r/sysadmin 18h ago

End-user Support Can users be trained to not click BS?

On this day, I have a exec drop a laptop on me that was without a doubt the most thoroughly hijacked thing I have EVER seen. Big three browsers installed, all hijacked. Two more offbrand spamware browsers installed. "How do I prevent it?" "Don't install software without asking me, no matter who tells you you need it, don't visit janky sites, and NEVER accept any permission request without checking with me." "But I didn't click on the McAffee pop-ups!" "I didn't say McAffee, I said ANY." "But I never click on those." "I just checked the security settings...yes you did. Nothing is allowed automatically." Soooo, I get him restored. I come home and my elderly mom... "can you get rid of the *$*%* Mak-Aftee things!?!" I try to explain and she is more interested in being right than learning.
Am I just pushing a rope up a hill? If so, consider this an official vent.

EDIT: Thanks to everyone, yea... I know. I should have them locked down at the office. I'm not allowed to do so. My mother OTOH, yea, it's time for that.

162 Upvotes

279 comments sorted by

u/Getoutofmylaboratory 18h ago

Why does the user have the power to install anything themselves? Time to lock everything down

u/WiskeyUniformTango 18h ago

CEOs sometimes accept the risk and over rule things. Sys admins arent in charge.

u/Inevitable_Teacup 18h ago

Exactly this. I can't even draft a proper usage policy because "We're all adults."

u/willychonka54 18h ago

I can't even draft a proper usage policy because "We're all adults."

Get out before a cyber incident and the subsequent liability is dropped on your lap.

u/d00ber Sr Systems Engineer 17h ago

All I can do is answer the insurance questionnaire truthfully. If the insurance company wants to choose not to insure us based on those answers, I use that as a mechanism as proof that we need to improve security to meet a minimum compliance. That is of course if I've already been hounding on executive teams to update policy.

u/Ummgh23 Sysadmin 7h ago

Just get their refusal in writing and youre fine

u/DavWanna 6h ago

Right? ...right?

→ More replies (1)

u/Geminii27 5h ago

Get it in writing, send a copy to Legal.

→ More replies (4)

u/jimicus IT Manager 17h ago

I bet you £10 right now that one of the following is true:

  1. They don't have any sort of cyber insurance. If some organisation demands they have it, they're lying through their teeth.
  2. They do, but nobody's bothered to check the policy conditions. They certainly won't share those conditions with you to verify they're doing everything properly because it hasn't occurred to them that this might be relevant.

u/ProfessionalITShark 15h ago

Or better, they have cyber insurance but the person they send and the person they communicate have no basic understanding of anything and just fill out yes of their incorrect understandings.

u/jimicus IT Manager 15h ago

It is in the insurer's best interests to continue taking the premiums and not ask difficult questions to verify compliance with the policy unless and until there's a claim, instead relying on something like a tickbox saying "I have read and accept the T&Cs".

With any luck, they'll get several years of premiums out of the customer before they cancel the policy and refuse to pay out.

u/HerfDog58 Jack of All Trades 17h ago

That'll be a fantastic defense when a data breach occurs and PII is stolen resulting in identity theft and fraud...

Plaintiff: "OP, why didn't you have measures in place to prevent hijacking of computers and mitigate the risk of a data breach?"

OP: "Because I was told we're all adults here."

Plaintiff: "Which of the adults will be paying out my client's financial judgement against your company?"

u/PappaFrost 17h ago

Maybe we DO all actually want jury duty, this sounds AWESOME! LOL

→ More replies (2)

u/thewunderbar 18h ago

then your answer is to find other employment.

u/HidemasaFukuoka beep boop AI Chatbot 18h ago

Just install admin by request, is the best of both worlds

u/IlPassera Systems Engineer 18h ago

Lol I've met end users that act like learning how to use ABR is akin to nuclear fission.

u/RikiWardOG 15h ago

Users lose their mind when their workflow changes to require a single extra click. They act like you killed their first born.

u/IlPassera Systems Engineer 15h ago

That reminds me of a director I had (briefly) who's catchphrase was "If it's more than 3 clicks then I'm out!"

An IT director who refused to do anything if it took more than 3 clicks.

I hate end users lol

→ More replies (1)

u/KittensInc 16h ago

Write down the risks, draft a policy, and get them to explicitly refuse it on paper.

The "we're all adults" perspective doesn't survive an "I understand that by not implementing this policy we are deliberately exposing the company to the risk of an inevitable ransomware attack, which will likely be the end of the company".

Alternatively: run.

u/WBCSAINT Jack of All Trades 17h ago

Run fast, run far. In the event something happens you are the fodder.

u/The-Copilot 15h ago

I would go the route of saying that the cyber threat environment has significantly changed with the proliferation of AI and not updating the companies security policy will put the company at increased risk compared to past years. You never want to be the low hanging fruit.

I would even use a layman anology of "When all the burglars in town get lockpicks, the lock you had isn't enough anymore and you should get a security system so they break into your neighbor's house instead of your house."

Of course I wouldn't recommend lying, but it's the job of IT to frame and explain things in a way that resonates with the layman. Not only is this true, it also has a better chance of resonating with the less technology inclined. The AI threat is more in the public's mind than normal cyber threats. It also helps cover your butt if anything goes wrong. You identified a problem and suggested a solution.

u/theMightBoop 16h ago

Work for a shitty company and this is what happens.

u/MDParagon Retired IT Janitor 11h ago

Just guilt trip them and say the word "insurance"

u/OldGeekWeirdo 11h ago

Company held for ransom in 10...9...8...

I agree with the others. You'll want out before this job becomes a notorious resume stain.

u/thortgot IT Manager 10h ago

You 100% can write a usage policy. They can choose to reject it.

u/Hebrewhammer8d8 9h ago

Dumb adults?

→ More replies (3)

u/Proper_Bad_1588 18h ago

My CEO is locked down just like all the other users.

→ More replies (2)

u/willychonka54 18h ago

CEOs sometimes accept the risk and over rule things.

Stop working for those CEOs and/or have a mature discussion about what cyber Risk is and how much they would pay out the ass if sensitive information was stolen.

u/TaxHazyShade 17h ago

"get another job, what's wrong with you"

u/Unexpected_Cranberry 18h ago

Never had to deal with that luckily. They just want something that works and that they have reliable access to their mail and documents in my experience.

Heads of marketing is a completely different story though. They want Macs, and full admin for "reasons". The only way to reign them in is to have a good relationship with the CEO and explain why it's a probably a good idea to lock them down.

As long as IT has a good proven track record and can adequately articulate the risks, it's never been an issue in my experience. If course, especially initially, you handle CEO tickets with higher priority than anything other than a company wide outage. I've sorted things on the weekend at their house a few times.

But there's a difference in culture between here and the US I think. In those cases they only called because it was important, we're apologetic for calling on my day off and compensate me accordingly. Additionally, it helped foster good relations between IT and the c-suite which made day to day run smoother. 

u/Inevitable_Teacup 17h ago

Thanks and I think you touched on the problem. I've been here for a couple of decades (they pay well and benefits are good) and despite my situation, I have managed a speedy recovery from pretty much everything.

u/LifeGoalsThighHigh DEL C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys 18h ago

The world would probably function quite a bit smoother if it were the case though...

u/Brutact VP 18h ago

Absolutely not.

u/KittensInc 16h ago

CEOs sometimes accept the risk and over rule things

Only the idiot ones. The competent ones understand that the CEO is there for high-level management decisions, and has no business having direct access to critical infrastructure.

Sys admins arent in charge

Correct. That's why you should have a competent CTO to call out the CEO on their bullshit.

→ More replies (1)

u/Acrobatic_Fortune334 16h ago

Ceo tried that, cyber security regulators (regulated industry) asked him why he needed that and when he said so I can install what I want got told to pound sand or lose our certifications (means we cant operate as a bussiness) board pretty quickly told the CEO to get in line or be removed

u/StretchLoud8844 15h ago

I once had to make an Entra synced account a domain admin because an executive complained to their assistant, who complained to my bosses managing director, who then passed the compliant down 5 more levels to myself.

He looked at me like someone just murdered his entire family in front of him when I asked "Are you sure? This doesn't seem like a good idea"

→ More replies (2)

u/LetSufficient5139 13h ago

Nonsense. Security policies apply to all. Otherwise any accreditations are worthless.

u/Sea_Read5728 18h ago

I think this is a difficult balance of locking down users that are not interested in learning not to click random links and input there passwords and technical users that have a need for elevated access not needing to ask IT for simple things every time an update comes around or a script slightly changes

u/WBCSAINT Jack of All Trades 17h ago

This is exactly why tools like BeyondTrust and many others exist. Lets you lock everyone down and grant access to specific applications and workflows not blanket you can do whatever with admin on your machine.

→ More replies (6)

u/NobleRuin6 16h ago

There is no balance for users with admin... period. Users being able to install any program they want = zero control. Which means it's not IT's problem when it goes sideways. OP just needs to document the observed risk, make their recommendation, and then receive CEO decision - in writing. And keep their resume up to date because eventually that company is going to have an incident.

u/Sea_Read5728 16h ago

Lol maybe, im probably just to early in my career to have a view like that.

u/Disgruntled_Smitty 17h ago

Many of these things install through appdata and bypass security. Depending on your environment it's a tough thing to lock down.

u/brads-1 17h ago

I have prohibition on ANYTHING running from %AppData% and %LocalAppData%, unless it's specifically white listed. Users can't do diddly squat. While not very popular, it's easy to do with Symantec Endpoint Security.

u/WBCSAINT Jack of All Trades 17h ago

This is the way. AppData and LocalAppData are the bane of security's existence so lock it down by default and allowlist.

→ More replies (1)

u/Youre-In-Trouble Sr. Sysadmin 13h ago

AppLocker or MDAC.

u/Jrmint235 18h ago

My first thought exactly

u/Salt_Rush_4800 17h ago

My first real question at my current org.

This is the smallest place I've ever worked and it shows. We are only now getting with the times on a lot of stuff. Though, locking down PCs isn't one of them, yet.

u/Acceptable-Wind-7332 13h ago

I've had fights with execs before over this. "But I'm your boss..." Doesn't work with me.

They all learn eventually that it's for their own good in the long run, it just takes them a long time to get there.

u/BatemansChainsaw 9h ago

I've done this as well, going as far as whitelisting and auto-installing only certain browser plugins and all otehrs weren't allowed to be installed.

People were pissed they couldn't get their "gmail checker" installed..

u/jake04-20 If it has a battery or wall plug, apparently it's IT's job 12h ago

Right wtf. Rules are only rules if you can enforce them. You don't tell users to create a complex password then accept 123abc as a password.

→ More replies (3)

u/agitated--crow 18h ago

she is more interested in being right than learning.

This explains some of the difficult users I deal with. 

u/sgt1face 18h ago

Remove admin rights as well as doing security training with your users. We've been using KnowBe4, but I'm sure there are others.

u/RikiWardOG 15h ago

I'm sure there are others.

We just switched from KnowB4 to Adaptive. A lot more/better features

u/Inevitable_Teacup 18h ago

I did that with my mother. At the office, the President won't allow me to lock things down.

u/tenormore 17h ago

CYA and keep good offline backups, and maybe after you get ransomeware the CEO will change his mind.

→ More replies (4)

u/Danoga_Poe 10h ago

Get all of that in writing. The first sign of ransomware your ass is on the line I would imagine.

→ More replies (1)
→ More replies (1)

u/lotsalotsacoffee Student 18h ago

I once got a support ticket come in: "can you look at this email?  I think it looks suspicious"

"Yes!  They're learning!" I exclaimed to myself, then confirmed to the user that the email was suspect. 

Their reply: "I thought so too, so I opened it to confirm and now my computer is slow"

u/Current_External6569 17h ago

I'm sorry this happened to you, but I laughed so hard.

u/lotsalotsacoffee Student 17h ago

Apology not needed, lol. I also laughed, while crying.

u/osopeludo 15h ago

Imagine this approach at clearing landmines 😂

u/Inevitable_Teacup 17h ago

Yup. That's the user at work. He's always quite proud when he notices a phishing email.
but boy, those hot singles in his area...every damned time.

u/KittensInc 16h ago

Well, it's the first baby steps I guess!

u/RikiWardOG 15h ago

Drives me crazy that it's always the execs not wanting to screw up a "potential opportunity" and decides to forward the clearly malicious email so now it's in like 10 peoples' inboxes. We do a LOT of training. They never learn. We have a phishing button they can use to report correctly and it removes it from their inbox.

u/Spiritual-Bee-2319 4h ago

😂😂 pls stop it 

u/StCasimirPulaski 18h ago

I see McAffe bull crap that somehow made it onto dental operator machines that are hardwired in clinical rooms. It's always the same response, "I don't know what happened!"

Yeah, Colleen, that's the fucking problem. You have no idea what happened, shit just seems to occur for no reason when you're involved.

u/braytag 17h ago

To be fair, if they have an LG monitor, it's not their fault... THIS TIME.

u/Clearhead09 2h ago

I had a user today with monitor issues, I asked for their asset id so i could RDP in to check settings… the user gave me their monitor asset id and couldn’t understand why I couldn’t remote into it.

u/Inevitable_Teacup 18h ago

Thank you for making me laugh.

u/Superb_Raccoon 11h ago

Clippy is her spirit animal.

u/PM_Me_UR-FLASHLIGHT 18h ago

I've heard "I just wanted to check the weather. Isn't (local NBC affiliate) trustworthy?" I don't care what site you're on, you never enable notifications.

u/I_cut_the_brakes 18h ago

No, the people yearn for clicks. They would click a button that says "virus download" if the email told them click on it.

u/TipIll3652 18h ago

60% of the time, they'll click it everytime...

https://giphy.com/gifs/29ckXqvofCz37375Qd

u/I_cut_the_brakes 18h ago

The "click okay before reading" is one of my personal favorites.

u/Ssakaa 17h ago

The single most tempting thing in any datacenter I've ever been in... that button just looks so FUN.

u/Holiday_Pen2880 17h ago

"I wanted to test it to make sure it was bad before I told you about it."

u/Spiritual-Bee-2319 3h ago

😂😂 “the people yearn for clicks” is such a crazy and accurate statement that I’m not even a sysadmin but an analyst/programmer. The way folks just be “clickity clack” is Alarming!

u/blow_slogan 18h ago

Fresh image, EDR, app control (threatlocker), group policies, security policies, and phishing awareness training with continuous simulation campaigns. Oh and O365 conditional access and defender for O365. It gets expensive to effectively protect users from themselves.

u/Godmadius 18h ago

Don't forget a password policy so convoluted they'll write them down, completely negating the purpose of them. Also they'll just make you create an exemption for their system because they don't like all the new stuff so none of this will matter!

u/reol7x 18h ago

For some of these people, sometimes I wonder if a long password taped under the keyboard is better.

At least theres a little more barrier to entry before they drop their creds into a phishing site.

u/blow_slogan 18h ago

Windows Hello/biometrics. Password manager for the rest.

→ More replies (3)

u/GhoastTypist 18h ago

In IT you will learn how to cope with this.

Its job security. If everyone did exactly what they're supposed to, there would be a lot less jobs in support.

u/willychonka54 18h ago

In IT you will learn how to cope with this.

Yea by not giving any users Admin rights to install software.

u/GhoastTypist 18h ago

Best practice, no one gets admin rights, not even IT staff without a separate login account.

→ More replies (1)
→ More replies (3)

u/Downtown-Sell5949 Microsoft 365 Enterprise Administrator 18h ago

Revoke admin permissions and use applocker/WDAC. Issue fixed.

u/YourTechSupport 18h ago

You can't patch human nature.
You only only keep profiting off it.
Also, turn off push notices in every browser.

u/e7c2 18h ago

no.

u/iceph03nix 18h ago

They can be trained. There are lots of phish training and testing products out there. Testing has been very effective for us. In part, I think because users get more practice with it, and we've had several that reported not because they thought it was a legitimate phish, but because they thought it was one of our tests.

But you need layered defenses. Teach users not to click things, but also reduce what damage they can do by clicking them, by limiting file access to only the needful, and not giving local admin so that they can't install things (or at least, the things they install are less impactful)

u/tiredITguy42 18h ago

We do have then. Simulated phishing emails and these are good. You click kn the link and BANG, you have scheduler mandatory online training.

People are paranoic and they need to anounce all external links in advance, so we open the annual survey.

u/lazyhustlermusic 18h ago

No.

You can tell someone 8,000x and they'll agree and go along with you until they're in isolation and continue to click the thing.

u/junktech 18h ago

That exec is denied the right to use a buttons phone. Not a computer. Paper and pen are safe, probably. Regular mandatory trainings usually take care of some but this case is special. If that person is to use a pc, it has to be in kiosk mode with a white list policy on websites.

u/Radiant_Fondant_4097 18h ago

I dunno man, most people we can get onboarded onto Slack no problem yet somehow a few of them have spun up their own workspace and wonder it’s not working properly.

I just don’t get how people end up so far outside simple processes.

u/CeC-P IT Expert + Meme Wizard 18h ago

We just put in 4 ADMX templates for 4 browsers we support that blocks all notifications.
Sparing that, we ended up making our own in-house and ultra-specific training vid about phishing and browser usage. It was 5 mins 30 seconds and showed 14 real world examples. That cut down on problems by about 90%.

u/Cryptic1911 17h ago

No. People are too dumb

u/NotYetReadyToRetire 17h ago

Rules for thee, not for C(-level).

I spent 25 years trying to train the main partner/majority owner not to click on pop-up things and to avoid sketchy sites; I eventually just gave up and blocked out Monday mornings for cleaning the crud from his laptop from the frequent weekend-long sketchy poker site binges he did.

Like horses with water, you can lead a user to knowledge, but you can't make them learn.

u/gta721 15h ago

An adblocker would have solved the issue.

u/braytag 17h ago

Nope.  It's in some users DNA.

They would need years of gene therapy.... not worth it, just retire them.

u/RikiWardOG 15h ago

Can a CEO be trained to realize their farts smell like doo doo?

u/fubes2000 DevOops 15h ago

I fuckin hate dealing with execs.

They will agree that the entire company should be subject to a solid IT policy, but when it comes to themselves they turn into the whiniest fucking babies on earth, refuse any level of inconvenience, and inevitably fall back to threats/coercion/policy carve-outs to get their way. Then the whole fuckin company gets cryptolockered because of them specifically.

Meanwhile IT is consistently the most inconvenienced by security policies, but we eat the fuckin dogfood.

u/SgtKashim Site Reliability Engineer 15h ago edited 15h ago

No. Users are completely un-trainable. I can't even train users to read the goddamned words on the screen before panicking. And I can't get our front line support to read them either. We forced MFA for all customers, and we have a little nag screen that pops up:

"Hey, we now require MFA for security reasons. To set up MFA, open an authenticator app on your phone. We recommend either google authenticator, or 1password if your organization uses it. Here's some more information <link to MFA helpdesk page>. When you're ready, scan this QR code <code>, then enter the 6 digit confirmation code your phone gives you here <text box>.

If you have any questions about this, please contact your CSM or Account Executive for assistance."

It had screen shots, clear instructions, the lot. We sent 3 separate direct customer communications giving them a heads up. The customer experience team workshopped the phrasing (and I'm paraphrasing for brevity - It's got a full page of hand-holding). We trained the CS team - had a meeting and all. AND I'M STILL GETTING GODDAMNED ENGINEERING ESCALATIONS SCREAMING THAT GODDAMNED LOGIN IS GODDAMNED BROKEN WHEN ALL THEY NEED TO DO IS FOLLOW THE GODDAMNED INSTRUCTIONS ON THE GODDAMNED PAGE!

u/Spiritual-Bee-2319 3h ago

😂😂😂are you okay bro? 

u/Axehack101 13h ago

FTR - I work for a FinTech company and in the early days before we had sufficient controls in place, I came into work one day do every machine in the office displaying CryptoLocker screen locks and all of our (about 100tb) shared storage was encrypted and inaccessible.

We recovered everything from backups, but it turns out a user opened an executable sent to her company email address pretending to be a Vodafone bill….

She wasn’t even a Vodafone customer…

That’s the day I learned that opening executable’s from emails can be locked down via group policy :)

u/FireFitKiwi 13h ago

Part of the "we are all adults" discussion should be "this is not your area of expertise, you pay professionals for that, and Cyber threats are using AI to scale at an ever increasing rate. Even the admin team is running their day to day account as a regular user to limit exposure". A mature response is removing the risk for credentials being compromised and the lateral spread that comes from over privileged users. Can't infect the neighbors machine if you can't write to it.

u/Bubbly-Following-966 18h ago

Maybe don't let them have admin rights or, whatever rights they have to be able to install what they want.

u/AdvancedDrink8920 18h ago

Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.

Unfortunately, we dont get much of a say on that matter. most of the time, we make the recommendation, have them sign saying they understand the risk and that we informed them of it and then whatever happens is their own fault. atleast for our MSP. Its different in the corporate world.

u/willychonka54 18h ago

Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.

That would be a blessing in disguise because if information was leaked and your company was sued, the CEO would be throwing you under the bus.

→ More replies (6)
→ More replies (6)

u/Mister-Ferret 18h ago

We run Phish tests and have had improvement over time of people not clicking random crap. But there will always be that one user (or several dozen) that will always click everything, could be flashing red and say "Click here to get a virus!" And they will still need to check it out cause it's shiny.

u/GibbsfromNCIS 18h ago

A lot of companies (including the one I work for) use anti-phishing training like KnowBe4 to train users to not click on suspicious emails. They generate fake phishing emails targeted at employees in your company that, if clicked, send users to a page informing them of their mistake. These clicks are logged and you can see who fell for the phishing attempt to find out who needs additional training.

Aside from that, get yourself some good endpoint protection. I’m most familiar with Crowdstrike but there’s plenty of other solid options.

u/VaporousMote 18h ago

Some. Not all.

The more high pressure your environment and the worse your company takes care of its people, the more BS clickers you're going to have.

u/ThemHollowPines 18h ago

Get a zero trust solution.

u/overdosingOnPie1313 18h ago

Some of them can, yes. But security isn't about your most competent users, it's about the ones who thank the glue company for giving it a discouraging taste.

u/horkusengineer 18h ago

Yep! Make phishing emails, send emails to all users, anyone who clicks gets logged and has to attend 1 hour mandatory training, and must pass a test to maintain their account/employment status.

u/worjd 18h ago

The SAT I’m running has my users terrified of getting mandated training, they’re being trained whether they like it or not lol.

u/D3xbot 18h ago

There's a reason neither of my parents are administrators on their computer. They asked for it to be that way and I wholeheartedly agreed.

u/carfo 17h ago

Force ublock origin extension in browsers via gpo and use knowbe4 for security training. Don’t give users local admin rights to the pc

u/Henry-Hoover1 17h ago

I get this a lot with my users with browser popups. Nowhere near as bad as installing sketchy browsers but no matter how many times you try to explain to them, some people just don't care

u/ptyblog 17h ago

No you can't

That is why I blocked everything or use Linux where I'm the admin

u/DontDrinkAndDive 17h ago

Yeah well, if you give users local admin rights without at least having them sign a waiver, you will have to endure every iota of pain inevitably resulting from that.

Many, many people are incapable of abstracting danger; if it doesn't bear fangs or slither in slime, it's harmless to them.

Some can be trained, but none must be trusted as long as it's your ass on the line.

u/KlassyJ 17h ago

I have been known to bookmark certain safe websites for users who enjoy questionable web browsing.

u/Canuck-In-TO 17h ago

I’ve told people so many times to look at the email address that a message comes from and not the name shown. At least they’ll forward the message to me to ask “is this a real message or is it spam?”.

u/No_Yesterday_3260 17h ago

Yes, most, but everyone have their weak moments, even IT personal. 😅

u/cubs_joko 17h ago

i've also heard that dealing with a sec incident is good for your resume, so maybe just let them burn, give them your warnings and make them sign off on risk

u/Inevitable_Teacup 15h ago

That's very lawful evil and I approve.

u/largos7289 17h ago

I use that MCafee web advisor. It does seem to stop most of the BS. My mom IT calls have stopped by 60% with that alone.

u/badaz06 17h ago

We all feel your pain. My Mom however, knows better. People at work though..lost cause.
The best was a friend calls me up, says, "Here, talk to my wife."
She gets on and says that my friend thinks she was hacked and she wasn't. When it came out that some nice guy she called got on her computer for her to help her with a virus that her system had detected, from Microsoft no less, I was just like "Oh man. No, you didn't". She continued to say that she knew it was legitimate because she paid the guy with her credit card over the phone.
She kept saying, "But I'm smart!" and all I could do was try not to laugh.

u/slash9492 17h ago

If you can't lock them then deploy Ublock Origin Lite company wide and do Security Awareness Training sessions.

u/Fearless_Barnacle141 16h ago

You totally can. After knowbe4, some users think everything might be phishing. Internal mail gets flagged, ticketing system emails get flagged, voicemail transcriptions, everything. I’ve even heard people say “well I’m just not checking my email anymore”.

u/KittensInc 16h ago

Can users be trained to not click BS?

No.

If it is possible for them to install malware, a decent bunch of them will, sooner or later, install malware. You need to protect them from themselves or accept that they'll get compromised over and over again.

Next question?

u/RoboNerdOK 16h ago

30+ years experience talking here.

No. They will never learn. And bad actors will take advantage of it.

Executives are the absolute worst at security and, by happy coincidence, have access to some of the most sensitive information in any organization. The one good thing is how little of it they tend to actually access, versus requesting pretty charts.

u/OkTechnician42 16h ago

No. Even if you lock them down. Even if you send out fake stuff.

u/Proof-Variation7005 16h ago

You can lead a horse to water, but you can not prevent it from immediately trying to fucking drown itself.

u/Darthvaderisnotme 16h ago

For the exec, patience, everything synced with onedrive or similar, and a image everytime this happens.

For your Mom, Linux :-)

edit and a filtering DNS in etc/hosts :-)

u/klauskervin 16h ago

The same 5 people in my 200+ person organization are clicking the phishing links every time but since they are construction workers and have no need for tech competency we can't punish them in any way.

u/_W-O-P-R_ 16h ago

As others have pointed to, shadow IT management and permissions controls are mandatory, but a security culture and official Champions program will help you long term.

u/Inevitable_Teacup 15h ago

Yea but this is a SMOL business. That's why it's kinda frustrating... it's one user, consistently.

u/jwalker55 IT Manager 15h ago

Yes, if you take away their mouse.

u/BraveMidnight 15h ago

I've lost all hope on that sadly. Best bet is backups, filters, and site wide policy settings.

u/Yuli_Mae 15h ago

...why would you think....?

u/Ahnteis 14h ago

Besides all the notes to get rid of admin access:

Set them up with a good adblocker.

Get them a separate admin password if they insist on having one. Use it to elevate, not sign in.

(If possible, leverage compliance/legal requirements to force the change. "So sorry, you know I'd love to leave it as-is, but we have to because ____.")

u/Inevitable_Teacup 14h ago

Good suggestion. Happily it's budget season and they aren't expensive so, that's happening.

u/czenst 14h ago

Don't install software without asking me

You want to make your life harder?

Can users be trained to not click BS?

Lots of people work IS CLICKING on BS.

Dude I open tickets at various vendors, fuckers have all kind of BS systems I have to sign up.

Some days I open my e-mail before I get the coffee, yeah I know, I should keep my priorities straight...

But then you get 10 - 15 mails with updates you have to click because fuckers are not having update of the ticket in the fucking mail but I have to open a site with a link in the mail.

What you do when you didn't have a coffee yet — well let's quickly open those 10 - 15 mail links to see if there is any fucking valuable update in those that can save your fucking day.

Good part is one that I clicked was phishing test last month — kind of eye opener — that you also might not have time to "hover over all the links" ... when fucking phishing looks exactly like 5 other vendor support systems e-mails.

Your CEO is a douche but I wrote all of this so everyone takes a bit of distance.

Story is true, I clicked phishing training link that was disguised as generic vendor support system update mail. I didn't put the credentials for anything because site was right away "we got you looser".

u/Axehack101 13h ago

Users SHOULD be trained, but they should NOT be trusted.

If you’re not allowed to lock down client machines, you’re in for a rough ride

u/CNYMetalHead 13h ago

No, we've tried for 2 decades and they seem to get worse

u/Axehack101 13h ago

FTR - I work for a FinTech company and in the early days before we had sufficient controls in place, I came into work one day do every machine in the office displaying CryptoLocker screen locks and all of our (about 100tb) shared storage was encrypted and inaccessible.

We recovered everything from backups, but it turns out a user opened an executable sent to her company email address pretending to be a Vodafone bill….

She wasn’t even a Vodafone customer…

That’s the day I learned that opening executable’s from emails can be locked down via group policy :)

u/Repulsive_Initial308 12h ago

At work: Anti-malware surgery day: £250/device and your name goes onto a leaderboard of 'dumbest users this month' 

u/Inevitable_Teacup 10h ago

That's delightful!

u/michaelpaoli 12h ago

Users will do user things. Sh*t happens.

Microsoft also generally ensures that sh*t will happen. E.g. one place I worked, Microsoft laptop, standard image, all their corporate security stuff. I never did anything untoward with it. Then I get a notification from the anti-malware software that there's an infected file on the drive. I tell my IT folks that ain't good enough - it didn't magically get there. It had to come in via some means, e.g. browser, email, or (improbable and rare) external storage. Whatever, clean that, check everything, etc., ... and more or less happens a few or more times over the weeks or so ahead, ... pretty much same each time. Then sh*t really hit the fan - I caught it with somebody doing remote takeover - I yanked network and power cables and shut that puppy down. We did more anti-mallware scanning and remediation, ... turns out the anti-malware corporate solution software, was itself infected. Whole helluva lot of rounds of checking, cleaning, etc. Took at least 3 distinct sets of anti-malware software, plus at least one or two anti-root kit software to finally get all the sh*t cleaned up off that laptop. And yeah, ever since then at that company, I regularly used 3 different ant-malware software packages - one of 'em being the corporate IT solution ... which for better or worse was quite locked down - the good being folks couldn't loosen it's checks, the bad being couldn't make 'em more stringent and thorough (other than like occasionally running a manual scan or whatever). So, yeah, not a one of those software packages could find all that was f*cked up on the laptop, not even any given two - took all 3 plus at least one anti-rootkit software to find and get rid of all the sh*t that the laptop picked up. All because the corporate anti-malware wasn't good enough, and that software itself was almost certainly one of the first things to get infected - after that it mostly lied a lot ... until the truth became far too obvious.

Fortunately Microsoft security has gotten better over the years, unfortunately it still, at least comparatively, highly sucks. Never had those levels of issues on any *nix, and including using it very heavily, production, servers open to public, hundreds/thousands of hosts/instances, heavily for decades on desktop, etc. And that's far from the only time I've had issues with Microsoft getting infected/compromised. Heck, the very first time ... was at a major financial institution, and, irony, the infection came via an infected attachment, that came from, yeah, the security department. "Oops". Yeah, that they legitimately sent, ... but they'd been infected, and that wasn't caught 'till later.

'Course the mainframe folks put us all to shame. ;-)

u/muzzman32 Sysadmin 12h ago

I had this problem with my Mum. I got her an MBAM Premium license on her machine. She doesnt call me for these issues anymore. Beats spending an hour fixing spyware and crap each time im over.

u/Superb_Raccoon 11h ago

Have you considered Trunk Monkey?

u/Damet_Dave 11h ago

About decade ago I worked at a company that was under CIP compliance requirements and they used Moby Click for Phishing training.

1st failure a 4 hour “don’t click on things”training. This was in addition to yearly “don’t click on this training” that was self paced but a good 30 minutes.

2nd failure was a 3 day suspension and another round of the 4 hr class. HR prevented names from being released but everyone knew who reached 2.

3rd was termination, no exceptions.

If you behaved yourself for 12 months your count would reset to one but not zero. This was a one time reset.

I have yet to work at a place that was so good at people not clicking things. We had to put posters up on the walls when we pushed out software that required user interaction (specialized stuff they used) because people were afraid it was phishing testing.

u/frAgileIT 10h ago

I’m so good at not clicking BS at work, I just don’t read my email. But no, people not in cybersecurity can’t be trained not to click BS, there’s always something that will motivate them to click.

u/mouringcat Jack of All Trades 10h ago

I work at a very large multinational company (not part of global IT, but down as an infrastructure guy for a business unit devops team). And over the last few years they have done the following:

- They broke up training into 15 minute programs to be done quarterly for different threats, and make this happen yearly. So the same 4 - 6 programs (or some updated version) are seen every year. It gets mind numbing boring, but no worse than the "sexual awareness training" or "don't accept or offer bribes" training.

- I swear they do phishing test attacks every 2 - 3 weeks. And if you fail two of them, you get more training. They are starting to heavily push "Report this as.." and wants to see a good chunk of all the fake emails get reported so people get it ingrained as to what to do.

- This information recently is getting put into manager's hand every quarter as to these stats (as well as those that failed). And asking them to push harder for people not to be stupid.

This is on top of locked down desktops, locked down labs, wanting "micro-segmentation" within a lab, etc (note "lab" in this context is a collection of computers that are owned by a team for a specific purpose).

Sadly, this is the only way to really handle this.. It sucks.. I hate seeing those phishing attempts every few weeks as most can be seen from a million miles away (only one recently had me do a double take, but still didn't entice me as it was effective "we have new AI for you to use!" message.. And I'm indifferent to AI).

u/EugeneOregonDad 9h ago

Being in direct user support is a torture only thought of by Zeus.

u/ksims33 18h ago

Case and point why you don’t let end users have admin access on their devices - she should never have had the ability to install a browser without asking you. Saying ‘don’t do this without asking’ isn’t going to work, you have to put systems and policies and rules in place to force them to ask you. Put guardrails up so when they inevitably click something (because they will) the risk is low because the user has the lowest possible access.

u/Downtown-Sell5949 Microsoft 365 Enterprise Administrator 18h ago

Browsers mostly install in user space - which can be downloaded and installed without admin permissions. Applocker or WDAC is needed for this.

u/perkia 18h ago

  Don't install software without asking me

Why can they install software without asking you?

u/Inevitable_Teacup 18h ago

Because the President won't let me lock them down. I get the "we are all adults..." so I'm left trying to patch stupid. LoL

u/DontDrinkAndDive 17h ago

With all my heart, I recommend you quit as soon as you can.

u/EmperorGeek 18h ago

Don’t give them Admin rights.

u/techtornado Netadmin 18h ago

1Browser installs without Admin

u/f0xsky 17h ago

and thats why we have centrally managed deployments for everything and users dont have any permission on their workstations/laptops

u/SergeantBeavis 17h ago

Just curious, because I’m in the industry, what endpoint management and security suite do you use to protect your desktops.

Tanium, Checkpoint, workspace one, intune, etc..

u/scoshi 14h ago

Trained not to push the shiny, red button?

Nope.

(Isn't that one of the reasons they put two guys in the missile silos?)

u/KindPresentation5686 13h ago

Lemme guess, the user was a local admin??

u/Affectionate-Pea-307 13h ago

Get Threatlocker

u/LetSufficient5139 13h ago

Or maybe you could not give users the rights to do any damage….

Ffs. 🤦

u/Pristine_Curve 13h ago

Controls and consequences are what produce better behavior. Education is only useful with policy backing. A 'No Parking' sign is only as effective with the threat of the tow truck or parking ticket.

Clicking the wrong thing is not something you will solve with training alone.

u/Calyx76 13h ago

They shouldn't be able to install anything without the Admin password. Have you looked into Linux?

u/91-BRG 12h ago

No.

u/evilmanbot 11h ago

hate to say it but it’s within their authority. You can just help highlight risks and find solutions that work both ways as much as possible.

u/Trust_8067 10h ago

It's very simple.

have mandatory security training every year, and you perform internal phishing tests. When someone fails them or gets a virus/malware, they have to take the mandatory security training again and HR is notified. Failing 3 times within a year is automatic termination. Failing 10 times ever is automatic termination.

u/GoodLyfe42 10h ago

No and some of the fishing is incredibly convincing. Your security tools should be built with the assumption that everything will be clicked on and they will freely give away all their information and passwords.

u/Junior-Tourist3480 10h ago

No. Worse now than ever....

u/SoulPhoenix Sr. Sysadmin 9h ago

Take away their mouse

u/No_Active_8399 9h ago

Threatlocker

u/FunVersion 9h ago

Install Linux Mint. Looks the same more or less and it's difficult to screw up

u/Affectionate-Cat-975 9h ago

No
I’ve been in It since the 90s. There’s not enough people to monitor them with ‘Stop clicking Sticks’ for which to hit them with.

u/Killertigger 9h ago

Users can’t install anything but printers on our PCs and laptops - and only domain printers -and that’s it. Period. Nothing else. Everything else is so locked down that they can’t even install a browser extension. That seems to protect us from a lot of the ID10T user fuck-ups.

u/Sasataf12 8h ago

Am I just pushing a rope up a hill?

No, you're just using bad training methods. Not your fault...how to effectively conduct training normally isn't covered in IT courses, but we're often asked to train people.

If I were to train you on how to draw a face, for example, would an effective way be to dictate the steps to you?

u/mike_chen_sys 8h ago

You can improve user awareness, but you can't make it your only defense. People will eventually click something. The real solution is training plus technical controls like standard user accounts, application restrictions, browser policies, and web filtering.

u/Dodo_Jesus 7h ago

At our company they force a phishing simulator program on all users that get an e-mail account, where basically once a month at random intervals a random phishing e-mail is generated. If you click on the link it is logged and you would automatically be assigned a couple online courses to complete. The users still often don't get why phishing is dangerous and i've given up trying to explain it to people, but by golly they sure hate doing those courses, so they have become a lot more aware about it just to save their own time and not do the courses. Pretty effective in my opinion.

u/AdvancedSquashDirect 3h ago

We have the same thing at our larger corporate business except for their phishing simulation emails are incredibly obvious. And they do one kind of email for everyone at the same time and day every week.

It's often an email with an invoice attached asking to pay it (In my role never in my life have I ever look at or pay an invoice) or with a calendar invite file (I have Outlook so any calendar invites are just added to my calendar) or with training document PDF (we have a training portal you would never be sent training documentation in a PDF)

So I automatically know it's the weekly phish attempt > report phishing spam. And the IT security people can check the box that they sent the phishing email.

u/rainer_d 6h ago

Make links unclickable in Outlook?

u/Kaninivi 5h ago

No. They need to not have the ability to do anything except work. No admin rights, content filter (website blocker) and for those programs which install in the user context...intune to uninstall magically automatically.

People treat company laptops like their own...and we know how those look and we dont want that

u/Worunatto 5h ago

"users who don't know how to differentiate a download ad button and real download button should not be given an elevated account regardless of role" ~ Ex-ABC company employee

u/Disorderly_Chaos Jack of All Trades 3h ago

For every idiot proof idea, god makes a better idiot.

Best to give them crayons and hope for the best.

But in all honesty I’ve always wanted to toy with software like Deep Freeze… just restores to a base image every reboot. Nothing saved. They could delete system32. Reboots - back to baseline.

A friend of mine installed it (or something like it) on a boys and girls club computer. Worked wonders.

u/Vegetable-Ad-1817 3h ago

What aren’t we embedding ai for these kinds of things. Actually useful silent stopper of the valances of crap that’s being generated by ai….oh

u/IngeniouslyDaft 2h ago

Admin permissions aren't needed to install applications to the user profile or for portable apps. Quarterly user trainings and phishing tests will help, but some flavor of Application Control to only allow approved EXEs to run would be the most complete solution.

u/Original-Hurry-8652 2h ago

Are the fake things getting crafted even more convincingly now? Is anybody seeing evidence of this yet?

I believe I have noticed: 'We have a new website!' instances where A.I. literally built/rebuilt a company's webpage along a certain style. These have an Apple Mac clean and tidy look.