Research / Principles

Principle 1 of 8

Psychographics > Demographics

Train for how people think and what they care about, not for the attributes on their HR record.

Studies (10)

SupportsQualitative · 2025

Phishing reporting in organizations: What motivates employees to take action?

The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.

SupportsLab experiment · 2019

Predicting susceptibility to social influence in phishing emails

In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.

SupportsField experiment · 2018

Who Provides Phishing Training? Facts, Stories, and People Like Me

Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.

MixedField experiment · 2025

Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital

Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.

MixedField experiment · 2019

Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content

43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.

MixedSurvey · 2010

Fear Appeals and Information Security Behaviors: An Empirical Study

Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.

FoundationalMixed methods · 2020

Categorizing human phishing difficulty: a Phish Scale

Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.

FoundationalField experiment · 2008

Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security

Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.

Related behaviors (2)