logo

On Fire Drills and Phishing Tests

ID: 86c0911a-31e2-53cc-8019-85f3e6cd13e6

STIX ID: report--86c0911a-31e2-53cc-8019-85f3e6cd13e6

Feed Name: Google Online Security Blog

Date Published: 2024-05-22

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

This blog critiques traditional, surprise-based phishing tests—often mandated by frameworks like FedRAMP—as ineffective, operationally burdensome, and harmful to user trust, arguing they don’t reduce successful phishing and can require bypassing real defenses. It proposes replacing them with transparent “phishing fire drills” that train employees to recognize and report phishing, measure response-oriented metrics (e.g., time to first report, escalation timing), and emphasize secure-by-default engineering controls such as passkeys and multi-party approvals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.