The Research · Studies

The evidence, for and against

6 studies · Download CSV

No. 012026 Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training Yin et al., MIS Quarterly

Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.

No. 022025 Understanding the Efficacy of Phishing Training in Practice Ho et al., 2025 IEEE Symposium on Security and Privacy (SP)

Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.

No. 032024 Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al., Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)

Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.

No. 042022 Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

No. 052014 Going Spear Phishing: Exploring Embedded Training and Awareness Caputo et al., IEEE Security & Privacy

Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.

No. 062010 Teaching Johnny not to fall for phish Kumaraguru et al., ACM Transactions on Internet Technology

Embedded email-based training (PhishGuru) and a game (Anti-Phishing Phil) built on learning-science principles improved users' ability to recognize phishing. The authors frame user education as a complement to automated detection, noting that users are unmotivated and that training can raise false alarms on legitimate messages.