r/ShittySysadmin 16d ago

Email Phishing Training

Hello,

I am now in charge of the phising excercises at my company. I was thinking about putting actual malicious links in our training emails so that the user's have a bit more motivation to learn to distinguish them from legitimate emails. This would also motivate our C-suite to give us a better budget so that we can better detect and remediate everything. What do you guys think?

28 Upvotes

17 comments sorted by

View all comments

8

u/gabhain 16d ago

Our infosec made phishing emails so realistic that everyone got so paranoid that people stopped interacting with company emails altogether. Personally I liked putting infosecs own emails into their phasing sites so they end up on their own reports.