Studies
6 studies · CSV
- How Experts Detect Phishing Scam Emails Wash (2020). Proceedings of the ACM on Human-Computer Interaction (CSCW) Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.
- Suspicion, Cognition, and Automaticity Model of Phishing Susceptibility Vishwanath et al. (2018). Communication Research, 45(8), 1146-1166 Because training effects fade as people slip back into email routines, the authors built a model (SCAM) combining conscious cognitive processing, preconscious suspicion and habitual, automatic email use, and tested it across two phishing experiments. Email habits emerged as a key predictor of susceptibility alongside cognitive processing.
- Security Fatigue Stanton et al. (2016). IT Professional, 18(5) Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.
- Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations Siponen & Vance (2010). MIS Quarterly, 34(3), 487-502 Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
- So long, and no thanks for the externalities: the rational rejection of security advice by users Herley (2009). Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09) Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
- The compliance budget: managing security behaviour in organisations Beautement et al. (2008). Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08) Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.