Influencing Outcomes and Behaviors in Simulated Phishing Exercises

Steven McElwee, George E. Murphy, P. W. Shelton · 2018

Phishing attacks are both a technical and a social problem. They exploit technical vulnerabilities and human weaknesses. As a result, both technical and social approaches are important. Simulated phishing exercises address the threat of phishing by reducing the susceptibility of end-users to falling for these cyberattacks. This research explores different approaches to reducing susceptibility to phishing using the primary mechanisms of agency theory. The goal of this research was to determine if information security managers should focus on outcome-based controls or behavior-based controls. Using four years of simulated phishing exercise data from an organization, this study defined and measured four variables that represent both types of controls. It found that behavior-based controls were more successful in reducing susceptibility to phishing, primarily when implemented as targeted training that was repeated multiple times.

Read the paper · More papers on PaperTik