TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Phishing Simulations Considered Harmful

4 点作者 bqe将近 5 年前

2 条评论

opsdisk将近 5 年前
&gt; It puts the onus on the employee, rather than the Security team to stop phishing attacks<p>Hits the nail on the head right there. Phishing simulation training (both externally paid and internal) is a way for organizations to say they are at least trying to do something to minimize the #1 attack vector. Plus, it&#x27;s cheaper than actually tackling the problem at the technical level (tweaking&#x2F;updating email rules&#x2F;settings) with whatever email defensive appliance is (or isn&#x27;t) being used.<p>I launched PhishBarrel (<a href="https:&#x2F;&#x2F;phishbarrel.com" rel="nofollow">https:&#x2F;&#x2F;phishbarrel.com</a>) based on the thesis that most phishing emails can be identified using technology, and if one gets by, having a robust API for investigations, security automation, and&#x2F;or remediation is table stakes in today&#x27;s security products. If you&#x27;re serious about upping your organization&#x27;s email phishing defensive capabilities, please reach out to me (email is on phishbarrel.com site). I&#x27;m looking for forward thinking infosec folks that are looking for a partner to tackle this problem!
thanksforfish将近 5 年前
&gt; One advanced strategy is to deliver real but defanged phishing emails to more employees than originally received it.<p>This isn&#x27;t recommending against phishing simulations, but instead suggests better crafted emails and gentler response when employees are tricked.