Cyber Security

IT department congratulates itself on successful phishing test that fooled absolutely nobody

The IT security team at Midlands-based logistics firm Branwell Solutions has declared its latest phishing simulation exercise an overwhelming success, having successfully tricked three members of staff out of a possible four hundred and seventy-two into clicking a link that promised them a £200 Tesco voucher for completing a one-minute survey about workplace satisfaction.

The test, which was the seventh such exercise this financial year, saw Chief Information Security Officer Graham Melrose send a company-wide email on Tuesday afternoon celebrating what he described as a significant improvement in staff awareness. The message, which ran to some nine hundred words and was marked as high importance, noted that the 99.4 per cent success rate demonstrated the effectiveness of the mandatory monthly cybersecurity training modules that employees are required to complete in their own time.

The email went on to remind staff that the three individuals who had clicked the link, whilst not named directly, worked in Accounts, Customer Services, and Accounts again. It added that these team members would be enrolled in additional remedial training and would receive personal coaching sessions with members of the IT security team, who would be blocking out their calendars accordingly.

“We’re really pleased with these results, which show that our investment in security awareness is paying dividends,” said Melrose, who has requested that senior management approve budget for a dedicated phishing simulation platform at a cost of £34,000 per year. “In today’s threat landscape, we cannot afford to be complacent. Even one click could compromise our entire infrastructure.”

The test email, which was sent from the address [email protected] at 3.47pm on a Friday afternoon, featured a banner image of Tesco vouchers that appeared to have been photographed on someone’s phone, and began with the greeting “Dear Valued Branwell Employee Person”. The link itself directed users to a webpage informing them that they had failed a security test and should feel appropriately ashamed.

Kevin Hutchins, a procurement officer who has now failed six consecutive phishing tests, told colleagues that he had clicked the link because he thought it might be legitimate this time. His manager confirmed that Kevin had also recently provided his bank details to a Nigerian prince, signed the office up for a timeshare presentation, and responded to seventeen separate emails about unclaimed inheritance from distant relatives he did not know existed.

“Look, I’m an optimistic person,” said Hutchins, who keeps his passwords on a Post-it note attached to his monitor. “How am I supposed to know which emails are real and which ones are Graham having a go. They all look dodgy to me.”

The IT department has announced that it will be running another phishing simulation next month, this time offering staff the chance to claim their Christmas bonus early by clicking a link and entering their network credentials. Melrose said he expected even better results, though he acknowledged that Kevin remained a statistical inevitability.

Leave a comment

Your email address will not be published. Required fields are marked *