My organization sends out just braindead crap that wouldn’t catch anyone, even boomers. I just flag half of them and then respond to their little congratulatory popup to remind them how pathetic they are with their half-assed attempt, that they should feel bad for failing this hard, and posting the link to the study that none of this crap helps with mitigating phishing and then click the ever loving crap out of the other half.
The number who fail is always to high, and the people sending out those tests usually don’t want to be sending out those tests, they are required to be sending them because the companies insurance requires such procedures. So they are having to check boxes so if someone fucks something up, the company is covered.
You are essentially talking trash to an untipped host who is required to bring bread to your table.
Hey at least that was somewhat tempting.
My organization sends out just braindead crap that wouldn’t catch anyone, even boomers. I just flag half of them and then respond to their little congratulatory popup to remind them how pathetic they are with their half-assed attempt, that they should feel bad for failing this hard, and posting the link to the study that none of this crap helps with mitigating phishing and then click the ever loving crap out of the other half.
The number who fail is always to high, and the people sending out those tests usually don’t want to be sending out those tests, they are required to be sending them because the companies insurance requires such procedures. So they are having to check boxes so if someone fucks something up, the company is covered.
You are essentially talking trash to an untipped host who is required to bring bread to your table.
You’d be surprised at the click-thru rate of those! I don’t think I’ve ever seen a phishing test get less than 10% click through rate