Skip to main navigation Skip to search Skip to main content

Simulated Phishing Attack and Embedded Training Campaign

  • William Yeoh
  • , He Huang
  • , Wang-Sheng Lee
  • , Fadi Al Jafari
  • , Rachel Mansson

Research output: Contribution to journalArticlepeer-review

43 Citations (Scopus)

Abstract

Phishing attacks are costly for both organizations and individuals, yet existing academic research has provided little guidance on how to strategize and implement a combined phishing awareness and training campaign. Drawing on operant conditioning theory, we conduct an in-depth case study on a large phishing awareness campaign and reveal that phishing awareness is a learning process through which individuals’ behavior can be strengthened by reinforcement and punishment. Based on the case study findings, we present several propositions for cybersecurity stakeholders. This study contributes to the phishing awareness literature and has implications for research and practice. This paper is useful for organizations planning or in the process of implementing or reviewing a phishing awareness and education program.

Original languageEnglish
Pages (from-to)802-821
Number of pages20
JournalJournal of Computer Information Systems
Volume62
Issue number4
DOIs
Publication statusPublished - 4 Jul 2022

Keywords

  • Cybersecurity
  • embedded training
  • phishing awareness
  • phishing education
  • simulated phishing attack

Fingerprint

Dive into the research topics of 'Simulated Phishing Attack and Embedded Training Campaign'. Together they form a unique fingerprint.

Cite this