Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #9
Security teams urged to measure phishing reports, not just clicks
Original: Ask a security team how its phishing programme is doing and you will get a click rate. Fewer measure the number that dec
A cybersecurity commentator argues that security teams judge their phishing programmes almost entirely by click rates, while too few measure how quickly employees report suspicious messages — the metric that determines how badly a real incident unfolds. Citing UK NCSC phishing guidance, the author says punishment and blame around clicking discourage reporting and undermine incident response.
Why now: Ongoing debate in the security community over which phishing metrics actually reflect organisational resilience.
NCSCsecurity teamsAdrian Hollister
Evidence
- Ask a security team how its phishing programme is doing and you will get a click rate. Fewer measure the number that decides how bad a real incident gets: how quickly someone reports. The NCSC's phishing guidance is direct about this. Punishment and blame around clicking make… · adrianhollister@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/964870