Google guru roasts useless phishing tests, calls for fire drill-style overhaul
ID: fa860a0b-d9ca-51e1-b630-4e0b7d911b98
STIX ID: report--fa860a0b-d9ca-51e1-b630-4e0b7d911b98
Feed Name: The Register (Security)
Google’s Matt Linton argues that traditional, deceptive phishing tests mandated by some standards bodies erode trust and show little evidence of reducing real phishing success, especially when controls are disabled for testing. He recommends shifting to transparent, fire-drill-like exercises and prioritizing secure-by-default engineering measures—such as passkeys, multi-party approvals, and layered defenses—aligned with UK NCSC guidance to make it harder for attackers to reach users, improve reporting, limit impact, and speed incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
