Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K Filings
Jonas Hielscher, Maximilian Golla
摘要
The Security Awareness and Training (SAT) market exceeds multiple billion dollars annually, yet reliable data on organizational adoption remains scarce. Conflicting, survey-based figures from cybersecurity vendors leave researchers and decision-makers reliant on questionable insights. A new U.S. Securities and Exchange Commission (SEC) regulation, effective since late 2023, requires companies to disclose cybersecurity strategies in annual Form 10-K filings, offering a more consistent data source. In this study, we crawl and analyze filings from 5,286 U.S. companies across diverse sectors and sizes, using keyword searches and thematic analysis, which offers a lower-bound estimate of prevalent topics. We find that 78% of companies report implementing SAT and 27% conduct phishing simulations, with adoption varying significantly by sector and size. Larger companies report more extensive SAT efforts, often aligned with standards like NIST CSF. While multi-factor authentication (11%) is the most common employee-facing security control, many filings frame employees as a risk factor. Our findings help organizations critically assess SAT strategies and vendor claims, offer actionable insights for policymakers, and equip scholars with a coded dataset and crawling tools for ongoing longitudinal analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 被引用 95 次
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- Privacy Legislation as Business Risks: How GDPR and CCPA are Represented in Technology Companies' Investment Risk DisclosuresRichmond Y. Wong, Andrew Chong, R. Cooper AspegrenCSCW 2023 · 被引用 56 次
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar 等S&P 2022 · 被引用 51 次
- SoK: Cyber Insurance - Technical Challenges and a System Security RoadmapSavino Dambra, Leyla Bilge, Davide BalzarottiS&P 2020 · 被引用 47 次
相关 Paper
- Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' PromisesJonas Hielscher, Markus Schöps, Jens Opdenbusch, Felix Reichmann 等CCS 2024 · 被引用 4 次
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong 等S&P 2025
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish ScaleAndrew T. Rozema, James C. DavisWWW 2026 · 被引用 1 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- "What Keeps People Secure is That They Met The Security Team": Deconstructing Drivers And Goals of Organizational Security AwarenessJonas Hielscher, Simon ParkinUSENIX Security 2024 · 被引用 7 次
