SupportsQualitative · 2023
Pilavakis et al. — Proceedings 2023 Symposium on Usable Security (USEC 2023)
People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.
SupportsField experiment · 2020
Reinheimer et al. — Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)
After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
SupportsConceptual · 2019
Zimmermann & Renaud — International Journal of Human-Computer Studies, 131, 169-187
A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.
SupportsMixed methods · 2018
Vance et al. — MIS Quarterly, 42(2), 355-380
Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.
SupportsQualitative · 2014
Kirlappos et al. — Workshop on Usable Security (USEC 2014)
Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.
MixedField experiment · 2026
Yin et al. — MIS Quarterly
Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.
MixedMixed methods · 2024
Lain et al. — Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)
Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.
MixedField experiment · 2022
Lain et al. — 2022 IEEE Symposium on Security and Privacy (SP)
Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
MixedField experiment · 2019
Lin et al. — ACM Transactions on Computer-Human Interaction (TOCHI)
43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.
MixedMixed methods · 2010
Kumaraguru et al. — ACM Transactions on Internet Technology
Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.
ChallengesField experiment · 2026
Rozema & Davis — Proceedings of the ACM Web Conference 2026 (WWW '26)
Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.
ChallengesRandomized controlled trial · 2025
Ho et al. — 2025 IEEE Symposium on Security and Privacy (SP)
Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.
ChallengesField experiment · 2014
Caputo et al. — IEEE Security & Privacy
Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.
FoundationalCase study · 2021
Althobaiti et al. — Proceedings of the ACM on Human-Computer Interaction (CSCW)
Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.
FoundationalConceptual · 2009
Kahneman & Klein — American Psychologist, 64(6), 515-526
A skeptic of intuition (heuristics-and-biases) and a champion of it (naturalistic decision making) agree that intuitive judgments can be trusted only when the environment is regular enough to be learnable and the person has had lots of practice with rapid, clear feedback.
FoundationalConceptual · 2000
Ryan & Deci — American Psychologist, 55(1), 68-78
Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.
FoundationalMixed methods · 1999
Edmondson — Administrative Science Quarterly, 44(2)
Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.
FoundationalConceptual · 1977
Bandura — Psychological Review, 84(2), 191-215
People's expectations that they can successfully perform a behavior determine whether they try, how hard they work and how long they persist. These efficacy beliefs are built mainly through actual successful performance, and also through watching others, verbal persuasion and emotional arousal.