Studies
2 studies · CSV
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al. (2024). Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24) Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.
- Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao (2009). European Journal of Information Systems, 18(2) Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.