The evidence, for and against
9 studies · Download CSV
The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al., Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.
Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al., International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
How are habits formed: Modelling habit formation in the real world Lally et al., European Journal of Social Psychology, 40(6), 998-1009Repeating a chosen behavior daily in a consistent context made it more automatic along an asymptotic curve. Time to reach 95% of peak automaticity ranged from 18 to 254 days, and missing a single day did not materially derail habit formation.
Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao, European Journal of Information Systems, 18(2)Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.
The compliance budget: managing security behaviour in organisations Beautement et al., Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08)Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.
Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being Ryan & Deci, American Psychologist, 55(1), 68-78Reviewing research on self-determination theory, the authors argue that people's intrinsic motivation and internalization of rules depend on meeting three basic needs: competence, autonomy and relatedness. Controlling environments undermine these needs and motivation, while supportive ones foster them.
Users are not the enemy Adams & Sasse, Communications of the ACM, 42(12)Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.
Self-efficacy: Toward a unifying theory of behavioral change Bandura, Psychological Review, 84(2), 191-215People's expectations that they can successfully perform a behavior determine whether they try, how hard they work and how long they persist. These efficacy beliefs are built mainly through actual successful performance, and also through watching others, verbal persuasion and emotional arousal.