Phishing Testing
Author
Discussion

bitchstewie

Original Poster:

67,584 posts

239 months

Friday 17th July 2020
quotequote all
I expect this will get moved but I'd rather like any feedback from the non-IT types who may not go in the Computer forum smile

Do any of you knowingly get phish tested by your employer?

If so do you know what tool they use to do it please and in particular if they make you do any sort of online training around phishing what product that is and what do you think of it?

alorotom

12,784 posts

216 months

Friday 17th July 2020
quotequote all
We do get tested on it and the whole process - training and feedback is handled by Total Group for us.

robbieduncan

1,993 posts

265 months

Friday 17th July 2020
quotequote all
Yes occasional test phishing emails come through. Click on the links and you win a training course! No idea on the tool used

Matt Cup

3,266 posts

133 months

Friday 17th July 2020
quotequote all
Yes our place sends out random phishing emails. If I remember on Monday I’ll have a look who they use.

toastyhamster

1,790 posts

125 months

Friday 17th July 2020
quotequote all
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.

Can be quite amusing (for those not targeted).

Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.

Edited by toastyhamster on Friday 17th July 18:34

stewies_minion

1,167 posts

216 months

Friday 17th July 2020
quotequote all
I use Knowbe4 for my users. It comes with a training tool in the suite and you can make it mandatory etc..

In fairness I've never used the training it as we do our own, because we're bound to be cleverer than them..

It's v. good

Spare tyre

12,558 posts

159 months

Friday 17th July 2020
quotequote all
I ask all employees for dick pics

They are Dammed if they do dammed if they don’t

bitchstewie

Original Poster:

67,584 posts

239 months

Saturday 18th July 2020
quotequote all
toastyhamster said:
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.

Can be quite amusing (for those not targeted).

Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.

Edited by toastyhamster on Friday 17th July 18:34
Interesting thank you and to everyone else so far smile

Has the training got a little more UK based?

The last time I looked at knowbe4 (which was a few years ago) the training was rather cheesy and US focussed in tone and content (social security, wire fraud etc.).

toastyhamster

1,790 posts

125 months

Saturday 18th July 2020
quotequote all
bhstewie said:
toastyhamster said:
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.

Can be quite amusing (for those not targeted).

Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.

Edited by toastyhamster on Friday 17th July 18:34
Interesting thank you and to everyone else so far smile

Has the training got a little more UK based?

The last time I looked at knowbe4 (which was a few years ago) the training was rather cheesy and US focussed in tone and content (social security, wire fraud etc.).
It's expanded massively so I would expect so, there are GDPR modules now for instance. We use our own consultants to do our security awareness training, even the receptionist can do the on line stuff blindfold.

bitchstewie

Original Poster:

67,584 posts

239 months

Saturday 18th July 2020
quotequote all
toastyhamster said:
It's expanded massively so I would expect so, there are GDPR modules now for instance. We use our own consultants to do our security awareness training, even the receptionist can do the on line stuff blindfold.
Yeah we usually do our own but given the current situation we're just thinking of the best format when it can't be quite as interactive as getting people in a hall etc.

toastyhamster

1,790 posts

125 months

Saturday 18th July 2020
quotequote all
bhstewie said:
toastyhamster said:
It's expanded massively so I would expect so, there are GDPR modules now for instance. We use our own consultants to do our security awareness training, even the receptionist can do the on line stuff blindfold.
Yeah we usually do our own but given the current situation we're just thinking of the best format when it can't be quite as interactive as getting people in a hall etc.
We've delivered some remote sessions via consultancy, if anything we're seeing more people picking up the technology, even if it's only for 12 months, just to satisfy their compliance requirements and also make their employees aware of the different attack surface they now present with much more focus on home working.

We've had to get a bit creative but we've shifted all our services (consultancy, pen testing, SOC/IR etc) completely remotely, it's been pretty successful and that's been reflected in sales numbers I would have dismissed as fantasy back when this all kicked off.

CAPP0

20,860 posts

232 months

Saturday 18th July 2020
quotequote all
We use KnowBe4 (and also sell it as a service) and we have a guy who customises and writes the phishing emails, which he's very good at. He hasn't got me (yet) but he's certainly made me stop and have a good long hard look at an email in the past.

stewies_minion

1,167 posts

216 months

Saturday 18th July 2020
quotequote all
When I find time I'll be using Knowbe4 to send something posing as our rewards partner.

40% off Apple this week on <name of extranet service here>

Bet I get people with that. Worth doing as that is what a targeted attack could look like.

Fatboy

8,268 posts

301 months

Tuesday 21st July 2020
quotequote all
Spare tyre said:
I ask all employees for dick pics

They are Dammed if they do dammed if they don’t

vourin

29 posts

229 months

Tuesday 21st July 2020
quotequote all
I have used Wombat (which included phishing and general awareness training in price - now part of Proofpoint), Microsoft's own Attack Simulator in ATP (quite basic) and looking to use Cyber Risk Aware (www.cyberriskaware.com) as the integration and notifications look really good. HoxHunt (www.hoxhunt.com) looks amazing but its pricey!

Matt Cup

3,266 posts

133 months

Tuesday 21st July 2020
quotequote all
Phishalarm outlook add-in seems to be the one our company uses.