Challenges · 2014
Going Spear Phishing: Exploring Embedded Training and Awareness
Deanna D. Caputo, Shari Lawrence Pfleeger, Jesse D. Freeman, M. Eric Johnson
Key finding
Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.
Why it mattersEarly field evidence that post-click training content goes unread, questioning feedback designs that rely on people reading after a mistake.
CiteCaputo, D. D., Pfleeger, S. L., Freeman, J. D., & Johnson, M. E. (2014). Going Spear Phishing: Exploring Embedded Training and Awareness. IEEE Security & Privacy. https://doi.org/10.1109/MSP.2013.106