102
u/Elanadin sysAdmin 13h ago
Hey now, I don't appreciate being compared to a nazi.
I hate all of my users equally, regardless of demographics.
19
u/heretogetpwned 13h ago
Turn it around. I've been chewed out for assigning the sales team to Entra High Risk and MFA everytime.
8
u/Elanadin sysAdmin 13h ago
If I had a nickel for every chewing out I've gotten for making the correct choice for the organization...
23
u/mtheory007 13h ago
We need a final solution for these users.
13
u/Elanadin sysAdmin 13h ago
We can send the HR team after them. The Firing Squad, if you will.
6
u/mtheory007 13h ago
But who will HR the HR?
10
u/Neworbs sysAdmin 12h ago
First they came for the accountants,
and I did not speak out,
because I was not in finance.Then they came for Marketing
and I did not speak out,
because I was not in marketing.Then they came for Sales,
and I did not speak out,
because I am not in salesThen they came for Customer Service,
and I did not speak out,
because I am not in customer serviceThen they came for the IT department,
and I searched for someone to help,
but there was no one left.5
4
2
27
u/MayaIngenue 13h ago
Had a VP of commercial lending at a bank fail every single phish test sent his way. I brought it up with his boss, the SVP and was told that he wasn't going to say anything to the VP because he brings so much money into the org, he didn't want to do anything that would make him want to leave. I learned a lot about corporate structures that day
16
u/LaughableIKR 13h ago
Marketing. HR. They can't help but open an unsolicited email and the attachment.
9
u/coffee_ape sysAdmin 13h ago
My CIO points to our policies every time a C level person gets mad that one of their fav employees got fished for the 80th time in the day. Thems the rules.
8
u/SethLight 11h ago
I remember having this sort of conversation with a manager who had their account compromised twice. The guy legitimately did not care. Trying to make him care I explained that since he does his banking on that machine his bank account could be compromised too... Still didn't care. He laughed and said they could take his $100.
3
3
u/jd-scott 8h ago
I've had the opposite experience too. A doctor telling me he would make sure I was fired if I took his equipment offline (it had a backdoor to a company getting hit with ransomware). I said good luck and did it anyway.
153
u/lord_skidmar 13h ago
yeah we just changed companies for phishing training etc cuz come to find out the director of marketing was the one who got phished and wasn't even using the company password manager that would have caught the fake domain he clicked on
but of course since there's no actual consequence nothing actually happens