We took the gamified approach to phishing. Even so far as giving users small monitary prizes for catching three fake phishes in a row or going x months without failing a test etc etc. I strongly feel the best approach is carrots instead of sticks. Treating people like crap because they made a mistake is the worst because when they click a real malicious email they are not going to say a thing if they got put on the chopping block for a fake one.
Do you have thoughts on an optimal to teach office people about this stuff that doesn't involve Sim phishing or boring slogs of stock photo videos?
Kanye: (praises Hitler)
Conservative show hosts: He’s not antisemitic. Let’s invite him on to prove it.
Kanye: I love Hitler.
Conservatives show hosts: We had no idea he would praise Hitler.