Research / Studies

Studies

Peer-reviewed research and foundational works, each summarized in plain English and tagged to PsySec principles, tactics, and the belief chain.

Filters (1 active)
Clear filters

10 studies match your filters

Download these as CSV

MixedField experiment · 2025

Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital

Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.

MixedMixed methods · 2024

Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training

Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.

MixedField experiment · 2022

Phishing in Organizations: Findings from a Large-Scale and Long-Term Study

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

MixedLarge-scale observational · 2019

Cognitive Triaging of Phishing Attacks

Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.

MixedSystematic review · 2019

Cyber security fear appeals: unexpectedly complicated

A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.

MixedField experiment · 2019

Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content

43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.

MixedSurvey · 2010

Fear Appeals and Information Security Behaviors: An Empirical Study

Fear appeals did increase people's intentions to adopt recommended security actions, but the effect varied across people and depended partly on self-efficacy, response efficacy, perceived threat severity and social influence.

MixedMixed methods · 2010

Teaching Johnny not to fall for phish

Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.