The evidence, for and against
8 studies · Download CSV
Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.
Phishing reporting in organizations: What motivates employees to take action? Burda et al., Information & Computer SecurityThe main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
"I didn't click": What users say when reporting phishing Pilavakis et al., Proceedings 2023 Symposium on Usable Security (USEC 2023)People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.
Phishing in Organizations: Findings from a Large-Scale and Long-Term Study Lain et al., 2022 IEEE Symposium on Security and Privacy (SP)Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
A Case Study of Phishing Incident Response in an Educational Organization Althobaiti et al., Proceedings of the ACM on Human-Computer Interaction (CSCW)Handling phishing reports is a distributed process across several teams, each with narrow system access and knowledge. Sudden large campaigns flooded the help desk with reports, disrupting work and slowing mitigations and reflection.
How Experts Detect Phishing Scam Emails Wash, Proceedings of the ACM on Human-Computer Interaction (CSCW)Experts detect phishing in three stages: making sense of the email and noticing small discrepancies, becoming suspicious when something (usually a link asking for action) triggers the phishing explanation, then investigating and deleting or reporting. Training should build this sensemaking process, not just checklists.
Cognitive Triaging of Phishing Attacks Heijden & Allodi, 28th USENIX Security Symposium (USENIX Security 19), pp. 1309-1326Measuring Cialdini-style persuasion triggers in real reported phishing let the authors predict which attacks would draw the most clicks, enabling response teams to prioritize takedowns. Consistency and scarcity triggers were associated with more clicks, reciprocity appeared counterproductive, and authority, social proof and liking showed no clear trend.
Psychological Safety and Learning Behavior in Work Teams Edmondson, Administrative Science Quarterly, 44(2)Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.