Craig_W Posted April 13, 2021 Posted April 13, 2021 I'm looking to create some Phishing awareness training for staff, has anybody else done this and how did you do it? Obviously want to ensure people engage and watch any videos/presentations that I create, without them being too long it puts them off Any suggestions appreciated
Rob_D Posted April 13, 2021 Posted April 13, 2021 We signed up to https://phishinsight.trendmicro.com/. We're still setting it up so haven't done more than a test run so far, but it all looks good.
Net-Ctrl Posted April 13, 2021 Posted April 13, 2021 Morning, we have recently partnered with a company called Boxphish who do just that - cybersecurity awareness and phishing simulation. It is all managed for you, so can be hands-off from an admin perspective, with some strong reporting that tracks progress. It requires 5mins of users time PCM and has free student modules. We've been really impressed with it - we're due to start a launch later this week, but we could send some information over to you before. We're also running some 20 min 1 on 1 demos. Alternatively, we have put this short (3 min) overview video together.
fiza Posted April 13, 2021 Posted April 13, 2021 There is also GoPhish which is open source. https://getgophish.com/
Koldov Posted April 13, 2021 Posted April 13, 2021 We will be looking at 'Sophos Phish' which comes with our LGfL bundle. However, I've seen concerns have been raised on other threads about the way in which it is done and the impact on the user though. How much do you tell them about what is about to happen (and how do you word it)? Do you have the time/resources to train the users where issues are identified? We may not see it as a problem and be quite certain of its necessity, but could be seen as an under-hand way of targetting certain individual employees... It could make others very upset if they believe they have done something wrong (even if they have) - 'you know Mavis in admin is nearly due for retirement and now won't even open her emails'.... Interested to hear others thoughts/opinions or how they have accomplished it.
TechMonkey Posted April 13, 2021 Posted April 13, 2021 We had one done as part of a penetration test. No one was told before hand what was happening, not even the rest of the IT team and I didn't know when it was coming. The way we went about it was that it was part of a wider security training push. I did a online Safety inset for staff and incorporated it with that. No names were used but the numerical results were shown to give people an idea of how it went and how far people went. I then showed the emails and how they could have been spotted. A bit softly, softly but the intention was to take people along a learning path, not scare the pants off them. Sorry if this is harsh but if Mavis is too scared to open emails she needs training to help her or she needs to retire. What would be done if a receptionist said they were too scared to let anyone in through the door or too scared to answer the phone.
Craig_W Posted April 13, 2021 Author Posted April 13, 2021 Thanks all - putting a PPT together and will look into GoPhish
smurfomatic Posted April 13, 2021 Posted April 13, 2021 We used KnowBe4 a couple of years ago. No-one was told about it (not even the Head!) and a "you must click here to change your password" message went out to all staff on a Friday afternoon, just after they all left for the day. I got a lot of forwarded emails, and a few phone calls about it. Only one person clicked on the link (that person claimed they knew it was a test and did it "just to see what happened") - it took them to a page explaining what they should have spotted in the original message.
Koldov Posted April 13, 2021 Posted April 13, 2021 (edited) Sorry if this is harsh but if Mavis is too scared to open emails she needs training to help her or she needs to retire. What would be done if a receptionist said they were too scared to let anyone in through the door or too scared to answer the phone. I know, I know... Well, it was more of a 'be aware' of how you portray this and how you deal with the outcomes, but I'll admit it was an extreme kind of example... But believe me, I know of one or two staff here that even if you try to frame 'help/guidance/training' in the best possible light it will be taken very poorly, as in 'I know how to do my job, I've been here 20 years'... Even if you try to tell them a lot of things have changed since fax machines! EDIT: ...and to be fair your examples are different situations, with different stimuli and fear responses for different reasons... they might actually need counselling rather than training. Edited April 13, 2021 by Koldov
nahtan Posted April 13, 2021 Posted April 13, 2021 We’re about to use Microsoft’s Attack Simulator which comes as part of our Office 365 subscription. We’ve trained staff about security threats including phishing and let them know that a test phishing email will be sent out over the coming month. After the results from that come back, we’ll look to launch another phishing email which staff aren’t pre-warned about. Microsoft Attack Simulator can be linked up so that users enter a training course (you can select which course you want them to do) if they interact with the phishing email, it also points out the things to look for with the specific email you sent out. The only thing I’ve found is that Chrome sometimes marks the site you’re taken to if you click the link as suspicious, so we had to play around until we found a domain that wasn’t flagged - there’s plenty of options.
supportman Posted April 22, 2021 Posted April 22, 2021 We’re about to use Microsoft’s Attack Simulator which comes as part of our Office 365 subscription. Doesn't that need the extra Office 365 defender 2 subscription?
Koldov Posted April 23, 2021 Posted April 23, 2021 Just to mention that whilst setting up and going through creating a 'campaign' in Sophos Phish, getting all the user emails in to the Sophos Central Admin portal, choosing a 'design' of email, working out whether to sign up to training etc... One thing I didn't count on was the email system we use. It is an O365 set-up (with a front-end by 'itsLearning') and it dumped the email in the Junk folder with all the links disabled... So, I guess 'reasonably' well protected already I don't think I'm going to have much luck asking them to whitelist all the IPs and Domains Sophos Phish requires and turning off whatever junk filter is applied... back to the drawing board.
FN-GM Posted April 23, 2021 Posted April 23, 2021 Just to mention that whilst setting up and going through creating a 'campaign' in Sophos Phish, getting all the user emails in to the Sophos Central Admin portal, choosing a 'design' of email, working out whether to sign up to training etc... One thing I didn't count on was the email system we use. It is an O365 set-up (with a front-end by 'itsLearning') and it dumped the email in the Junk folder with all the links disabled... [ATTACH=CONFIG]61592[/ATTACH] So, I guess 'reasonably' well protected already I don't think I'm going to have much luck asking them to whitelist all the IPs and Domains Sophos Phish requires and turning off whatever junk filter is applied... back to the drawing board. I’m pretty sure you could create a quick transport rule to bypass it.
Koldov Posted April 23, 2021 Posted April 23, 2021 Not sure I follow... Unfortunately I don't have any access to anywhere I put any rules in, the service is managed for us
kennysarmy Posted April 23, 2021 Posted April 23, 2021 Morning, we have recently partnered with a company called Boxphish who do just that - cybersecurity awareness and phishing simulation. It is all managed for you, so can be hands-off from an admin perspective, with some strong reporting that tracks progress. It requires 5mins of users time PCM and has free student modules. We've been really impressed with it - we're due to start a launch later this week, but we could send some information over to you before. We're also running some 20 min 1 on 1 demos. Alternatively, we have put this short (3 min) overview video together. We're interested. Please can you DM me so we can get a quote? 1
Net-Ctrl Posted April 23, 2021 Posted April 23, 2021 Will do. Pricing is based on staff numbers, students come free. I will send you a PM now.
FN-GM Posted April 24, 2021 Posted April 24, 2021 Not sure I follow... Unfortunately I don't have any access to anywhere I put any rules in, the service is managed for us You will probably need your provider to do it then.
armadillo Posted April 28, 2021 Posted April 28, 2021 As part of this to minimise cyber scurity threat risk to the IT system, has any of you thought of having/ or have subscribed to a Cyber security essentials for schools service, with security baseline assessment and some include accreditation towards Essentials assessment? as detailed here https://iasme.co.uk/cyber-essentials-for-schools/ 1
fiza Posted April 29, 2021 Posted April 29, 2021 As part of this to minimise cyber scurity threat risk to the IT system, has any of you thought of having/ or have subscribed to a Cyber security essentials for schools service, with security baseline assessment and some include accreditation towards Essentials assessment? as detailed here https://iasme.co.uk/cyber-essentials-for-schools/ There is a separate thread on this http://www.edugeek.net/forums/security/220988-cyber-essentials-schools.html
armadillo Posted April 29, 2021 Posted April 29, 2021 There is a separate thread on this http://www.edugeek.net/forums/security/220988-cyber-essentials-schools.html I've seen that thread already, the question is if undertaking the cyber essential C or C+ a requirement for schools? Thanks
kennysarmy Posted April 30, 2021 Posted April 30, 2021 I’m pretty sure you could create a quick transport rule to bypass it. I'm looking at Sophos Threat Management - but obviously want to avoid all the emails going in to Spam - can you give me a clue as to where in Exchange Online we'd make the transport rules so I can check it out?
kennysarmy Posted May 4, 2021 Posted May 4, 2021 Found this guide: https://help.usecure.io/en/articles/3675054-whitelisting-by-ip-address-in-office-365
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now