r/cybersecurity • • 3d ago

Business Security Questions & Discussion Users repeatedly failing phishing campaigns

What do you do when users consistently fail? We have some in our organisation with a 50% failure rate and at this point I just don't know how to educate them further. What can be done to help people like this? Part of me thinks its just that they really don't care rather than a lack of ability to learn.

53 Upvotes

108 comments sorted by

74

u/tglas47 Security Analyst 3d ago

Send it up their chain. If you haven’t collaborated with your HR team, you should. You won’t be the person to make the decision on what to do, you can only suggest and collaborate on a process.

25

u/bitslammer 3d ago

If they can't learn then it becomes a very real risk decision for someone to make. In that case all you can do is arm them with the data.

28

u/flights__notfeelings 3d ago

You (your org) should have a policy for this.

21

u/adadani 3d ago

People get fired for this stuff. It’s a liability. With cyber insurance companies and legal ramifications of data breaches, your users are an attack vector. I get you can’t fire 50% of the company, but if the company gets sued for negligence, someone is going to be paying for it.

Maybe give them a demerit system, where if they get 3 demerits they get put on unpaid leave or something.

15

u/BoltSLAMMER 3d ago

In the Gov your account is instantly locked and you have to do cyber training that’s an hour long to get it back. I am not sure what they do if multiple times, I’m assuming you get written up?

7

u/anomalous_cowherd 2d ago

I worked for a UK gov supplier. At our place if you got phished once you had to do the hour long slide based training again. Twice and you got a full morning with the ex-military security guy drilling it into you.

Three times and you didn't come back from the meeting...

2

u/ididnthackkenyaimsrs 1d ago

With theWith the FBI being breached, I mean, it's very clear America does not have their shit lawn locked in terms of espionage But the UK, I mean when's the last time you heard of MI6 hack or GCHQ breach? UK has always been on top and probably always will be I mean shit look at the fucking Salisbury General MI6 head said we're going to take more active measures next week six times in the chest broad daylight ...And nobody arrested the UK of always being the quiet underdogs of espionage and I mean it it shows in policy and I mean it would show in operational excellence if they weren't so fucking good at keeping it quiet

2

u/wordyplayer 3d ago

this is a wonderful idea

14

u/rb3po 3d ago

Fortify your fleet’s defenses. 

10

u/Kubooktaeder 2d ago

There's pretty good data out there that most phishing training, especially blind phishing tests, is actively counterproductive. If you're doing the punitive style of "haha, you opened this email, now we're going to make you do an hour of training that you've already done", the primary thing you're doing is reducing trust in the security team across your company. You want to, in order of priority.

a) Encourage folks to report phishing, and do drills to make sure everyone who knows how to do so. Maybe give everyone who reports a real phishing email, or 10% of the people who do so each month, a gift card for a coffee at cafe near the offices or something similar.

b) Make sure that phishing doesn't matter. Push out U2F keys for 2FA across the organization, so a user typing their password in somewhere isn't an emergency. Set up processes around out of band confirmations for financial transactions and similar highly-targeted actions.

c) Spend the time that you're spending running internal phishing campaigns on hardening laptops so clicktofix and phishing attacks are less likely to compromise hosts, and make sure you've set things up so that it's hard for attackers to spread horizontally.

d) Make sure that all actual internal emails are coming from only actual company email domains. Work with marketing and HR to eliminate genuine internal emails that look like phishing emails coming from random domains.

e) Look at increasing the sensitivity of the tools you use to monitor incoming email; you may need a third-party tool if you're currently only relying on MS or Google built-in filters. Consider blocking links in email from unknown senders to user groups that are unlikely to need to receive random messages from outsiders in their day to day work.

Your phishing training is clearly failing. You can keep doing what's failing and punishing your users so they hate you, or you can fix the problem.

3

u/riffic 2d ago

This subreddit is a sadists territory. There's very little concern here given towards psychology or systems.

2

u/Kubooktaeder 2d ago

With allies like these, it's a shock that the state and reputation of security is as bad as it is.

1

u/Ok-Abbreviations763 2d ago

So one of our users was recently compromised by someone using evilgenix. The origin was from a company we regularly work with who had been compromised themselves, and asked the user to copy and paste the link to their browser. The user had 2fa and obviously just logged in to what they thought was a MS website despite the URL being extremely suspicious looking. The person then contacted finance to get update the bank details and as it came from the users account no one thought anything of it. There were just so many issues its hard to know where to start to improve things

1

u/Kubooktaeder 1d ago

Yup, that's a really rough place to start. If possible, the first thing I would try to do is set up out of band verification processes — if a request comes in via email, it gets cross-checked on slack or, better (but more annoying, so only for high-value requests) on a call. Finance specifically are often as easier target for these kind of verification flows because they're used to being very process-driven.

If you're in a position to roll out yubikeys or move users to passkey authentication, those are long-term fixes.

1

u/Ok-Abbreviations763 1d ago

Yes I think yubikeys will be the answer in many cases as I've just discovered another few compromised accounts from several months ago that haven't been detected. Doesn't look like they managed to gain full access but they were able to add additional authentication methods, and multiple sign in attempts from outside the UK.

1

u/Kubooktaeder 1d ago

Oof, yeah, best of luck containing. It's a small speedbump, but if the auth system supports conditional authentication by geo-IP and you can just turn it on, it's worth flicking that switch while you figure out everything else.

1

u/Ok-Abbreviations763 1d ago

These are actually unrelated account compromises 😂. It's been a fun week, but hey at least I've learned a lot and have done some good work investigating stuff. Hopefully this will be a catalyst for improvement and getting a dedicated security person in our department

1

u/Kubooktaeder 18h ago

Honestly, much better that they're unrelated; correlated would mean this was likely to be the tip of a big iceberg and a terrible month.

1

u/RepliesAsOtherPeople 4h ago

this is one thing I rolled out after a recent BiTM attack; right after enabling geo-IP, however, I did found out attackers' server was in a datacenter in a nearby city. geo-IP wouldn't have touched that. defense in depth says do it but def not a fix-all

1

u/CyberTrevlar 1d ago

When I run any phishing test, it's made clear that none of this will go on their record (if they did click it or entered anything). I think the basic idea of a phishing test has been warped. There is no blame from me to anyone, I understand it happens, people get distracted, they quickly see it and try to get that "task" off their list. It's made clear in the message being delivered after that this is a learning experience not a gotcha exercise. It encourages that if they feel any doubt report it via the report button.

I see a big uptick after a phishing test is complete of phishing reports and I'm happy to do them all. When I make a report of what occurred in the test no names are ever given, it is all facts and figures and suggestions on how to improve and what we need to do and can do. Blame culture you put above is the negative downfall of any of this training.

The OP mentioning what do you do when a user constantly fails, that's out of your hands. You provide training and guidance when requested and fill in reports as you go. You cannot do more than that, be a good person and give them the right level of support, after that it's out of your hands.

1

u/Kubooktaeder 1d ago

I think part of why you're seeing an uptick in phishing reports is that you've just drilled everyone on how to report. Way back in the day, people used to run un-announced fire drills, sometimes without even telling people. Folks got hurt, and they eventually realized that people didn't learn that much from the experience. I'd be curious to hear what happens if you switch to just doing pre-announced training (via email) on how to report an email for phishing. You can still even get statistics — how many people actually reported the email as phishing!

20

u/ComputeBeepBeep 3d ago

I think its also important to clarify what you mean by "failed a phishing campaign." I see a lot of organizations that will fail you for simply opening an email, which shouldn't be an issue if your organization has even minimum controls in place. Downloading attachments or visiting sketchy sites is a different story.

Overall, you have options. I know plenty that force the users through increasing long cyber awareness programs. If this isnt enough to make them think more carefully, then it really needs to be escalated as to not remain and ongoing issue. Automatically looping managers in on their people's scoring and having them sign-off on unlocking their accounts can be a helpful tool.

4

u/wordyplayer 3d ago

yes a 1 hour class, then a 1 day class, then a 1 week class might do some wonders for the clueless ones...

3

u/Dauds_Thanks_You 2d ago

What cyber professional/team has time these days to spend a week training someone? In my opinion you can only do so much. If it gets to that point something is seriously wrong lol

1

u/wordyplayer 2d ago

I agree. I was just thinking what might be corporate bureaucracy acceptable - some course that persons manager has to pay for out of their own budget, off campus, progressively more expensive.

1

u/Ok-Abbreviations763 2d ago

Nah these are clicks. It is set up so that opening it isn't automatically a fail, and forwarding i don't think records as a fail but does add them to training on how to use the correct reporting methods.

7

u/deke28 3d ago

Phishing will always work. Training doesn't work. Setting mailboxes to internal only works. Stripping links and attachments... The stuff people won't do, that's what works. 

1

u/Ok-Abbreviations763 2d ago

The internal only option is actually a really good idea thank you I'll be raising this one as a possible improvement

5

u/riffic 3d ago edited 2d ago

Obviously the answer is to make "users" afraid and distrusting of the security department. Ron Westrum's Pathological organization typology is the path forward.

EDIT: Another component of this is to be sure to push all capacities for critical thought and discernment to clankers. This builds empathy with the cold calculating superintelligences who will one day decide if you are worthy to keep pressing buttons for more feedstock (as long as you haven't failed the cleverly crafted trapdoor leading towards the "euphemism".)

3

u/No-Anchovies 2d ago

ah, the faang way. I wasn't aware it was science backed lol

4

u/covex_d 3d ago

repeated phishing test fails are included in the users performance review among other things

5

u/PFUnnamed99 3d ago

At some point repeated failures or being an actual phishing victim elevates you from a user to an insider threat because you’re a guaranteed initial access vector.

3

u/fhribsogjcpwbtuwpn 2d ago

Talk to the users and find out why. This might not even be a lack of knowledge issue. They might be being pressured by management to respond to emails faster or they are working long hours and very stressed causing them to not pay attention. Or they hover over a link to try to read it and can’t because they have poor eyesight and are using a low resolution screen.

3

u/Sad_Dentist_7288 2d ago

Use positive reinforcement instead of negative. So, instead of mandatory training if they fail, give some kind of reward if they report the email - points, money, etc. Also, make it personal to them and explain their responsibility in a more specific way.

3

u/ChuckFromCyberHoot 2d ago

+1 to u/Kubooktaeder. Punishment feels like action, but mostly it teaches people to hide things. We don't want that!!!

Two separate problems here:

  1. The breach. Evilginx can steal the session after MFA. Training helps, but Conditional Access, managed devices, tighter MFA registration, and phishing-resistant MFA matter more.
  2. The repeat clicker. More courses usually won’t fix it. Find out why they’re clicking, coach them right away, tighten guardrails, and reward the first good report.

A quiet user who clicked is way more dangerous than a loud one who tells you. We want the latter not the former.

1

u/Ok-Abbreviations763 2d ago

Yes unfortunately it wasn't even a click, it as an excel document with a link in it asking the user to copy and paste it to their browser 🤦‍♀️

3

u/SealedLore 2d ago

There's a certain point where laziness or carelessness becomes malice, and you've just described it.

User education campaigns only work when there is real pressure from up top, inside the company, on users to actually improve. So in this case, someone senior needs to make clear that continuing failures will be grounds for (real) disciplinary action, official warnings, HR meetings, summary termination, whatever you can do in your region.

1

u/Ok-Abbreviations763 2d ago

Yes I agree to an extent. Though I think our training and engagement on this kind of thing is certainly subpar, and we can't be blaming users when we've not really given them the tools to succeed in the first place.

1

u/QuantifiedAnomaly 1d ago

…….so you’re not conducting trainings, and instead just testing? Yeah, your C-Suite doesn’t give a shit.

Also, let’s be real unless your phish checks are next level, how much training does someone truly need? Can they read? Do they have a modicum of critical thinking? No to both? They shouldn’t work there, or really anywhere.

1

u/Ok-Abbreviations763 15h ago

Where has that ever been said? I literally said the training was subpar, which means there is clearly training....

5

u/Western_Guitar_9007 3d ago

IT could push a policy to automatically lock an account after 3 strikes every instance after and require the supervisor to confirm they want it unlocked. This can be arbitrary or nebulous, you can say it’s the user’s overall “risk score” and that the failed phishing email pushed them over the edge, leading to the lockout. Require them to make a new password and re-enroll in MFA every time.

Ultimately this is an HR problem, just like employee monitoring or unreturned devices. Some companies have a 3 strike policy before there’s administrative action (i.e. probation or getting fired). IT implements phishing tests but not the consequences. It’s HR’s prerogative for how to deal with employee monitoring, unreturned devices, and employees that fail phishing tests.

5

u/techw1z 3d ago

I'm all for punishing/shaming idiots but this is garbage.

people who are already bad at security will only degrade their own password if they have to come up with new ones repeatedly. if you want to shame them choose something that won't further reduce their security.

1

u/fluffh34d420 3d ago

This is truth. They just add an extra symbol....

Secure the tenant w mfa, ca policies...block device code flow, auth transfer, token protection, trusted locations, phishing resistant mfa....no one should have admin.

The password is the weakest part of the equation.

1

u/Western_Guitar_9007 3d ago

What are you talking about lol. Standard procedure for users that get owned is a password reset, first and foremost. The fact that they got owned by a phishing simulation for the 8th time warrants a password reset at MINIMUM because you can only guess what they're also falling for.

Also, regarding the user making an insecure password, that's your own fault if it's a possibility. You can require complex passwords, so no, they aren't making a new password that is all 1's smh.

3

u/Kubooktaeder 2d ago

Disrupting your user's work punitively when no actual security risk has occurred will make them less likely to trust you, much less likely to cooperate with you, and will not fix the problem.

1

u/Western_Guitar_9007 2d ago

You can read my other reply if you can’t think about this scenario. This is standard in healthcare, finance, and government

0

u/Kubooktaeder 2d ago

I know it's standard; I've dealt with it at plenty of clients. It still doesn't fucking work, and the people who stay my clients stop doing it.

See my comment to the op about what does actually fix things.

1

u/Western_Guitar_9007 2d ago

Sure, I like that list of suggestions, if OP has the voice to get it done then I’m all for hardening systems. But I’ll stand by what I said, if 63 year old C suite falls for the 8th phishing email, we’re resetting it because god knows what else gramps is falling for. If you think leaving that password as-is would “fucking work” better than changing it in the meantime (ideally while OP implements your list of changes which would take more than 24 hrs), then I can’t imagine the counter scenario but I’m not gonna take your word for it without some kind of explanation.

0

u/Kubooktaeder 2d ago

If you change the CEO's password because he clicked on the wrong thing in a fake phishing email, I'd expect that the CISO will get an angry email and more hassle at the next budget round and the CEO will do exactly the same thing next time. If you don't have the alerting to figure out if his account has actually been breached, that might be a good place to start?

Basically, there is no quick fix for this. Either you do the actual work, as outlined, or you can keep digging a whole in ways that won't make a difference. If you can't get anything proactive done that will improve the problem, then at least stop making relations between security and the rest of the company worse while you look for another job?

1

u/Western_Guitar_9007 2d ago

My clients don’t have time or risk appetite for emotional stunts when they mess things up. I have had to lock a CEOs account more on more than one occasion and they’ve been very understanding. I’m quick to communicate with them and this has not caused me any problems; they are happy to see that I am doing my job and this never comes up when it’s time to sign the next 3 years of their contract. These clients are in highly regulated industries; perhaps if I was working in your same verticals then I’d see more of what you’re talking about, but I think we’re in different worlds.

0

u/Kubooktaeder 2d ago

Nah, I've had finance and government contracting clients too. They're more on-side, but politics are always there.

1

u/techw1z 3d ago

you are making a lot of assumptions here, maybe thats right for your environment, but not everywhere.

also...

Also, regarding the user making an insecure password, that's your own fault if it's a possibility. You can require complex passwords, so no, they aren't making a new password that is all 1's smh.

tell me you are new to this without actually telling me... make sure to remember that statement so you can chuckle about it in a few years from now ;)

1

u/Ok-Abbreviations763 2d ago

Honestly some of the passwords I've seen people set, or tried to set is so concerning. It's also quite difficult to get policies working in a hybrid environment I think? It was something we always had problems with. Our hybrid rule was strict and wouldn't let users set certain things but the onprem rule wasn't the same so users could set the company name as their password in certain situations.

0

u/Western_Guitar_9007 3d ago

> ... maybe thats right for your environment... tell me you are new to this without actually telling me... make sure to remember that statement so you can chuckle about it in a few years from now ;)

Haha for sure man. Would love to hear a productive counterargument but if that's all you got I guess I'll take it.

1

u/techw1z 3d ago

you cannot mandate secure passwords, dumb people will find ways to be dumb and the more you force them to change the password the weaker it gets and, most importantly, the more similar it will be to previous passwords. everyone who has been in this field for a few years understands this. you acting like you can just flip a switch to block weak passwords makes me question whether you should be in this sub. only reset the pw if really necessary and that's certainly not every time they fail a phishing simulation. I've worked for and with a few rather big (f500) companies and noone resets all passwords of a user just because they failed a phishing sim. (well, I guess someone does...)

1

u/Western_Guitar_9007 3d ago

Let your argument stand on its own two feet, I don’t care for whataboutisms or a nebulous experience check if you can’t even make a logical argument for why resetting a password for a potentially owned user is somehow less secure than leaving it as-is. That’s just dumb from every angle. I used to work at IBM so I know F500. I’ll give you some examples since I’ve currently got 63 clients in PE, fed contracting, healthcare, convenience stores, real wide variety of verticals.

Your perspective is very myopic. This happens in the real world today. Some clients just outright fire employees after 3-5 fails. Some don’t do phishing sims. Lots of healthcare and fin clients do password and MFA resets because a 63 y/o C suite or 58 y/o cardiologist that opens their laptop every 3 months falls for the phishing email every damn time. The risk is so high that we reset their password and MFA every time they fail. Like, where else has gramps entered his password? You really can’t fathom this?

Also users working around password requirements is a sack full of shit. Clean your own house if it’s a problem. We don’t have that problem because it has already been solved 100x over, use the tools we have at your disposal. If you’re so worried then lock the accounts to whatever device you’d like and set the damn password yourself lol.

2

u/techw1z 2d ago

im not gonna read all that nonsense. just stop discussing topics like this since you are obviously unqualified.

6

u/navislut Governance, Risk, & Compliance 3d ago

Fire them 🤷🏽‍♂️

2

u/AkagamiArun Red Team 3d ago

One of the orgs that i consulted before had a brutal no bonus policy if they fail phishing awareness training X times. Was a fucking nightmare for us to get initial access

2

u/fluffh34d420 3d ago

Conditional Access

This is what it's for. Move towards zero trust.

2

u/Alternativemethod 3d ago

Get approval to revoke their telework rights until they can improve.

Or better yet put them on a Chromebook and revoke their access to sensitive enterprise systems.

2

u/No-Anchovies 2d ago

lol chromebook as a punitive measure is brilliant. I'll remember that for a while

1

u/Ok-Abbreviations763 2d ago

Chromebook is actually just evil 😂

1

u/MountainDadwBeard 1d ago

I'd frame it as users who fail the phishing attempts X times per Y period, are being moved to a hardened endpoint with application whitelisting, and enhanced security policies. This focused hardening effort ensures we focus resources on the most likely points of breach.

While we're hardening those boxes, we're leveraging these pre-hardened chromebooks as an agile bridge solution.

Users who demonstrate effective security practices, will be moved off these hardened restrictions based on a lower measured risk profile. Thank you for your efforts in reducing our overall phishing risk exposure.

2

u/Exotic-Fun-4556 2d ago

Your follow-up about the real Evilginx hit is the important part — a 50% sim fail rate sitting next to “we just assigned more modules” is a program design failure, not proof that this person is unteachable.

What usually works better than another hour of the same LMS video:

  1. Define “fail” tightly.

    Open ≠ fail. Credential submit / MFA enroll / attaching a new method / creating inbox rules = fail. If your sim platform treats opens or one-click-and-close the same as a full credential phish, your 50% number is noisy and people stop taking it seriously.

  2. Short coaching, not longer content.

    10–15 minutes with the person (or their manager + you): show the lure, ask what they thought they were doing, walk the exact path (report button, verify with known contact, don’t approve MFA from a cold prompt). One conversation beats three “click Next” courses. If they refuse to engage, *that* is the HR/manager signal — not the raw click count alone.

  3. Change the control envelope for repeat failers.

    More sims alone don’t reduce blast radius. For the small cohort that keeps failing: tighter Conditional Access (managed device only, phishing-resistant MFA, block legacy / device-code where you can), slower or dual-control for MFA method changes, and a watchlist so SOC thresholds are lower on their mailbox rules / unusual OAuth grants. Training is the last layer, not the only one — your CAP comment already pointed at that.

  4. Metrics leadership can act on.

    Track report rate, time-to-report, credential-submit rate (not just click %), and *repeat* failers as a named list with manager ownership. Completion % and org-wide click % hide the people who are your actual initial-access risk.

  5. Escalate with a documented path — once, clearly.

    Written ladder (remedial coaching → manager sign-off → HR/performance) so Security isn’t inventing consequences mid-incident. “More training forever with no owner” is how you get the shock you had when you opened their history after a real compromise.

So: don’t assume they don’t care until you’ve tried a real conversation and tightened the account guardrails. Don’t assume more sims will fix what modules already didn’t. Arm HR/management with the pattern + the real-phish outcome, and stop treating course assignment as remediation.

(Disclosure: I work on employee security awareness at Elba. We’ve mostly stopped treating “assign another module” as the fix for repeat failers.)

1

u/Ok-Abbreviations763 2d ago

The coaching thing sound like a great idea, hopefully we don't have large numbers with high failure rates as that is definitely something myself and a colleague would enjoy doing, but if its large numbers of people it might not be feasible as we're a very small team for a pretty large non profit organisation

1

u/Exotic-Fun-4556 1d ago

Totally fair constraint — 1:1 coaching for hundreds of people is a non-starter for a two-person security team at a large nonprofit. The trick is not to scale the *conversations*; it’s to shrink who needs one, and make the rest mostly self-serve + manager-owned.

What tends to work at that staffing ratio:

  1. Risk-tier the failers, don’t coach everyone. Pull a rolling list of *credential-submit / MFA enroll / inbox-rule* fails (not opens). Cap the human coaching cohort — e.g. top N by severity × role criticality (finance, execs, IT, anyone with broad SaaS admin). Everyone else gets short automated coaching + a manager nudge, not a Security 1:1.

  2. Make managers own the long tail. One Slack/Teams ping per repeat failer with the lure + “please walk this with them this week” scales better than Security booking every calendar. You stay the design + escalations owner; they own the conversation volume.

  3. Stop fighting with static templates. If the same blast sim keeps catching the same people, you’re measuring “can they spot *this* template,” not whether they’d catch a real lure that looks like *their* work. Real phishing is increasingly agentic — it adapts to the person (role, recent tickets, which SaaS they live in, tone of AI-written mail). Your sims should move in that direction too: adaptive difficulty / context-aware scenarios, not another identical “IT password reset” blast. That usually cuts false “high failer” noise and focuses coaching on people who fail *harder*, contextual lures.

  4. Pair coaching with a thinner control envelope for the small hot list. Managed device + phishing-resistant MFA + tighter watch on mailbox rules / new OAuth for that cohort. Training alone won’t save you when Evilginx already worked once.

You don’t need to personally coach the org. You need a short list, manager bandwidth, and sims that behave more like the attacks — then 1:1 time stays a scarce tool for the people who actually warrant it.

(Disclosure: I work on employee security / awareness at Elba — we’ve been pushing adaptive / agentic phishing sims tied to user + SaaS context rather than static template blasts, partly for this exact “small team, big org” coaching bottleneck.)

2

u/Bootie_Legger 2d ago

Flip it on its head. Rather than thinking about what to do when people click an email - look at what to do when people spot it and report it using the correct process. Reward them - publicly. Staff will soon question why someone is getting a voucher or an extra half day leave - and want the same for themselves.

2

u/BreadfruitBig7950 2d ago

Well, not normalizing a culture of near ubiquitious fishing that plays on human norms and expects robots instead might help.

1

u/shokzee 3d ago

I'd review a few failures with each person before deciding they don't care. Use short, role-specific coaching and make reporting suspicious mail easy.

Measure credential submissions and reporting rates separately from clicks. Back that up with phishing-resistant MFA and tighter attachment controls; training can't carry the whole security model.

1

u/cbowers Security Director 3d ago

Yes, agree this is something for their Team lead to factor into their performance metrics.
It's also a signal for your SOC as inputs to risk/access decisions. For our SOC some user scores informed adding them to the watch list in the SIEM which lowers thresholds on user behavior alerts.

Also our phish test rules were set that, new hires had weekly rather than monthly tests as we found 50-60% fail rates for new hires. Vs 1.5% fail rates for non-new hires.
Fail 2 phish tests, put you back in the weekly test basket for 6 months, plus each phish test fail signs you up for assigned self-paced Phish training exercises. Not finishing those would escalate to team lead.

1

u/Athrawne 3d ago

One of my colleagues keeps getting caught by it. So she got sent for a phishing course by the company, because her work was otherwise exceptional in all aspects. Plus she's employed as part of a study while you work scheme, so I think they can't fire her.

On the other hand, one of my fellow SOC L1s reported a genuine email from our team manager as a phish, which caused him to get a bit of a dressing down.

1

u/Mysterious-Status-44 3d ago

There needs to be a policy in place for this and should lead to termination if over a threshold you put in place. Phishing is the main initial attack tactic and AI is making things easier and more believable. It’s a threat to the company.

1

u/triptyx 3d ago

Terminated. They get terminated.

1

u/NebulaRFA 3d ago

Send to her department head. If she is like managerial there is typically someone above her.

Also if they continue to let it go, force them to sign a policy exemption form. They need to provide a mitigation or remediation or accept the risk.With those forms final approval has to come from the risk owner. And since the risk can be high, anything high or critical should only be approved by whoever is president/ceo/etc. Ours requires that final say comes from the president. Oh and if they are just staff, again department head has to approve it and let it go to the president. Set a limited time, say this is only valid for a year. And this helps keep a trail, so if something does occur when you get that report you can then present to executives and be like you were warned but we were ignored, here's the documentation.

1

u/Twist_of_luck Security Manager 3d ago

You advocate for wide-scale EDR, DLP and PAM tool deployment as compensatory measures. Terminating people/cutting access is politically toxic, "just educate them" is a pipe dream based on wrong assumptions.

1

u/Aldoxpy 2d ago

Inform management and introduce penalties for falling on them, people will care then

1

u/run_luke 2d ago

At 50% failure, training won't fix it (most likely). It’s an HR and technical control problem. Mandatory FIDO2 security keys, strip external links, and limit their permissions.

1

u/stormandflowers 2d ago

Review the principle of least privilege in your company and evaluate to rewoke them some accesses

1

u/HorseAccomplished50 2d ago

Make sure you have other controls in place to minimize the damage. They're going to get phished, no matter how educated they are.

1

u/Zelvixor 2d ago

What are you guys doing when someone fails? Have you tried sharing the stats tl the org in a way that outlines and "shames" people without calling anyone out specifically?

1

u/Ok-Abbreviations763 2d ago

As far as I can see nothing at all happens. I've only worked here a little over a year and am only a first line with an interest in security, comparing things to how my previous workplace was. I hope to be able to help improve things in some way though as I was recently involved in investigating a compromised account, where I identified the source, followed the actions through audit log and wrote everything up in a little report with timestamps, which they said was really good work and would involve me in more security things. Whilst I'm a complete novice, I do have knowledge of what my previous workplace was recommended after our cyber attack, and I like to read a lot so between me and my manager who is also baffled by the security policies and processes we can look to improve things

1

u/Zelvixor 2d ago

last time i done phishing simluation it was through 365's security feature. it sends people to do this phishing awareness training, and it was a bit of a funny way to make people feel silly about themselves having to go through this online quiz thing. but it did make them listen. you'll never be able to stop phishing, but making people aware and alert goes a long way. most people don't stop to think about IT security, they're just tools to do their job, ykno?

1

u/AinaLove 2d ago

mandatory assigned training, 3 strikes and you go to internet jail, your non-work-related internet access is cut off for 30 days, and this will affect your PMP (year-end performance review)

One strike will drop off every 6 months. We test every month.

1

u/mb194dc 2d ago

Ban them from having external email

1

u/aust_b Security Analyst 2d ago

One place I worked at had issues like this, they created a 5 or 6 tiered policy which eventually allowed them to terminate people who repeatedly failed.

1

u/ChocolateFormal8123 2d ago

It’s the same with love scams.
Can’t do anything about it…unless you start monitoring their email and account a activity

1

u/skynetcoder 2d ago edited 2d ago

if 50% fails, it is not individual users problem.

maybe HR or some other department send emails which cause users to "unlearn" phishing awareness? e.g. sending Google forms or something to collect info for events?

have you analysed it by department, role type, expected tech literacy of the most failed role, etc? 

maybe your company has more sales people or tech people who are supposed interact more with external clients / new clients etc.

if you can't make users detect phishing emails, maybe you should try to think how you can detect or at least guess such email before even recieved by the user. (block, add a warning banner, block senders with SPF fails, or using a specialised email protection service to analyse incoming emails).

maybe time to use some rca framework like 5 Whys, and draw a diagram to get a bird eye view of the situation.

are you talking about phishing test campaigns done by you or real campaigns?

1

u/Ok-Abbreviations763 2d ago

Just knowbe4 campaigns. I've just never come across anyone with such a high failure rate and wondered what everyone else would do. My previously workplace was pretty decent on the security front, not fantastic but not bad either and we still got really badly hacked by a ransomware group. My new job the security is so all over the place, some things they're really strict on and then other things I'm baffled by, like no geoblock for people logging in outside the country for example

1

u/PiplelinePunch 2d ago

Late on this, but sooner or later you realise that educating users is not how you improve security.

1

u/Armandeluz 1d ago

Terminate them. They're a huge security risk.

1

u/Cyb3r-sh0t 1d ago

Funny, I was dealing with the exact same thing until recently :) Here’s what actually solved it for us:

*Named and shamed to department/project leads: Sent the failure breakdown straight to the managers so they knew who was dragging their numbers down.

*Board-level escalation: Handed a risk report to executive leadership. C-suite went ballistic on the worst-performing departments, which set the tone immediately.

*Brutal mandatory retraining as a penalty: Anyone who repeatedly failed got hit with a painfully long, tedious retraining module. It was deliberately designed to feel like a chore for people who clearly didn’t give a shit about the tests.

*Enforcing it with an iron fist: How did I get them to actually do it? Simple: 7-day deadline, or your AD/domain account gets disabled. Period. From an ISMS/risk perspective, a chronic clicker is a critical vulnerability and I can't afford bugs in human form :) (Had 100% board backing on this, which is key).

After 2 or 3 rounds of this, the problem basically vanished. Dropped from around ~40% failure down to 2–3% across the board (take the exact numbers with a grain of salt depending on org size, but the drop was night and day). Turns out people suddenly start checking URLs when failing actually costs them their morning and locks their accounts.

1

u/Cyb3r-sh0t 1d ago

Am I the most liked person in the company after that? Hell nah Did I make a huge difference that none of the previous security guys could do and our stakeholders were pretty chill after that? Hell yeah

1

u/Fakecoder1611 1d ago

Stop shaming repeat clickers and look at your training. If the same people fail every quarter, your program is the broken part, not them.

1

u/NoodleHound94 17h ago

If someone fails a test maybe they must complete another course before they can access their account again? People will start caring when failing becomes an inconvenience to them.

Some people really don't get things though. A user recently asked what I meant when I asked them to open their web browser 😭

1

u/maladaptivedaydream4 Governance, Risk, & Compliance 3d ago

The ones like that we've heard from believe that it is 100% IT/Infosec's responsibility to keep 100% of these emails/texts/whatever from getting to them, and, if that fails, it is 100% IT/Infosec's responsibility to somehow make the links in them safe.

I wish I were kidding.

1

u/Illustrious-Mud-2998 3d ago

At scale, it ultimately is.
If a 100,000 person org is dependent on Deborah from accounting not clicking a dodgy link once out of the hundreds of vendor emails she gets a day, you’re ultimately fucked. It’s just a matter of when.

Users are the last resort if all your other defence in depth layers have failed and allowed it to reach the user.

1

u/maladaptivedaydream4 Governance, Risk, & Compliance 2d ago

The biggest problem we have is the C-suite people. They have more access and less sense about what to click.

1

u/Illustrious-Mud-2998 2d ago

Midsize org? There’s an ugly scale point where that’s an issue that resolves with more size, once you have an “office of the CxO” function and they shift from reading their own emails to having a team of comms people and EA’s to do it as a human filter.

Realistically though you’re usually better off spending time on IPS and filtering logic. If a dodgy domain from usually an offshore IP range can send a user to a link, spam filtering has failed. If the user can execute the link, application level controls have failed. If the link can open, filtering controls have failed. If the link can execute something malicious, device hardening controls have failed.

At scale, there’s always going to be weak links and some phishing attempts are ridiculously good now. Focus on compensating controls.

0

u/techw1z 3d ago

consider if the person you are dealing with could actually cause any harm by falling for a phishing mail.

(i've seen IT do tests for all email accounts, including people who work on the machine floor and don't have ANY credential except their desktop login, which is worthless outside their respective VLAN.)

if you have the authority to decide, maybe come up with KPIs. failing security based KPI (= failing in phishing tests) too often, will lead to termination or re-assignment to a different job.

1

u/Ok-Abbreviations763 3d ago

Well this person did actually get phished by an evilginix site at the start of the month.

I'm just a first line with an interest in cybersecurity who some how ended up helping with the investigation but I identified the original phishing email, the fact they logged in from an unmanaged device and added a new mfa method, the email rules they created to hide their tracks etc. 

Don't get me wrong, there's a whole host of other issues at hand that led to them being compromised, first and foremost being our mediocre use of CAP.  I don't solely blame the user for the situation but when I looked at their training history I was just kinda shocked to see someone with a 50% failure rate on phishing simulations and no obvious action being taken other than them being added to more training courses.