Defense in Depth cover image

Defense in Depth

Are Phishing Tests Helping or Hurting Our Security Program?

Sep 19, 2024
Dennis Pickett, VP and CISO at Westat, dives into the complexities of phishing tests in cybersecurity. He argues that not all education requires testing, emphasizing the need for building a culture of security awareness over punishment. Pickett champions empowering employees to report suspicious activities and discusses the significance of implementing supportive tools like phishing alert buttons. He advocates for a positive security culture that recognizes and incentivizes proactive engagement, rather than blaming victims.
27:36

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Phishing tests should shift focus from grading employees to fostering a reporting culture that enhances overall cybersecurity awareness.
  • Investing in advanced security measures alongside phishing simulations is essential to create a comprehensive defense strategy against potential attacks.

Deep dives

Revisiting the Purpose of Phishing Tests

Phishing tests often serve as a measurement tool, but relying solely on them does little to improve cybersecurity awareness among employees. Instead of grading individuals as pass or fail, organizations should focus on how phishing simulations can provide insights into overall employee behavior and awareness. The effectiveness of these tests is better evaluated by measuring the ratio of employees who report suspicious emails versus those who click on them. This shift toward encouraging a reporting culture is crucial, as it allows organizations to identify vulnerabilities and develop strategies to strengthen their defenses.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode