← Studies

Challenges · 2014

Going Spear Phishing: Exploring Embedded Training and Awareness

Deanna D. Caputo, Shari Lawrence Pfleeger, Jesse D. Freeman, M. Eric Johnson

Key finding

Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.

Why it matters

Early field evidence that post-click training content goes unread, questioning feedback designs that rely on people reading after a mistake.

Cite
Caputo, D. D., Pfleeger, S. L., Freeman, J. D., & Johnson, M. E. (2014). Going Spear Phishing: Exploring Embedded Training and Awareness. IEEE Security & Privacy. https://doi.org/10.1109/MSP.2013.106