logo

Google guru roasts useless phishing tests, calls for fire drill-style overhaul

ID: fa860a0b-d9ca-51e1-b630-4e0b7d911b98

STIX ID: report--fa860a0b-d9ca-51e1-b630-4e0b7d911b98

Feed Name: The Register (Security)

Date Published: 2024-05-23

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Google’s Matt Linton argues that traditional, deceptive phishing tests mandated by some standards bodies erode trust and show little evidence of reducing real phishing success, especially when controls are disabled for testing. He recommends shifting to transparent, fire-drill-like exercises and prioritizing secure-by-default engineering measures—such as passkeys, multi-party approvals, and layered defenses—aligned with UK NCSC guidance to make it harder for attackers to reach users, improve reporting, limit impact, and speed incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.