Educause Security Discussion mailing list archives

Re: Self-Phishing - show of hands


From: Sol Bermann <solb () UMICH EDU>
Date: Fri, 12 Feb 2016 09:02:23 -0500

Ditto to enough real life phishing to both keep us busy and teach employees.

We are working on a phishing game training, some research with faculty, and
potential post-phish survey...that is plenty for now

Sol Bermann
Privacy Officer and IT Policy, Compliance Strategist
ITS - Information & Infrastructure Assurance
University of Michigan

734/615-9661
solb () umich edu



On Thu, Feb 11, 2016 at 1:25 PM, Jenny Blaine <blain004 () umn edu> wrote:

We outsource ours to Nigeria and Russia. 8)

On Thu, Feb 11, 2016 at 10:45 AM, Christine Streeter <
christinestreeter () adams edu> wrote:

1. Phish tests for all employees.
2. KnowBe4.com
3. Phishing since July 2015

We also leverage KnowBe4's security awareness training for our employees.

[image: adams state logo]
*Christine Streeter*
IT Support Administrator
Adams State University | Computing Services
208 Edgemont Boulevard, Suite 4070 | Alamosa, CO 81101
719-587-7741 (phone) | 719-587-8022 (fax)
                      Computing Services
<http://www.adams.edu/administration/computing/index.php> | Like Us on
Facebook <http://www.facebook.com/ASUComputingServices>



On Thu, Feb 11, 2016 at 9:23 AM, Dennis Duncan <dduncan () cord edu> wrote:

1.       We run phish tests against all employee accounts, Faculty &
Staff

2.       KnowBe4.com

3.       Since the start of the school year, September 2015



Along with the phishing email campaigns, we also have employees go
through KnowBe4’s security awareness training.  This training has been very
well received by our community.



--

*Dennis Duncan, CISSP*

Director, IT Infrastructure Services

Information Security Officer

CONCORDIA COLLEGE│901 8TH ST S│MOORHEAD, MN 56562

ph: 218.299.4192 │ dduncan () cord edu │ www.cord.edu



*From:* The EDUCAUSE Security Constituent Group Listserv [mailto:
SECURITY () LISTSERV EDUCAUSE EDU] *On Behalf Of *Eric Weakland
*Sent:* Thursday, February 11, 2016 9:38 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] Self-Phishing - show of hands



Greetings,

I'm working on a publication on self phishing for HEISC and preparing to
leverage our self-phishing service (SANS) in the coming year.  I am trying
to develop a list of universities who are doing "self phishing".

If your institution is self phishing your community - would you mind
dropping me a note with the following items.

Who are you phishing? (Select groups, All Staff, All Faculty, All
Students, everyone etc.)
What are you using? (Vendor, custom or opensource and the name of the
vendor or project.)
How long have you been phishing your customers?

Thanks everyone!

Regards,

Eric Weakland, CISSP, CISM, CRISC
Director, Information Security
Office of Information Technology
American University
eric at american.edu
202.885.2241

_____________________________________________
Emails from IT asking you to log in with a link are scams!





--
Jenny C. Blaine
Security Analyst
University of Minnesota - University Information Security
jenny () umn edu - 612.625.8807 (office) - 612.978.7215 (mobile)
GSEC GCIH GCFE

CONFIDENTIALITY NOTICE:  This e-mail, including attachments, may include confidential information, and may be used 
only by the person(s) to whom it is addressed or intended. Be aware that the use of any information within may be 
restricted by privacy laws.  If the reader of this e-mail is not the intended recipient, the reader is hereby 
notified that any distribution or copying of this e-mail is prohibited. If you have received this e-mail in error, 
please notify the sender by replying to this message and delete this e-mail immediately.



Current thread: