Most breaches start with a person, not a firewall. We teach the people who are being targeted, using the kinds of attempts we see in the field.
You can buy every tool on the market and still lose to one convincing email. The people being targeted are usually the ones with the least technical background and the most authority to move money: the office manager, the bookkeeper, the person who processes wires. They aren't going to read a security policy.
We send controlled phishing attempts and see who clicks. Nobody gets named or embarrassed. The point is to find out which patterns work on your particular staff, then teach against those specifically rather than against a generic list.
Not everyone is going to become good at spotting a fake, and pretending otherwise is how programs fail. We teach the staff who can learn it and build the controls tighter around the ones who can't, so a mistake doesn't become an incident.
Watch the reports as much as the clicks. Somebody forwarding a suspicious message to us is a chance to stop the real one. That's the habit that catches the real one.
We send the controlled version first, so the real one arrives at people who have seen it before.
Start a Conversation