No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.
In my experience (I’m not in IT), the IT folks only get recognized for fuckups. When they do things right nobody notices and thinks they’re a waste of money, resulting in the company cutting back on their budget then freaking out when they’re not equipped to do their job and something goes wrong.
Ok let me rephrase: IT management never gets the flak they often deserve.
But also there’s a distinction to be made between competent IT and IT service contracts where the contract officers are corrupt and/or incompetent and then the service is awful as a whole.
No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.
In my experience (I’m not in IT), the IT folks only get recognized for fuckups. When they do things right nobody notices and thinks they’re a waste of money, resulting in the company cutting back on their budget then freaking out when they’re not equipped to do their job and something goes wrong.
Ok let me rephrase: IT management never gets the flak they often deserve.
But also there’s a distinction to be made between competent IT and IT service contracts where the contract officers are corrupt and/or incompetent and then the service is awful as a whole.