21
That time my coworker publicly shamed me for clicking a phishing link at 2pm on a Tuesday
He stood up in the middle of the open office and said 'you just gave our domain away to a bot in Latvia' as a joke, but it actually made me rethink how we handle mistakes. Is public embarrassment a decent deterrent for security slip-ups, or does it just make people hide their clicks and never report anything? Has anyone else seen a team handle this better?
2 comments
Log in to join the discussion
Log In2 Comments
anderson.piper1mo ago
Oh man, that story gave me secondhand cringe! I used to think calling people out in front of everyone was the only way to make the lesson stick, but I totally changed my mind after watching it backfire at my old place. One guy got roasted for a mistake, and after that everyone just quietly clicked and never said a word, which made things way worse when something finally blew up. Now I figure the real trick is making people feel safe to say "hey, I messed up" so you can fix it fast, not shame them into hiding it.
7
hugoj121mo ago
Take the trust angle even further, because once people know they can be honest without getting burned, they start flagging small issues before they turn into big ones. In my experience, that quiet warning early on saves everyone a whole lot of headache compared to waiting for the loud breakdown later. So yeah, making it safe to mess up is basically the cheapest insurance a team can buy, just takes a bit of patience to build.
1