Testing people rather than systems.
WHAT IT INVOLVES
Attempting to obtain access or information by deceiving people, with authorisation.
WHAT FORMS IT TAKES
Simulated phishing messages Telephone approaches Attempts to gain physical access Requests for information
WHY IT IS ASSESSED
People are the route used in most real compromises.
WHY IT REQUIRES PARTICULAR CARE
It involves deceiving your own staff, and it can cause real harm to individuals.
WHAT TO ESTABLISH BEFORE COMMISSIONING IT
What the objective is How results will be used Whether individuals will be identified What support exists for those who fail
WHY THAT LAST POINT
Staff who are deceived frequently feel humiliated, and it affects whether they report real incidents.
WHAT TO ESTABLISH
That the purpose is improving defences, not identifying individuals for blame.
WHAT TO AVOID
Naming individuals in reports Disciplining those who failed Scenarios that are cruel or exploit personal circumstances
WHY
They produce fear, and fear produces concealment of real incidents.
WHAT TO PREFER
Aggregate results, and training as the response.
WHAT TO ESTABLISH ABOUT SCENARIOS
That they are realistic but not distressing.
WHAT TO EXCLUDE
Scenarios involving personal matters Scenarios suggesting job loss or emergencies Anything that would cause genuine distress
WHAT TO PROVIDE AFTERWARDS
Explanation to those involved Training on what to look for Recognition of those who reported it
WHY RECOGNITION
Reporting is the behaviour you want, and it should be visibly valued.
WHAT TO MEASURE
Reporting rate, as much as failure rate.
WHY
A workforce that reports quickly is better than one that never clicks.