The evidence, for and against
8 studies · Download CSV
Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.
Understanding the Efficacy of Phishing Training in Practice Ho et al., 2025 IEEE Symposium on Security and Privacy (SP)Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.
Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al., HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer ScienceGovernment security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al., Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
Categorizing human phishing difficulty: a Phish Scale Steves et al., Journal of CybersecurityClick rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.
Defining organisational information security culture—Perspectives from academia and industry Veiga et al., Computers & Security, 92, 101713Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.
Cyber security fear appeals: unexpectedly complicated Renaud & Dupuis, Proceedings of the New Security Paradigms Workshop (NSPW '19)A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.