The Research · Studies

The evidence, for and against

8 studies · Download CSV

No. 012026 Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale Rozema & Davis, Proceedings of the ACM Web Conference 2026 (WWW '26)

Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.

No. 022025 Understanding the Efficacy of Phishing Training in Practice Ho et al., 2025 IEEE Symposium on Security and Privacy (SP)

Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.

No. 032023 Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al., HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science

Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.

No. 042022 Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

No. 052020 An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al., Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)

After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.

No. 062020 Categorizing human phishing difficulty: a Phish Scale Steves et al., Journal of Cybersecurity

Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.

No. 072020 Defining organisational information security culture—Perspectives from academia and industry Veiga et al., Computers & Security, 92, 101713

Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.

No. 082019 Cyber security fear appeals: unexpectedly complicated Renaud & Dupuis, Proceedings of the New Security Paradigms Workshop (NSPW '19)

A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.