Re: Find the weak spots
"Would it be legal to send emails to your own employees to identify these individuals and then "allow them to pursue new opportunities" before they have the chance to compromise your company?"
Actually our company DOES send out test emails, though I believe it is more for testing and educating - at least I am not aware of any more serious action being taken.
All email coming from outside our enterprise is automatically delivered with red text at the top saying "External Email" so at least it is harder for someone to spoof coming from a legitimate company employee. My thoughts are that if they fail this one "education" should only be an option the first time.