IT managers fail to anticipate employees’ reactions. Employee phishing tests can, and do, leak “into the wild” and cause your business trouble.

The unexpected employee reactions to phishing tests cost time, effort and sometimes money to counteract. When faced with a live phishing test employees might take one of these three actions:

1. Contacting an impersonated entity instead of the help desk

Contacting an impersonated entity (internal or external) rather than the help desk costs that organization and may damage both organizations reputation. (Remember the story about DOJ and Thrift Savings Plan.)

2. Contacting the news or social media to vent their emotions

Employees contacting news or social media will definitely cause an impact on reputation of the organization, and may require PR or legal damage control.

A live phishing test causes an employee to be angry at their computer

Photo via Getty Images + Unsplash+

It’s been a “super-fantastic” experience to see people learning and talking about security threats.

For just $325 USD, you can run a 6 week, automated program for gamified phishing awareness training and challenges.  (Limited time offer. Normally valued at $999 USD)

Use Promo Code: 6WEEKS

3. Contacting other employees to warn them of the test

Contacting other employees to warn them may sound good because “it’s a behavior you want”, but it may not help when spear-phishing attack hits employees who were “tipped off” during a test. It can cost the price of an attack in the end.

Technical vulnerability assessments are easier to predict impacts and mitigate. We shouldn’t treat phishing tests the same as we do other vulnerability assessments, when the cost to mitigate unexpected outcomes is much higher.

 

Scott Wright is CEO of Click Armor, the gamified simulation platform that helps businesses avoid breaches by engaging employees to improve their proficiency in making decisions for cyber security risk and corporate compliance. He has over 20 years of cyber security coaching experience and was creator of the Honey Stick Project for Smartphones as a demonstration in measuring human vulnerabilities.

Cyber Security

Phishing Defense

Phishing threatens businesses and opens the door to ransomware. Fight phishing and spear phishing attacks with gamified learning.

Social Engineering Defense

Social engineering scams are a serious hazard to businesses. Fight back with Click Armor.

Cyber Security Awareness for Remote Workers

Home-based workers are vulnerable to cyber attacks. Build team immunity today.

Privacy and Compliance

PCI Compliance Awareness

When team members work in an environment where they may encounter cardholder data, they need to know what to do to protect it.

Gamified HIPAA Compliance Awareness

If your business is a supplier to a healthcare provider in the USA or Canada, your team needs to know what to do to protect Protected Health information (PHI).

Gamified Learning Platform

Active Awareness Platform

Experience the power of tailored gamified learning with Click Armor. Take your security awareness training to the next level.