Hacker News new | ask | show | jobs
by litoorachure 1877 days ago
At least those phishing exercises are done with the informed consent of the organization.

If they go too far and impact day-to-day work, or if people complain, the executives understand what is going on and who they can talk to about improving the process.

And if it feels lacking in empathy, consider that the company's management needs to sign off on any (legal) phishing tests that their employees are subjected to.