Studies
2 studies · CSV
- Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al. (2022). 2022 IEEE Symposium on Security and Privacy (SP) Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
- Cognitive Triaging of Phishing Attacks Heijden & Allodi (2019). 28th USENIX Security Symposium (USENIX Security 19), pp. 1309-1326 Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.