{
  "count": 48,
  "license": "CC BY 4.0",
  "source": "https://psysec.io/research",
  "studies": [
    {
      "slug": "rozema-2026-anti-phishing-training-still-does-not-work",
      "title": "Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale",
      "authors": [
        "Andrew T. Rozema",
        "James C. Davis"
      ],
      "year": 2026,
      "venue": "Proceedings of the ACM Web Conference 2026 (WWW '26)",
      "pub_type": "conference",
      "doi": "10.1145/3774904.3792467",
      "url": "https://doi.org/10.1145/3774904.3792467",
      "open_access_url": "https://doi.org/10.1145/3774904.3792467",
      "method": "field-experiment",
      "sample": "12,511 employees",
      "setting": "US financial technology firm",
      "key_finding": "Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.",
      "psysec_relevance": "Independent reproduction that standard training does not change clicks or reporting, while showing that measuring difficulty and report-before-click timing is informative.",
      "stance": "challenges",
      "principles": [
        3,
        2
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "phishing-simulation",
        "measurement",
        "reporting",
        "awareness-programs"
      ],
      "citations_approx": 4,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "yin-2026-learning-by-phishing",
      "title": "Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training",
      "authors": [
        "Dezhi Yin",
        "Matthew Mullarkey",
        "Gert-Jan de Vreede",
        "Moez Limayem"
      ],
      "year": 2026,
      "venue": "MIS Quarterly",
      "pub_type": "journal",
      "doi": "10.25300/MISQ/2025/19354",
      "url": "https://doi.org/10.25300/MISQ/2025/19354",
      "open_access_url": null,
      "method": "field-experiment",
      "sample": "Three randomized field experiments on a commercial phishing simulation platform",
      "setting": "Organizations using a leading phishing simulation platform",
      "key_finding": "Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.",
      "psysec_relevance": "Supports giving everyone fast, non-judgmental post-simulation feedback rather than reserving feedback for those who 'failed'.",
      "stance": "mixed",
      "principles": [
        3
      ],
      "tactics": [],
      "chain": [
        "behavior",
        "habit"
      ],
      "topics": [
        "feedback",
        "embedded-training",
        "phishing-simulation"
      ],
      "citations_approx": 2,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "tolsdorf-2025-phishing-university-hospital",
      "title": "Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital",
      "authors": [
        "Jan Tolsdorf",
        "David Langer",
        "Luigi Lo Iacono"
      ],
      "year": 2025,
      "venue": "Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)",
      "pub_type": "conference",
      "doi": "10.1145/3719027.3765164",
      "url": "https://doi.org/10.1145/3719027.3765164",
      "open_access_url": "https://dl.acm.org/doi/pdf/10.1145/3719027.3765164",
      "method": "field-experiment",
      "sample": "7,044 email accounts; 11 in-situ interventions; follow-up surveys",
      "setting": "German university hospital",
      "key_finding": "Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.",
      "psysec_relevance": "Documents the emotional cost of simulations (shame, hostility) and that role and context shape susceptibility, both central to non-punitive design.",
      "stance": "mixed",
      "principles": [
        1,
        6,
        2
      ],
      "tactics": [
        "Authority",
        "Urgency"
      ],
      "chain": [
        "emotion",
        "behavior"
      ],
      "topics": [
        "phishing-simulation",
        "blame-and-fear",
        "susceptibility",
        "individual-differences"
      ],
      "citations_approx": 2,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "burda-2025-phishing-reporting-motivation",
      "title": "Phishing reporting in organizations: What motivates employees to take action?",
      "authors": [
        "Pavlo Burda",
        "Luca Allodi",
        "Alexander Serebrenik",
        "Nicola Zannone"
      ],
      "year": 2025,
      "venue": "Information & Computer Security",
      "pub_type": "journal",
      "doi": "10.1108/ICS-02-2025-0037",
      "url": "https://doi.org/10.1108/ICS-02-2025-0037",
      "open_access_url": null,
      "method": "qualitative",
      "sample": "49 employees who report phishing, semi-structured interviews",
      "setting": "European university",
      "key_finding": "The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.",
      "psysec_relevance": "Reporting is driven by prosocial motives and belonging rather than compliance, supporting culture-based, non-punitive reporting programs.",
      "stance": "supports",
      "principles": [
        2,
        1
      ],
      "tactics": [
        "Helpfulness"
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "reporting",
        "motivation",
        "security-culture"
      ],
      "citations_approx": 2,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "ho-2025-efficacy-of-phishing-training",
      "title": "Understanding the Efficacy of Phishing Training in Practice",
      "authors": [
        "Grant Ho",
        "Ariana Mirian",
        "Elisa Luo",
        "Khang Tong",
        "Euyhyun Lee",
        "Lin Liu",
        "et al."
      ],
      "year": 2025,
      "venue": "2025 IEEE Symposium on Security and Privacy (SP)",
      "pub_type": "conference",
      "doi": "10.1109/SP61157.2025.00076",
      "url": "https://doi.org/10.1109/SP61157.2025.00076",
      "open_access_url": null,
      "method": "randomized-controlled-trial",
      "sample": "19,500+ employees, 10 simulated phishing campaigns over 8 months",
      "setting": "Large US healthcare organization",
      "key_finding": "Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.",
      "psysec_relevance": "The largest RCT to date showing conventional annual and embedded training barely moves behavior, a direct challenge any simulation-based program must answer.",
      "stance": "challenges",
      "principles": [
        3,
        2
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "phishing-simulation",
        "embedded-training",
        "awareness-programs",
        "measurement"
      ],
      "citations_approx": 43,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "lain-2024-content-nudges-incentives",
      "title": "Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training",
      "authors": [
        "Daniele Lain",
        "Tarek Jost",
        "Sinisa Matetic",
        "Kari Kostiainen",
        "Srdjan Capkun"
      ],
      "year": 2024,
      "venue": "Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)",
      "pub_type": "conference",
      "doi": "10.1145/3658644.3690348",
      "url": "https://doi.org/10.1145/3658644.3690348",
      "open_access_url": "https://arxiv.org/abs/2409.01378",
      "method": "mixed-methods",
      "sample": "4,554 employees, 3 simulated phishing emails over 6 weeks; 25 interviews",
      "setting": "Partner company (organizational field setting)",
      "key_finding": "Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.",
      "psysec_relevance": "Suggests frequent, light-touch reminders and attention cues matter more than content dumps or incentives, which bears on how feedback and habit loops are designed.",
      "stance": "mixed",
      "principles": [
        3,
        6
      ],
      "tactics": [],
      "chain": [
        "behavior",
        "habit"
      ],
      "topics": [
        "embedded-training",
        "phishing-simulation",
        "feedback",
        "motivation"
      ],
      "citations_approx": 26,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "heiding-2024-devising-detecting-phishing-llms",
      "title": "Devising and Detecting Phishing Emails Using Large Language Models",
      "authors": [
        "Fredrik Heiding",
        "Bruce Schneier",
        "Arun Vishwanath",
        "Jeremy Bernstein",
        "Peter S. Park"
      ],
      "year": 2024,
      "venue": "IEEE Access, 12",
      "pub_type": "journal",
      "doi": "10.1109/ACCESS.2024.3375882",
      "url": "https://doi.org/10.1109/ACCESS.2024.3375882",
      "open_access_url": "https://ieeexplore.ieee.org/ielx7/6287639/6514899/10466545.pdf",
      "method": "field-experiment",
      "sample": "112 recruited participants across four email conditions",
      "setting": "Red-team style phishing emails sent to study participants (USA university)",
      "key_finding": "Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.",
      "psysec_relevance": "Shows AI lowers the cost of psychologically tuned emails, raising the stakes for tactic-level recognition rather than spotting typos.",
      "stance": "supports",
      "principles": [
        6,
        8
      ],
      "tactics": [
        "Trust",
        "Authority",
        "Urgency"
      ],
      "chain": [
        "behavior"
      ],
      "topics": [
        "ai-and-social-engineering",
        "persuasion",
        "susceptibility"
      ],
      "citations_approx": 97,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "heiding-2024-llm-automated-spear-phishing",
      "title": "Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects",
      "authors": [
        "Fred Heiding",
        "Simon Lermen",
        "Andrew Kao",
        "Bruce Schneier",
        "Arun Vishwanath"
      ],
      "year": 2024,
      "venue": "arXiv:2412.00586",
      "pub_type": "preprint",
      "doi": null,
      "url": "https://arxiv.org/abs/2412.00586",
      "open_access_url": "https://arxiv.org/pdf/2412.00586",
      "method": "field-experiment",
      "sample": "101 participants across four email groups",
      "setting": "Human-subjects spear-phishing study using a custom AI automation tool",
      "key_finding": "Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.",
      "psysec_relevance": "Signals that personalized, psychologically tuned social engineering is now cheap and automated, so defenses must rest on recognizing manipulation tactics rather than message quality.",
      "stance": "supports",
      "principles": [
        6,
        8
      ],
      "tactics": [
        "Trust",
        "Authority"
      ],
      "chain": [
        "behavior"
      ],
      "topics": [
        "ai-and-social-engineering",
        "susceptibility",
        "persuasion"
      ],
      "citations_approx": null,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "pilavakis-2023-i-didnt-click",
      "title": "\"I didn't click\": What users say when reporting phishing",
      "authors": [
        "Nikolas Pilavakis",
        "Adam Jenkins",
        "Nadin Kökciyan",
        "Kami Vaniea"
      ],
      "year": 2023,
      "venue": "Proceedings 2023 Symposium on Usable Security (USEC 2023)",
      "pub_type": "conference",
      "doi": "10.14722/usec.2023.233129",
      "url": "https://doi.org/10.14722/usec.2023.233129",
      "open_access_url": "https://doi.org/10.14722/usec.2023.233129",
      "method": "qualitative",
      "sample": "270 help desk phishing tickets over nine months",
      "setting": "Organizational IT help desk (UK university)",
      "key_finding": "People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.",
      "psysec_relevance": "Shows reporters are active, reasoning agents who want answers, supporting fast two-way feedback on reports.",
      "stance": "supports",
      "principles": [
        3,
        8
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "reporting",
        "incident-response",
        "feedback"
      ],
      "citations_approx": 17,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "jacobs-2023-measuring-us-government-awareness-programs",
      "title": "Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study",
      "authors": [
        "Jody L. Jacobs",
        "Julie M. Haney",
        "Susanne M. Furman"
      ],
      "year": 2023,
      "venue": "HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science",
      "pub_type": "book-chapter",
      "doi": "10.1007/978-3-031-35969-9_2",
      "url": "https://www.nist.gov/publications/measuring-effectiveness-us-government-security-awareness-programs-mixed-methods-study-0",
      "open_access_url": "https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=936132",
      "method": "mixed-methods",
      "sample": "29 focus group participants and 96 survey respondents (federal awareness program staff)",
      "setting": "U.S. federal government organizations",
      "key_finding": "Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.",
      "psysec_relevance": "Documents the compliance-metric trap that PsySec's culture-over-compliance principle targets.",
      "stance": "supports",
      "principles": [
        2
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "measurement",
        "compliance",
        "awareness-programs"
      ],
      "citations_approx": 4,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "lain-2022-phishing-in-organizations",
      "title": "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study",
      "authors": [
        "Daniele Lain",
        "Kari Kostiainen",
        "Srdjan Čapkun"
      ],
      "year": 2022,
      "venue": "2022 IEEE Symposium on Security and Privacy (SP)",
      "pub_type": "conference",
      "doi": "10.1109/SP46214.2022.9833766",
      "url": "https://doi.org/10.1109/SP46214.2022.9833766",
      "open_access_url": "https://www.research-collection.ethz.ch/bitstream/20.500.11850/588856/7/Phishing_in_Organizations.pdf",
      "method": "field-experiment",
      "sample": "14,000+ employees, 15 months of simulated phishing plus a reporting button",
      "setting": "Large partner company (Europe)",
      "key_finding": "Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.",
      "psysec_relevance": "Strong field evidence that click-then-lecture training is weak while empowering people as reporters (agency, collective defense) works.",
      "stance": "mixed",
      "principles": [
        3,
        2
      ],
      "tactics": [],
      "chain": [
        "behavior",
        "habit"
      ],
      "topics": [
        "phishing-simulation",
        "embedded-training",
        "reporting",
        "measurement"
      ],
      "citations_approx": 107,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "althobaiti-2021-phishing-incident-response",
      "title": "A Case Study of Phishing Incident Response in an Educational Organization",
      "authors": [
        "Kholoud Althobaiti",
        "Adam D. G. Jenkins",
        "Kami Vaniea"
      ],
      "year": 2021,
      "venue": "Proceedings of the ACM on Human-Computer Interaction (CSCW)",
      "pub_type": "journal",
      "doi": "10.1145/3476079",
      "url": "https://doi.org/10.1145/3476079",
      "open_access_url": null,
      "method": "case-study",
      "sample": "Interviews and observations of help desk and security teams",
      "setting": "Large university",
      "key_finding": "Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.",
      "psysec_relevance": "Reminds programs that encouraging reporting only helps if the back end can process reports and close the feedback loop.",
      "stance": "foundational",
      "principles": [
        3,
        2
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "reporting",
        "incident-response"
      ],
      "citations_approx": 27,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "reinheimer-2020-phishing-awareness-over-time",
      "title": "An investigation of phishing awareness and education over time: When and how to best remind users",
      "authors": [
        "Benjamin Reinheimer",
        "Lukas Aldag",
        "Peter Mayer",
        "Mattia Mossano",
        "Reyhan Duezguen",
        "Bettina Lofthouse",
        "Tatiana von Landesberger",
        "Melanie Volkamer"
      ],
      "year": 2020,
      "venue": "Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)",
      "pub_type": "conference",
      "doi": null,
      "url": "https://www.usenix.org/conference/soups2020/presentation/reinheimer",
      "open_access_url": "https://www.usenix.org/conference/soups2020/presentation/reinheimer",
      "method": "field-experiment",
      "sample": "409 employees",
      "setting": "German public administration organization",
      "key_finding": "After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.",
      "psysec_relevance": "Shows awareness decays without reinforcement, supporting spaced, recurring touchpoints to build durable habits.",
      "stance": "supports",
      "principles": [
        3,
        7
      ],
      "tactics": [],
      "chain": [
        "habit",
        "behavior"
      ],
      "topics": [
        "awareness-programs",
        "habit-formation",
        "measurement"
      ],
      "citations_approx": null,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "steves-2020-phish-scale",
      "title": "Categorizing human phishing difficulty: a Phish Scale",
      "authors": [
        "Michelle Steves",
        "Kristen Greene",
        "Mary Theofanos"
      ],
      "year": 2020,
      "venue": "Journal of Cybersecurity",
      "pub_type": "journal",
      "doi": "10.1093/cybsec/tyaa009",
      "url": "https://doi.org/10.1093/cybsec/tyaa009",
      "open_access_url": "https://doi.org/10.1093/cybsec/tyaa009",
      "method": "mixed-methods",
      "sample": "Previously published and new enterprise phishing-exercise data",
      "setting": "US government (NIST) enterprise phishing exercises",
      "key_finding": "Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.",
      "psysec_relevance": "Argues raw click rates are misleading without context, supporting measurement beyond punitive click-rate leaderboards.",
      "stance": "foundational",
      "principles": [
        1,
        2
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "measurement",
        "phishing-simulation",
        "susceptibility"
      ],
      "citations_approx": 49,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "daveiga-2020-defining-security-culture",
      "title": "Defining organisational information security culture—Perspectives from academia and industry",
      "authors": [
        "Adéle da Veiga",
        "Liudmila V. Astakhova",
        "Adéle Botha",
        "Marlien Herselman"
      ],
      "year": 2020,
      "venue": "Computers & Security, 92, 101713",
      "pub_type": "journal",
      "doi": "10.1016/j.cose.2020.101713",
      "url": "https://doi.org/10.1016/j.cose.2020.101713",
      "open_access_url": "https://repository.up.ac.za/bitstream/2263/76240/1/DaVeiga_Defining_2020.pdf",
      "method": "mixed-methods",
      "sample": "Scoping review + industry survey of 512 respondents",
      "setting": "Organisations, many operating internationally",
      "key_finding": "Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.",
      "psysec_relevance": "Provides a consolidated, evidence-based definition and factor model of security culture for measuring and shaping it.",
      "stance": "foundational",
      "principles": [
        2
      ],
      "tactics": [],
      "chain": [
        "belief",
        "habit"
      ],
      "topics": [
        "security-culture",
        "measurement",
        "compliance"
      ],
      "citations_approx": 153,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "wash-2020-how-experts-detect-phishing",
      "title": "How Experts Detect Phishing Scam Emails",
      "authors": [
        "Rick Wash"
      ],
      "year": 2020,
      "venue": "Proceedings of the ACM on Human-Computer Interaction (CSCW)",
      "pub_type": "journal",
      "doi": "10.1145/3415231",
      "url": "https://doi.org/10.1145/3415231",
      "open_access_url": "https://dl.acm.org/doi/pdf/10.1145/3415231",
      "method": "qualitative",
      "sample": "21 IT experts, interviews about real phishing they caught",
      "setting": "Real-world inboxes of IT experts",
      "key_finding": "Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.",
      "psysec_relevance": "Describes detection as trained noticing of 'something off', matching PsySec's emphasis on instinct and recognition over rules.",
      "stance": "supports",
      "principles": [
        8,
        6
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "intuition",
        "decision-making",
        "reporting"
      ],
      "citations_approx": 91,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "vanderheijden-2019-cognitive-triaging-phishing",
      "title": "Cognitive Triaging of Phishing Attacks",
      "authors": [
        "Amber van der Heijden",
        "Luca Allodi"
      ],
      "year": 2019,
      "venue": "28th USENIX Security Symposium (USENIX Security 19), pp. 1309-1326",
      "pub_type": "conference",
      "doi": null,
      "url": "https://www.usenix.org/conference/usenixsecurity19/presentation/van-der-heijden",
      "open_access_url": "https://www.usenix.org/system/files/sec19-van_der_heijden.pdf",
      "method": "large-scale-observational",
      "sample": "115,698 user-reported emails and 11,936 malicious-link alerts, Feb-Dec 2018",
      "setting": "Anti-phishing division of a large European financial organisation",
      "key_finding": "Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.",
      "psysec_relevance": "Links specific psychological tactics in real attacks to real victim response, and shows user reports can feed tactic-aware incident response.",
      "stance": "mixed",
      "principles": [
        6
      ],
      "tactics": [
        "Scarcity",
        "Authority",
        "Social Proof",
        "Trust",
        "Helpfulness"
      ],
      "chain": [
        "emotion",
        "behavior"
      ],
      "topics": [
        "persuasion",
        "susceptibility",
        "reporting",
        "incident-response"
      ],
      "citations_approx": null,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "renaud-2019-fear-appeals-complicated",
      "title": "Cyber security fear appeals: unexpectedly complicated",
      "authors": [
        "Karen Renaud",
        "Marc Dupuis"
      ],
      "year": 2019,
      "venue": "Proceedings of the New Security Paradigms Workshop (NSPW '19)",
      "pub_type": "conference",
      "doi": "10.1145/3368860.3368864",
      "url": "https://doi.org/10.1145/3368860.3368864",
      "open_access_url": "https://rke.abertay.ac.uk/ws/files/17678964/Renaud_Cyber_Security_Fear_Accepted_2020.pdf",
      "method": "systematic-review",
      "sample": null,
      "setting": null,
      "key_finding": "A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.",
      "psysec_relevance": "Shows that the evidence for fear-based security messaging is contested and methodologically uneven, which matters when programs rely on scare tactics.",
      "stance": "mixed",
      "principles": [
        4,
        6
      ],
      "tactics": [],
      "chain": [
        "emotion",
        "behavior"
      ],
      "topics": [
        "fear-appeals",
        "blame-and-fear",
        "measurement"
      ],
      "citations_approx": 51,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "zimmermann-2019-human-as-solution",
      "title": "Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset",
      "authors": [
        "Verena Zimmermann",
        "Karen Renaud"
      ],
      "year": 2019,
      "venue": "International Journal of Human-Computer Studies, 131, 169-187",
      "pub_type": "journal",
      "doi": "10.1016/j.ijhcs.2019.05.005",
      "url": "https://doi.org/10.1016/j.ijhcs.2019.05.005",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.",
      "psysec_relevance": "Provides a peer-reviewed framework for treating employees as security assets rather than liabilities, the core cultural shift PsySec advocates.",
      "stance": "supports",
      "principles": [
        2,
        3
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "security-culture",
        "blame-and-fear",
        "psychological-safety"
      ],
      "citations_approx": 156,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "ferreira-2019-persuasion-phishing-emails",
      "title": "Persuasion: How phishing emails can influence users and bypass security measures",
      "authors": [
        "Ana Ferreira",
        "Soraia Teles"
      ],
      "year": 2019,
      "venue": "International Journal of Human-Computer Studies",
      "pub_type": "journal",
      "doi": "10.1016/j.ijhcs.2018.12.004",
      "url": "https://doi.org/10.1016/j.ijhcs.2018.12.004",
      "open_access_url": null,
      "method": "qualitative",
      "sample": "194 phishing email subject lines (2008-2017) from a public phishing archive, coded by two researchers",
      "setting": "Millersmiles.co.uk phishing archive",
      "key_finding": "Merging Cialdini, Gragg and Stajano & Wilson into one set of social-engineering persuasion principles, the authors found authority, strong affect, integrity and reciprocation were the most common in phishing subject lines. Strong-affect and authority emails leaned on 'you/your' wording, reciprocation on 'we/us/our'.",
      "psysec_relevance": "Provides an evidence-based catalogue of the persuasion tactics attackers actually use, including emotional arousal, which grounds tactic-focused training.",
      "stance": "foundational",
      "principles": [
        6
      ],
      "tactics": [
        "Authority",
        "Urgency",
        "Helpfulness",
        "Trust"
      ],
      "chain": [
        "emotion"
      ],
      "topics": [
        "persuasion",
        "susceptibility"
      ],
      "citations_approx": 97,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "parsons-2019-predicting-susceptibility-social-influence",
      "title": "Predicting susceptibility to social influence in phishing emails",
      "authors": [
        "Kathryn Parsons",
        "Marcus Butavicius",
        "Paul Delfabbro",
        "Meredith Lillie"
      ],
      "year": 2019,
      "venue": "International Journal of Human-Computer Studies",
      "pub_type": "journal",
      "doi": "10.1016/j.ijhcs.2019.02.007",
      "url": "https://doi.org/10.1016/j.ijhcs.2019.02.007",
      "open_access_url": null,
      "method": "lab-experiment",
      "sample": "985 participants, role-play scenario-based phishing study",
      "setting": "Online role-play study (Australia)",
      "key_finding": "In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.",
      "psysec_relevance": "Supports profiling individuals by which tactics they are vulnerable to (psychographics) rather than treating all users alike.",
      "stance": "supports",
      "principles": [
        1,
        6
      ],
      "tactics": [
        "Scarcity",
        "Social Proof",
        "Authority",
        "Trust",
        "Helpfulness"
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "persuasion",
        "susceptibility",
        "individual-differences"
      ],
      "citations_approx": 97,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "lin-2019-susceptibility-spear-phishing-demographics",
      "title": "Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content",
      "authors": [
        "Tian Lin",
        "Daniel E. Capecci",
        "Donovan M. Ellis",
        "Harold A. Rocha",
        "Sandeep Dommaraju",
        "Daniela S. Oliveira",
        "Natalie C. Ebner"
      ],
      "year": 2019,
      "venue": "ACM Transactions on Computer-Human Interaction (TOCHI)",
      "pub_type": "journal",
      "doi": "10.1145/3336141",
      "url": "https://doi.org/10.1145/3336141",
      "open_access_url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC7274040/",
      "method": "field-experiment",
      "sample": "158 internet users (100 young, 58 older), daily simulated phishing emails over 21 days",
      "setting": "Participants' home computers (USA), browser plugin logging clicks",
      "key_finding": "43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.",
      "psysec_relevance": "Shows persuasion tactics work differently for different people and that self-assessed awareness diverges from behavior, arguing for personalized, behavior-based feedback.",
      "stance": "mixed",
      "principles": [
        1,
        3
      ],
      "tactics": [
        "Scarcity",
        "Authority",
        "Social Proof",
        "Trust",
        "Helpfulness"
      ],
      "chain": [
        "behavior",
        "belief"
      ],
      "topics": [
        "susceptibility",
        "persuasion",
        "individual-differences",
        "phishing-simulation"
      ],
      "citations_approx": 174,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "williams-2018-susceptibility-phishing-workplace",
      "title": "Exploring susceptibility to phishing in the workplace",
      "authors": [
        "Emma J. Williams",
        "Joanne Hinds",
        "Adam N. Joinson"
      ],
      "year": 2018,
      "venue": "International Journal of Human-Computer Studies",
      "pub_type": "journal",
      "doi": "10.1016/j.ijhcs.2018.06.004",
      "url": "https://doi.org/10.1016/j.ijhcs.2018.06.004",
      "open_access_url": "https://www.sciencedirect.com/science/article/pii/S1071581918303628",
      "method": "mixed-methods",
      "sample": "Study 1: nine simulated spear-phishing emails sent to ~62,000 employees over six weeks; Study 2: six focus groups in a second organisation",
      "setting": "Two large UK organisations (public sector)",
      "key_finding": "Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.",
      "psysec_relevance": "Real-world evidence that authority cues move clicks, and that the work context, not just individual knowledge, drives susceptibility.",
      "stance": "supports",
      "principles": [
        2,
        6
      ],
      "tactics": [
        "Authority",
        "Urgency"
      ],
      "chain": [
        "behavior",
        "habit"
      ],
      "topics": [
        "persuasion",
        "susceptibility",
        "phishing-simulation",
        "security-culture"
      ],
      "citations_approx": 106,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "renaud-2018-responsibilization",
      "title": "Is the responsibilization of the cyber security risk reasonable and judicious?",
      "authors": [
        "Karen Renaud",
        "Stephen Flowerday",
        "Merrill Warkentin",
        "Paul Cockshott",
        "Craig Orgeron"
      ],
      "year": 2018,
      "venue": "Computers & Security, 78",
      "pub_type": "journal",
      "doi": "10.1016/j.cose.2018.06.006",
      "url": "https://doi.org/10.1016/j.cose.2018.06.006",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": "Home computer users / national policy",
      "key_finding": "Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.",
      "psysec_relevance": "Challenges the premise that individuals should bear the blame for cyber risk, supporting shared, systemic responsibility over individual fault.",
      "stance": "supports",
      "principles": [
        2
      ],
      "tactics": [],
      "chain": [
        "belief"
      ],
      "topics": [
        "blame-and-fear",
        "security-culture",
        "compliance"
      ],
      "citations_approx": 52,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "vishwanath-2018-scam-model-phishing-susceptibility",
      "title": "Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility",
      "authors": [
        "Arun Vishwanath",
        "Brynne Harrison",
        "Yu Jie Ng"
      ],
      "year": 2018,
      "venue": "Communication Research, 45(8), 1146-1166",
      "pub_type": "journal",
      "doi": "10.1177/0093650215627483",
      "url": "https://doi.org/10.1177/0093650215627483",
      "open_access_url": null,
      "method": "lab-experiment",
      "sample": "Two experimental studies with participants exposed to email-based phishing attacks",
      "setting": "University participants (USA)",
      "key_finding": "Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.",
      "psysec_relevance": "Positions habit and automaticity, not just knowledge, at the center of phishing susceptibility, which is the core Belief-to-Habit argument.",
      "stance": "supports",
      "principles": [
        6,
        8
      ],
      "tactics": [],
      "chain": [
        "habit",
        "behavior"
      ],
      "topics": [
        "habit-formation",
        "susceptibility",
        "decision-making"
      ],
      "citations_approx": 221,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "vance-2018-tuning-out-security-warnings",
      "title": "Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments",
      "authors": [
        "Anthony Vance",
        "Jeffrey L. Jenkins",
        "Bonnie Brinton Anderson",
        "Daniel K. Bjornn",
        "C. Brock Kirwan"
      ],
      "year": 2018,
      "venue": "MIS Quarterly, 42(2), 355-380",
      "pub_type": "journal",
      "doi": "10.25300/MISQ/2018/14124",
      "url": "https://doi.org/10.25300/MISQ/2018/14124",
      "open_access_url": null,
      "method": "mixed-methods",
      "sample": "Lab: fMRI + eye tracking over a 5-day workweek; field: 3-week experiment with mobile users installing apps",
      "setting": "University lab (fMRI) and participants' own mobile devices (field)",
      "key_finding": "Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.",
      "psysec_relevance": "Shows that repetition of the same security stimulus trains people to tune it out, so feedback and nudges must vary to keep engaging fast neural systems.",
      "stance": "supports",
      "principles": [
        6,
        3
      ],
      "tactics": [],
      "chain": [
        "habit",
        "behavior"
      ],
      "topics": [
        "habituation",
        "security-fatigue",
        "usable-security"
      ],
      "citations_approx": 113,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "wash-2018-who-provides-phishing-training",
      "title": "Who Provides Phishing Training? Facts, Stories, and People Like Me",
      "authors": [
        "Rick Wash",
        "Molly M. Cooper"
      ],
      "year": 2018,
      "venue": "Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems",
      "pub_type": "conference",
      "doi": "10.1145/3173574.3174066",
      "url": "https://doi.org/10.1145/3173574.3174066",
      "open_access_url": "https://dl.acm.org/doi/pdf/10.1145/3173574.3174066",
      "method": "field-experiment",
      "sample": "Field experiment comparing training formats and messengers before simulated phishing",
      "setting": "University setting",
      "key_finding": "Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.",
      "psysec_relevance": "Direct evidence that narrative from relatable peers changes phishing behavior, supporting story-driven, social transmission of security lessons.",
      "stance": "supports",
      "principles": [
        5,
        1
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "awareness-programs",
        "persuasion",
        "phishing-simulation"
      ],
      "citations_approx": 120,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "stanton-2016-security-fatigue",
      "title": "Security Fatigue",
      "authors": [
        "Brian Stanton",
        "Mary F. Theofanos",
        "Sandra Spickard Prettyman",
        "Susanne Furman"
      ],
      "year": 2016,
      "venue": "IT Professional, 18(5)",
      "pub_type": "journal",
      "doi": "10.1109/MITP.2016.84",
      "url": "https://doi.org/10.1109/MITP.2016.84",
      "open_access_url": "https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10986461",
      "method": "qualitative",
      "sample": "40 semi-structured interviews",
      "setting": "US adults (NIST study)",
      "key_finding": "Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.",
      "psysec_relevance": "Documents the emotional cost of constant security demands, a key reason fear- and volume-heavy programs backfire.",
      "stance": "supports",
      "principles": [
        6
      ],
      "tactics": [],
      "chain": [
        "emotion",
        "behavior"
      ],
      "topics": [
        "security-fatigue",
        "decision-making",
        "usable-security"
      ],
      "citations_approx": 120,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "bada-2015-awareness-campaigns-fail",
      "title": "Cyber Security Awareness Campaigns: Why do they fail to change behaviour?",
      "authors": [
        "Maria Bada",
        "Angela M. Sasse",
        "Jason R. C. Nurse"
      ],
      "year": 2015,
      "venue": "International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)",
      "pub_type": "conference",
      "doi": null,
      "url": "https://arxiv.org/abs/1901.02672",
      "open_access_url": "https://arxiv.org/pdf/1901.02672",
      "method": "conceptual",
      "sample": null,
      "setting": "Examples of campaigns in the UK and Africa",
      "key_finding": "Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.",
      "psysec_relevance": "Explains why information-only awareness training rarely changes behavior and points to motivation, attitudes and culture as the levers.",
      "stance": "supports",
      "principles": [
        2,
        6,
        5
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "awareness-programs",
        "fear-appeals",
        "motivation",
        "persuasion"
      ],
      "citations_approx": 463,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "sasse-2015-scaring-and-bullying",
      "title": "Scaring and Bullying People into Security Won't Work",
      "authors": [
        "Angela Sasse"
      ],
      "year": 2015,
      "venue": "IEEE Security & Privacy, 13(3), 80-83",
      "pub_type": "journal",
      "doi": "10.1109/MSP.2015.65",
      "url": "https://doi.org/10.1109/MSP.2015.65",
      "open_access_url": "https://discovery.ucl.ac.uk/1495933/1/scare_security_ieee2np2015.pdf",
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.",
      "psysec_relevance": "A direct expert critique of fear- and coercion-based security programs, including punitive phishing-simulation approaches.",
      "stance": "supports",
      "principles": [
        4,
        2
      ],
      "tactics": [],
      "chain": [
        "emotion",
        "belief"
      ],
      "topics": [
        "blame-and-fear",
        "fear-appeals",
        "habituation",
        "phishing-simulation"
      ],
      "citations_approx": 66,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "caputo-2014-going-spear-phishing",
      "title": "Going Spear Phishing: Exploring Embedded Training and Awareness",
      "authors": [
        "Deanna D. Caputo",
        "Shari Lawrence Pfleeger",
        "Jesse D. Freeman",
        "M. Eric Johnson"
      ],
      "year": 2014,
      "venue": "IEEE Security & Privacy",
      "pub_type": "journal",
      "doi": "10.1109/MSP.2013.106",
      "url": "https://doi.org/10.1109/MSP.2013.106",
      "open_access_url": null,
      "method": "field-experiment",
      "sample": "Large-scale experiment with employees across three spear-phishing trials and four training conditions",
      "setting": "Large organization (workplace field study)",
      "key_finding": "Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.",
      "psysec_relevance": "Early field evidence that post-click training content goes unread, questioning feedback designs that rely on people reading after a mistake.",
      "stance": "challenges",
      "principles": [
        3,
        6
      ],
      "tactics": [],
      "chain": [
        "behavior"
      ],
      "topics": [
        "embedded-training",
        "phishing-simulation",
        "awareness-programs"
      ],
      "citations_approx": 277,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "kirlappos-2014-shadow-security",
      "title": "Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security",
      "authors": [
        "Iacovos Kirlappos",
        "Simon Parkin",
        "M. Angela Sasse"
      ],
      "year": 2014,
      "venue": "Workshop on Usable Security (USEC 2014)",
      "pub_type": "conference",
      "doi": "10.14722/usec.2014.23007",
      "url": "https://doi.org/10.14722/usec.2014.23007",
      "open_access_url": null,
      "method": "qualitative",
      "sample": "118 in-depth employee interviews",
      "setting": "Large multinational organization",
      "key_finding": "Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.",
      "psysec_relevance": "Shows that employees often want to be secure, and that treating non-compliance as learning rather than violation can improve both culture and controls.",
      "stance": "supports",
      "principles": [
        2,
        3
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "compliance",
        "security-culture",
        "usable-security",
        "insider-behavior"
      ],
      "citations_approx": 96,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "johnston-2010-fear-appeals",
      "title": "Fear Appeals and Information Security Behaviors: An Empirical Study",
      "authors": [
        "Allen C. Johnston",
        "Merrill Warkentin"
      ],
      "year": 2010,
      "venue": "MIS Quarterly, 34(3), 549-566",
      "pub_type": "journal",
      "doi": "10.2307/25750691",
      "url": "https://doi.org/10.2307/25750691",
      "open_access_url": null,
      "method": "survey",
      "sample": "275 university affiliates",
      "setting": "US university",
      "key_finding": "Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.",
      "psysec_relevance": "Heavily cited evidence that fear messaging can raise security intentions, provided people believe they can act; this complicates a blanket rejection of fear.",
      "stance": "mixed",
      "principles": [
        4,
        1
      ],
      "tactics": [],
      "chain": [
        "emotion",
        "belief"
      ],
      "topics": [
        "fear-appeals",
        "self-efficacy",
        "individual-differences"
      ],
      "citations_approx": 1372,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "lally-2010-how-are-habits-formed",
      "title": "How are habits formed: Modelling habit formation in the real world",
      "authors": [
        "Phillippa Lally",
        "Cornelia H. M. van Jaarsveld",
        "Henry W. W. Potts",
        "Jane Wardle"
      ],
      "year": 2010,
      "venue": "European Journal of Social Psychology, 40(6), 998-1009",
      "pub_type": "journal",
      "doi": "10.1002/ejsp.674",
      "url": "https://doi.org/10.1002/ejsp.674",
      "open_access_url": "https://onlinelibrary.wiley.com/doi/pdfdirect/10.1002/ejsp.674",
      "method": "field-experiment",
      "sample": "96 volunteers (82 analysed), 12 weeks / 84 days of daily self-report",
      "setting": "Everyday life (UK volunteers)",
      "key_finding": "Repeating a chosen behavior daily in a consistent context made it more automatic along an asymptotic curve. Time to reach 95% of peak automaticity ranged from 18 to 254 days, and missing a single day did not materially derail habit formation.",
      "psysec_relevance": "Grounds the claim that secure behaviors become habits through consistent, context-linked repetition over weeks to months, not a one-off annual course.",
      "stance": "foundational",
      "principles": [
        7,
        6
      ],
      "tactics": [],
      "chain": [
        "habit"
      ],
      "topics": [
        "habit-formation",
        "motivation"
      ],
      "citations_approx": 1905,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "siponen-2010-neutralization",
      "title": "Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations",
      "authors": [
        "Mikko Siponen",
        "Anthony Vance"
      ],
      "year": 2010,
      "venue": "MIS Quarterly, 34(3), 487-502",
      "pub_type": "journal",
      "doi": "10.2307/25750688",
      "url": "https://doi.org/10.2307/25750688",
      "open_access_url": null,
      "method": "survey",
      "sample": "Scenario-based survey, ~1,449 scenario responses from employees",
      "setting": "Organizations (Finland)",
      "key_finding": "Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.",
      "psysec_relevance": "Suggests that threatening punishment does less than engaging with the reasons people give themselves for bending rules.",
      "stance": "supports",
      "principles": [
        2,
        6
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "compliance",
        "insider-behavior",
        "blame-and-fear",
        "decision-making"
      ],
      "citations_approx": 900,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "kumaraguru-2010-teaching-johnny",
      "title": "Teaching Johnny not to fall for phish",
      "authors": [
        "Ponnurangam Kumaraguru",
        "Steve Sheng",
        "Alessandro Acquisti",
        "Lorrie Faith Cranor",
        "Jason Hong"
      ],
      "year": 2010,
      "venue": "ACM Transactions on Internet Technology",
      "pub_type": "journal",
      "doi": "10.1145/1754393.1754396",
      "url": "https://doi.org/10.1145/1754393.1754396",
      "open_access_url": "https://figshare.com/articles/journal_contribution/Teaching_Johnny_Not_to_Fall_for_Phish/6468080",
      "method": "mixed-methods",
      "sample": "Multiple lab and real-world user studies of PhishGuru and Anti-Phishing Phil",
      "setting": "Carnegie Mellon University studies",
      "key_finding": "Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.",
      "psysec_relevance": "Foundational evidence that teachable-moment feedback and game-based learning can work, which later field studies have complicated.",
      "stance": "mixed",
      "principles": [
        3,
        7
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "embedded-training",
        "usable-security",
        "feedback"
      ],
      "citations_approx": 449,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "kahneman-2009-conditions-intuitive-expertise",
      "title": "Conditions for intuitive expertise: A failure to disagree",
      "authors": [
        "Daniel Kahneman",
        "Gary Klein"
      ],
      "year": 2009,
      "venue": "American Psychologist, 64(6), 515-526",
      "pub_type": "journal",
      "doi": "10.1037/a0016755",
      "url": "https://doi.org/10.1037/a0016755",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "A skeptic of intuition (heuristics-and-biases) and a champion of it (naturalistic decision making) agree that intuitive judgments can be trusted only when the environment is regular enough to be learnable and the person has had lots of practice with rapid, clear feedback.",
      "psysec_relevance": "Specifies the conditions under which 'trained instincts' for spotting social engineering can be built: frequent, realistic exposure with fast feedback.",
      "stance": "foundational",
      "principles": [
        8,
        3
      ],
      "tactics": [],
      "chain": [
        "belief",
        "habit"
      ],
      "topics": [
        "intuition",
        "decision-making",
        "feedback"
      ],
      "citations_approx": 2221,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "herath-2009-protection-motivation-deterrence",
      "title": "Protection motivation and deterrence: a framework for security policy compliance in organisations",
      "authors": [
        "Tejaswini Herath",
        "H Raghav Rao"
      ],
      "year": 2009,
      "venue": "European Journal of Information Systems, 18(2)",
      "pub_type": "journal",
      "doi": "10.1057/ejis.2009.6",
      "url": "https://doi.org/10.1057/ejis.2009.6",
      "open_access_url": null,
      "method": "survey",
      "sample": "312 employees from 78 organisations",
      "setting": "Multiple organisations",
      "key_finding": "Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.",
      "psysec_relevance": "Shows that commitment, peer influence and self-efficacy drive compliance alongside threat and deterrence perceptions, so culture sits next to enforcement.",
      "stance": "mixed",
      "principles": [
        2,
        1
      ],
      "tactics": [
        "Social Proof"
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "compliance",
        "self-efficacy",
        "security-culture",
        "motivation"
      ],
      "citations_approx": 1403,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "herley-2009-so-long-and-no-thanks",
      "title": "So long, and no thanks for the externalities: the rational rejection of security advice by users",
      "authors": [
        "Cormac Herley"
      ],
      "year": 2009,
      "venue": "Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09)",
      "pub_type": "conference",
      "doi": "10.1145/1719030.1719050",
      "url": "https://doi.org/10.1145/1719030.1719050",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.",
      "psysec_relevance": "Reframes non-compliance as a reasonable response to burdensome advice, shifting responsibility to how security asks are designed and prioritized.",
      "stance": "supports",
      "principles": [
        2,
        6
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "security-fatigue",
        "decision-making",
        "usable-security",
        "compliance"
      ],
      "citations_approx": 679,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "darcy-2009-deterrence-countermeasures",
      "title": "User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach",
      "authors": [
        "John D'Arcy",
        "Anat Hovav",
        "Dennis Galletta"
      ],
      "year": 2009,
      "venue": "Information Systems Research, 20(1)",
      "pub_type": "journal",
      "doi": "10.1287/isre.1070.0160",
      "url": "https://doi.org/10.1287/isre.1070.0160",
      "open_access_url": null,
      "method": "survey",
      "sample": "269 computer users from 8 companies",
      "setting": "Eight companies (US)",
      "key_finding": "User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.",
      "psysec_relevance": "Evidence that sanction-based deterrence can reduce intentional misuse, a counterpoint to purely non-punitive approaches (though it concerns deliberate misuse, not phishing susceptibility).",
      "stance": "challenges",
      "principles": [
        1
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "compliance",
        "insider-behavior",
        "awareness-programs",
        "blame-and-fear"
      ],
      "citations_approx": 1313,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "beautement-2008-compliance-budget",
      "title": "The compliance budget: managing security behaviour in organisations",
      "authors": [
        "Adam Beautement",
        "M. Angela Sasse",
        "Mike Wonham"
      ],
      "year": 2008,
      "venue": "Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08)",
      "pub_type": "conference",
      "doi": "10.1145/1595676.1595684",
      "url": "https://doi.org/10.1145/1595676.1595684",
      "open_access_url": null,
      "method": "qualitative",
      "sample": "17 employee interviews",
      "setting": "Two major commercial organizations",
      "key_finding": "Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.",
      "psysec_relevance": "Shows that piling on security demands exhausts employee goodwill, so security teams must spend people's effort deliberately.",
      "stance": "supports",
      "principles": [
        2
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "compliance",
        "motivation",
        "security-fatigue",
        "decision-making"
      ],
      "citations_approx": 382,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "workman-2008-wisecrackers-phishing-pretext",
      "title": "Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security",
      "authors": [
        "Michael Workman"
      ],
      "year": 2008,
      "venue": "Journal of the American Society for Information Science and Technology, 59(4), 662-674",
      "pub_type": "journal",
      "doi": "10.1002/asi.20779",
      "url": "https://doi.org/10.1002/asi.20779",
      "open_access_url": null,
      "method": "field-experiment",
      "sample": "Employees of a single organisation subjected to phishing and pretext attempts, combined with survey measures",
      "setting": "Corporate field setting (USA)",
      "key_finding": "Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.",
      "psysec_relevance": "An early theory-grounded field test linking persuasion psychology (commitment, trust, deference to authority) to real social-engineering victimization.",
      "stance": "foundational",
      "principles": [
        6,
        1
      ],
      "tactics": [
        "Authority",
        "Trust",
        "Helpfulness"
      ],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "persuasion",
        "susceptibility",
        "individual-differences"
      ],
      "citations_approx": 175,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "wood-2007-habits-habit-goal-interface",
      "title": "A new look at habits and the habit-goal interface",
      "authors": [
        "Wendy Wood",
        "David T. Neal"
      ],
      "year": 2007,
      "venue": "Psychological Review, 114(4), 843-863",
      "pub_type": "journal",
      "doi": "10.1037/0033-295X.114.4.843",
      "url": "https://doi.org/10.1037/0033-295X.114.4.843",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "Habits are learned links between context cues and responses that form through repetition and can then be triggered directly by those cues without the goal that originally drove them. Goals shape habits mainly by motivating the early repetition and by steering people toward cues, rather than by directly activating the habit.",
      "psysec_relevance": "Explains why secure behavior must be anchored to real contextual cues (the inbox moment) and why changing intentions alone rarely changes habitual clicking.",
      "stance": "foundational",
      "principles": [
        6,
        8
      ],
      "tactics": [],
      "chain": [
        "habit",
        "behavior"
      ],
      "topics": [
        "habit-formation",
        "decision-making"
      ],
      "citations_approx": 1338,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "ryan-2000-self-determination-theory",
      "title": "Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being",
      "authors": [
        "Richard M. Ryan",
        "Edward L. Deci"
      ],
      "year": 2000,
      "venue": "American Psychologist, 55(1), 68-78",
      "pub_type": "journal",
      "doi": "10.1037/0003-066X.55.1.68",
      "url": "https://doi.org/10.1037/0003-066X.55.1.68",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.",
      "psysec_relevance": "Explains why punitive, controlling security programs erode motivation while programs that support autonomy, competence and belonging build lasting engagement.",
      "stance": "foundational",
      "principles": [
        2,
        3
      ],
      "tactics": [],
      "chain": [
        "belief",
        "emotion"
      ],
      "topics": [
        "motivation",
        "self-efficacy",
        "psychological-safety"
      ],
      "citations_approx": 41740,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "edmondson-1999-psychological-safety",
      "title": "Psychological Safety and Learning Behavior in Work Teams",
      "authors": [
        "Amy Edmondson"
      ],
      "year": 1999,
      "venue": "Administrative Science Quarterly, 44(2)",
      "pub_type": "journal",
      "doi": "10.2307/2666999",
      "url": "https://doi.org/10.2307/2666999",
      "open_access_url": "http://nrs.harvard.edu/urn-3:HUL.InstRepos:37968728",
      "method": "mixed-methods",
      "sample": "51 work teams",
      "setting": "Manufacturing company (US)",
      "key_finding": "Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.",
      "psysec_relevance": "Foundational evidence that people surface mistakes and learn only when they will not be punished for speaking up, which underpins non-punitive reporting cultures.",
      "stance": "foundational",
      "principles": [
        3,
        2
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "psychological-safety",
        "feedback",
        "reporting",
        "security-culture"
      ],
      "citations_approx": 10829,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "adams-1999-users-are-not-the-enemy",
      "title": "Users are not the enemy",
      "authors": [
        "Anne Adams",
        "Martina Angela Sasse"
      ],
      "year": 1999,
      "venue": "Communications of the ACM, 42(12)",
      "pub_type": "journal",
      "doi": "10.1145/322796.322806",
      "url": "https://doi.org/10.1145/322796.322806",
      "open_access_url": "https://discovery.ucl.ac.uk/id/eprint/20247/2/CACM%20FINAL.pdf",
      "method": "mixed-methods",
      "sample": "139 web questionnaire responses + 30 semi-structured interviews",
      "setting": "Two organizations (technology company; construction sector) plus international respondents",
      "key_finding": "Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.",
      "psysec_relevance": "Landmark evidence that blaming users misdiagnoses the problem and that communication and design, not control, drive secure behavior.",
      "stance": "supports",
      "principles": [
        2,
        6
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "usable-security",
        "blame-and-fear",
        "compliance",
        "motivation"
      ],
      "citations_approx": 1643,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "bechara-1997-deciding-advantageously",
      "title": "Deciding Advantageously Before Knowing the Advantageous Strategy",
      "authors": [
        "Antoine Bechara",
        "Hanna Damasio",
        "Daniel Tranel",
        "Antonio R. Damasio"
      ],
      "year": 1997,
      "venue": "Science, 275(5304), 1293-1295",
      "pub_type": "journal",
      "doi": "10.1126/science.275.5304.1293",
      "url": "https://doi.org/10.1126/science.275.5304.1293",
      "open_access_url": null,
      "method": "lab-experiment",
      "sample": "Healthy participants and patients with prefrontal damage performing the Iowa Gambling Task",
      "setting": "Neuropsychology lab (USA)",
      "key_finding": "Healthy participants began choosing advantageously and showed anticipatory skin-conductance responses to risky options before they could explain which strategy was best. Patients with prefrontal damage never developed these signals and kept choosing badly even after knowing the right strategy.",
      "psysec_relevance": "Evidence that emotion-based, nonconscious signals guide good decisions before explicit knowledge does, supporting training that builds gut-level recognition rather than only facts.",
      "stance": "foundational",
      "principles": [
        6,
        8
      ],
      "tactics": [],
      "chain": [
        "emotion",
        "behavior"
      ],
      "topics": [
        "intuition",
        "decision-making"
      ],
      "citations_approx": 3544,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    },
    {
      "slug": "bandura-1977-self-efficacy",
      "title": "Self-efficacy: Toward a unifying theory of behavioral change",
      "authors": [
        "Albert Bandura"
      ],
      "year": 1977,
      "venue": "Psychological Review, 84(2), 191-215",
      "pub_type": "journal",
      "doi": "10.1037/0033-295X.84.2.191",
      "url": "https://doi.org/10.1037/0033-295X.84.2.191",
      "open_access_url": null,
      "method": "conceptual",
      "sample": null,
      "setting": null,
      "key_finding": "People's expectations that they can successfully perform a behavior determine whether they try, how hard they work and how long they persist. These efficacy beliefs are built mainly through actual successful performance, and also through watching others, verbal persuasion and emotional arousal.",
      "psysec_relevance": "Underpins the idea that people act securely when they believe they can, and that mastery experiences (e.g., successful reports) build that belief more than warnings do.",
      "stance": "foundational",
      "principles": [
        3,
        7
      ],
      "tactics": [],
      "chain": [
        "belief",
        "behavior"
      ],
      "topics": [
        "self-efficacy",
        "motivation"
      ],
      "citations_approx": 56258,
      "verified": true,
      "added_on": "2026-09-27",
      "updated_on": "2026-09-27"
    }
  ]
}