Studies
2 studies · CSV
- Categorizing human phishing difficulty: a Phish Scale Steves et al. (2020). Journal of Cybersecurity Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
- Defining organisational information security culture—Perspectives from academia and industry Veiga et al. (2020). Computers & Security, 92, 101713 Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.