The Research · Studies

The evidence, for and against

24 studies · Download CSV

No. 012025 Phishing reporting in organizations: What motivates employees to take action? Burda et al., Information & Computer Security

The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.

No. 022020 Defining organisational information security culture—Perspectives from academia and industry Veiga et al., Computers & Security, 92, 101713

Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.

No. 032020 How Experts Detect Phishing Scam Emails Wash, Proceedings of the ACM on Human-Computer Interaction (CSCW)

Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.

No. 042019 Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset Zimmermann & Renaud, International Journal of Human-Computer Studies, 131, 169-187

A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.

No. 052019 Predicting susceptibility to social influence in phishing emails Parsons et al., International Journal of Human-Computer Studies

In a role-play study of 985 people, emails using consistency and reciprocity were most effective while scarcity and social proof were least effective. People who scored as susceptible to a given principle were usually more fooled by emails using it, and age, computer time, social-proof susceptibility and impulsivity predicted detection ability.

No. 062019 Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content Lin et al., ACM Transactions on Computer-Human Interaction (TOCHI)

43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.

No. 072018 Is the responsibilization of the cyber security risk reasonable and judicious? Renaud et al., Computers & Security, 78

Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.

No. 082018 Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper, Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems

Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.

No. 092015 Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al., International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)

Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.

No. 102015 Scaring and Bullying People into Security Won't Work Sasse, IEEE Security & Privacy, 13(3), 80-83

Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.

No. 112014 Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security Kirlappos et al., Workshop on Usable Security (USEC 2014)

Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.

No. 122010 Fear Appeals and Information Security Behaviors: An Empirical Study Johnston & Warkentin, MIS Quarterly, 34(3), 549-566

Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.

No. 132010 Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations Siponen & Vance, MIS Quarterly, 34(3), 487-502

Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.

No. 142010 Teaching Johnny not to fall for phish Kumaraguru et al., ACM Transactions on Internet Technology

Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.

No. 152009 Conditions for intuitive expertise: A failure to disagree Kahneman & Klein, American Psychologist, 64(6), 515-526

A skeptic of intuition (heuristics-and-biases) and a champion of it (naturalistic decision making) agree that intuitive judgments can be trusted only when the environment is regular enough to be learnable and the person has had lots of practice with rapid, clear feedback.

No. 162009 Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao, European Journal of Information Systems, 18(2)

Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.

No. 172009 So long, and no thanks for the externalities: the rational rejection of security advice by users Herley, Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09)

Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.

No. 182009 User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach D'Arcy et al., Information Systems Research, 20(1)

User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.

No. 192008 The compliance budget: managing security behaviour in organisations Beautement et al., Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08)

Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.

No. 202008 Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security Workman, Journal of the American Society for Information Science and Technology, 59(4), 662-674

Drawing on marketing-persuasion theory, a field study tested whether the factors that make marketing campaigns work also explain who falls for phishing and pretext phone attacks, and found that they do: dispositional factors tied to persuasion predicted victimization.

No. 212000 Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being Ryan & Deci, American Psychologist, 55(1), 68-78

Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.

No. 221999 Psychological Safety and Learning Behavior in Work Teams Edmondson, Administrative Science Quarterly, 44(2)

Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.

No. 231999 Users are not the enemy Adams & Sasse, Communications of the ACM, 42(12)

Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.

No. 241977 Self-efficacy: Toward a unifying theory of behavioral change Bandura, Psychological Review, 84(2), 191-215

People's expectations that they can successfully perform a behavior determine whether they try, how hard they work and how long they persist. These efficacy beliefs are built mainly through actual successful performance, and also through watching others, verbal persuasion and emotional arousal.