article Open access

Phishing feedback: just-in-time intervention improves online security

  • Behavioural Public Policy
  • Cambridge University Press
Research footprint

At a glance

Citations
4
References
25
Comments
0
Paper overview

Abstract

Abstract Phishing emails cost companies millions. In the absence of technology to perfectly block phishing emails, the responsibility falls on employees to identify and appropriately respond to phishing attempts and on employers to train them to do so. We report results from an experiment with around 11,000 employees of a large U.S. corporation, testing the efficacy of just-in-time feedback delivered at a teachable moment – immediately after succumbing to a phishing email – to reduce susceptibility to phishing emails. Employees in the study were sent an initial pseudo-phishing email, and those who either ignored or fell victim to the phishing email were randomized to receive or not receive feedback about their response. Just-in-time feedback for employees who fell victim to or ignored the initial pseudo-phishing email reduced susceptibility to a second pseudo-phishing email sent by the research team. Additionally, for employees who ignored the initial email, feedback also increased reporting rates.

Record transparency

Publication details

DOI
10.1017/bpp.2024.19
OpenAlex
W4402460632
Document type
article
Language
EN
Source
Behavioural Public Policy
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.