Every month since 2010, employees at Lockheed Martin get hit with phishing attacks … but at least some of the attacks are launched by the company’s security pros. These simulated assaults are part of a training program that has helped the defense contractor detect real intrusions each year, reports Kelly Jackson Higgins at Dark Reading.
Since the program was deployed, 45 percent fewer employees have been duped by phishing emails, and some attacks have been thwarted because employees reported suspicious-looking messages in their inboxes, said Chandra McMahon, CISO at Lockheed.
More enterprises are making use of simulated phishing expeditions, and many alert users to the program when it’s launched because the objective is to integrate users into the organization’s security architecture. If employees at Lockheed get duped by a simulated phishing email, they are automatically sent to an interactive training session.
“We look at our employees as being the first line of defense: That’s why we have made an investment in education and awareness,” McMahon said. “If a user doesn’t click on a spearphish, it helps us stop a cyberintrusion from getting started.”
Sounds like a great training exercise. Just make sure the CEO, CFO and other top executives take part in it.
For more:
– see Kelly Jackson Higgins’ article at Dark Reading
Related Articles:
How hackers tricked Coca-Cola
Elusive Trojan used to spy on energy firms
Phishers go after White House officials’ Gmail accounts
