{
  "count": 25,
  "license": "CC BY 4.0",
  "source": "https://psysec.io/research/behaviors",
  "behaviors": [
    {
      "code": "PB-01",
      "slug": "reports-suspicious-messages",
      "actor": "person",
      "name": "Reports suspicious messages",
      "summary": "Uses the reporting button or channel whenever a message feels wrong, whether or not they clicked.",
      "why": "Reports turn one person's instinct into an early warning for everyone. In large field studies, employee reporting spotted real campaigns quickly, even when training changed little else.",
      "observe": "Suspicious Email Reporting Rate (SERR): reports per simulation and per real phish, and time from delivery to first report.",
      "tactics": [
        "Urgency",
        "Scarcity",
        "Trust",
        "Helpfulness",
        "Authority",
        "Social Proof"
      ],
      "principles": [
        3,
        8
      ],
      "chain": [
        "behavior",
        "habit"
      ],
      "impacts": [
        "Account compromise",
        "Data compromise",
        "Financial loss"
      ],
      "evidence": "Strong",
      "sort": 1,
      "studies": [
        {
          "slug": "lain-2022-phishing-in-organizations",
          "relation": "supports"
        },
        {
          "slug": "burda-2025-phishing-reporting-motivation",
          "relation": "supports"
        },
        {
          "slug": "pilavakis-2023-i-didnt-click",
          "relation": "context"
        },
        {
          "slug": "rozema-2026-anti-phishing-training-still-does-not-work",
          "relation": "challenges"
        }
      ]
    },
    {
      "code": "PB-02",
      "slug": "pauses-under-pressure",
      "actor": "person",
      "name": "Pauses when a message pushes them to act fast",
      "summary": "Treats deadlines, threats, and 'act now' language as a signal to slow down, not speed up.",
      "why": "Pressure pushes people into fast, habitual email routines where warning signs get skipped. Pausing gives conscious processing a chance to catch up.",
      "observe": "Click rates on high-urgency Simulations compared with low-urgency ones; reports that cite urgency as the reason.",
      "tactics": [
        "Urgency",
        "Scarcity"
      ],
      "principles": [
        6,
        8
      ],
      "chain": [
        "emotion",
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Financial loss"
      ],
      "evidence": "Moderate",
      "sort": 2,
      "studies": [
        {
          "slug": "vishwanath-2018-scam-model-phishing-susceptibility",
          "relation": "supports"
        },
        {
          "slug": "ferreira-2019-persuasion-phishing-emails",
          "relation": "supports"
        },
        {
          "slug": "vanderheijden-2019-cognitive-triaging-phishing",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-03",
      "slug": "verifies-unusual-requests",
      "actor": "person",
      "name": "Verifies unusual requests through a second channel",
      "summary": "Confirms payment changes, credential requests, and odd asks by calling or messaging the person through a known, separate channel.",
      "why": "Authority and familiar-sender cues raise clicks, and AI now writes convincing personalized messages. Out-of-band checks hold up even when the message itself looks perfect.",
      "observe": "Share of payment-change or gift-card Simulations that end in a verification call or report instead of a reply.",
      "tactics": [
        "Authority",
        "Trust",
        "Helpfulness"
      ],
      "principles": [
        8
      ],
      "chain": [
        "behavior",
        "habit"
      ],
      "impacts": [
        "Financial loss",
        "Account compromise",
        "Identity theft & fraud"
      ],
      "evidence": "Moderate",
      "sort": 3,
      "studies": [
        {
          "slug": "williams-2018-susceptibility-phishing-workplace",
          "relation": "supports"
        },
        {
          "slug": "heiding-2024-llm-automated-spear-phishing",
          "relation": "supports"
        },
        {
          "slug": "wash-2020-how-experts-detect-phishing",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-04",
      "slug": "trusts-the-sense-something-is-off",
      "actor": "person",
      "name": "Acts on the sense that something is off",
      "summary": "Stops when a message feels wrong, even before they can say exactly why.",
      "why": "Experts detect phishing by noticing small discrepancies first, and the body can signal risk before the conscious mind explains it. That instinct is reliable only where feedback is fast and patterns are real, so it needs practice.",
      "observe": "Reports that mention a 'gut feeling' or a small mismatch; improvement in reporting over repeated Simulations.",
      "tactics": [
        "Trust",
        "Authority"
      ],
      "principles": [
        6,
        8
      ],
      "chain": [
        "emotion",
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Data compromise"
      ],
      "evidence": "Moderate",
      "sort": 4,
      "studies": [
        {
          "slug": "wash-2020-how-experts-detect-phishing",
          "relation": "supports"
        },
        {
          "slug": "bechara-1997-deciding-advantageously",
          "relation": "context"
        },
        {
          "slug": "kahneman-2009-conditions-intuitive-expertise",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-05",
      "slug": "reports-own-mistakes",
      "actor": "person",
      "name": "Reports their own mistakes quickly",
      "summary": "Tells the security team right away after clicking a link, opening a file, or entering a password on a suspicious page.",
      "why": "Minutes matter after a compromise. People only admit mistakes where it feels safe to do so; fear and shame make them hide the click.",
      "observe": "Self-reports after a click in Simulations; median time from click to self-report.",
      "tactics": [],
      "principles": [
        2,
        3
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Data compromise",
        "Business interruption"
      ],
      "evidence": "Emerging",
      "sort": 5,
      "studies": [
        {
          "slug": "edmondson-1999-psychological-safety",
          "relation": "supports"
        },
        {
          "slug": "tolsdorf-2025-phishing-university-hospital",
          "relation": "supports"
        },
        {
          "slug": "pilavakis-2023-i-didnt-click",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-06",
      "slug": "questions-apparent-authority",
      "actor": "person",
      "name": "Questions requests that lean on authority",
      "summary": "Checks before acting when a message invokes a boss, executive, government body, or IT department.",
      "why": "Authority cues raised clicks in a simulation sent to about 62,000 employees. Evidence across studies is mixed, so this behavior is best paired with verification (PB-03).",
      "observe": "Click and report rates on authority-themed Simulations compared with other Tactics.",
      "tactics": [
        "Authority"
      ],
      "principles": [
        8
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Financial loss",
        "Account compromise"
      ],
      "evidence": "Contested",
      "sort": 6,
      "studies": [
        {
          "slug": "williams-2018-susceptibility-phishing-workplace",
          "relation": "supports"
        },
        {
          "slug": "ferreira-2019-persuasion-phishing-emails",
          "relation": "supports"
        },
        {
          "slug": "parsons-2019-predicting-susceptibility-social-influence",
          "relation": "context"
        },
        {
          "slug": "vanderheijden-2019-cognitive-triaging-phishing",
          "relation": "challenges"
        }
      ]
    },
    {
      "code": "PB-07",
      "slug": "confirms-before-helping",
      "actor": "person",
      "name": "Confirms identity before helping",
      "summary": "Stays helpful, but confirms who is asking before sharing files, codes, or access.",
      "why": "Attackers exploit the wish to help and to return favors. In role-play research, reciprocity-style messages were among the most persuasive.",
      "observe": "Outcomes on helpfulness-themed Simulations (for example, 'can you forward the deck?').",
      "tactics": [
        "Helpfulness",
        "Trust"
      ],
      "principles": [
        8
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Data compromise",
        "Account compromise"
      ],
      "evidence": "Emerging",
      "sort": 7,
      "studies": [
        {
          "slug": "parsons-2019-predicting-susceptibility-social-influence",
          "relation": "supports"
        },
        {
          "slug": "ferreira-2019-persuasion-phishing-emails",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-08",
      "slug": "discounts-social-proof",
      "actor": "person",
      "name": "Discounts 'everyone else already did it' claims",
      "summary": "Does not treat claims that coworkers already acted as a reason to act.",
      "why": "Social proof is a common tactic, but studies disagree on how much it works in email. Evidence is thin, so treat this as a hypothesis to test in your own data.",
      "observe": "Click and report rates on social-proof Simulations.",
      "tactics": [
        "Social Proof"
      ],
      "principles": [
        8
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Contested",
      "sort": 8,
      "studies": [
        {
          "slug": "parsons-2019-predicting-susceptibility-social-influence",
          "relation": "challenges"
        },
        {
          "slug": "vanderheijden-2019-cognitive-triaging-phishing",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-09",
      "slug": "keeps-habits-when-tired",
      "actor": "person",
      "name": "Keeps secure habits when tired or busy",
      "summary": "Holds to a few key routines (report, verify, pause) even when overloaded.",
      "why": "People tune out repeated warnings, and security fatigue leads to resignation and shortcuts. Habits that are cued by context survive fatigue better than conscious effort.",
      "observe": "Outcomes by time of day and day of week; drift in results over long Programs.",
      "tactics": [],
      "principles": [
        6,
        7
      ],
      "chain": [
        "habit"
      ],
      "impacts": [
        "Account compromise",
        "Data compromise"
      ],
      "evidence": "Moderate",
      "sort": 9,
      "studies": [
        {
          "slug": "stanton-2016-security-fatigue",
          "relation": "supports"
        },
        {
          "slug": "vance-2018-tuning-out-security-warnings",
          "relation": "supports"
        },
        {
          "slug": "wood-2007-habits-habit-goal-interface",
          "relation": "context"
        },
        {
          "slug": "lally-2010-how-are-habits-formed",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-10",
      "slug": "shares-scam-stories",
      "actor": "person",
      "name": "Shares scam stories with coworkers",
      "summary": "Tells teammates about attempted scams they spotted, in their own words.",
      "why": "Story-based training worked better when a peer told it, and people report largely to protect coworkers. Stories spread recognition faster than a training portal.",
      "observe": "Mentions in team channels; clusters of reports after one person shares.",
      "tactics": [],
      "principles": [
        5
      ],
      "chain": [
        "belief",
        "emotion"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Emerging",
      "sort": 10,
      "studies": [
        {
          "slug": "wash-2018-who-provides-phishing-training",
          "relation": "supports"
        },
        {
          "slug": "burda-2025-phishing-reporting-motivation",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-11",
      "slug": "raises-friction-openly",
      "actor": "person",
      "name": "Raises security friction openly",
      "summary": "Tells the security team when a rule blocks their work, instead of quietly building a workaround.",
      "why": "When policy clashes with getting work done, conscientious people invent their own 'shadow security'. Surfacing the clash lets the organization fix the policy.",
      "observe": "Volume of policy-friction feedback; share of workarounds discovered by report rather than audit.",
      "tactics": [],
      "principles": [
        2
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Data compromise",
        "Business interruption"
      ],
      "evidence": "Moderate",
      "sort": 11,
      "studies": [
        {
          "slug": "kirlappos-2014-shadow-security",
          "relation": "supports"
        },
        {
          "slug": "adams-1999-users-are-not-the-enemy",
          "relation": "supports"
        },
        {
          "slug": "beautement-2008-compliance-budget",
          "relation": "context"
        }
      ]
    },
    {
      "code": "PB-12",
      "slug": "alert-to-ai-personalized-messages",
      "actor": "person",
      "name": "Stays alert to personalized, well-written messages",
      "summary": "No longer relies on typos and bad grammar as the main warning sign.",
      "why": "AI-generated spear phishing matched human experts, with about 54% click-through in a controlled study. Recognizing the Tactic matters more than spotting mistakes.",
      "observe": "Outcomes on high-quality, personalized Simulations compared with generic ones.",
      "tactics": [
        "Trust",
        "Authority",
        "Urgency"
      ],
      "principles": [
        8
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Financial loss"
      ],
      "evidence": "Emerging",
      "sort": 12,
      "studies": [
        {
          "slug": "heiding-2024-llm-automated-spear-phishing",
          "relation": "supports"
        },
        {
          "slug": "heiding-2024-devising-detecting-phishing-llms",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-01",
      "slug": "recognizes-every-report",
      "actor": "organization",
      "name": "Answers every report with fast, positive feedback",
      "summary": "Thanks the reporter quickly and tells them whether the message was real, and why.",
      "why": "People report mainly to protect coworkers and want to know the outcome. Evidence on rewards is mixed: one field study found incentives added little, so feedback should inform, not just reward.",
      "observe": "Share of reports that get a response; median response time; repeat reporting by the same people.",
      "tactics": [],
      "principles": [
        3
      ],
      "chain": [
        "emotion",
        "habit"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Contested",
      "sort": 13,
      "studies": [
        {
          "slug": "burda-2025-phishing-reporting-motivation",
          "relation": "supports"
        },
        {
          "slug": "pilavakis-2023-i-didnt-click",
          "relation": "supports"
        },
        {
          "slug": "lain-2024-content-nudges-incentives",
          "relation": "challenges"
        }
      ]
    },
    {
      "code": "OB-02",
      "slug": "feedback-to-everyone",
      "actor": "organization",
      "name": "Gives Simulation feedback to everyone, not only those who clicked",
      "summary": "Explains each Simulation to the whole audience afterward, instead of only showing a page to those who clicked.",
      "why": "Feedback shown only after a click reaches few people and showed weak field effects. Delayed feedback to all employees showed more promise.",
      "observe": "Share of recipients who see post-Simulation feedback; change in outcomes on the next Simulation.",
      "tactics": [],
      "principles": [
        3
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Moderate",
      "sort": 14,
      "studies": [
        {
          "slug": "yin-2026-learning-by-phishing",
          "relation": "supports"
        },
        {
          "slug": "lain-2022-phishing-in-organizations",
          "relation": "supports"
        },
        {
          "slug": "ho-2025-efficacy-of-phishing-training",
          "relation": "context"
        }
      ]
    },
    {
      "code": "OB-03",
      "slug": "no-shaming-or-punishment",
      "actor": "organization",
      "name": "Does not shame, punish, or publicly name people who click",
      "summary": "Treats clicks as data about the Program, not as verdicts on people.",
      "why": "Security research argues that scaring and bullying people into security does not work, and staff in a hospital study reacted to Simulations with fear, shame, and hostility. Deterrence research finds perceived sanctions can reduce misuse, so the evidence is not one-sided.",
      "observe": "Written policy on consequences; self-report rates after clicks; employee sentiment surveys.",
      "tactics": [],
      "principles": [
        2,
        4
      ],
      "chain": [
        "belief",
        "emotion"
      ],
      "impacts": [
        "Account compromise",
        "Business interruption"
      ],
      "evidence": "Contested",
      "sort": 15,
      "studies": [
        {
          "slug": "sasse-2015-scaring-and-bullying",
          "relation": "supports"
        },
        {
          "slug": "tolsdorf-2025-phishing-university-hospital",
          "relation": "supports"
        },
        {
          "slug": "renaud-2019-fear-appeals-complicated",
          "relation": "context"
        },
        {
          "slug": "darcy-2009-deterrence-countermeasures",
          "relation": "challenges"
        },
        {
          "slug": "herath-2009-protection-motivation-deterrence",
          "relation": "challenges"
        }
      ]
    },
    {
      "code": "OB-04",
      "slug": "measures-reporting-first",
      "actor": "organization",
      "name": "Measures reporting first, clicks second",
      "summary": "Uses reporting rate as the headline outcome and treats click rate as a diagnostic.",
      "why": "Programs that track only completion and click rates struggle to tell whether behavior changed. Click rates also swing with email difficulty, while reporting shows active defense.",
      "observe": "Which metric leads board and leadership reports.",
      "tactics": [],
      "principles": [
        2,
        3
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Moderate",
      "sort": 16,
      "studies": [
        {
          "slug": "jacobs-2023-measuring-us-government-awareness-programs",
          "relation": "supports"
        },
        {
          "slug": "steves-2020-phish-scale",
          "relation": "supports"
        },
        {
          "slug": "lain-2022-phishing-in-organizations",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-05",
      "slug": "rates-simulation-difficulty",
      "actor": "organization",
      "name": "Rates Simulation difficulty before judging results",
      "summary": "Scores each Simulation's difficulty (for example, with the NIST Phish Scale) and compares results only at similar difficulty.",
      "why": "Difficulty predicted behavior in replication research while training did not. Without difficulty, a falling click rate may just mean easier emails.",
      "observe": "Difficulty rating recorded for every Simulation; trend lines reported by difficulty band.",
      "tactics": [],
      "principles": [
        1
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Strong",
      "sort": 17,
      "studies": [
        {
          "slug": "steves-2020-phish-scale",
          "relation": "supports"
        },
        {
          "slug": "rozema-2026-anti-phishing-training-still-does-not-work",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-06",
      "slug": "varies-content-and-cadence",
      "actor": "organization",
      "name": "Varies content and cadence to prevent tune-out",
      "summary": "Changes Simulation themes, formats, and timing so people keep paying attention.",
      "why": "Attention to repeated warnings drops measurably within a week. The benefit of embedded training appears to come mostly from periodic reminders, not the content itself.",
      "observe": "Number of distinct Tactics and formats per quarter; outcome drift across repeated themes.",
      "tactics": [],
      "principles": [
        6,
        7
      ],
      "chain": [
        "habit"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Moderate",
      "sort": 18,
      "studies": [
        {
          "slug": "vance-2018-tuning-out-security-warnings",
          "relation": "supports"
        },
        {
          "slug": "lain-2024-content-nudges-incentives",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-07",
      "slug": "reinforces-within-four-months",
      "actor": "organization",
      "name": "Reinforces awareness at least every four months",
      "summary": "Schedules reminders or short refreshers before awareness fades.",
      "why": "Gains from an awareness program held at four months and were gone by six. Video and interactive reminders worked best.",
      "observe": "Maximum gap between touches for any Person.",
      "tactics": [],
      "principles": [
        7
      ],
      "chain": [
        "habit"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Moderate",
      "sort": 19,
      "studies": [
        {
          "slug": "reinheimer-2020-phishing-awareness-over-time",
          "relation": "supports"
        },
        {
          "slug": "vishwanath-2018-scam-model-phishing-susceptibility",
          "relation": "context"
        }
      ]
    },
    {
      "code": "OB-08",
      "slug": "policies-people-can-follow",
      "actor": "organization",
      "name": "Designs security rules people can actually follow",
      "summary": "Keeps the effort that policies demand within what people can sustain alongside their real work.",
      "why": "People weigh the cost of compliance against their work; when rules cost too much, they reasonably skip them or build workarounds.",
      "observe": "Friction reports; workaround discovery; time-cost estimates for key policies.",
      "tactics": [],
      "principles": [
        2
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "impacts": [
        "Data compromise",
        "Business interruption"
      ],
      "evidence": "Moderate",
      "sort": 20,
      "studies": [
        {
          "slug": "beautement-2008-compliance-budget",
          "relation": "supports"
        },
        {
          "slug": "herley-2009-so-long-and-no-thanks",
          "relation": "supports"
        },
        {
          "slug": "adams-1999-users-are-not-the-enemy",
          "relation": "supports"
        },
        {
          "slug": "kirlappos-2014-shadow-security",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-09",
      "slug": "builds-psychological-safety",
      "actor": "organization",
      "name": "Builds a culture where it's safe to admit mistakes",
      "summary": "Leaders model admitting errors and respond to self-reports with help, not blame.",
      "why": "Team psychological safety predicts learning behavior. Security culture research names leadership and trust among its core influences.",
      "observe": "Self-report rate after clicks; culture survey items on safety to speak up.",
      "tactics": [],
      "principles": [
        2
      ],
      "chain": [
        "belief",
        "emotion"
      ],
      "impacts": [
        "Business interruption",
        "Data compromise"
      ],
      "evidence": "Emerging",
      "sort": 21,
      "studies": [
        {
          "slug": "edmondson-1999-psychological-safety",
          "relation": "supports"
        },
        {
          "slug": "daveiga-2020-defining-security-culture",
          "relation": "context"
        },
        {
          "slug": "siponen-2010-neutralization",
          "relation": "context"
        }
      ]
    },
    {
      "code": "OB-10",
      "slug": "easy-reporting-and-triage",
      "actor": "organization",
      "name": "Makes reporting one click and staffs triage for surges",
      "summary": "Gives everyone a one-click report button and a triage process that can absorb a sudden flood of reports.",
      "why": "Large campaigns swamped help desks in a real incident study, and crowdsourced reports only help if someone acts on them.",
      "observe": "Report-to-triage time during peak campaigns; share of reports closed with feedback.",
      "tactics": [],
      "principles": [
        3
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Business interruption"
      ],
      "evidence": "Moderate",
      "sort": 22,
      "studies": [
        {
          "slug": "althobaiti-2021-phishing-incident-response",
          "relation": "supports"
        },
        {
          "slug": "lain-2022-phishing-in-organizations",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-11",
      "slug": "builds-efficacy-not-fear",
      "actor": "organization",
      "name": "Builds confidence, not fear, in awareness messages",
      "summary": "Pairs every warning with a clear, doable action people believe they can take.",
      "why": "Fear appeals raised intentions only when people believed they could act; information alone does not change behavior. Belief in one's own ability predicts effort and persistence.",
      "observe": "Share of content with a concrete action; self-efficacy survey items.",
      "tactics": [],
      "principles": [
        4,
        6
      ],
      "chain": [
        "belief",
        "emotion"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Moderate",
      "sort": 23,
      "studies": [
        {
          "slug": "johnston-2010-fear-appeals",
          "relation": "supports"
        },
        {
          "slug": "bandura-1977-self-efficacy",
          "relation": "supports"
        },
        {
          "slug": "bada-2015-awareness-campaigns-fail",
          "relation": "supports"
        },
        {
          "slug": "renaud-2019-fear-appeals-complicated",
          "relation": "context"
        }
      ]
    },
    {
      "code": "OB-12",
      "slug": "supports-autonomy-and-belonging",
      "actor": "organization",
      "name": "Treats people as partners in security",
      "summary": "Designs training that supports autonomy, competence, and belonging, and uses peers as messengers.",
      "why": "Intrinsic motivation depends on autonomy, competence, and relatedness. Treating humans as the solution rather than the problem is a growing position in security research.",
      "observe": "Voluntary participation rates; peer-led content; language audits of training materials.",
      "tactics": [],
      "principles": [
        1,
        2,
        5
      ],
      "chain": [
        "belief"
      ],
      "impacts": [
        "Account compromise"
      ],
      "evidence": "Emerging",
      "sort": 24,
      "studies": [
        {
          "slug": "ryan-2000-self-determination-theory",
          "relation": "supports"
        },
        {
          "slug": "zimmermann-2019-human-as-solution",
          "relation": "supports"
        },
        {
          "slug": "renaud-2018-responsibilization",
          "relation": "context"
        },
        {
          "slug": "wash-2018-who-provides-phishing-training",
          "relation": "supports"
        }
      ]
    },
    {
      "code": "OB-13",
      "slug": "pairs-controls-with-people",
      "actor": "organization",
      "name": "Pairs technical controls with human reporting",
      "summary": "Invests in filtering and warnings first, and treats trained people as the layer that catches what gets through.",
      "why": "Technical measures and email warnings outperformed training in field studies. People are the best defense for what filters miss, not a substitute for filters.",
      "observe": "Share of real phish caught by filters compared with caught by reports.",
      "tactics": [],
      "principles": [
        8
      ],
      "chain": [
        "behavior"
      ],
      "impacts": [
        "Account compromise",
        "Data compromise"
      ],
      "evidence": "Strong",
      "sort": 25,
      "studies": [
        {
          "slug": "tolsdorf-2025-phishing-university-hospital",
          "relation": "supports"
        },
        {
          "slug": "lain-2022-phishing-in-organizations",
          "relation": "supports"
        },
        {
          "slug": "ho-2025-efficacy-of-phishing-training",
          "relation": "context"
        }
      ]
    }
  ]
}