
Defense in Depth
Are Phishing Tests Helping or Hurting Our Security Program?
Sep 19, 2024
Dennis Pickett, VP and CISO at Westat, dives into the complexities of phishing tests in cybersecurity. He argues that not all education requires testing, emphasizing the need for building a culture of security awareness over punishment. Pickett champions empowering employees to report suspicious activities and discusses the significance of implementing supportive tools like phishing alert buttons. He advocates for a positive security culture that recognizes and incentivizes proactive engagement, rather than blaming victims.
27:36
Episode guests
AI Summary
AI Chapters
Episode notes
Podcast summary created with Snipd AI
Quick takeaways
- Phishing tests should shift focus from grading employees to fostering a reporting culture that enhances overall cybersecurity awareness.
- Investing in advanced security measures alongside phishing simulations is essential to create a comprehensive defense strategy against potential attacks.
Deep dives
Revisiting the Purpose of Phishing Tests
Phishing tests often serve as a measurement tool, but relying solely on them does little to improve cybersecurity awareness among employees. Instead of grading individuals as pass or fail, organizations should focus on how phishing simulations can provide insights into overall employee behavior and awareness. The effectiveness of these tests is better evaluated by measuring the ratio of employees who report suspicious emails versus those who click on them. This shift toward encouraging a reporting culture is crucial, as it allows organizations to identify vulnerabilities and develop strategies to strengthen their defenses.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.