← Studies

Foundational · 2020

Categorizing human phishing difficulty: a Phish Scale

Michelle Steves, Kristen Greene, Mary Theofanos

Key finding

Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.

Why it matters

Argues raw click rates are misleading without context, supporting measurement beyond punitive click-rate leaderboards.

Informs Cite
Steves, M., Greene, K., & Theofanos, M. (2020). Categorizing human phishing difficulty: a Phish Scale. Journal of Cybersecurity. https://doi.org/10.1093/cybsec/tyaa009