Phishing isn't the employee's fault

If a single click can compromise the company, the problem isn't the click. It's the architecture.

Employee training is necessary, but it isn't a strategy. People will make mistakes — under pressure, at the end of the day, on holiday, on a phone. A healthy organization assumes the mistake and limits its consequences.

Two-step authentication, least privilege, separate administrative accounts, and monitoring on critical accounts: four measures that turn a bad click from a crisis into a minor incident.

The message for leadership: don't just buy training. Require that a single human mistake cannot stop the company.

Back to writing