Phishing in Organizations: Findings from a Large-Scale and Long-Term Study

12/14/2021
by   Daniele Lain, et al.
0

In this paper, we present findings from a large-scale and long-term phishing experiment that we conducted in collaboration with a partner company. Our experiment ran for 15 months during which time more than 14,000 study participants (employees of the company) received different simulated phishing emails in their normal working context. We also deployed a reporting button to the company's email client which allowed the participants to report suspicious emails they received. We measured click rates for phishing emails, dangerous actions such as submitting credentials, and reported suspicious emails. The results of our experiment provide three types of contributions. First, some of our findings support previous literature with improved ecological validity. One example of such results is good effectiveness of warnings on emails. Second, some of our results contradict prior literature and common industry practices. Surprisingly, we find that embedded training during simulated phishing exercises, as commonly deployed in the industry today, does not make employees more resilient to phishing, but instead it can have unexpected side effects that can make employees even more susceptible to phishing. And third, we report new findings. In particular, we are the first to demonstrate that using the employees as a collective phishing detection mechanism is practical in large organizations. Our results show that such crowd-sourcing allows fast detection of new phishing campaigns, the operational load for the organization is acceptable, and the employees remain active over long periods of time.

READ FULL TEXT

page 1

page 5

page 6

page 8

page 9

page 17

research
11/10/2021

Agile Information System Development Organizations Transforming to Large-Scale Collaboration

We report findings from a case study of a large agile information system...
research
03/16/2022

On the evolution and impact of Architectural Smells – An industrial case study

Architectural smells (AS) are notorious for their long-term impact on th...
research
11/26/2019

Drivers affecting cloud ERP deployment decisions: an Australian study

Cloud-based Enterprise Resources Planning (Cloud ERP) is hosting an ERP ...
research
06/14/2022

Hidden Influences of Crowd Behavior in Crowdfunding: An Experimental Study

Crowdfunding continues to transform financing opportunities for many acr...
research
06/30/2020

Learning to Ignore: A Case Study of Organization-Wide Bulk Email Effectiveness

Bulk email is a primary communication channel within organizations, with...
research
09/01/2023

Long-Term Memorability On Advertisements

Marketers spend billions of dollars on advertisements but to what end? A...
research
03/31/2019

Video Game Development in a Rush: A Survey of the Global Game Jam Participants

Video game development is a complex endeavor, often involving complex so...

Please sign up or login with your details

Forgot password? Click here to reset