Studies
3 studies · CSV
- Phishing reporting in organizations: What motivates employees to take action? Burda et al. (2025). Information & Computer Security The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
- "I didn't click": What users say when reporting phishing Pilavakis et al. (2023). Proceedings 2023 Symposium on Usable Security (USEC 2023) People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.
- How Experts Detect Phishing Scam Emails Wash (2020). Proceedings of the ACM on Human-Computer Interaction (CSCW) Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.