Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"
Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert, Zinaida Benenson
摘要
E-mail phishing attacks remain one of the most significant challenges in IT security and are often used for initial access. Many organizations rely on phishing simulations to educate their staff to recognize suspicious e-mails. Previous studies have analyzed the effectiveness of these phishing simulations with mixed findings. However, the perception of and attitudes towards phishing simulations among staff have received little to no attention. This paper presents findings from a study that we carried out in cooperation with a multinational company that conducted phishing simulations over more than 12 months. We first conducted a quantitative survey involving 757 employees and then qualitative interviews with 22 participants to gain deeper insights into the perception of phishing simulations and the corresponding e-learning. We could not find evidence that employees feel attacked by their organization, as previous studies suspected. On the contrary, we found that a majority (86.9 %) have a positive or very positive attitude towards phishing simulations. The interviews revealed that some employees developed new routines for e-mail processing, but most describe themselves as having become more vigilant without concrete changes. Furthermore, we found evidence that phishing simulations create a false sense of security, as the employees feel protected by them. Additionally, a lack of communication and feedback can negatively impact employees' attitudes and lead to adverse consequences. Finally, we show that only a small portion of the employees who clicked on the phishing website interacted with the interactive e-learning elements, which raises questions about its objective usefulness, although they are perceived as useful.
• Security and privacy → Social aspects of security and privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University HospitalJan Tolsdorf, David Langer, Luigi Lo IaconoCCS 2025
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong 等S&P 2025
它引用的顶会 Paper5
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception StudyVerena DistlerCHI 2023 · 被引用 26 次
- The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentXiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff 等CHI 2024 · 被引用 21 次
- "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing CampaignsLina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela SasseUSENIX Security 2023
相关 Paper
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 被引用 7 次
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen 等CCS 2024 · 被引用 9 次
- Fear, Fun or None: A Qualitative Quest Towards Unlocking Cybersecurity AttitudesAlexandra von Preuschen, Carolin Benda, Monika Christine Schuhmacher, Verena ZimmermannCHI 2025 · 被引用 4 次
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 等CSCW 2023 · 被引用 11 次
- It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationLorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier 等CHI 2025 · 被引用 5 次
