Mixed
Phishing in Organizations: Findings from a Large-Scale and Long-Term Study
Daniele Lain, Kari Kostiainen, Srdjan Čapkun · 2022 IEEE Symposium on Security and Privacy (SP), 2022
Key finding
Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
Why it matters for PsySec
Strong field evidence that click-then-lecture training is weak while empowering people as reporters (agency, collective defense) works.
Stance: Mixed. Findings cut both ways. Summaries are written by the database editors; read the original for full results and limitations.
Tags
P2. Culture eats compliance for breakfastP3. Feedback, Feedback, Feedback
BehaviorHabit
Phishing simulationEmbedded trainingReportingMeasurement
Behaviors this study informs
- supports
PB-01 · Reports suspicious messages - supports
OB-02 · Gives Simulation feedback to everyone, not only those who clicked - supports
OB-04 · Measures reporting first, clicks second - supports
OB-10 · Makes reporting one click and staffs triage for surges - supports
OB-13 · Pairs technical controls with human reporting
Cite this study
APA
Lain, D., Kostiainen, K., & Čapkun, S. (2022). Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. 2022 IEEE Symposium on Security and Privacy (SP). https://doi.org/10.1109/SP46214.2022.9833766
BibTeX
@inproceedings{lain_2022_phishing_in_organizations,
title = {Phishing in Organizations: Findings from a Large-Scale and Long-Term Study},
author = {Daniele Lain and Kari Kostiainen and Srdjan Čapkun},
year = {2022},
booktitle = {2022 IEEE Symposium on Security and Privacy (SP)},
doi = {10.1109/SP46214.2022.9833766},
url = {https://doi.org/10.1109/SP46214.2022.9833766}
}