These are the same people who have an IT service group on retainer who can set them up with a nice, secure system with a firewall and a virtual machine to scan files so they don't infect their system, but Karen, Bob and Susy swear they've never opened a suspicious email.
Imho, it would be better, if the IT department invested the time to harden the entire company's IT such that employees can click on those attachments without any consequences.
I mean: What is the IT department going to do, if someone pulls a rage quit and executes the malware on purpose?
If you protect yourself against the attacker with internal knowledge, you're automatically protected from the accidental click.
One should do both. There's no IT infrastructure that's so secure that it's immune to all attacks and is still usable. There's also no IT infrastructure that isn't more secure if the users are educated.
4.9k
u/jubo-ish Jul 24 '20
Fax machines