Educause Security Discussion mailing list archives

Re: Faculty Acceptance of Security Awareness Education?


From: Valdis Kletnieks <Valdis.Kletnieks () VT EDU>
Date: Tue, 1 Dec 2009 12:39:39 -0500

On Tue, 01 Dec 2009 12:29:02 EST, Matthew Wollenweber said:

While I was doing pen testing, our phishing service tended to have a 40-60%
success rate for unsophisticated targeted attacks.

At this point, I think we need to make sure we're all on the same page.

Do we mean 60% success that "60% of the time, we got back *A* credential
that allowed us to continue", or "we send 100 copies of the phish, and
get back 60 credentials"?

I suspect that may explain why some groups are reporting 75% success and
others are reporting 7%...

Attachment: _bin
Description:


Current thread: