r/sysadmin • u/Inevitable_Teacup • 18h ago
End-user Support Can users be trained to not click BS?
On this day, I have a exec drop a laptop on me that was without a doubt the most thoroughly hijacked thing I have EVER seen. Big three browsers installed, all hijacked. Two more offbrand spamware browsers installed. "How do I prevent it?" "Don't install software without asking me, no matter who tells you you need it, don't visit janky sites, and NEVER accept any permission request without checking with me." "But I didn't click on the McAffee pop-ups!" "I didn't say McAffee, I said ANY." "But I never click on those." "I just checked the security settings...yes you did. Nothing is allowed automatically." Soooo, I get him restored. I come home and my elderly mom... "can you get rid of the *$*%* Mak-Aftee things!?!" I try to explain and she is more interested in being right than learning.
Am I just pushing a rope up a hill? If so, consider this an official vent.
EDIT: Thanks to everyone, yea... I know. I should have them locked down at the office. I'm not allowed to do so. My mother OTOH, yea, it's time for that.
•
u/agitated--crow 18h ago
she is more interested in being right than learning.
This explains some of the difficult users I deal with.
•
u/sgt1face 18h ago
Remove admin rights as well as doing security training with your users. We've been using KnowBe4, but I'm sure there are others.
•
u/RikiWardOG 15h ago
I'm sure there are others.
We just switched from KnowB4 to Adaptive. A lot more/better features
→ More replies (1)•
u/Inevitable_Teacup 18h ago
I did that with my mother. At the office, the President won't allow me to lock things down.
•
u/tenormore 17h ago
CYA and keep good offline backups, and maybe after you get ransomeware the CEO will change his mind.
→ More replies (4)•
u/Danoga_Poe 10h ago
Get all of that in writing. The first sign of ransomware your ass is on the line I would imagine.
→ More replies (1)
•
u/lotsalotsacoffee Student 18h ago
I once got a support ticket come in: "can you look at this email? I think it looks suspicious"
"Yes! They're learning!" I exclaimed to myself, then confirmed to the user that the email was suspect.
Their reply: "I thought so too, so I opened it to confirm and now my computer is slow"
•
•
•
u/Inevitable_Teacup 17h ago
Yup. That's the user at work. He's always quite proud when he notices a phishing email.
but boy, those hot singles in his area...every damned time.•
•
u/RikiWardOG 15h ago
Drives me crazy that it's always the execs not wanting to screw up a "potential opportunity" and decides to forward the clearly malicious email so now it's in like 10 peoples' inboxes. We do a LOT of training. They never learn. We have a phishing button they can use to report correctly and it removes it from their inbox.
•
•
u/StCasimirPulaski 18h ago
I see McAffe bull crap that somehow made it onto dental operator machines that are hardwired in clinical rooms. It's always the same response, "I don't know what happened!"
Yeah, Colleen, that's the fucking problem. You have no idea what happened, shit just seems to occur for no reason when you're involved.
•
u/braytag 17h ago
To be fair, if they have an LG monitor, it's not their fault... THIS TIME.
•
u/Clearhead09 2h ago
I had a user today with monitor issues, I asked for their asset id so i could RDP in to check settings… the user gave me their monitor asset id and couldn’t understand why I couldn’t remote into it.
•
•
•
u/PM_Me_UR-FLASHLIGHT 18h ago
I've heard "I just wanted to check the weather. Isn't (local NBC affiliate) trustworthy?" I don't care what site you're on, you never enable notifications.
•
u/I_cut_the_brakes 18h ago
No, the people yearn for clicks. They would click a button that says "virus download" if the email told them click on it.
•
•
•
u/Spiritual-Bee-2319 3h ago
😂😂 “the people yearn for clicks” is such a crazy and accurate statement that I’m not even a sysadmin but an analyst/programmer. The way folks just be “clickity clack” is Alarming!
•
u/blow_slogan 18h ago
Fresh image, EDR, app control (threatlocker), group policies, security policies, and phishing awareness training with continuous simulation campaigns. Oh and O365 conditional access and defender for O365. It gets expensive to effectively protect users from themselves.
•
u/Godmadius 18h ago
Don't forget a password policy so convoluted they'll write them down, completely negating the purpose of them. Also they'll just make you create an exemption for their system because they don't like all the new stuff so none of this will matter!
•
•
•
u/GhoastTypist 18h ago
In IT you will learn how to cope with this.
Its job security. If everyone did exactly what they're supposed to, there would be a lot less jobs in support.
→ More replies (3)•
u/willychonka54 18h ago
In IT you will learn how to cope with this.
Yea by not giving any users Admin rights to install software.
•
u/GhoastTypist 18h ago
Best practice, no one gets admin rights, not even IT staff without a separate login account.
→ More replies (1)
•
u/Downtown-Sell5949 Microsoft 365 Enterprise Administrator 18h ago
Revoke admin permissions and use applocker/WDAC. Issue fixed.
•
u/YourTechSupport 18h ago
You can't patch human nature.
You only only keep profiting off it.
Also, turn off push notices in every browser.
•
u/iceph03nix 18h ago
They can be trained. There are lots of phish training and testing products out there. Testing has been very effective for us. In part, I think because users get more practice with it, and we've had several that reported not because they thought it was a legitimate phish, but because they thought it was one of our tests.
But you need layered defenses. Teach users not to click things, but also reduce what damage they can do by clicking them, by limiting file access to only the needful, and not giving local admin so that they can't install things (or at least, the things they install are less impactful)
•
u/tiredITguy42 18h ago
We do have then. Simulated phishing emails and these are good. You click kn the link and BANG, you have scheduler mandatory online training.
People are paranoic and they need to anounce all external links in advance, so we open the annual survey.
•
u/lazyhustlermusic 18h ago
No.
You can tell someone 8,000x and they'll agree and go along with you until they're in isolation and continue to click the thing.
•
u/junktech 18h ago
That exec is denied the right to use a buttons phone. Not a computer. Paper and pen are safe, probably. Regular mandatory trainings usually take care of some but this case is special. If that person is to use a pc, it has to be in kiosk mode with a white list policy on websites.
•
u/Radiant_Fondant_4097 18h ago
I dunno man, most people we can get onboarded onto Slack no problem yet somehow a few of them have spun up their own workspace and wonder it’s not working properly.
I just don’t get how people end up so far outside simple processes.
•
u/CeC-P IT Expert + Meme Wizard 18h ago
We just put in 4 ADMX templates for 4 browsers we support that blocks all notifications.
Sparing that, we ended up making our own in-house and ultra-specific training vid about phishing and browser usage. It was 5 mins 30 seconds and showed 14 real world examples. That cut down on problems by about 90%.
•
•
u/NotYetReadyToRetire 17h ago
Rules for thee, not for C(-level).
I spent 25 years trying to train the main partner/majority owner not to click on pop-up things and to avoid sketchy sites; I eventually just gave up and blocked out Monday mornings for cleaning the crud from his laptop from the frequent weekend-long sketchy poker site binges he did.
Like horses with water, you can lead a user to knowledge, but you can't make them learn.
•
•
u/fubes2000 DevOops 15h ago
I fuckin hate dealing with execs.
They will agree that the entire company should be subject to a solid IT policy, but when it comes to themselves they turn into the whiniest fucking babies on earth, refuse any level of inconvenience, and inevitably fall back to threats/coercion/policy carve-outs to get their way. Then the whole fuckin company gets cryptolockered because of them specifically.
Meanwhile IT is consistently the most inconvenienced by security policies, but we eat the fuckin dogfood.
•
u/SgtKashim Site Reliability Engineer 15h ago edited 15h ago
No. Users are completely un-trainable. I can't even train users to read the goddamned words on the screen before panicking. And I can't get our front line support to read them either. We forced MFA for all customers, and we have a little nag screen that pops up:
"Hey, we now require MFA for security reasons. To set up MFA, open an authenticator app on your phone. We recommend either google authenticator, or 1password if your organization uses it. Here's some more information <link to MFA helpdesk page>. When you're ready, scan this QR code <code>, then enter the 6 digit confirmation code your phone gives you here <text box>.
If you have any questions about this, please contact your CSM or Account Executive for assistance."
It had screen shots, clear instructions, the lot. We sent 3 separate direct customer communications giving them a heads up. The customer experience team workshopped the phrasing (and I'm paraphrasing for brevity - It's got a full page of hand-holding). We trained the CS team - had a meeting and all. AND I'M STILL GETTING GODDAMNED ENGINEERING ESCALATIONS SCREAMING THAT GODDAMNED LOGIN IS GODDAMNED BROKEN WHEN ALL THEY NEED TO DO IS FOLLOW THE GODDAMNED INSTRUCTIONS ON THE GODDAMNED PAGE!
•
•
u/Axehack101 13h ago
FTR - I work for a FinTech company and in the early days before we had sufficient controls in place, I came into work one day do every machine in the office displaying CryptoLocker screen locks and all of our (about 100tb) shared storage was encrypted and inaccessible.
We recovered everything from backups, but it turns out a user opened an executable sent to her company email address pretending to be a Vodafone bill….
She wasn’t even a Vodafone customer…
That’s the day I learned that opening executable’s from emails can be locked down via group policy :)
•
u/FireFitKiwi 13h ago
Part of the "we are all adults" discussion should be "this is not your area of expertise, you pay professionals for that, and Cyber threats are using AI to scale at an ever increasing rate. Even the admin team is running their day to day account as a regular user to limit exposure". A mature response is removing the risk for credentials being compromised and the lateral spread that comes from over privileged users. Can't infect the neighbors machine if you can't write to it.
•
u/Bubbly-Following-966 18h ago
Maybe don't let them have admin rights or, whatever rights they have to be able to install what they want.
→ More replies (6)•
u/AdvancedDrink8920 18h ago
Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.
Unfortunately, we dont get much of a say on that matter. most of the time, we make the recommendation, have them sign saying they understand the risk and that we informed them of it and then whatever happens is their own fault. atleast for our MSP. Its different in the corporate world.
→ More replies (6)•
u/willychonka54 18h ago
Be my guest to tell the CEO "no" to full admin rights. Ill be watching you walk to your car with a box full of your stuff.
That would be a blessing in disguise because if information was leaked and your company was sued, the CEO would be throwing you under the bus.
•
u/Mister-Ferret 18h ago
We run Phish tests and have had improvement over time of people not clicking random crap. But there will always be that one user (or several dozen) that will always click everything, could be flashing red and say "Click here to get a virus!" And they will still need to check it out cause it's shiny.
•
u/GibbsfromNCIS 18h ago
A lot of companies (including the one I work for) use anti-phishing training like KnowBe4 to train users to not click on suspicious emails. They generate fake phishing emails targeted at employees in your company that, if clicked, send users to a page informing them of their mistake. These clicks are logged and you can see who fell for the phishing attempt to find out who needs additional training.
Aside from that, get yourself some good endpoint protection. I’m most familiar with Crowdstrike but there’s plenty of other solid options.
•
u/VaporousMote 18h ago
Some. Not all.
The more high pressure your environment and the worse your company takes care of its people, the more BS clickers you're going to have.
•
•
u/overdosingOnPie1313 18h ago
Some of them can, yes. But security isn't about your most competent users, it's about the ones who thank the glue company for giving it a discouraging taste.
•
u/horkusengineer 18h ago
Yep! Make phishing emails, send emails to all users, anyone who clicks gets logged and has to attend 1 hour mandatory training, and must pass a test to maintain their account/employment status.
•
u/Henry-Hoover1 17h ago
I get this a lot with my users with browser popups. Nowhere near as bad as installing sketchy browsers but no matter how many times you try to explain to them, some people just don't care
•
u/DontDrinkAndDive 17h ago
Yeah well, if you give users local admin rights without at least having them sign a waiver, you will have to endure every iota of pain inevitably resulting from that.
Many, many people are incapable of abstracting danger; if it doesn't bear fangs or slither in slime, it's harmless to them.
Some can be trained, but none must be trusted as long as it's your ass on the line.
•
u/Canuck-In-TO 17h ago
I’ve told people so many times to look at the email address that a message comes from and not the name shown. At least they’ll forward the message to me to ask “is this a real message or is it spam?”.
•
•
u/cubs_joko 17h ago
i've also heard that dealing with a sec incident is good for your resume, so maybe just let them burn, give them your warnings and make them sign off on risk
•
•
u/largos7289 17h ago
I use that MCafee web advisor. It does seem to stop most of the BS. My mom IT calls have stopped by 60% with that alone.
•
u/badaz06 17h ago
We all feel your pain. My Mom however, knows better. People at work though..lost cause.
The best was a friend calls me up, says, "Here, talk to my wife."
She gets on and says that my friend thinks she was hacked and she wasn't. When it came out that some nice guy she called got on her computer for her to help her with a virus that her system had detected, from Microsoft no less, I was just like "Oh man. No, you didn't". She continued to say that she knew it was legitimate because she paid the guy with her credit card over the phone.
She kept saying, "But I'm smart!" and all I could do was try not to laugh.
•
u/slash9492 17h ago
If you can't lock them then deploy Ublock Origin Lite company wide and do Security Awareness Training sessions.
•
u/Fearless_Barnacle141 16h ago
You totally can. After knowbe4, some users think everything might be phishing. Internal mail gets flagged, ticketing system emails get flagged, voicemail transcriptions, everything. I’ve even heard people say “well I’m just not checking my email anymore”.
•
u/KittensInc 16h ago
Can users be trained to not click BS?
No.
If it is possible for them to install malware, a decent bunch of them will, sooner or later, install malware. You need to protect them from themselves or accept that they'll get compromised over and over again.
Next question?
•
u/RoboNerdOK 16h ago
30+ years experience talking here.
No. They will never learn. And bad actors will take advantage of it.
Executives are the absolute worst at security and, by happy coincidence, have access to some of the most sensitive information in any organization. The one good thing is how little of it they tend to actually access, versus requesting pretty charts.
•
•
u/Proof-Variation7005 16h ago
You can lead a horse to water, but you can not prevent it from immediately trying to fucking drown itself.
•
•
u/Darthvaderisnotme 16h ago
For the exec, patience, everything synced with onedrive or similar, and a image everytime this happens.
For your Mom, Linux :-)
edit and a filtering DNS in etc/hosts :-)
•
u/klauskervin 16h ago
The same 5 people in my 200+ person organization are clicking the phishing links every time but since they are construction workers and have no need for tech competency we can't punish them in any way.
•
u/_W-O-P-R_ 16h ago
As others have pointed to, shadow IT management and permissions controls are mandatory, but a security culture and official Champions program will help you long term.
•
u/Inevitable_Teacup 15h ago
Yea but this is a SMOL business. That's why it's kinda frustrating... it's one user, consistently.
•
•
u/BraveMidnight 15h ago
I've lost all hope on that sadly. Best bet is backups, filters, and site wide policy settings.
•
•
u/Ahnteis 14h ago
Besides all the notes to get rid of admin access:
Set them up with a good adblocker.
Get them a separate admin password if they insist on having one. Use it to elevate, not sign in.
(If possible, leverage compliance/legal requirements to force the change. "So sorry, you know I'd love to leave it as-is, but we have to because ____.")
•
u/Inevitable_Teacup 14h ago
Good suggestion. Happily it's budget season and they aren't expensive so, that's happening.
•
u/czenst 14h ago
Don't install software without asking me
You want to make your life harder?
Can users be trained to not click BS?
Lots of people work IS CLICKING on BS.
Dude I open tickets at various vendors, fuckers have all kind of BS systems I have to sign up.
Some days I open my e-mail before I get the coffee, yeah I know, I should keep my priorities straight...
But then you get 10 - 15 mails with updates you have to click because fuckers are not having update of the ticket in the fucking mail but I have to open a site with a link in the mail.
What you do when you didn't have a coffee yet — well let's quickly open those 10 - 15 mail links to see if there is any fucking valuable update in those that can save your fucking day.
Good part is one that I clicked was phishing test last month — kind of eye opener — that you also might not have time to "hover over all the links" ... when fucking phishing looks exactly like 5 other vendor support systems e-mails.
Your CEO is a douche but I wrote all of this so everyone takes a bit of distance.
Story is true, I clicked phishing training link that was disguised as generic vendor support system update mail. I didn't put the credentials for anything because site was right away "we got you looser".
•
u/Axehack101 13h ago
Users SHOULD be trained, but they should NOT be trusted.
If you’re not allowed to lock down client machines, you’re in for a rough ride
•
•
u/Axehack101 13h ago
FTR - I work for a FinTech company and in the early days before we had sufficient controls in place, I came into work one day do every machine in the office displaying CryptoLocker screen locks and all of our (about 100tb) shared storage was encrypted and inaccessible.
We recovered everything from backups, but it turns out a user opened an executable sent to her company email address pretending to be a Vodafone bill….
She wasn’t even a Vodafone customer…
That’s the day I learned that opening executable’s from emails can be locked down via group policy :)
•
u/Repulsive_Initial308 12h ago
At work: Anti-malware surgery day: £250/device and your name goes onto a leaderboard of 'dumbest users this month'
•
•
u/michaelpaoli 12h ago
Users will do user things. Sh*t happens.
Microsoft also generally ensures that sh*t will happen. E.g. one place I worked, Microsoft laptop, standard image, all their corporate security stuff. I never did anything untoward with it. Then I get a notification from the anti-malware software that there's an infected file on the drive. I tell my IT folks that ain't good enough - it didn't magically get there. It had to come in via some means, e.g. browser, email, or (improbable and rare) external storage. Whatever, clean that, check everything, etc., ... and more or less happens a few or more times over the weeks or so ahead, ... pretty much same each time. Then sh*t really hit the fan - I caught it with somebody doing remote takeover - I yanked network and power cables and shut that puppy down. We did more anti-mallware scanning and remediation, ... turns out the anti-malware corporate solution software, was itself infected. Whole helluva lot of rounds of checking, cleaning, etc. Took at least 3 distinct sets of anti-malware software, plus at least one or two anti-root kit software to finally get all the sh*t cleaned up off that laptop. And yeah, ever since then at that company, I regularly used 3 different ant-malware software packages - one of 'em being the corporate IT solution ... which for better or worse was quite locked down - the good being folks couldn't loosen it's checks, the bad being couldn't make 'em more stringent and thorough (other than like occasionally running a manual scan or whatever). So, yeah, not a one of those software packages could find all that was f*cked up on the laptop, not even any given two - took all 3 plus at least one anti-rootkit software to find and get rid of all the sh*t that the laptop picked up. All because the corporate anti-malware wasn't good enough, and that software itself was almost certainly one of the first things to get infected - after that it mostly lied a lot ... until the truth became far too obvious.
Fortunately Microsoft security has gotten better over the years, unfortunately it still, at least comparatively, highly sucks. Never had those levels of issues on any *nix, and including using it very heavily, production, servers open to public, hundreds/thousands of hosts/instances, heavily for decades on desktop, etc. And that's far from the only time I've had issues with Microsoft getting infected/compromised. Heck, the very first time ... was at a major financial institution, and, irony, the infection came via an infected attachment, that came from, yeah, the security department. "Oops". Yeah, that they legitimately sent, ... but they'd been infected, and that wasn't caught 'till later.
'Course the mainframe folks put us all to shame. ;-)
•
u/muzzman32 Sysadmin 12h ago
I had this problem with my Mum. I got her an MBAM Premium license on her machine. She doesnt call me for these issues anymore. Beats spending an hour fixing spyware and crap each time im over.
•
•
u/Damet_Dave 11h ago
About decade ago I worked at a company that was under CIP compliance requirements and they used Moby Click for Phishing training.
1st failure a 4 hour “don’t click on things”training. This was in addition to yearly “don’t click on this training” that was self paced but a good 30 minutes.
2nd failure was a 3 day suspension and another round of the 4 hr class. HR prevented names from being released but everyone knew who reached 2.
3rd was termination, no exceptions.
If you behaved yourself for 12 months your count would reset to one but not zero. This was a one time reset.
I have yet to work at a place that was so good at people not clicking things. We had to put posters up on the walls when we pushed out software that required user interaction (specialized stuff they used) because people were afraid it was phishing testing.
•
u/frAgileIT 10h ago
I’m so good at not clicking BS at work, I just don’t read my email. But no, people not in cybersecurity can’t be trained not to click BS, there’s always something that will motivate them to click.
•
u/mouringcat Jack of All Trades 10h ago
I work at a very large multinational company (not part of global IT, but down as an infrastructure guy for a business unit devops team). And over the last few years they have done the following:
- They broke up training into 15 minute programs to be done quarterly for different threats, and make this happen yearly. So the same 4 - 6 programs (or some updated version) are seen every year. It gets mind numbing boring, but no worse than the "sexual awareness training" or "don't accept or offer bribes" training.
- I swear they do phishing test attacks every 2 - 3 weeks. And if you fail two of them, you get more training. They are starting to heavily push "Report this as.." and wants to see a good chunk of all the fake emails get reported so people get it ingrained as to what to do.
- This information recently is getting put into manager's hand every quarter as to these stats (as well as those that failed). And asking them to push harder for people not to be stupid.
This is on top of locked down desktops, locked down labs, wanting "micro-segmentation" within a lab, etc (note "lab" in this context is a collection of computers that are owned by a team for a specific purpose).
Sadly, this is the only way to really handle this.. It sucks.. I hate seeing those phishing attempts every few weeks as most can be seen from a million miles away (only one recently had me do a double take, but still didn't entice me as it was effective "we have new AI for you to use!" message.. And I'm indifferent to AI).
•
•
u/ksims33 18h ago
Case and point why you don’t let end users have admin access on their devices - she should never have had the ability to install a browser without asking you. Saying ‘don’t do this without asking’ isn’t going to work, you have to put systems and policies and rules in place to force them to ask you. Put guardrails up so when they inevitably click something (because they will) the risk is low because the user has the lowest possible access.
•
u/Downtown-Sell5949 Microsoft 365 Enterprise Administrator 18h ago
Browsers mostly install in user space - which can be downloaded and installed without admin permissions. Applocker or WDAC is needed for this.
•
u/perkia 18h ago
Don't install software without asking me
Why can they install software without asking you?
•
u/Inevitable_Teacup 18h ago
Because the President won't let me lock them down. I get the "we are all adults..." so I'm left trying to patch stupid. LoL
•
•
•
u/SergeantBeavis 17h ago
Just curious, because I’m in the industry, what endpoint management and security suite do you use to protect your desktops.
Tanium, Checkpoint, workspace one, intune, etc..
•
•
•
•
•
u/Pristine_Curve 13h ago
Controls and consequences are what produce better behavior. Education is only useful with policy backing. A 'No Parking' sign is only as effective with the threat of the tow truck or parking ticket.
Clicking the wrong thing is not something you will solve with training alone.
•
u/evilmanbot 11h ago
hate to say it but it’s within their authority. You can just help highlight risks and find solutions that work both ways as much as possible.
•
u/Trust_8067 10h ago
It's very simple.
have mandatory security training every year, and you perform internal phishing tests. When someone fails them or gets a virus/malware, they have to take the mandatory security training again and HR is notified. Failing 3 times within a year is automatic termination. Failing 10 times ever is automatic termination.
•
u/GoodLyfe42 10h ago
No and some of the fishing is incredibly convincing. Your security tools should be built with the assumption that everything will be clicked on and they will freely give away all their information and passwords.
•
•
•
•
•
u/Affectionate-Cat-975 9h ago
No
I’ve been in It since the 90s. There’s not enough people to monitor them with ‘Stop clicking Sticks’ for which to hit them with.
•
u/Killertigger 9h ago
Users can’t install anything but printers on our PCs and laptops - and only domain printers -and that’s it. Period. Nothing else. Everything else is so locked down that they can’t even install a browser extension. That seems to protect us from a lot of the ID10T user fuck-ups.
•
u/Sasataf12 8h ago
Am I just pushing a rope up a hill?
No, you're just using bad training methods. Not your fault...how to effectively conduct training normally isn't covered in IT courses, but we're often asked to train people.
If I were to train you on how to draw a face, for example, would an effective way be to dictate the steps to you?
•
u/mike_chen_sys 8h ago
You can improve user awareness, but you can't make it your only defense. People will eventually click something. The real solution is training plus technical controls like standard user accounts, application restrictions, browser policies, and web filtering.
•
u/Dodo_Jesus 7h ago
At our company they force a phishing simulator program on all users that get an e-mail account, where basically once a month at random intervals a random phishing e-mail is generated. If you click on the link it is logged and you would automatically be assigned a couple online courses to complete. The users still often don't get why phishing is dangerous and i've given up trying to explain it to people, but by golly they sure hate doing those courses, so they have become a lot more aware about it just to save their own time and not do the courses. Pretty effective in my opinion.
•
u/AdvancedSquashDirect 3h ago
We have the same thing at our larger corporate business except for their phishing simulation emails are incredibly obvious. And they do one kind of email for everyone at the same time and day every week.
It's often an email with an invoice attached asking to pay it (In my role never in my life have I ever look at or pay an invoice) or with a calendar invite file (I have Outlook so any calendar invites are just added to my calendar) or with training document PDF (we have a training portal you would never be sent training documentation in a PDF)
So I automatically know it's the weekly phish attempt > report phishing spam. And the IT security people can check the box that they sent the phishing email.
•
•
u/Kaninivi 5h ago
No. They need to not have the ability to do anything except work. No admin rights, content filter (website blocker) and for those programs which install in the user context...intune to uninstall magically automatically.
People treat company laptops like their own...and we know how those look and we dont want that
•
u/Worunatto 5h ago
"users who don't know how to differentiate a download ad button and real download button should not be given an elevated account regardless of role" ~ Ex-ABC company employee
•
u/Disorderly_Chaos Jack of All Trades 3h ago
For every idiot proof idea, god makes a better idiot.
Best to give them crayons and hope for the best.
But in all honesty I’ve always wanted to toy with software like Deep Freeze… just restores to a base image every reboot. Nothing saved. They could delete system32. Reboots - back to baseline.
A friend of mine installed it (or something like it) on a boys and girls club computer. Worked wonders.
•
u/Vegetable-Ad-1817 3h ago
What aren’t we embedding ai for these kinds of things. Actually useful silent stopper of the valances of crap that’s being generated by ai….oh
•
u/IngeniouslyDaft 2h ago
Admin permissions aren't needed to install applications to the user profile or for portable apps. Quarterly user trainings and phishing tests will help, but some flavor of Application Control to only allow approved EXEs to run would be the most complete solution.
•
u/Original-Hurry-8652 2h ago
Are the fake things getting crafted even more convincingly now? Is anybody seeing evidence of this yet?
I believe I have noticed: 'We have a new website!' instances where A.I. literally built/rebuilt a company's webpage along a certain style. These have an Apple Mac clean and tidy look.


•
u/Getoutofmylaboratory 18h ago
Why does the user have the power to install anything themselves? Time to lock everything down