←back to thread

114 points BenjaminN | 2 comments | | HN request time: 0.912s | source

Ahoy Hacker News! I'm Ben, founder of Riot (https://tryriot.com), a tool that sends phishing emails to your team to get them ready for real attacks. It's like a fire drill, but for cybersecurity.

Prior to Riot, I was the co-founder and CTO of a fintech company operating hundred of millions of euros of transactions every year. We were under attack continuously. I was doing an hour-long security training once a year, but was always curious if my team was really ready for an attack. In fact, it kept me up at night thinking we were spending a lot of money on protecting our app, but none on preparing the employees for social engineering.

So I started a side project at that previous company to test this out. On the first run, 9% of all the employees got scammed. I was pissed, but it convinced me we needed a better way to train employees for cybersecurity attacks. This is what grew into Riot.

For now we are only training for phishing, but our intention is to grow this into a tool that will continuously prepare your team for good practices (don't reuse passwords for example) and upcoming attacks (CEO fraud is next), in a smart way.

Your questions, feedback, and ideas are most welcome. Would love to hear your war stories on phishing scams, and how you train your teams!

1. the-pigeon ◴[] No.22676901[source]
Love the idea! Unfortunately the IT group in my company is swamped with COVID-19 related work at the moment. But will be sure to bring it up with them once things calm down a little.

My company recently had a user fall for a very poor phishing attack (entered password into a Google Sheets request) so something like this could save IT and the company a lot of money.

replies(1): >>22676949 #
2. BenjaminN ◴[] No.22676949[source]
Since everyone is moving to remote right now, hackers are enjoying the overall disorganization of companies. I've seen a growing number of phishing attacks for the past few weeks.

I wouldn't be surprised if we get a major data leak caused by COVID-19 in the coming days.

PS: great username by the way.