Phishing Testing
Discussion
I expect this will get moved but I'd rather like any feedback from the non-IT types who may not go in the Computer forum 
Do any of you knowingly get phish tested by your employer?
If so do you know what tool they use to do it please and in particular if they make you do any sort of online training around phishing what product that is and what do you think of it?

Do any of you knowingly get phish tested by your employer?
If so do you know what tool they use to do it please and in particular if they make you do any sort of online training around phishing what product that is and what do you think of it?
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.
Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Edited by toastyhamster on Friday 17th July 18:34
toastyhamster said:
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.
Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Interesting thank you and to everyone else so far Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Edited by toastyhamster on Friday 17th July 18:34

Has the training got a little more UK based?
The last time I looked at knowbe4 (which was a few years ago) the training was rather cheesy and US focussed in tone and content (social security, wire fraud etc.).
b
hstewie said:
hstewie said:toastyhamster said:
phish.me is quite popular, working in the industry even the sales types in the company are super paranoid so run of the mill stuff gets spotted easily. Unfortunately for all of us we have the specialist knowledge in house to craft a sophisticated campaign against our own employees, and usually they are successful, simply because they are so believable. Nothing obvious like mis-spelt URLs/domain squatting etc.
Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Interesting thank you and to everyone else so far Can be quite amusing (for those not targeted).
Edit: Am biased as we are a knowbe4 partner but it's pretty good for remote learning, or we can do bespoke professional services security awareness training 1-2-1, 1-2-Many or train the trainer.
Edited by toastyhamster on Friday 17th July 18:34

Has the training got a little more UK based?
The last time I looked at knowbe4 (which was a few years ago) the training was rather cheesy and US focussed in tone and content (social security, wire fraud etc.).
toastyhamster said:
It's expanded massively so I would expect so, there are GDPR modules now for instance. We use our own consultants to do our security awareness training, even the receptionist can do the on line stuff blindfold.
Yeah we usually do our own but given the current situation we're just thinking of the best format when it can't be quite as interactive as getting people in a hall etc.b
hstewie said:
hstewie said:toastyhamster said:
It's expanded massively so I would expect so, there are GDPR modules now for instance. We use our own consultants to do our security awareness training, even the receptionist can do the on line stuff blindfold.
Yeah we usually do our own but given the current situation we're just thinking of the best format when it can't be quite as interactive as getting people in a hall etc.We've had to get a bit creative but we've shifted all our services (consultancy, pen testing, SOC/IR etc) completely remotely, it's been pretty successful and that's been reflected in sales numbers I would have dismissed as fantasy back when this all kicked off.
I have used Wombat (which included phishing and general awareness training in price - now part of Proofpoint), Microsoft's own Attack Simulator in ATP (quite basic) and looking to use Cyber Risk Aware (www.cyberriskaware.com) as the integration and notifications look really good. HoxHunt (www.hoxhunt.com) looks amazing but its pricey!
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff


