Distributing a phishing exercise is not advisable when attempting to address the issue of colleagues not reporting personal data breaches. Instead, the recommended steps are to review reporting activity on breaches, improve communication, and provide role-specific training to areas where breaches are happening. These steps will help to ensure that everyone is aware of their responsibilities and that they understand how to report a breach should one occur.
[References:, https://www.itgovernance.co.uk/blog/5-reasons-why-employees-dont-report-data-breaches/, https://www.ncsc.gov.uk/guidance/report-cyber-incident, https://www.ncsc.gov.uk/guidance/phishing-staff-awareness, , ]
Submit