SupportsQualitative · 2025
Burda et al. — Information & Computer Security
The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
SupportsMixed methods · 2023
Jacobs et al. — HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science
Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
SupportsConceptual · 2019
Zimmermann & Renaud — International Journal of Human-Computer Studies, 131, 169-187
A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.
SupportsConceptual · 2018
Renaud et al. — Computers & Security, 78
Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.
SupportsMixed methods · 2018
Williams et al. — International Journal of Human-Computer Studies
Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.
SupportsConceptual · 2015
Sasse — IEEE Security & Privacy, 13(3), 80-83
Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.
SupportsConceptual · 2015
Bada et al. — International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)
Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
SupportsQualitative · 2014
Kirlappos et al. — Workshop on Usable Security (USEC 2014)
Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.
SupportsSurvey · 2010
Siponen & Vance — MIS Quarterly, 34(3), 487-502
Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
SupportsConceptual · 2009
Herley — Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09)
Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
SupportsQualitative · 2008
Beautement et al. — Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08)
Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.
SupportsMixed methods · 1999
Adams & Sasse — Communications of the ACM, 42(12)
Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.
MixedField experiment · 2025
Tolsdorf et al. — Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)
Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
MixedField experiment · 2022
Lain et al. — 2022 IEEE Symposium on Security and Privacy (SP)
Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
MixedSurvey · 2009
Herath & Rao — European Journal of Information Systems, 18(2)
Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.
ChallengesField experiment · 2026
Rozema & Davis — Proceedings of the ACM Web Conference 2026 (WWW '26)
Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.
ChallengesRandomized controlled trial · 2025
Ho et al. — 2025 IEEE Symposium on Security and Privacy (SP)
Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.
FoundationalCase study · 2021
Althobaiti et al. — Proceedings of the ACM on Human-Computer Interaction (CSCW)
Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.
FoundationalMixed methods · 2020
Steves et al. — Journal of Cybersecurity
Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
FoundationalMixed methods · 2020
Veiga et al. — Computers & Security, 92, 101713
Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.
FoundationalConceptual · 2000
Ryan & Deci — American Psychologist, 55(1), 68-78
Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.
FoundationalMixed methods · 1999
Edmondson — Administrative Science Quarterly, 44(2)
Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.