Reply to post:

To test its security mid-pandemic, GitLab tried phishing its own work-from-home staff. 1 in 5 fell for it

ThunderCougarFalconBird

The company I work for does stuff like this regularly. If you get a phishing email an *DO NOT* report it to security, then that's a demerit. If you open the email and click on any of the links in the email, that's a demerit. If you expose any secure information like passwords or confidential information or documents, that's a demerit. You are only allowed 3 demerits (a 3 strikes rule) After your 3rd demerit, you are escorted out of the building. I only know of one employee where this happened to them. I was working with her on an issue and I said I'll send a test email. She asked not to because she was already at 2 demerits and as a result, she doesn't open emails anymore...well, a week went by and I saw her out in the parking lot with a box of her stuff. She later told me she had gotten her 3rd strike that day and was gone! Oh well...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon