What Does KnowBe4 Think About Link Re-writing?

Stu Sjouwerman | Jan 16, 2019

gregkrasThis is a question that was asked by a customer who was implementing our Phish Alert Button so that employees could report phishy emails.

Greg Kras, our Chief Success Officer replied with:

"In doing some surveying of customers and folks that have constant interaction with customers it seems that strategies vary between sites but there are a few commonalities that I can share:

  • Most organizations instruct their end users to err very much on the side of caution, dodgy links get reported and response team responds either automatically or manually
  • Some organizations have implemented policies of “normal vendors” and created training campaigns that contain a list of known URLs as a reference that users can look at
  • Some organizations have rolled out Second Chance and whitelisted the known vendors, that way users get prompted for the unknown and get a moment to pause and think*

Safe link and link re-writing services are certainly something that we’ve seen adoption of by customers but we have found that those often serve to confuse the end user as now everything “goes to the same place”.

I’m personally not a fan of reducing the already limited information a user can glean from an email, particularly since the link re-writing is typically executed a technical control that should have blocked/caught the message before getting in front of the user. I prefer URL inspection on egress if feasible.

Ultimately we always find that user education is the answer that transcends the technical controls, the more isolated the user is from making awareness driven decisions the more likely they are to be taken advantage of when the inevitable threat emerges.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Topics: KnowBe4

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.