Studies
3 studies · CSV
- Exploring susceptibility to phishing in the workplace Williams et al. (2018). International Journal of Human-Computer Studies Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.
- Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper (2018). Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.
- Scaring and Bullying People into Security Won't Work Sasse (2015). IEEE Security & Privacy, 13(3), 80-83 Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.