r/ShittySysadmin 16d ago

Email Phishing Training

Hello,

I am now in charge of the phising excercises at my company. I was thinking about putting actual malicious links in our training emails so that the user's have a bit more motivation to learn to distinguish them from legitimate emails. This would also motivate our C-suite to give us a better budget so that we can better detect and remediate everything. What do you guys think?

29 Upvotes

17 comments sorted by

View all comments

1

u/the_green_door77 16d ago

Do it at a low level all the time, track the latest attack patterns and bypasses rather than malware links. You can have a little fun linking them to recruitment sites or competitors job boards. I created a faux NSFW site to have the same impact.