It is now considered general knowledge among information security professionals that the weakest link in any enterprise is the user. Phishing and spear-phishing — broad and more targeted attempts, respectively — have become the prime mode of attack for many hackers and coordinated campaigns can be highly effective.
Some agencies are doing annual cyber hygiene training with employees but that’s not nearly enough, according to Maj. Gen. Sarah Zabel, vice director of the Defense Information Systems Agency.
Zabel said DISA employees get weekly training right from their log-in screens.
“Once a week, as you log in a banner comes up and asks you a cyber question,” she said during a panel discussion at the April 12 FireEye Government Forum. “We hit phishing hard but we hit other things as well, like handling classified information.”
If the user answers wrongly, they are redirected to more information.
“This is a constant, weekly reminder that these are your responsibilities,” Zabel said. “Making sure that users realize they’re on a mission system — even if it’s their email — and they have to protect it.”
Training employees to spot suspicious emails is fast becoming a part of agency cybersecurity plans but they’re not always effective at preventing breaches. A comprehensive spear-phishing campaign only needs to trick one user and even well-trained employees will fail at times. (See my own thoughts on this: The user knows nothing.)
But having an active education program does more than just warn employees of the dangers of phishing. It helps create what Commerce Department CISO Rod Turk referred to as a “cybersecurity culture.”
“Instead of just launching an anti-phishing campaign where I just send out emails and try to do the gotcha thing, I’ll send out a broadcast to all my people in my organization saying, ‘We’re going to do this phishing campaign, this is what it’s going to look like, this is why you don’t want to click on it … and that then becomes a training opportunity,” he explained.
Turk said he sends those “broadcasts” a few times before the campaign starts, giving employees plenty of warning.
“I look at it as not specifically an anti-phishing campaign; I look at it as a greater cybersecurity training opportunity,” he said. “In my mind, the more I can get anti-phishing and/or cybersecurity in front of my employees, the better off I am.”




