The Research · Studies

The evidence, for and against

12 studies · Download CSV

No. 012026 Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale Rozema & Davis, Proceedings of the ACM Web Conference 2026 (WWW '26)

Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.

No. 022026 Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training Yin et al., MIS Quarterly

Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.

No. 032025 Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital Tolsdorf et al., Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25)

Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.

No. 042025 Understanding the Efficacy of Phishing Training in Practice Ho et al., 2025 IEEE Symposium on Security and Privacy (SP)

Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.

No. 052024 Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training Lain et al., Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS '24)

Whatever benefit embedded training has comes from the nudge of being periodically reminded of the threat, not from the training content, which employees rarely read. Delaying training was as effective as immediate training, rewards did not improve behavior, and phishing looked like an attention problem rather than a knowledge problem.

No. 062022 Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

No. 072020 Categorizing human phishing difficulty: a Phish Scale Steves et al., Journal of Cybersecurity

Click rates should be expected to vary with how hard a phishing email is for a given audience, especially when its premise fits the recipient's work context. The authors propose the NIST Phish Scale so programs can rate exercise difficulty and interpret click rates.

No. 082019 Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content Lin et al., ACM Transactions on Computer-Human Interaction (TOCHI)

43% of participants clicked at least one simulated phishing email, with older women most susceptible. Young users' susceptibility dropped over the 21 days while older users' stayed flat, and the effectiveness of each persuasion technique and life-domain topic varied by age group. Older users also rated their own susceptibility lower than it was.

No. 092018 Exploring susceptibility to phishing in the workplace Williams et al., International Journal of Human-Computer Studies

Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.

No. 102018 Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper, Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems

Facts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.

No. 112015 Scaring and Bullying People into Security Won't Work Sasse, IEEE Security & Privacy, 13(3), 80-83

Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.

No. 122014 Going Spear Phishing: Exploring Embedded Training and Awareness Caputo et al., IEEE Security & Privacy

Differently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.