Foundational · 2020
Categorizing human phishing difficulty: a Phish Scale
Michelle Steves, Kristen Greene, Mary Theofanos
Key finding
Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
Why it mattersArgues raw click rates are misleading without context, supporting measurement beyond punitive click-rate leaderboards.
Informs- Measures reporting first, clicks second supports
- Rates Simulation difficulty before judging results supports
Steves, M., Greene, K., & Theofanos, M. (2020). Categorizing human phishing difficulty: a Phish Scale. Journal of Cybersecurity. https://doi.org/10.1093/cybsec/tyaa009