Jump to content

Recommended Posts

Posted

I'm looking to create some Phishing awareness training for staff, has anybody else done this and how did you do it?

 

Obviously want to ensure people engage and watch any videos/presentations that I create, without them being too long it puts them off

 

Any suggestions appreciated

Posted
Morning, we have recently partnered with a company called Boxphish who do just that - cybersecurity awareness and phishing simulation. It is all managed for you, so can be hands-off from an admin perspective, with some strong reporting that tracks progress. It requires 5mins of users time PCM and has free student modules. We've been really impressed with it - we're due to start a launch later this week, but we could send some information over to you before. We're also running some 20 min 1 on 1 demos. Alternatively, we have put this short (3 min) overview video together.
Posted

We will be looking at 'Sophos Phish' which comes with our LGfL bundle.

 

However, I've seen concerns have been raised on other threads about the way in which it is done and the impact on the user though.

 

How much do you tell them about what is about to happen (and how do you word it)?

 

Do you have the time/resources to train the users where issues are identified?

 

We may not see it as a problem and be quite certain of its necessity, but could be seen as an under-hand way of targetting certain individual employees...

 

It could make others very upset if they believe they have done something wrong (even if they have) - 'you know Mavis in admin is nearly due for retirement and now won't even open her emails'....

 

Interested to hear others thoughts/opinions or how they have accomplished it.

Posted

We had one done as part of a penetration test. No one was told before hand what was happening, not even the rest of the IT team and I didn't know when it was coming. The way we went about it was that it was part of a wider security training push. I did a online Safety inset for staff and incorporated it with that. No names were used but the numerical results were shown to give people an idea of how it went and how far people went. I then showed the emails and how they could have been spotted. A bit softly, softly but the intention was to take people along a learning path, not scare the pants off them.

 

Sorry if this is harsh but if Mavis is too scared to open emails she needs training to help her or she needs to retire. What would be done if a receptionist said they were too scared to let anyone in through the door or too scared to answer the phone.

Posted
We used KnowBe4 a couple of years ago. No-one was told about it (not even the Head!) and a "you must click here to change your password" message went out to all staff on a Friday afternoon, just after they all left for the day. I got a lot of forwarded emails, and a few phone calls about it. Only one person clicked on the link (that person claimed they knew it was a test and did it "just to see what happened") - it took them to a page explaining what they should have spotted in the original message.
Posted (edited)
Sorry if this is harsh but if Mavis is too scared to open emails she needs training to help her or she needs to retire. What would be done if a receptionist said they were too scared to let anyone in through the door or too scared to answer the phone.

 

I know, I know... :p

 

Well, it was more of a 'be aware' of how you portray this and how you deal with the outcomes, but I'll admit it was an extreme kind of example...

 

But believe me, I know of one or two staff here that even if you try to frame 'help/guidance/training' in the best possible light it will be taken very poorly, as in 'I know how to do my job, I've been here 20 years'...

 

Even if you try to tell them a lot of things have changed since fax machines! ;)

 

EDIT: ...and to be fair your examples are different situations, with different stimuli and fear responses for different reasons... they might actually need counselling rather than training.

Edited by Koldov
Posted

We’re about to use Microsoft’s Attack Simulator which comes as part of our Office 365 subscription.

 

We’ve trained staff about security threats including phishing and let them know that a test phishing email will be sent out over the coming month.

After the results from that come back, we’ll look to launch another phishing email which staff aren’t pre-warned about.

 

Microsoft Attack Simulator can be linked up so that users enter a training course (you can select which course you want them to do) if they interact with the phishing email, it also points out the things to look for with the specific email you sent out.

 

The only thing I’ve found is that Chrome sometimes marks the site you’re taken to if you click the link as suspicious, so we had to play around until we found a domain that wasn’t flagged - there’s plenty of options.

  • 2 weeks later...
Posted
We’re about to use Microsoft’s Attack Simulator which comes as part of our Office 365 subscription.

 

Doesn't that need the extra Office 365 defender 2 subscription?

Posted

Just to mention that whilst setting up and going through creating a 'campaign' in Sophos Phish, getting all the user emails in to the Sophos Central Admin portal, choosing a 'design' of email, working out whether to sign up to training etc...

 

One thing I didn't count on was the email system we use. It is an O365 set-up (with a front-end by 'itsLearning') and it dumped the email in the Junk folder with all the links disabled...

 

Phish.jpg

 

So, I guess 'reasonably' well protected already

 

I don't think I'm going to have much luck asking them to whitelist all the IPs and Domains Sophos Phish requires and turning off whatever junk filter is applied... back to the drawing board.

Posted
Just to mention that whilst setting up and going through creating a 'campaign' in Sophos Phish, getting all the user emails in to the Sophos Central Admin portal, choosing a 'design' of email, working out whether to sign up to training etc...

 

One thing I didn't count on was the email system we use. It is an O365 set-up (with a front-end by 'itsLearning') and it dumped the email in the Junk folder with all the links disabled...

 

[ATTACH=CONFIG]61592[/ATTACH]

 

So, I guess 'reasonably' well protected already

 

I don't think I'm going to have much luck asking them to whitelist all the IPs and Domains Sophos Phish requires and turning off whatever junk filter is applied... back to the drawing board.

 

I’m pretty sure you could create a quick transport rule to bypass it.

Posted
Morning, we have recently partnered with a company called Boxphish who do just that - cybersecurity awareness and phishing simulation. It is all managed for you, so can be hands-off from an admin perspective, with some strong reporting that tracks progress. It requires 5mins of users time PCM and has free student modules. We've been really impressed with it - we're due to start a launch later this week, but we could send some information over to you before. We're also running some 20 min 1 on 1 demos. Alternatively, we have put this short (3 min) overview video together.

 

We're interested.

 

Please can you DM me so we can get a quote?

  • Thanks 1
Posted
Not sure I follow...

 

Unfortunately I don't have any access to anywhere I put any rules in, the service is managed for us

 

You will probably need your provider to do it then.

Posted
As part of this to minimise cyber scurity threat risk to the IT system, has any of you thought of having/ or have subscribed to a Cyber security essentials for schools service, with security baseline assessment and some include accreditation towards Essentials assessment? as detailed here https://iasme.co.uk/cyber-essentials-for-schools/

 

There is a separate thread on this http://www.edugeek.net/forums/security/220988-cyber-essentials-schools.html

Posted
I’m pretty sure you could create a quick transport rule to bypass it.

 

I'm looking at Sophos Threat Management - but obviously want to avoid all the emails going in to Spam - can you give me a clue as to where in Exchange Online we'd make the transport rules so I can check it out?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...