Studies
4 studies · CSV
- Phishing reporting in organizations: What motivates employees to take action? Burda et al. (2025). Information & Computer Security The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
- Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al. (2015). International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019) Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
- The compliance budget: managing security behaviour in organisations Beautement et al. (2008). Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08) Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.
- Users are not the enemy Adams & Sasse (1999). Communications of the ACM, 42(12) Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.