Research / Principles

Principle 2 of 8

Culture eats compliance for breakfast

Compliance programs produce box-checking. Culture produces people who care about getting it right because their team does.

Studies (22)

SupportsQualitative · 2025

Phishing reporting in organizations: What motivates employees to take action?

The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.

SupportsConceptual · 2019

Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset

A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.

SupportsMixed methods · 2018

Exploring susceptibility to phishing in the workplace

Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.

SupportsConceptual · 2015

Scaring and Bullying People into Security Won't Work

Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.

SupportsConceptual · 2015

Cyber Security Awareness Campaigns: Why do they fail to change behaviour?

Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.

SupportsQualitative · 2008

The compliance budget: managing security behaviour in organisations

Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.

SupportsMixed methods · 1999

Users are not the enemy

Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.

MixedField experiment · 2025

Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital

Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.

MixedField experiment · 2022

Phishing in Organizations: Findings from a Large-Scale and Long-Term Study

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

ChallengesField experiment · 2026

Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale

Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.

ChallengesRandomized controlled trial · 2025

Understanding the Efficacy of Phishing Training in Practice

Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.

FoundationalCase study · 2021

A Case Study of Phishing Incident Response in an Educational Organization

Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.

FoundationalMixed methods · 2020

Categorizing human phishing difficulty: a Phish Scale

Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.

FoundationalMixed methods · 1999

Psychological Safety and Learning Behavior in Work Teams

Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.

Related behaviors (7)

PB-05Emerging evidence

Reports their own mistakes quickly

Tells the security team right away after clicking a link, opening a file, or entering a password on a suspicious page.

BeliefBehavior
PB-11Moderate evidence

Raises security friction openly

Tells the security team when a rule blocks their work, instead of quietly building a workaround.

BeliefBehavior