Studies
4 studies · CSV
- An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al. (2020). Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020) After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
- Exploring susceptibility to phishing in the workplace Williams et al. (2018). International Journal of Human-Computer Studies Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.
- Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility Vishwanath et al. (2018). Communication Research, 45(8), 1146-1166 Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.
- Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments Vance et al. (2018). MIS Quarterly, 42(2), 355-380 Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.