Sometimes I wonder whether all this “security awareness training” has any effect at all.

  • Iced Raktajino@startrek.website
    link
    fedilink
    arrow-up
    36
    arrow-down
    1
    ·
    edit-2
    2 days ago

    Sometimes I wonder whether all this “security awareness training” has any effect at all.

    Nope lol.

    My org sends out phishing tests randomly. I used to report every single one and have never clicked on any. But we all have to take the stupid training regardless of whether we successfully detect/report them or not. So I’ve just stopped reporting them since there’s no incentive whatsoever.

    • Trex202@lemmy.world
      link
      fedilink
      arrow-up
      20
      ·
      2 days ago

      I came to say the same thing

      I reported the test phish (the only phish we ever got) and laughed at coworkers who had to take the training only to turn around and see I needed to take it too

      • Iced Raktajino@startrek.website
        link
        fedilink
        arrow-up
        13
        ·
        edit-2
        2 days ago

        Yep.

        Most of them are phishing test emails (where the org sends out fake “phishing” emails which have a UUID link tied to your email address) so they KNOW who clicks on these and who reports them. Until I stopped giving a fuck, I had reported 100% of them and clicked on 0. But since that doesn’t let you “test out” of the 45 minute quarterly security awareness training, I stopped wasting my time and just delete them

        • Windex007@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          2 days ago

          About 9 years ago I wrote a script that looked for links to domains registered to wombat (the company that most companies seem to use for phishing simulation) and would autoreport and delete them. So just never saw them.

          Still had to do the training. Every six months.

          • Nasan@sopuli.xyz
            link
            fedilink
            arrow-up
            2
            ·
            2 days ago

            One of my former managers had this habit of setting up email rules for known phishing simulation domains whenever he started somewhere new.

            Microsoft domains listed in a table here for anyone else unfortunate enough to have to use their products within your org.

      • HeyJoe@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        2 days ago

        Isn’t the big difference that they have to take it everytime they fail and open one they shouldn’t? At least thats how it is at my place. They get a lecture, and then retake the course. Everyone else does it once a year along with all the other mandatory training we need to do for compliance.

        • Sc00ter@lemmy.zip
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          Its also not about the individual. The company is doing an assessment of their security and vulnerabilities. If your company has any sort of restrictions on email attachments or methods of sharing files, theyre probably a result of people failing these tests

    • nymnympseudonym@piefed.social
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      You say that but do you have any objective data?

      I’d love to see studies of phishing success in orgs that do vs. do not have regular trainings.

      I bet it works like PSA advertising. It’s stuff everyone should know and 98% of people already do. But it also helps keep the issues closer to conscious awareness and is actually educational for the 2%

      • cron@feddit.orgOP
        link
        fedilink
        arrow-up
        5
        ·
        2 days ago

        There is a 2025 study that was widely reported:

        In summary, our results confirm the ineffectiveness of current phishing training approaches while offering a refined study design for future work.

        arXiv:2506.19899

        • nymnympseudonym@piefed.social
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 days ago

          training interventions showed no significant main effects on click rates (p=0.450) or reporting rates (p=0.417), with negligible effect sizes

          Thank you. I stand corrected, and with my Bayesian priors updated.