
If you discovered that business had been hackedbecause one of your employees was fooled by a phishing email, would you consider firing that employee? Or if this was all part of a test you were conducting to test your employees, would you take such action?
But let's start with the reasons why you would want to take such a test.
You certainly want your business to be safe from the increasingly evolving risks of our time. From 2005 to 2018, more than 8,854 attacks have been reported and there are certainly many more that have never been reported
In addition, Phishing has proven to be a particularly useful tool for hackers and can have devastating results for a business, while at the same time being a relatively easy method for a malicious actor.
So it is vital for an organization that the people working for it are able to recognize a phishing email. A test could potentially inform you about an employee's abilities in terms of recognizing and dealing with such an incident. However, you should keep in mind that this test does not assess the general abilities of your employees.

Some companies have a very low tolerance for failing a phishing test. This is especially true in the financial industry, but also among other industries for reasons that are quite understandable. However, there are those companies that will fire employees who fail a large number of these assessments. Others, however, do these tests to keep their employees on their toes.
Unfortunately for these companies, what they fail to realize is that these behaviors will not improve security . Sure, firing someone who has trouble recognizing a phishing email means that person won’t put the company at risk, but who’s to say that whoever takes their place will be able to recognize them better? Not to mention, firing one person won’t help educate the rest of your employees about phishing attacks.
Finally, consider how the threat of consequences can influence an employee’s decisions. Many solutions offer the ability to report suspicious emails, and many employees (even if they’ve already clicked on the link) will report them. But if there are consequences for their mistake, they lose the incentive to report it. In short, your employees won’t trust you enough to tell you the truth.
What is the most correct way?
An unannounced phishing test is good, as long as it is accompanied by a review of the results and followed by training that will help employees improve.
You can also, instead of focusing on the negative, use positive reinforcement. Rewarding the department with the highest score on the test with a small bonus or gift cards will motivate all employees to be more attentive. You can also impose some kind of punishment on the group with the lowest score, such as buying lunch for the rest, which is somewhat negative for the one who did not do well, but certainly not as extreme as firing.
