If leadership won’t bring the same rigour of safety culture - which is mandated by legislation - to security? Don’t bother, just move on.
If leadership won’t bring the same rigour of safety culture - which is mandated by legislation - to security? Don’t bother, just move on.
SitusAMC https://www.situsamc.com/databreach
Harvard University https://www.bleepingcomputer.com/news/security/harvard-unive...
Iberia Airline https://www.bleepingcomputer.com/news/security/iberia-disclo...
Salesforce via gainsight https://status.salesforce.com/generalmessages/20000233
Online, we've made it exceptionally easy to make those sorts of checks: a website, served over HTTPS, is coming from the url. Other systems are so, so much worse about this. Any system where unauthorized impersonation is possible is a technical failure, and the fault for abuse of that unauthorized impersonation is on the providers and designers of that system. Like phone calls. Or email.
People tend to be pretty good at differentiating between "this person can be trusted with sensitive information", and "I shouldn't trust this stranger". What they need are the tools to determine who they're talking to.