What sort of rewards do employees get for successfully reporting suspicious emails or other kinds of phishing?

2k viewscircle icon2 Comments
Sort by:
Director of Engineering2 years ago

Whilst we do not (generally) reward users for successfully reporting simulated, or even legitimate phishing mails, we do recognise their efforts. However, during the Security Awareness Week in Oct, we have used prizes for users who complete all training and successfully identify the phishing emails sent during that week.

I think that recognition, resulting in closing the loop, awareness and learning are the best outcomes to drive behaviour.

Lightbulb on1
Head of Information Security in Services (non-Government)2 years ago

We don't currently offer rewards for reporting phishing, but it's something we're interested in pursuing. We want to reward good behavior and, when people do report phishing attempts, we also want to tell them whether it actually was or was not a phishing email. Through certain platforms, you can provide that affirmation for positive identifications and if an email is mistakenly reported, you can tell the user that it wasn’t phishing but thank them for reporting it anyway.

Lightbulb on1

Content you might like

We are fully remote.15%

At home but we are transitioning to a hybrid model.27%

At home but we are transitioning to full time in-office.9%

At home & in-office; we use a hybrid model.41%

In office full time.5%

View Results

Use vendor integrations46%

Fragmented ecosystem59%

Utilize in-house staff41%

Other (comment below)1%

View Results