Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale.
Assuming humans won't do stupid things 100% of the time is never an effective security control.
Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale.
Assuming humans won't do stupid things 100% of the time is never an effective security control.
I also worry that the emails might not represent real attack emails, and we end up training users to identify the test emails but not real attack emails.
(Not that i got any better solution)
It’s not a solution to the problem, but it certainly helps.
My gut feeling is for engineers, the phising training that most companies use is wholly ineffective at doing anything, and in particular it is especially ineffective against targeted attacks. But i have yet to see any research one way or another.
I suspect less technical users might benefit from such training a bit more (but still not that much)