Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"
Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert, Zinaida Benenson
Abstract
E-mail phishing attacks remain one of the most significant challenges in IT security and are often used for initial access. Many organizations rely on phishing simulations to educate their staff to recognize suspicious e-mails. Previous studies have analyzed the effectiveness of these phishing simulations with mixed findings. However, the perception of and attitudes towards phishing simulations among staff have received little to no attention. This paper presents findings from a study that we carried out in cooperation with a multinational company that conducted phishing simulations over more than 12 months. We first conducted a quantitative survey involving 757 employees and then qualitative interviews with 22 participants to gain deeper insights into the perception of phishing simulations and the corresponding e-learning. We could not find evidence that employees feel attacked by their organization, as previous studies suspected. On the contrary, we found that a majority (86.9 %) have a positive or very positive attitude towards phishing simulations. The interviews revealed that some employees developed new routines for e-mail processing, but most describe themselves as having become more vigilant without concrete changes. Furthermore, we found evidence that phishing simulations create a false sense of security, as the employees feel protected by them. Additionally, a lack of communication and feedback can negatively impact employees' attitudes and lead to adverse consequences. Finally, we show that only a small portion of the employees who clicked on the phishing website interacted with the interactive e-learning elements, which raises questions about its objective usefulness, although they are perceived as useful.
• Security and privacy → Social aspects of security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 884f0958-755e-44bb-bfc4-15c2cef2aee5Cited by top-tier papers3
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University HospitalJan Tolsdorf, David Langer, Luigi Lo IaconoCCS 2025
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
Builds on5
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception StudyVerena DistlerCHI 2023 · 26 citations
- The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentXiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff et al.CHI 2024 · 21 citations
- "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing CampaignsLina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela SasseUSENIX Security 2023
Related papers
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 7 citations
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen et al.CCS 2024 · 9 citations
- Fear, Fun or None: A Qualitative Quest Towards Unlocking Cybersecurity AttitudesAlexandra von Preuschen, Carolin Benda, Monika Christine Schuhmacher, Verena ZimmermannCHI 2025 · 4 citations
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CSCW 2023 · 11 citations
- It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationLorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier et al.CHI 2025 · 5 citations
