Breakdown 1 — Phishing program
From class — Module C: develop a culture of security awareness; defending against social engineering → train employees.
| Element | What to do |
|---|---|
| Campaigns | Send simulated phishing regularly; measure click rate and report rate; escalate difficulty over time; never shame — retrain |
| Recognizing a phishing attempt | Urgency/threats, mismatched sender vs. display name, hover the link (look-alike/typosquat domains), unexpected attachments (double extensions), requests for credentials or payment changes, generic greetings |
| Responding to reported suspicious messages | One-click "Report phish" button → SOC triages → if malicious: block sender/URL, purge from mailboxes, warn users, thank the reporter |
Breakdown 2 — Anomalous behavior recognition
| Behavior | Example | Response |
|---|---|---|
| Risky | Disabling AV, using unauthorized cloud storage, plugging in found USBs | Coaching, policy reminder, technical block |
| Unexpected | Logging in at 3 a.m., accessing data outside their role, mass downloads | Investigate (could be compromise or insider) |
| Unintentional | Emailing a spreadsheet to the wrong person, misconfiguring a share | Fix, train, add guard rails (DLP prompts) |
Breakdown 3 — User guidance and training topics
| Topic | Key message |
|---|---|
| Policy / handbooks | Where the rules live; sign the AUP |
| Situational awareness | Notice tailgaters, shoulder surfers, odd emails |
| Insider threat | Report concerning behavior; least privilege applies to everyone |
| Password management | Long passphrases, no reuse, use the password manager, MFA |
| Removable media and cables | Don't plug in unknown USB drives or cables; use sheep-dip station |
| Social engineering | Authority, urgency, scarcity, familiarity, consensus, intimidation, trust — verify out of band |
| Operational security (OPSEC) | Don't post org charts/badges/travel on social media; clean desk |
| Hybrid/remote work | Secure home Wi-Fi (WPA3), VPN, lock screens, no family on work devices, beware public Wi-Fi/evil twins |
Breakdown 4 — Program lifecycle
- Reporting and monitoring — initial (baseline metrics: phish click rate, quiz scores) and recurring (track improvement; feed results to management).
- Development — build content for roles (developers → secure coding; finance → BEC; execs → whaling).
- Execution — onboarding training, annual refreshers, just-in-time micro-training after a simulated-phish click, posters/newsletters.
Exam tip: "Employee reports a suspicious email — what next?" → analyze it, don't click it; contain if malicious. "Reduce phishing success org-wide" → campaigns + training (technical controls help, but the objective is awareness). "User keeps disabling the screen saver" → risky behavior → coaching + technical enforcement. "Measure whether training works" → recurring reporting/metrics.
Quick self-check
- Three signs of a phishing email?
- Risky vs. unexpected vs. unintentional behavior?
- What's OPSEC in a home-office context?
Sources: 20260917_173252.jpg, 20260917_173259.jpg, 20260917_173312.jpg