Research / Principles

Principle 6 of 8

Brains are not computers

Manipulation hits the fast, emotional systems that fire before reasoning. Training has to reach that layer, not just the rational one.

Studies (22)

SupportsField experiment · 2024

Devising and Detecting Phishing Emails Using Large Language Models

Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.

SupportsField experiment · 2024

Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects

Fully AI-automated spear-phishing emails drew a 54% click-through rate, matching human experts (54%) and far above arbitrary control phishing (12%), a big jump from comparable AI results a year earlier. The AI's reconnaissance profiles were accurate and useful for 88% of targets, and AI can raise attacker profitability up to 50-fold at scale.

SupportsQualitative · 2020

How Experts Detect Phishing Scam Emails

Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.

SupportsLab experiment · 2019

Predicting susceptibility to social influence in phishing emails

In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.

SupportsMixed methods · 2018

Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments

Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.

SupportsMixed methods · 2018

Exploring susceptibility to phishing in the workplace

Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.

SupportsLab experiment · 2018

Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility

Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.

SupportsQualitative · 2016

Security Fatigue

Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.

SupportsConceptual · 2015

Cyber Security Awareness Campaigns: Why do they fail to change behaviour?

Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.

SupportsMixed methods · 1999

Users are not the enemy

Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.

MixedField experiment · 2025

Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital

Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.

MixedMixed methods · 2024

Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training

Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.

MixedSystematic review · 2019

Cyber security fear appeals: unexpectedly complicated

A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.

MixedLarge-scale observational · 2019

Cognitive Triaging of Phishing Attacks

Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.

ChallengesField experiment · 2014

Going Spear Phishing: Exploring Embedded Training and Awareness

Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.

FoundationalQualitative · 2019

Persuasion: How phishing emails can influence users and bypass security measures

Merging Cialdini, Gragg and Stajano & Wilson into one set of social-engineering persuasion principles, the authors found authority, strong affect, integrity and reciprocation were the most common in phishing subject lines. Strong-affect and authority emails leaned on 'you/your' wording, reciprocation on 'we/us/our'.

FoundationalField experiment · 2010

How are habits formed: Modelling habit formation in the real world

Repeating a chosen behavior daily in a consistent context made it more automatic along an asymptotic curve. Time to reach 95% of peak automaticity ranged from 18 to 254 days, and missing a single day did not materially derail habit formation.

FoundationalField experiment · 2008

Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security

Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.

FoundationalConceptual · 2007

A new look at habits and the habit-goal interface

Habits are learned links between context cues and responses that form through repetition and can then be triggered directly by those cues without the goal that originally drove them. Goals shape habits mainly by motivating the early repetition and by steering people toward cues, rather than by directly activating the habit.

FoundationalLab experiment · 1997

Deciding Advantageously Before Knowing the Advantageous Strategy

Healthy participants began choosing advantageously and showed anticipatory skin-conductance responses to risky options before they could explain which strategy was best. Patients with prefrontal damage never developed these signals and kept choosing badly even after knowing the right strategy.

Related behaviors (5)