The Research · Studies

The evidence, for and against

11 studies · Download CSV

No. 012026 Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training Yin et al., MIS Quarterly

Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.

No. 022024 Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al., Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)

Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.

No. 032022 Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

No. 042020 An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al., Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)

After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.

No. 052020 Defining organisational information security culture—Perspectives from academia and industry Veiga et al., Computers & Security, 92, 101713

Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.

No. 062018 Exploring susceptibility to phishing in the workplace Williams et al., International Journal of Human-Computer Studies

Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.

No. 072018 Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility Vishwanath et al., Communication Research, 45(8), 1146-1166

Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.

No. 082018 Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments Vance et al., MIS Quarterly, 42(2), 355-380

Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.

No. 092010 How are habits formed: Modelling habit formation in the real world Lally et al., European Journal of Social Psychology, 40(6), 998-1009

Repeating a chosen behavior daily in a consistent context made it more automatic along an asymptotic curve. Time to reach 95% of peak automaticity ranged from 18 to 254 days, and missing a single day did not materially derail habit formation.

No. 102009 Conditions for intuitive expertise: A failure to disagree Kahneman & Klein, American Psychologist, 64(6), 515-526

A skeptic of intuition (heuristics-and-biases) and a champion of it (naturalistic decision making) agree that intuitive judgments can be trusted only when the environment is regular enough to be learnable and the person has had lots of practice with rapid, clear feedback.

No. 112007 A new look at habits and the habit-goal interface Wood & Neal, Psychological Review, 114(4), 843-863

Habits are learned links between context cues and responses that form through repetition and can then be triggered directly by those cues without the goal that originally drove them. Goals shape habits mainly by motivating the early repetition and by steering people toward cues, rather than by directly activating the habit.