The Internet is a den for hackers, crackers, thieves, thugs, tricksters, slicksters and con-artists. Corporate network, IT and security managers face an ongoing and all out assault on their systems, with the low-brows of the Net intent on stealing money, intellectual property and employee identities.
The sad reality is that no organization is truly secure. The goal is to throw up enough road blocks so the criminals move on to other targets.
Last year, endpoint security vendor Senforce Technologies asked Strategic Communications Group (Strategic) to handle the public relations launch for a new version of its security suite. Our challenge was one of time – there was a four month gap between the start of our campaign and the formal introduction of the product.
To create interest among journalists and analysts about endpoint security requirements, Strategic initially focused on educating the market about a new threat called thumb sucking (http://en.wikipedia.org/wiki/Data_theft#Thumbsucking). This involves the use of a flash drive to steal documents from someone working in a public setting on a laptop computer.
To spread the word we sent security writers by overnight a package that included a thumb drive with malicious code to demonstrate how easy it was to execute a thumb sucking attack. Before handing the packages over to UPS, we gave a lot of thought about the ethics of our actions. Even with our best intentions and a clear explanation in the package of how to use the thumb drives, the very act of sending such corrupt code was questionable.
A respected security journalist agreed:
That’s one way to create demand for a solution
Government Computer News
http://www.gcn.com/print/26_18/44704-1.html
Fast forward a year and I come across an interesting article in Informationweek about a new offering called PhishMe from NY-based security firm Intrepidus Group.
This service allows IT and security executives to simulate a real phishing attack against their own employees to identify those who are most easily duped. The company can then take the necessary steps to educate the employee about how to best recognize and discard a malicious message.
Like Strategic’s thumb drives, I recognize Intrepidus’ best intentions with PhishMe. Phishing, spear phishing and whaling attacks have run rampant, claiming more than 15,000 corporate victims in the past 15 months alone (iDefense Labs).
Yet, a company conducting mock phishing attacks on its staff just doesn’t feel right. My take is that it steps across the acceptable boundary of employer/employee trust. And is it not feasible for a company to achieve a comparable result through proactive training?
Phish Me
Informationweek
http://www.informationweek.com/news/security/client/showArticle.jhtml?articleID=209400255
Showing posts with label PhishMe. Show all posts
Showing posts with label PhishMe. Show all posts
Sunday, July 27, 2008
PhishMe's Cruel Intentions
Posted by
Marc Hausman
at
6:56 PM
3
comments
Labels: Intrepidus Group, phishing, PhishMe, Senforce
Subscribe to:
Posts (Atom)


