Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That seems okay though, since it's also behavior you'd want if real phishing emails were coming in.


No. Because the department that has advance warning of internal tests will be unlikely to be the first targeted by real phishing emails.


This doesn't seem like much of a reason to try and dissuade employees from discussing these things though.

I think there are probably a great many sysadmins, security analysts, and ciso's who can only dream of a day when run-of-the-mill employees are having casual conversations about phishing and identity security at the office.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: