FoundationalCase study · 2021
Althobaiti et al. — Proceedings of the ACM on Human-Computer Interaction (CSCW)
Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.
FoundationalMixed methods · 2020
Steves et al. — Journal of Cybersecurity
Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
FoundationalMixed methods · 2020
Veiga et al. — Computers & Security, 92, 101713
Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.
FoundationalConceptual · 2000
Ryan & Deci — American Psychologist, 55(1), 68-78
Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.
FoundationalMixed methods · 1999
Edmondson — Administrative Science Quarterly, 44(2)
Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.