
A security consultancy in February will launch a portal to <A HREF="http://www.eweek.com/article2/0,1895,2234759,00.asp?kc=EWKNLNAV121707STR1">automate the infliction of faux spear-phishing attempts</A> on one's own work force--an educational tactic that experts are increasingly pointing to as one effective method to stem the tide of information being unwittingly handed to thieves. The site, PhishMe.com, will be launched by Intrepidus Group, a consultancy with offices in New York and Chantilly, Va. It will feature templates for crafting customized faux phishing attacks and WYSIWYG workflow. In addition, the service will provide educational error message warnings to employees who attempt to enter sensitive information.
Intrepidus will provide statistics on how many employees open the faux phishing messages, how many of them open links directly from the phony phishing email, how many copy and paste the URLs into their own browser windows (considered a safer method to check out an emailed link than clicking directly from the email), how many employees ignore the messages altogether, and how many attempt to enter sensitive information. No sensitive information will be collected or allowed to be entered, according to Intrepidus Managing Partner Aaron Higbee.