If a single click on a phishing email can ruin the entire company, the blame doesn’t lie with that individual.

  • TheEighthDoctor@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Yes but not every user need access to every system all the time and there should be alerts set up for logins outside of working hours, expected devices and IPs. There should be behavior based alerts, for example, why is the HR lady opening PS?

    There are many things that can be done to secure the systems post-compromise.