Modern day reliability and security best practices are based on planning for failures assuming they are all inevitable.
Back in the old days we would just assume everything is going to work out but that just isn’t sustainable now with how complex and expansive systems have become. Basically, there are too many moving parts to account for every single possibility so people should expect systems to fail and know how to react when it happens.
Don’t show them the email in the first place, seems like an IT problem to me 🤷
New threats slip through, it will always happen. It’s why user training is an important part of security for a company.
It’s not a case of if there will be a security incident but when, you can only limit the likelihood and damage.
Yeah, what world is this person living in where email security is 100% effective!? I bet they also have zero false-positives in that fantasy land.
And the users will always click
Modern day reliability and security best practices are based on planning for failures assuming they are all inevitable.
Back in the old days we would just assume everything is going to work out but that just isn’t sustainable now with how complex and expansive systems have become. Basically, there are too many moving parts to account for every single possibility so people should expect systems to fail and know how to react when it happens.
Then IT should expect users to fail, it’s the thing they’re best at