No route to report a suspicious email, and none was reported
- Affected asset
- Staff phishing campaign, 240 recipients
- Rating
- Moderate Possible 3 × High 4 = 12
Description
A credential-harvesting campaign reached 240 staff. A number engaged and a smaller number entered credentials on the monitored landing page. More telling than the click rate was that not one recipient reported the email, because there is no button or address to report to, and the response process was never triggered.
Evidence
Campaign: "Payroll update required" (consented, monitored)
Delivered : 240
Opened : 171 (71%)
Clicked the link : 86 (36%)
Entered credentials : 29 (12%)
Reported to IT : 0 ( 0%) # no reporting route exists
The engagement figures matter less than the last line: with no way to report, the incident-response process never started.
Impact
A real campaign would have harvested twenty-nine sets of credentials with the defenders entirely unaware, because nothing and no one raised the alarm. The absence of a reporting route turns a survivable incident into a silent compromise, and it is a process gap, not a failing of any individual.
Remediation
Add a one-click report button to the mail client and a monitored address, and make reporting the trained response rather than deletion. Rehearse the process that a report triggers, and measure reporting rate as the primary metric in future campaigns, above click rate.