A month ago, my friend Wolfgang Goerlich posted a hot take on LinkedIn that is less and less of a hot take these days.
He posted, "our industry needs to kill the phish test",and I knew we needed to have a chat, ideally captured here on the podcast.
I've been on the fence when it comes to phishing simulation, partly because I used to phish people as a penetration tester. It always succeeded, and always would succeed, as long as it's part of someone's job to open emails and read them. Did that make phishing simulation a Sisyphean task? Was there any value in making some of the employees more 'phishing resistant'?
And who is in charge of these simulations? Who looks at a fake end-of-quarter bonus email and says, "yeah, that's cool, send that out."
Segment Resources:
- Phishing in Organizations: Findings from a Large-Scale and Long-Term Study
- The GoDaddy Phishing Awareness Test
- The Chicago Tribune - How a Phishing Awareness Test Went Very Wrong
- University of California Santa Cruz - This uni thought it would be a good idea to do a phishing test with a fake Ebola scare
I’ve spent my career immersed in solving the constant and ever evolving challenge of cybersecurity. The constant change and evolution always keeps it interesting. Right now I’m defining security models for LLM. In the past, l’ve co-led the industry charge towards securing cloud, putting the Sec in DevOps, and making Zero trust deployable and manageable for enterprises of every size. I’m an IANS Al, Zero Trust, and Security Leadership expert and you’ll find me speaking as well as listening at conferences.
Leader, coach, mentor, manager, tinker, tailor, soldier, spy.
