Studies
4 studies · CSV
- Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content Lin et al. (2019). ACM Transactions on Computer-Human Interaction (TOCHI) 43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.
- Fear Appeals and Information Security Behaviors: An Empirical Study Johnston & Warkentin (2010). MIS Quarterly, 34(3), 549-566 Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.
- Teaching Johnny not to fall for phish Kumaraguru et al. (2010). ACM Transactions on Internet Technology Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.
- Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao (2009). European Journal of Information Systems, 18(2) Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.