Studies
9 studies · CSV
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital Tolsdorf et al. (2025). Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
- Cognitive Triaging of Phishing Attacks Heijden & Allodi (2019). 28th USENIX Security Symposium (USENIX Security 19), pp. 1309-1326 Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.
- Cyber security fear appeals: unexpectedly complicated Renaud & Dupuis (2019). Proceedings of the New Security Paradigms Workshop (NSPW '19) A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.
- Persuasion: How phishing emails can influence users and bypass security measures Ferreira & Teles (2019). International Journal of Human-Computer Studies Merging Cialdini, Gragg and Stajano & Wilson into one set of social-engineering persuasion principles, the authors found authority, strong affect, integrity and reciprocation were the most common in phishing subject lines. Strong-affect and authority emails leaned on 'you/your' wording, reciprocation on 'we/us/our'.
- Security Fatigue Stanton et al. (2016). IT Professional, 18(5) Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.
- Scaring and Bullying People into Security Won't Work Sasse (2015). IEEE Security & Privacy, 13(3), 80-83 Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.
- Fear Appeals and Information Security Behaviors: An Empirical Study Johnston & Warkentin (2010). MIS Quarterly, 34(3), 549-566 Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.
- Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being Ryan & Deci (2000). American Psychologist, 55(1), 68-78 Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.
- Deciding Advantageously Before Knowing the Advantageous Strategy Bechara et al. (1997). Science, 275(5304), 1293-1295 Healthy participants began choosing advantageously and showed anticipatory skin-conductance responses to risky options before they could explain which strategy was best. Patients with prefrontal damage never developed these signals and kept choosing badly even after knowing the right strategy.