Chapter 81. Let’s Go Phishing
Siggi Bjarnason
The majority of security incidents happen due to phishing, and I have a surefire way to avoid becoming a phishing victim. Just don’t click on links in emails or open attachments. Yes, I do realize that this advice is about as useful as telling someone to stop smoking or not eat donuts. It is a lot easier said than done. Also, any suggestion that starts with the word “just” tends to be suspect. Hear me out, though, as I explain how this could be implemented.
This needs to start with a culture of not sending unexpected links or attachments around. There needs to be an internal document repository site that is automatically a part of everyone’s bookmarks. Rather than attaching a file or sending a link to it, in the email describe where on the internal site it can be found. Something like “the document can be found under documents ˃ ProjectX > design.”
This way, people will fall out of the habit of clicking on links or opening attachments, and it will start to become abnormal and strange to do so. Emails offering free ice cream and the like will continue to be tempting because human beings love games and contests. They especially like getting something free. If you set up an internal contest about finding malicious emails and notifying the security team, that could satisfy that urge.
Rather than trying to train folks in deciphering URLs ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access