The Language of Cyber Attacks by Aaron Mauro
Author:Aaron Mauro
Language: eng
Format: epub
ISBN: 9781350354708
Publisher: Bloomsbury Publishing Plc
Published: 2024-06-24T00:00:00+00:00
Ethical Phish
If your workplace begins referring to employees as family, you know that they are either not paying you enough, cutting your benefits, or conducting a phishing simulation. The ethics of ethical phishing has long been an issue within institutions with many managed accounts. Universities, corporations, and governments often test their employees by asking (or forcing) them to participate in âphishing simulations.â A phishing simulation allows IT security to test usersâ ability to detect deceit, like email or any other cloud service with messagingâby attempting to tricking them into clicking, downloading, or otherwise engage in risky behavior that would result in a point of compromise. The simulation is generally designed to test security policies and practices, as well as train users to reduce susceptibility to legitimate attacks. There is a broad consensus among vendors of phishing simulation services about some basic ground rules: avoid playing on an employeesâ trust in the organization, including a lure predicated on bonus pay-outs, losing work benefits, termination notices, loss of personal possessions in the workplace, or personal company-protected data leaks; avoid threatening an employeesâ homes or personal sense of security;81 avoid embarrassing or shaming employees; and avoid punishing employees for making a mistake during a simulation.82 It is more than a little concerning that any of these ethical practices need to be spelled out, but here we are.
To conduct an ethical phishing simulation, several best practices are recommended. First, a pre-launch campaign should be initiated to clearly define the purpose and scope of the phishing simulation, establish lines of communication for the duration of the test, and ensure that managers are equipped to support their teams. Second, the simulation should be designed with the mental well-being of participants in mind, considering the potential for heightened anxiety or panic. Lastly, it is crucial that the results of the simulation are communicated transparently to employees, and that any subsequent training is framed as a supportive measure rather than a punitive action.83
There are many vendors for these services and all large cloud service providers offer documentation on how they will run a successful phishing simulation. While this is a common security service offering that helps managers feel as though their employees are well trained, the effectiveness of human subject experimentation as a testing and training exercise is not clear. There is good research suggesting that phishing simulations do very little to reduce susceptibility to phishing in the workplace, specifically in the university context, in actual terms.84 The authors of a study exploring the susceptibility to phishing in the university-based workplace report â67 percent of employees who respond to simulated phishing attacks are repeat victims and therefore likely to respond to phishing emails more than once.â85
The authors of this study used many of the terms associated with Hadnagyâs central tenets of manipulation and influence defined under social engineering, including authority, urgency, reciprocity, and scarcity.86 The authors of this study went on to discover that urgency and authority cues âcontribute to increased susceptibility with a workplace setting.â87 Perhaps most
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(185738)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(94081)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(93890)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(93513)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74472)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50916)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40299)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40237)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40124)
Alkaline-earth metals promote propane dehydrogenation with carbon dioxide through geometric effects: Altering the reaction pathway by unknow(32761)
Induced iron vacancies boosting FeOOH loaded on sustainable Fenton-like collagen fiber membrane for efficient removal of emerging contaminants by unknow(32544)
Efficient electric-field-assisted photochemical conversion of methane to n-propanol exclusively over penetrated TiO2Ti hollow fibers by Guanghui Feng(32476)
Bi2SiO5 nanosheets as piezo-photocatalyst for efficient degradation of 2,4-Dichlorophenol by Hangyu Shi & Yifu Li & Lishan Zhang & Guoguan Liu & Qian Zhang & Xuan Ru & Shan Zhong(32415)
A novel NDIPTA organic heterojunction photocatalyst with built-in electric field for efficient hydrogen production by Jiahui Yang & Baojun Ma & Yongfa Zhu(32386)
Enhanced conversion of methane to liquid-phase oxygenates via hollow ferrite nanotube@horseradish peroxidase based photoenzymatic catalysis by Jun Duan & Shiying Fan & Xinyong Li & Shaomin Liu(32353)
Ordered macroporous superstructure of defective carbon adorned with tiny cobalt sulfide for selective electrocatalytic hydrogenation of cinnamaldehyde by Xiao-Shi Yuan & Sheng-Hua Zhou & San-Mei Wang & Wenbo Wei & Xiaofang Li & Xin-Tao Wu & Qi-Long Zhu(32275)
What's Done in Darkness by Kayla Perrin(27168)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26557)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26490)