SupportsQualitative · 2025
Burda et al. — Information & Computer Security
The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
SupportsLab experiment · 2019
Parsons et al. — International Journal of Human-Computer Studies
In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.
SupportsField experiment · 2018
Wash & Cooper — Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems
Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.
MixedField experiment · 2025
Tolsdorf et al. — Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)
Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
MixedField experiment · 2019
Lin et al. — ACM Transactions on Computer-Human Interaction (TOCHI)
43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.
MixedSurvey · 2010
Johnston & Warkentin — MIS Quarterly, 34(3), 549-566
Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.
MixedSurvey · 2009
Herath & Rao — European Journal of Information Systems, 18(2)
Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.
ChallengesSurvey · 2009
D'Arcy et al. — Information Systems Research, 20(1)
User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.
FoundationalMixed methods · 2020
Steves et al. — Journal of Cybersecurity
Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
FoundationalField experiment · 2008
Workman — Journal of the American Society for Information Science and Technology, 59(4), 662-674
Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.