Studies
5 studies · CSV
- Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training Yin et al. (2026). MIS Quarterly Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital Tolsdorf et al. (2025). Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al. (2024). Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24) Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.
- Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al. (2022). 2022 IEEE Symposium on Security and Privacy (SP) Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
- Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content Lin et al. (2019). ACM Transactions on Computer-Human Interaction (TOCHI) 43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.