Skip to content

Jul 15, 2026

Fire Drills, Not Gotchas

When it comes to IT security, everyone has their own view on how it should be done. Every IT guy has their favorite antivirus product and their reasons as to why it’s better than yours. That’s one reason why the switching costs from one IT company to another can be very high. Almost no two companies use the same security stack. But even when professionals can’t agree on which products to use, we generally all agree on the underlying security principles.

A lot of those principles are low-hanging fruit these days. Gone are the times when you had to shell out subscriptions to Norton to get decent antivirus and firewall protection for Windows. Microsoft’s Defender platform is perfectly adequate for most folks. Thanks to wireless routers, almost no one has a direct connection to the Internet anymore on their devices. And I’m pretty sure that you’ve got some second form of authentication on your most important private data, even if it’s a phone call to your copper landline. Yes, I know some people that won’t get a smart phone in 2026.

One of the things that all IT professionals agree on is that it is always better to have tested your assumptions out before something bad happens. No one wants the first time that they try to recover from a backup to be when all your files are already encrypted. We prefer to install updates on our equipment first, then give them out to clients after we’ve seen what they do. And in the case of a new type of email attack, I’d much rather the bad guys get to me first than my clients.

One of our assumptions is that when a phishing email shows up in our employee’s inbox, they’ll know what it is and get rid of it. As we have seen time and time again, it’s never that easy. Not only do the methods that the bad guys use constantly evolve, but employees can get complacent and start to trust their email if they haven’t seen a scam in a while.

That’s where phishing simulation training comes into play. Like fire drills train us how to act when the alarm goes off in a building, phishing simulations train us on what to look for to recognize a threat, and what to do when we see one. Just like the fire drill in elementary school wasn’t designed to see how many kids screw up to punish them, phishing training is all about building muscle memory, so we don’t have to think when something bad comes into our inbox. We just hit the report button and move on. Yes, there is training if you miss one, but that’s just to help so that next time you can see why.

Consistent training is also helpful as threats evolve. As Multi-Factor Authentication became the standard and not the exception, threat actors changed their methods to steal tokens or get malicious apps authenticated to users’ cloud accounts. Old tricks like looking at the address bar to ensure the site that is asking for permission is actually Microsoft’s don’t work with those anymore. So as threats evolve, our training should also evolve.

As with all tools, each IT vendor will have their preference on which one to recommend to their client. We recommend Microsoft Defender Plan 2, because it not only gives us access to deliver phishing simulations, but also expands our EDR, AIR, and threat hunting capabilities. It also integrates perfectly with Microsoft Exchange without the need for a third-party connection.

If you are interested in increasing your organization’s security posture, let us know and we’d be happy to talk more about Defender Plan 2 and other initiatives we have lined up for Nordic IT Solutions.

-Nate

Read More

Related Posts