Studies
4 studies · CSV
- Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al. (2023). HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
- An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al. (2020). Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020) After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
- Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper (2018). Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.
- Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al. (2015). International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019) Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.