Lune

WWW2026顶会

Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale

Andrew T. Rozema, James C. Davis

2026年份
1被引次数

摘要

Social engineering attacks delivered via email, commonly known as phishing, represent a persistent cybersecurity threat leading to significant organizational incidents and data breaches. Although many organizations train employees on phishing, often mandated by compliance requirements, the real-world effectiveness of this training remains debated. Past work has demonstrated the ineffectiveness of training, but reproduction across different organizations, training approaches, and with a standardized threat assessment will help the generalizability of this phenomenon. To contribute to evidence-based cybersecurity policy, we conducted a large-scale reproduction study (N=12,511) at a US-based financial technology firm. Our design refined prior work by comparing training modalities in operational environments, applying NIST's standardized phishing difficulty measurement, and introducing novel organizational-level temporal resilience metrics. Echoing prior work, training interventions showed no significant main effects on click rates (p=0.450) nor reporting rates (p=0.417), with negligible effect sizes. However, we found that the NIST Phish Scale predicted user behavior, with click rates increasing from 7.0% (easy lures) to 15.0% (hard lures). Our organizational-level resilience result was mixed: 36-55% of campaigns achieved ''inoculation'' patterns where reports preceded clicks, but training did not significantly improve organizational-level temporal protection. Our results confirm the ineffectiveness of current phishing training approaches and offer a refined study design for future work.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper7

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖