies of your own staff, a hostile workplace is exploitable, not to mention unpleasant and demotivating.
My god are people bad at security. Security people especially so. Actual security is not bound to the mechanics of securing things. It is bound entirely to risk. Did you just fire the best accountant your company has because they were too focused on solving your huge tax liability to notice a phishing attempt. Risk.
Everyone is fallible including your IT security group. If phishing attacks are actually causing appreciable damage to your company, it's the security group who needs replacing. Can they report quantitatively how much more value your organization has captured with it's 90 day password replacement policy, and does it account for all the passwords written on post-it notes laying round, and the productivity impact of constant forgotten passwords?
The purpose of security is to mitigate the risk of loss, but so is insurance. Don't fixate on the machinery of security, and don't fire people for poor email filtering who's value is not to filter emails.
My god are people bad at security. Security people especially so. Actual security is not bound to the mechanics of securing things. It is bound entirely to risk. Did you just fire the best accountant your company has because they were too focused on solving your huge tax liability to notice a phishing attempt. Risk.
Everyone is fallible including your IT security group. If phishing attacks are actually causing appreciable damage to your company, it's the security group who needs replacing. Can they report quantitatively how much more value your organization has captured with it's 90 day password replacement policy, and does it account for all the passwords written on post-it notes laying round, and the productivity impact of constant forgotten passwords?
The purpose of security is to mitigate the risk of loss, but so is insurance. Don't fixate on the machinery of security, and don't fire people for poor email filtering who's value is not to filter emails.
I think it depends on the level of trust that you are given in your position.
I got reamed on another forum for saying someone shouldn't be allowed in a certain role, after they sent $1 million to a fake bank account to someone posing as a supplier. But if your work place doesn't have controls in place to prevent that, it's part of your job to be that control and take additional steps to protect yourself and your employer.
I got reamed on another forum for saying someone shouldn't be allowed in a certain role, after they sent $1 million to a fake bank account to someone posing as a supplier. But if your work place doesn't have controls in place to prevent that, it's part of your job to be that control and take additional steps to protect yourself and your employer.
My company uses similar tests - you get a random email and if you click on the link you're required to take some training. One of the things they emphasize is to ensure the actual URL seems legitimate, or is pointing to a company domain if the email claims to be from within the company. Ditto for the From field.
Recently there were reports of an active shooter on site. Everyone got email alerts about it. Many (most?) employees ignored the alert because the From address was an unknown external domain. Fortunately there wasn't an active shooter (although the person who was arrested was armed).
And then the company sent out an email asking us not to ignore those types of emails even if it appears to be a phishing attempt.
I think from now on, just for the heck of it, I'll click on the links but modify some of the characters in the URL. Hopefully someone else in my/some company will be notified that they need training.
Recently there were reports of an active shooter on site. Everyone got email alerts about it. Many (most?) employees ignored the alert because the From address was an unknown external domain. Fortunately there wasn't an active shooter (although the person who was arrested was armed).
And then the company sent out an email asking us not to ignore those types of emails even if it appears to be a phishing attempt.
I think from now on, just for the heck of it, I'll click on the links but modify some of the characters in the URL. Hopefully someone else in my/some company will be notified that they need training.
Depends on what you're doing, but if your employees are dangerously gullible, of course firing them should be on the table if they (especially repeatedly) exercise that gullibility, and it is not feasible to give them tools to mitigate that risk (like PGP, though that's not perfect either).
My general approach is to create computing environments which make it generally impossible to send/receive general communications, and access sensitive information (or the web), at the same time on the same machine. The communication channels available to an agent while accessing a customer file are heavily sanitized, and the environment does not allow for opening links; images are transcoded in fresh containers on a remote machine with no general access to the database or the internet.
The real question is: do many businesses understand the risks well enough to make that determination well?
My general approach is to create computing environments which make it generally impossible to send/receive general communications, and access sensitive information (or the web), at the same time on the same machine. The communication channels available to an agent while accessing a customer file are heavily sanitized, and the environment does not allow for opening links; images are transcoded in fresh containers on a remote machine with no general access to the database or the internet.
The real question is: do many businesses understand the risks well enough to make that determination well?
[deleted]
We definitely do not enforce tailgating enough at DoD. I find it best to stand aside at let people pass before I swipe. The funny thing is that they have security that ensures there is ample space between us, but still some jackhole wants to bend the rules because they are special.
I work at a firm that creates and sends these phishing tests for our clients. Prior to doing this type of work we always assess the "tone at the top" regarding the culture of the workplace, to assess the suitability of doing these tests.
However, if there are staff that repeatedly fail these tests and receive constant training, then that's a question for the business in how willing they are to accept the risk.
Given that there are tools that can quite often successfully block these types of emails before they get to the end user. Most often when we are crafting these emails we need to ask the IT teams to unblock the domain.
In my opinion I think in most cases no, however depending on the industry and the strike rate you might have a case for it at some point.
However, if there are staff that repeatedly fail these tests and receive constant training, then that's a question for the business in how willing they are to accept the risk.
Given that there are tools that can quite often successfully block these types of emails before they get to the end user. Most often when we are crafting these emails we need to ask the IT teams to unblock the domain.
In my opinion I think in most cases no, however depending on the industry and the strike rate you might have a case for it at some point.
I think I'm a pretty technical guy. I'm fairly certain if my job was more dependent on email, I'd get phished eventually. If the IT department hasn't made a move towards using 2FA, it doesn't seem right to punish employees with termination.
I'm interested if the company which would fire a random employee for 3 strikes would also fire a VP-level employee. If they don't, then it's just BS, not security, given how much more access a VP level person has.
They also did have a reporting system. Presumably you wouldn't get a strike if you clicked and reported. People who reported "legitimate" phishing attempts were rewarded. Spear phishing is a totally different game and nobody in their right mind would fail people for clicking on a (well crafted) spear phishing email.