| > Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100% coverage. I wish you luck, but don't get discouraged if it doesn't work. We've been trying to educate people about phishing for 17+ years. :) We shifted our focus to tracking the phishing sites and then tying that back to which user accounts were hacked, and disabling the hacked accounts and notifying the users before damage could be done. PayPal actually holds the patent on what we built, along with a ton of other anti-phishing and phishing site tracking patents. |
A friend works for a company that fires employees after failing three phishing tests.
It doesn’t solve the problem for those people, but it does work for that company. What has priority depends on your management style :)