preprint وصول مفتوح

Falling for phishing attempts: An investigation of individual differences that are associated with behavior in a naturalistic phishing simulation

Research footprint

At a glance

الاستشهادات
1
المراجع
56
Comments
0
Paper overview

Abstract

Social engineering cyber-attacks such as phishing emails pose a serious threat to the safety of many organizations. Given that the effectiveness of these attacks heavily relies on poor human decision making, an improved understanding of the individual characteristics that increase cybersecurity vulnerability could inform more targeted training. The current study aimed to identify whether several factors, including phishing email detection ability, confidence in one’s phishing identification decisions, attitudes toward one’s level of responsibility and efficacy, and employee satisfaction and loyalty to the organization, can predict behavior in a naturalistic phishing simulation in an employment setting. We followed up employees of a large organization who had been recently targeted by a phishing simulation and asked them to complete a survey that included a phishing detection task. The employee’s behavior in the phishing simulation was ranked according to its safety: reporting the suspicious email, neither reporting nor clicking on the embedded link, and clicking on the link. We found that fewer years of employment at the organization and lower employee satisfaction and loyalty predicted increasingly unsafe behavior in the simulation. This suggests that newer and unsatisfied employees are most vulnerable to phishing attempts and might benefit most from targeted cybersecurity training.

Record transparency

Publication details

DOI
10.31234/osf.io/xdk53
OpenAlex
W4308592907
Document type
preprint
Language
EN
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.