Alt text: Michael Scott Handshake meme. Managers text: “My company Congratulating me on avoiding a phishing test email”. Michael Scott text: “Me, terminally behind on answering email.”

  • Thorry84@feddit.nl
    link
    fedilink
    arrow-up
    2
    ·
    8 months ago

    Where I work you only pass the test if you report it to IT, otherwise it’s 3 hours of training with the rest of the idiots.

      • Thorry84@feddit.nl
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        8 months ago

        The IT people send out the phishing mail themselves as part of a test. It isn’t an actual phishing mail, just something made to look and act like one. In the end they have a report which people fell for it, which ignored it (or were ooo) and which reported it.

        Reporting is done via the report phishing feature in Outlook. For consumers it’s sent to Microsoft, but for businesses you can configure those reports to do what you want. It’s actually a really good feature and people should always use it.

        • bamboo@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 months ago

          Does your IT team tell you that they’re performing the test and to report, or is reporting phishing always constantly recommended. I’ve managed a small org ( <100 ) email server and we tried to have people report suspicious emails and it was so much noise and wasted so much time. Of course the CEO isn’t requesting you buy gift cards, what am I going to do about it. I’d say the money would be better spent on a better system rather than hope one human forwards it to another human.

      • Black616Angel@feddit.de
        link
        fedilink
        arrow-up
        1
        ·
        8 months ago

        No, it’s better to get some useless reports than to get no reports at all because “somebody will surely report this”.

        Also people stay alert when punishment is an option.