Phishing test "do's and don'ts" - what are the most important DON'Ts in your opinion?

1.1k views7 Comments
Sort By:
Oldest
Director Information Security in Healthcare and Biotech7 months ago
Don't ever consider any strategies that could be emotionally abusive. For example, sending flower notifications on Valentine's Day, fake bonus notifications, or similar situations. It won't net a positive user response and can lower the trust in your team, if not impact company morale.

Sure, there are threat actors who play on that, but there are better, more effective ways we can test and train users without employing such tactics and stay that trusted party to the staff which helps your program stay successful.
2
Senior Director, Global Information Security in Consumer Goods7 months ago
Building trust in your phishing exercise program is critical. Ensure your company culture is represented in your program.  Get feedback and alignment with key stakeholders like HR, Legal and corporate communications.  Employee privacy should be a non-negotiable.  Consider communications to your employee base explaining the phishing program and their privacy concerns.
Business Information Security Officer, Director in Banking6 months ago
Biggest opportunity these days is to take advantage of the opportunity for real-time training if someone fails the phishing test. Many phishing test providers provide the option, and there's no better way to cement the knowledge necessary to pass phishing tests than getting people in that moment just after "gotcha". No one likes that feeling, and its likely those same people understand their organization is trying to protect their customers and their business priorities.
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Senior Information Security Manager in Software6 months ago
Effective phishing programs should educate, not alienate.

GoDaddy did the latter. Don’t be like GoDaddy.

 

https://www.engadget.com/godaddy-sent-fake-phising-email-promising-holiday-bonus-220756457.html
CISO in Software6 months ago
Do not run it so often, employees know exactly what to look for. 

Content you might like

Director of IT in IT Services4 days ago
Implementation of Zero trust architecture, its modules across the organisation is a priority for us. So, we will be implementing zero trust strategies in IAM, inline with overall strategy.
1.4k views1 Comment

Implementation complete23%

Implementation in progress54%

Planned within the next 12 months12%

Not planned7%

Not enabling O365 on mobile2%

View Results
2.4k views2 Upvotes

Yes79%

No20%

5k views3 Comments