Cyber Security

IT department confirms they’ve moved the phishing awareness training email to junk folder

The IT security team at Meridian Financial Services has quietly acknowledged that this month’s mandatory phishing awareness training email has been automatically redirected to the junk folder of all 847 employees, a move which head of infrastructure Martin Peasley described as both inevitable and probably for the best.

The training module, the fourth since January, was flagged by the company’s own email filters due to its subject line containing the words ‘urgent’, ‘action required’, ‘verify your account’, and ‘click here’. These are also the four warning signs that previous phishing awareness training modules have instructed employees to watch out for.

Peasley confirmed that the IT department made no effort to retrieve the email from quarantine. He noted that engagement with the previous three training sessions had averaged 4.2 per cent, with most of that coming from two people in accounts who appear to have confused it with actual work.

The system is working exactly as designed. Employees now treat all our communications with the suspicion they would afford a Romanian prince offering cryptocurrency opportunities.

The training email, sent from the external contractor CyberAware Solutions using a domain that bears no resemblance to the company’s own, asks employees to click a link and enter their login credentials to access the training portal. Those who fail to complete the module within five days receive escalating reminder emails, each more urgent and threatening than the last, which are also sent to junk.

Jennifer Holloway, a senior analyst who has worked at Meridian for six years, said she now operates on the assumption that any email about security is either spam or can safely be ignored until her manager mentions it in person. This has not yet happened.

The IT department’s own ticket system shows 23 requests in the past fortnight asking whether various legitimate company emails are phishing attempts. These include messages from HR about pension enrolment, a note from the chief executive about office refurbishment, and the weekly fire safety bulletin. All were genuine. None were opened.

Peasley said his team had considered sending a preliminary email to warn staff that the phishing training email was coming, but decided this would only add another layer to what he termed the palimpsest of unread security notices that now forms the bedrock of corporate communication.

The training module itself, which takes 45 minutes to complete and features a cartoon badger explaining what a URL is, has been mandatory company policy since an incident two years ago when someone in marketing clicked on an email offering cut-price toner cartridges. The company lost no data and suffered no breach. The person in marketing saved £340 on toner.

CyberAware Solutions will receive their £8,400 fee regardless of completion rates. They have already scheduled next month’s training, which will focus on the importance of reading security emails.

Leave a comment

Your email address will not be published. Required fields are marked *