Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training
Daniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen, Srdjan Capkun
Abstract
A common form of phishing training in organizations is the use of simulated phishing emails to test employees' susceptibility to phishing attacks, and the immediate delivery of training material to those who fail the test. This widespread practice is dubbed embedded training; however, its effectiveness in decreasing the likelihood of employees falling for phishing again in the future is questioned by the contradictory findings of several recent field studies. We investigate embedded phishing training in three aspects. First, we observe that the practice incorporates different componentsknowledge gains from its content, nudges and reminders from the test itself, and the deterrent effect of potential consequences-our goal is to study which ones are more effective, if any. Second, we explore two potential improvements to training, namely its timing and the use of incentives. Third, we analyze employees' reception and perception of the practice. For this, we conducted a largescale mixed-methods (quantitative and qualitative) study on the employees of a partner company. Our study contributes several novel findings on the training practice: in particular, its effectiveness comes from its nudging effect, i.e., the periodic reminder of the threat rather than from its content, which is rarely consumed by employees due to lack of time and perceived usefulness. Further, delaying training to ease time pressure is as effective as currently established practices, while rewards do not improve secure behavior. Finally, some of our results support previous findings with increased ecological validity, e.g., that phishing is an attention problem, rather than a knowledge one, even for the most susceptible employees, and thus enforcing training does not help.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a6c9f352-e8d0-4406-b5e8-ee2d2836e940Cited by top-tier papers7
- It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationLorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier et al.CHI 2025 · 5 citations
- PiMRef: Deducing Ever-evolving Spear-phishing Emails with Knowledge Base InvariantsRuofan Liu, Yun Lin, Yuxin Wang, Xiwen Teoh et al.CCS 2026 · 4 citations
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish ScaleAndrew T. Rozema, James C. DavisWWW 2026 · 1 citation
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University HospitalJan Tolsdorf, David Langer, Luigi Lo IaconoCCS 2025
Builds on4
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- The Influence of Human Factors on the Intention to Report Phishing EmailsIoana Andreea Marin, Pavlo Burda, Nicola Zannone, Luca AllodiCHI 2023 · 30 citations
- "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing CampaignsLina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela SasseUSENIX Security 2023
- "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred SecurityJonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge et al.USENIX Security 2023
Related papers
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 7 citations
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das et al.CSCW 2023 · 11 citations
- The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception StudyVerena DistlerCHI 2023 · 26 citations
- Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessJustin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer et al.S&P 2025
