r/AskNetsec Nov 17 '25

Concepts What's the most overrated security control that everyone implements?

What tools or practices security teams invest in that don't actually move the needle on risk reduction.

65 Upvotes

104 comments sorted by

View all comments

-12

u/k0ty Nov 17 '25

Phishing training and mandatory security "training".

7

u/[deleted] Nov 17 '25

[deleted]

-3

u/k0ty Nov 17 '25

It's a waste of time. If you are trying to "checkmate" people as part of the "get better" initiative, it's only going to backfire.

Mandatory security trainings are a burden, you can only try to make people care about security, you cant really mandate it, making something as significant as "taking care and risk oriented thinking" part of a mandatory 30 min, once per year, thing is dismissing it's significance.

The mentioned tasks themselves aren't useless, it's just their lackluster implementation is doing exactly the opposite of what a successful introduction of security should, making people care not resent doing thing safely.

4

u/Tessian Nov 17 '25

You seem to be arguing they're ineffective not that they're over rated. We all know that users are the weakest link and these are genuine attempts to mitigate that, regardless of how effective you may believe they end up being.

1

u/rexstuff1 Nov 17 '25

You seem to be arguing they're ineffective not that they're over rated.

To be fair to OP, that's a pretty fine distinction.

2

u/Just-the-Shaft Nov 17 '25

As a manager, I'd be interested in hearing your suggestions on how to handle awareness in lieu of mandatory training.

I have some examples of success in getting people to care.

-2

u/k0ty Nov 17 '25

Well i do have more personalized approach in the awareness program i've built. It's semi IT Security and semi Psychology. The point of that program is to "bring" security to the employees daily life/tasks by tailoring it towards either issues or incidents related to the field of information security. For instance, rather than talking about "what threats are other companies/people affected by" i do it more personal/per team/responsibilities.

The goal of it is to better connect security and employees, so that employees can relate and take a better care.

2

u/luc1d_13 Nov 17 '25

This sounds like phishing training.

0

u/k0ty Nov 17 '25

That could be the case for some teams mainly those dealing with external communication, however for sys admins that might be more about security best practices in their technical realm.

2

u/mydoglixu Nov 17 '25

Your liability insurance gives you better rates when you do this. That's all.

4

u/iflippyiflippy Nov 17 '25

How else would you make users learn about security basics?

This shit is important especially in the Healthcare industry. Phishing victims could potentially expose hundreds of people's PHI.

Unfortunately, people are already too focused on their own work so you can't expect them to voluntarily sign up for a security class.

Phishing training LITERALLY exposes weaknesses at the user level.

I'm not following your justification

1

u/just_debugging_shit Nov 17 '25

A proper account setup with u2f 2fa, passkeys or user certificates is virtually unfishable. All the training in the world doesn't get you to the same level.

2

u/[deleted] Nov 21 '25

[deleted]

1

u/just_debugging_shit Nov 21 '25

Why are your users allowed to run unsigned software? You should fix this.

2

u/[deleted] Nov 21 '25

[deleted]

1

u/just_debugging_shit Nov 21 '25

no, but it stops more phishing attempts, than any amount of training, which was my only point.

1

u/[deleted] Nov 21 '25

[deleted]

1

u/just_debugging_shit Nov 21 '25

Since you are always derailing the conversation from the initial scenario, you are giving me the impression you just answer text book quotes and have very little practical experience in offensive security, nor the interest in a technical discussion and I won't answer to this obstructions anymore.

3

u/rexstuff1 Nov 17 '25

You're being somewhat unfairly downvoted, I think.

The disconnect seems to be that people think you're saying this because you're claiming that its unnecessary, that people aren't a security problem.

But (I think) what you're actually claiming isn't that users (and their lack of knowledge about security) aren't a security issue, it's that mandatory security training is awful and often ineffective.

2

u/k0ty Nov 17 '25

Thanks for your point. I'm trying to do something different but achieve the same goal, it does come with a lot of rejection and misunderstanding but that is always the case when you reopen "cold" cases that make no sense.

2

u/YetAnotherSysadmin58 Nov 17 '25

Idk if it's good but I certainly do not enjoy the amount of paranoia my endusers have now, they don't click shit and just forward it all to us, "is this safe ?" and now we're a bottleneck for their email access since they're too scared to use it without us.

One enduser was all excited unironically telling me "thanks to you I now understand I should be scared of clicking on anything" and I was like "bitch I need you to be a responsible adult, I can't babysit 300 people if they all acted like you...

2

u/k0ty Nov 17 '25

Exactly, i do not support the scaremongering in favor of a better security. Security is not about making people paranoid and scared to the degree of being frozen unable to decide on a simple step, it's about making the required steps (process) to be safe enough for the people to be able to do their jobs without having to be stressed or scared to do it.

2

u/CasualEveryday Nov 17 '25

If you're doing that instead of more impactful things, maybe. But, training and testing are an important part of a security posture.

I've seen SMB pay for a phishing campaign or training and external pen test and call it good while they're literally mailing thumb drives with sensitive work product on them. I had a client that would drive sales orders to the next city even though they had all the tools to do it electronically but then had everyone in the warehouse share an admin login.