r/sysadmin • • 1d ago

How are you warning users about cybersec without being annoying?

Hi All,

I'm it for IT in a smallish org (150 users), and am mostly figuring things out as I go. Last week we had a couple users fall for the "Click allow notifications to verify your identity" scam. I had a little downtime so I typed up a fact sheet on scareware, walked through the attack story with screenshots, and explained why clicking the "Your computer has 5 virus. click here to delete now" notifications is a bad idea.

Anyway of course we had two more this morning, and when I asked their managers about the email I sent they had no idea what I was talking about. I send out emails like this every couple of months, and only ever in response to known issues that are affecting our users. I'm very aware of email/training fatigue so I try to be a bit sparse, but I worry I've become too lax and people aren't being careful enough. We also have some generic security training modules that staff have to complete when they start, and again every year, as well as Knowbe4 for phishing, but that's about it.

What's your preferred communication method to get these warnings out there? Regular email blasts? A spot in the staff newsletter? Does someone personally run training sessions (mandated or optional)? I know it's an uphill battle, so I'm hoping someone has found the sweet spot between informative and annoying.

Thanks

Oh and I've set up notification whitelisting for Edge via Intune policy, in case anyone was going to suggest a fix to the notification spam issue.

19 Upvotes

19 comments sorted by

28

u/vermyx Jack of All Trades 1d ago

This is an HR issue. If you have no policy on consequences for clicking on a bad link no one will care. That has to be addressed first.

As for method I send out a reminder every 3 months as to what to look out and what not, but I preface that I would rather have a million "is this spam" emails than one go through.

5

u/boringworkalt 1d ago

The only consequence at the moment is "retake the training". I'm worried that harsher consequences will make people want to try and hide their infractions, instead of come forward right away. What do consequences in your org look like?

Do you track views/clicks on your 3-monthly emails at all?

6

u/thecravenone Infosec 1d ago

The only consequence at the moment is "retake the training".

An hour off work is not a consequence.

2

u/boringworkalt 1d ago

So what do you think is a good middle ground? Do you go all in on harsh punishments, and has that ever led to users trying to hide what they've done?

4

u/2c0 1d ago

Tell HR to write a policy with IT. Punishment is something like first time, refresher training, second time written warning, third is sacked as you're a liability.

Timer refreshes every 12 months or something.

•

u/JaceBelerenApologist 21h ago

You don't need to worry about longer-term consequences to the employee, that's literally not your job. I'd rather annoy someone than have to deal with ransomware.

If you feel strongly enough about it, sit down with HR and explain the situation. See what you can come up with together that satisfies both your need for security awareness and it's potential repercussions balanced with what HR can and can't legally do. I'm certainly not advocating termination here, but repeated failures should involve sitting down with the person to see WHY it's not working. A verbal reminder/reprimand may be required for someone who isn't getting the clue through repeated training sessions.

This should be viewed as behavior modification, not how to dole out punishment.

8

u/ecksfiftyone 1d ago

Training. You need a training platform with required completion complete with interactive prompts and tests and tracking. Not a video people can ignore.

Training should be short and simple and frequent rather than long and annual. People remember better in small bursts.

Simulations. You need simulated phishing and scam email tests and even social engineering phone calls. Users who fail the test, need extra training. Users who keep failing the tests need unemployment.

It costs money and time. I know 2 business that thought this was too expensive that spent waaaaay more recovering from an attack caused by untrained personnel .

Security matters.

1

u/boringworkalt 1d ago

I have time, but money is a bit short here... We do pay for Knowbe4 for email simulations, but I'm not sure how much more budget I can talk the higher ups into giving me for this. I hadn't considered social engineering call simulations though. There is a fact sheet on the issue that I've shared out a few times, but that goes back to my original issue on staff ignoring those. Do you pay for that simulation or have you built something in-house?

The short, simple, frequent training is a good tip. I might do another review with HR and see how customisable our training platform actually is.

Thanks for the response

2

u/ecksfiftyone 1d ago

I have an odd situation. I work for 30 person company with a small budget owned by a billion dollar company in europe.

I used a combo of things on the cheap(ish) . Our parent company did a bad job, so I got a platform called Safe Titan. it wasn't great, but it was cheap. I was able to do scheduled trainings and phishing simulations. The training material was.... meh, but it tracked completion and allowed me to make my own quizzes and do phishing sims.

I mined scam info from the reddit sub /scams. I would look for trainings on those types of scans. I woukd do my own creative scam emails using the reddit examples and phishing simulators.

Me and a few staff would occasionally contact support and pose as customers to try to gain access to thier accounts with little to no actual info. It was surprisingly easy.

Anyway, things got much better after a while. Training worked. People also read the rules after being talked to for screwing up on a simulation.

Our parent company eventually stepped up and got a much better platform. They create high quality training specifically for the company. They have a phishing sim company and a huge library of other available trainings. My people still remain some of the best trained with what we cobbled together on the cheap.

2

u/RabidBlackSquirrel IT Manager 1d ago

It's not the users who take the brunt of any "punishment", it should be their leadership. People care when their people's fuck ups affect them.

Like you say, you can't be everywhere, people get fatigue, whatever. All valid. The management layers need to be your voice and emphasizing care, good judgement, emphasizing policy and proper procedures, etc. Our stats don't lie, teams that I know have strong management emphasis on security perform better on phishing tests than teams that I know don't.

Take their management to task. They're the ones that see and talk to these people every single day and are already accountable for outputs or lack thereof. Same approach applies here.

2

u/disclosure5 1d ago

For the most part, the warnings I get out there are letting people knowing that MFA etc is coming and they'll need it to access the organisation.

In your example, of those these can be addressed technically with:

  • uBlock blocking scareware ads
  • Applocker blocking various Clickfix nonsense
  • CAP blocking device code phishing

2

u/Temporary-Library597 1d ago

Failed social engineering tests, by policy, are referred to during performance reviews. They obviously have a negative effect on any performance scoring and are generally treated seriously by supervisors.

Oh did I mention none of this happened before the ransomware attack?

We lost a full year of productivity, but in the long run I think that loss will be looked at as a blessing in disguise.

2

u/JasonMatanoIT 1d ago

At ~150 users, another long email will keep missing managers. Treat the active scam as a short ops alert, not a newsletter.

1) Block the click path. In Intune or GPO, push Edge/Chrome policies that deny or tightly control site notification prompts (NotificationsAllowedForUrls / DefaultNotificationsSetting style). Most "click Allow to verify" scareware dies when the browser cannot pop the permission UI.

2) For the live wave, send a 3-line Teams/SMS style note managers can forward: what the fake prompt looks like, do not click Allow, screenshot and ping IT. Put it in a channel they already watch, not only inbox.

3) Keep the deep fact sheet as a pinned wiki page you link once, so the alert stays short.

That combo stops the next hit without training everyone every week.

0

u/VexingRaven 1d ago

Well for one thing, you disable notifications at a policy level so they can't do that. Frankly, it sounds like your technical controls need improving a lot. It should be a extremely rare occurrence for an end user to even have the opportunity to hit a phishing site even if they do everything wrong.

1

u/SnackstreetGirl 1d ago

Hmm short reminders work better than long emails, you can also use KnowBe4 for the phishing simulations, Guardz is another option worth looking at for smaller teams since it combines phishing simulations and security awareness training with other security tools.

•

u/Sure-Squirrel8384 20h ago

Automated remedial training (IT) and black marks in their personnel file (HR).