Rant: Got hit with a phishing email so good I almost clicked, and now I can't decide if my security training is working or not | Cybersecurity - Opinions Matter
Rant: Got hit with a phishing email so good I almost clicked, and now I can't decide if my security training is working or not
Last Tuesday I got an email at work that looked exactly like our HR portal, same logo, same footer, even the same font. It said my direct deposit info needed to be confirmed by 5pm or pay would be delayed, and I kid you not, I had my mouse on the link before something felt off. I checked the sender address and it was one letter different from the real domain, like an r instead of an n. I reported it to IT and turns out 4 other people in my building clicked it and 2 of them actually typed in their login info. Here is my problem, I sit through the same 20 minute security video every year and I still almost fell for it, so I keep going back and forth on whether these trainings actually help anyone or if we are just wasting time. Side A says training works because I caught it at the last second, side B says training is useless if a near perfect copy fools most people anyway and we should just push for hardware keys everywhere. Where do you all land on this, is user training worth the money or should companies just lock everything down on the tech side and stop blaming people?
The thing nobody talks about is timing. Your training video gets watched once a year in a calm room with a bagel and a coffee, but the actual attack lands on a Tuesday afternoon when you are behind on three things and payroll is on your mind. That gap is the whole ballgame. No 20 minute video can put you in the same mental state as a real urgent email, so we end up testing memory instead of judgment. What actually saved you was not the video, it was a tiny moment of pause you have probably built up from years of seeing junk mail. That instinct is worth something, but it is also fragile and it fails when people are tired or rushed. So my answer is both sides are right, keep the training but make it short and constant instead of long and yearly, and put the hardware keys in place for anything tied to money or logins. Training should be the seatbelt, not the only brake.