Its not the actual individuals - its the culture it creates, "HA! We caught you, you dumbass, here's 2hrs of training". This means people are afraid to report or take ownership over looking out for phishing as it creates no benefit for them, its just there to make the security team smug.
Having been part of and designed these campaigns before (with open source options like https://getgophish.com/), there is no way to report as phishing or reward users who detected but therefore didn't interact with it. This means in your example - did the other 81% just not open it, ignored it, or actively thought it was phishing? These are key metrics a company needs to know their potential attack surface.
"If just one user reports a phish, you can get a head start on defending your company against that phishing campaign and every spotted email is one less opportunity for attackers...but phishing your own users isn't your only option.
Try being more creative; some companies have had a lot of success with training that gets the participants to craft their own phishing email, giving them a much richer view of the influence techniques used. Others are experimenting with gamification, making a friendly competition between peers, rather than an 'us vs them' situation with security."
I find it amazing they offer a brilliant online streaming service but you have to be abroad (Gamepass - I'm UK based).
I pay something like 20GBP a month during football season and get every game live in HD via chromecast, iOS, Web or Android plus redzone. They evidently have the chops and infrastructure to do it but its all a question of running the oligolpoly with the broadcasting services in the US.
I think has a lot to do with manual transmission which allows for natural and controlled engine breaking, thus not creating the brake light to come on (and therefore the wave of copy-cat type braking).
our product stores all the logs raw in flats files on the file system, we don't use databases for keeping the logs in, this allows you to scale massively (ingestion limit is that of the correlation engine and disk bandwidth). You then just need an efficient search crawler and use of metadata so search performance is good too.
Issue is if you every need to pull the logs for court and you have messed with them (i.e. normalized them and stuffed them into a DB) then your chain of custody is broken.
Best of both worlds means parsed out normalisation so I don't have to remember that Juniper calls source ip srcIP and Cisco SourceIP, but the original logs under the covers for grepping if you need.
Moved to PFSense a few months ago and I cannot recommend it enough, I have it on a Thinkserver tower which hosts all my VMs on ESX and out of a second NIC comes my wifi router.
Pfsense is such a great piece of software, DNS forwarder and build in OpenVPN.
I feel lucky like yourself of being in one of the divisions with massive growth.
I don't think people appreciate the size and breadth of IT IBM does, my "tiny" division of security if an independent company would be the 3rd biggest Security vendor in the market.
I think you are underestimating the scale of what a Z system can run... You might not have a use but every fortune 500 and banking institution in the world does - and they need it to work, 5 9's isn't good enough.
> IBM Hursley laboratory director Rob Lamb says: “There are 6,900 tweets, 30,000 Facebook likes and 60,000 Google searches per second." The mainframe CICS runs 1.1m transactions per second, which equates to 10bn per day [0]
I drove one a few summers ago as a chauffeur for Farmers Classic, it was all in/around LA so was incredible on jammed freeways, It's nothing new though or Tesla specific.
He was a soldier in the Army, so very likely he got reprimanded rather strongly by his CO. I am not sure where "poor" and "rich" people come into this?
Arrived slightly later and not known who the perpetrator was or have admissible evidence to that effect. The guy had already run away onto another street - it's likely he wouldn't have been caught.
It also very much changed the officer handling us behaviour I would imagine, as usually in such brawls they detain everyone then get he said/she said stories. Instead he knew the guy had run across the street after we hadn't even acknowledged him, so knew my friend was the "victim".
It's interesting as the only involvement I have had with CCTV was positive.
On a night out in a city, myself and my friend were walking home from a club about 3.30am. We were joking about me being from the North and him being southern (a common UK joke), this was unfortunately overheard by someone nearby who took it personally and started punching my friend in the head, I managed to break it up and the other chaps mates pulled him away as his was rather inebriated. A girl nearby ran over after seeing this and called the police and within a minute a police officer had arrived - the most interesting and relevant part was that the officer had been dispatached by CCTV operators who had seen the whole incident. The policeman was being relayed that the perpetrator had been already arrested by a colleague down the street (after CCTV identified him), the officer with us knew it was an unprovoked attack as the CCTV operator saw at no point did we interact with the assailant, so treated us with respect and started explaining the options for prosecution.
I appreciate the flip side of the coin but personally now feel much safer when in an area with CCTV.
It does, it's just centralised and called a power station... it's incredibly naive to think a Telsa isn't contributing to burning fossil fuels - it's just not in front of your face.
Also I am not sure whether any modern power grid in the world could cope if even 10% of cars became PHEV, imagine the spike when everyone got home and plugged in their car - would be like a "TV Pickup[0]" on steriods, they usually cover these with short term solutions such as hydro pump but this wouldn't run the time it takes to charge a car.
I would immediately reply to the company rescinding my account and informing them this highlights a total lack of understanding of securing peoples personal details.
Having been part of and designed these campaigns before (with open source options like https://getgophish.com/), there is no way to report as phishing or reward users who detected but therefore didn't interact with it. This means in your example - did the other 81% just not open it, ignored it, or actively thought it was phishing? These are key metrics a company needs to know their potential attack surface.