TY - JOUR
T1 - Evaluating organizational phishing awareness training on an enterprise scale
AU - Hillman, Doron
AU - Harel, Yaniv
AU - Toch, Eran
N1 - Publisher Copyright:
© 2023
PY - 2023/9
Y1 - 2023/9
N2 - Employees are often the victims of phishing attacks, posing a threat to both themselves and their organizations. In response, organizations are dedicating resources, time, and employee effort to train staff to identify simulated phishing attacks. However, the real-world effectiveness of these training efforts in large enterprises remains largely unexplored. To address this, we carried out a controlled experiment in an Israeli financial institution with approximately 5,000 employees. The experiment included three simulated phishing emails, and we examined how different factors influence the phishing Click-Through Rate (CTR). Our findings suggest that employees are more likely to engage with phishing simulation emails that use personalized phrasing. We also found that phishing CTR varies between business units, and that the timing of training before the simulated email did not significantly affect phishing CTR. Furthermore, it became clear that training prior to phishing simulations and adopting a data-driven approach that includes process, variable and measure analysis, can enhance organizational awareness of phishing. Although advanced technologies can mitigate some phishing attacks, our research indicates that employee awareness and proactive behavior will continue to play a critical role in the foreseeable future. The paper concludes by providing guidelines to information security officers on establishing effective organizational awareness to prevent phishing attacks.
AB - Employees are often the victims of phishing attacks, posing a threat to both themselves and their organizations. In response, organizations are dedicating resources, time, and employee effort to train staff to identify simulated phishing attacks. However, the real-world effectiveness of these training efforts in large enterprises remains largely unexplored. To address this, we carried out a controlled experiment in an Israeli financial institution with approximately 5,000 employees. The experiment included three simulated phishing emails, and we examined how different factors influence the phishing Click-Through Rate (CTR). Our findings suggest that employees are more likely to engage with phishing simulation emails that use personalized phrasing. We also found that phishing CTR varies between business units, and that the timing of training before the simulated email did not significantly affect phishing CTR. Furthermore, it became clear that training prior to phishing simulations and adopting a data-driven approach that includes process, variable and measure analysis, can enhance organizational awareness of phishing. Although advanced technologies can mitigate some phishing attacks, our research indicates that employee awareness and proactive behavior will continue to play a critical role in the foreseeable future. The paper concludes by providing guidelines to information security officers on establishing effective organizational awareness to prevent phishing attacks.
KW - Awareness
KW - Organizational cyber security
KW - Phishing
KW - Phishing wave
KW - Social engineering
KW - Training
UR - http://www.scopus.com/inward/record.url?scp=85164224854&partnerID=8YFLogxK
U2 - 10.1016/j.cose.2023.103364
DO - 10.1016/j.cose.2023.103364
M3 - ???researchoutput.researchoutputtypes.contributiontojournal.article???
AN - SCOPUS:85164224854
SN - 0167-4048
VL - 132
JO - Computers and Security
JF - Computers and Security
M1 - 103364
ER -