Phishing tests are testing the security team’s technical controls and education; if an employee is duped, it’s the security team, not the employee, that failed. 1/3 coppercourier.com/story/goda…

Dec 25, 2020 · 7:24 PM UTC

1
That’s why employees hate phishing tests when they’re held accountable, it doesn’t prove anything. It’s trivial to create a highly clicked-on email, I’ve created many. Use the click-thru rate as a means to shore up controls and training. 2/3
1
Even better, don’t send phishing emails at all, save that money and time for other more valuable efforts, and instead use your real phishing emails as the basis for improving your program. 3/3
1