Posts

Showing posts with the label Security Awareness

Security Awareness Training: Building a Program That Changes Behavior

Security awareness training has a reputation problem, and mostly it is deserved. An annual compliance video that everyone clicks through at 4:50 p.m. on the last day of the quarter changes nobody's behavior. CompTIA tests awareness as a program with components, cadence and metrics — not as an event. Why It Is a Control at All People are involved in the large majority of breaches, usually through phishing, credential reuse or misconfiguration. Technical controls handle what they can, but no filter catches every message and no policy engine stops someone from approving a fraudulent invoice. Awareness is the control that addresses the decision itself. It is a compensating control, not a primary one. If your answer to a phishing question is "train the users" and nothing else, the answer is incomplete. Training reduces the rate; layered technical controls handle what gets through. Program Components Security+ expects familiarity with the standard pieces: Onboardin...

Phishing Simulation Programs: Design, Metrics, and What Not to Do

A phishing simulation sends controlled, harmless lookalike messages to your own staff and measures what happens. Gophish is the common open-source platform for running them, but the platform is the easy part. Program design is what determines whether a simulation improves security or quietly damages the relationship between the security team and everyone else. How a simulation works The mechanics are the same as real phishing, minus the payload. You define a target group, compose a message, host a landing page on a domain you control, and send. Each recipient gets a uniquely tracked link, so the platform can record who opened the message, who clicked, who submitted data on the landing page, and who reported it. The landing page is where the training happens. Rather than a fake login that harvests credentials, a well-built simulation lands the user on a short page explaining what just happened and pointing out the specific cues in the message they missed. Delivery requires preparat...

Credential Harvesting Pages: How Social Engineering Attacks Are Built

Social engineering toolkits automate the mechanics of an attack that is fundamentally about people. Understanding what they automate is useful to defenders because each automated stage is a stage you can break, and the controls that break them are different at each step. The credential harvesting page The most common attack in the category is also the simplest. An attacker clones a login page — the real one, fetched and saved so the HTML, CSS, and images match exactly — and hosts it on a domain of their own. A victim who reaches it and enters credentials hands them straight to the attacker, who then forwards the browser to the genuine site so the user sees a normal login and suspects nothing. Nothing about the page is exploited. It is a copy, and the deception is entirely in the domain name and the context that got the victim there. That is why the technical countermeasures aim at the domain and at what the credentials are worth once stolen, rather than at the page. Loo...

Pretexting: How Attackers Build a Believable Story to Get What They Want

Pretexting is inventing a scenario — a role, a reason, a context — that makes a request seem legitimate. It is the foundation underneath most social engineering rather than a separate technique. A phishing email works because it comes with a pretext; remove the story and it is just a link nobody clicks. What makes a pretext work The lever is specificity. Anyone can claim to be from IT. Someone who names your actual ticketing system, your actual IT manager, and the actual maintenance window scheduled for this weekend is not obviously lying, and checking would feel insulting. That detail comes from reconnaissance. Staff directories, job postings, press releases, social media, conference talks, and document metadata supply names, titles, reporting lines, vendor relationships, and technology in use. The material is public and individually harmless; assembled, it is a script. Authority does most of the remaining work. A request that appears to come from an executive, an audi...

Phishing Campaigns Explained: Simulation and Training for Security+

A phishing campaign, in the Security+ sense, is an internal simulation: you send your own staff a realistic but harmless phishing email, measure what happens, and use the result to target training. The exam treats it as a security awareness control, and the questions tend to be about what you measure and how you run it responsibly rather than how to craft the email. Why simulate at all Technical controls stop a great deal of phishing, and some still arrives. Once it does, the decision rests with a person. Training that consists of an annual slide deck does not change behaviour under time pressure; practice does, and the only way to know whether it worked is to measure. Simulations also find where the risk is concentrated. A finance team that handles payment changes is a different exposure from a warehouse team that rarely uses email, and the response should differ. Running one Get authorisation first. Written approval from senior management, and involve HR and legal before anyth...

Clean Desk Policy: The Low-Tech Control That Closes Real Gaps

A clean desk policy requires that workspaces be cleared of sensitive material whenever they are unattended. Papers go in locked storage, screens are locked, whiteboards are erased, removable media is put away. It sounds like housekeeping, and it is routinely dismissed as such — which is exactly why it appears on the Security+ exam as an administrative control with a physical effect . What it is protecting against The threats are unglamorous and common. Shoulder surfing needs nothing more than a visitor glancing at a monitor or a printout while walking past. Casual data collection by anyone with routine building access — cleaning staff, contractors, delivery personnel, a candidate waiting in a conference room — requires no skill at all when the material is lying face up. Credentials on sticky notes remain a real finding in real assessments. So do printed reports left in output trays, notepads with system names and IP addresses, and whiteboards holding an architectur...

Public Wi-Fi and Captive Portals: Real Risks and Sensible Advice

Public Wi-Fi advice has not kept up with what changed. Ten years ago an open network meant your traffic was readable; today almost everything is encrypted end to end, and the standard warnings describe a threat that has largely moved elsewhere. Knowing what is still true matters, because advice people recognize as outdated gets ignored entirely. What is no longer the main problem On an open network, frames are unencrypted at the radio layer, so anyone nearby can capture them. That used to mean reading traffic. Now it mostly does not. The overwhelming majority of connections use TLS, so a captured frame contains ciphertext. What remains visible is metadata: which hostnames were requested, via DNS unless encrypted and via the server name in the TLS handshake, along with volumes and timing — which is real and is a different exposure from reading content, as discussed under packet capture . Enhanced Open — the opportunistic encryption in WPA3 — encrypts an open networ...