frehi,

My employer lets a private company send fake phishing mails to all staff in order to train them. Now that company, which most personnel do not know, sends an e-mail in its own name to all our staff, asking them to click on a link to follow an anti-phishing training. So it looks like the message they are giving to all our staff is: it's OK to click on links from unknown companies, as long as they tell you that it's anti-phishing training. 🤦‍♂️ #phishing #infosec

Viss,
@Viss@mastodon.social avatar

@frehi this isnt 'training', so much as it is 'the lowest possible denominator in an ecosystem where companies have to prove they are doing a thing, and so snakeoil salesmen create garbage tier "solutions" for the box checkers'.

what you're experiencing is box checking, not training.

your org does this so their insurance is cheaper, and so they can pass certain compliance mandates

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • DreamBathrooms
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • megavids
  • lostlight
  • All magazines