"But, But, But... I Didn't Click!" False Positives In Phishing Tests

Stu Sjouwerman | Sep 10, 2016

The following question was posted in the SANS Securing The Human forum. I thought it was a very good point and asked our VP Product Greg Kras for his perspective.  First the question:

But I didn't click! Our vendor for phishing assessments uses a custom link for the recipient. It works well except when the recipient forwards the email and someone else clicks on the same link. Can you share with me if you use a different type of tracking mechanism to reduce false positives?

 Greg answered:

"The same thing would happen with our platform, you would only know to whom the original email was sent and not necessarily who was the actual clicker. However what we do have that mitigates this problem is our Phish Alert Button (PAB) which is an add-in for Outlook/Office365 (soon Gmail & Lotus).

"This button is designed for a controlled method of reporting phish emails that ensures that the messages go to the right team and include all of the important information such as original headers. The PAB detects if the message is a simulated phish and lets the user know upon submission that it was simulated, deleting the message and not forwarding it to the incident team."  


Free Phish Alert Button

When new ransomware campaigns hit your organization, it is vital that IT staff be alerted immediately. One of the easiest ways to convert your employees from potential targets and victims into allies and partners in the fight against ransomware is to roll out KnowBe4's free Phish Alert Button to your employees' desktops. Once installed, the Phish Alert Button allows your users on the front lines to sound the alarm when suspicious and potentially dangerous phishing emails slip past the other layers of protection your organization relies on to keep the bad guys at bay.

Get your Phish Alert Button

Don't like to click on redirected links? Cut & Paste this link in your browser:

https://www.knowbe4.com/free-phish-alert? 

 

Topics: Phishing

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.