On Fire Drills and Phishing Tests
ID: 86c0911a-31e2-53cc-8019-85f3e6cd13e6
STIX ID: report--86c0911a-31e2-53cc-8019-85f3e6cd13e6
Feed Name: Google Online Security Blog
This blog critiques traditional, surprise-based phishing tests—often mandated by frameworks like FedRAMP—as ineffective, operationally burdensome, and harmful to user trust, arguing they don’t reduce successful phishing and can require bypassing real defenses. It proposes replacing them with transparent “phishing fire drills” that train employees to recognize and report phishing, measure response-oriented metrics (e.g., time to first report, escalation timing), and emphasize secure-by-default engineering controls such as passkeys and multi-party approvals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
