
Information Technology Services (ITS) is using a phishing simulation program to evaluate how the George Mason University community recognizes and responds to phishing emails.
Matthew Dalton, Chief Information Security Officer, compares the simulation to an inoculation program, where a vaccine is administered to fight off a virus and build immunity. The program will help community members recognize phishing emails and not take the bait, he said.
Through the simulation, community members will receive an email that imitates a phishing message. Recipients who respond will see a message stating that the email was a simulated phishing attempt. They will also get information about recognizing phishing emails and why it is important not to respond.
Dalton said the simulation is like a ‘catch and release’ program — if people get caught responding to the simulated phishing email, they are released back into the pond with information to keep them safe.
Responses to the simulation are not meant to penalize people, but to provide ITS with information, said J.D. Sayle, an analyst with Cybersecurity Operations. “This is not punitive. It is to give us a baseline for where our population is.”
The simulation is another tool Cybersecurity Operations is using to combat phishing, Sayle said. Microsoft predicts that 40 of an organization’s population will respond to a phishing email. Results from the simulation will allow ITS to determine George Mason’s response baseline. It will help guide email security messaging and training to better protect community members’ personal and financial information, including George Mason’s IT assets.
Simulations will not capture or store passwords, Sayle said. “We cannot see passwords or Duo Two-Factor Authentication (2FA) codes in the simulator. In fact, ITS will never call or email asking users to share their passwords or 2FA codes.”
Sayle said it is important to remember this is not a ‘gotcha’ operation but an effort to raise vigilance among the George Mason community.
People who receive phishing emails in their Microsoft Outlook inbox should report them directly to ITS by right clicking the email, selecting ‘Report,’ and then ‘Report phishing.’ For more information about reporting phishing, see Reporting a Phishing Email in Outlook.