Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices

要旨

Preventing workplace phishing depends on the actions of every employee, regardless of cybersecurity expertise. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old) at two U.S. universities, we found that less than 21% of our participants had any formal anti-phishing training. Much of what our participants know about phishing comes from informal sources that emphasize “tips” and "tricks" like those found in conversations with friends, news stories, newsletters, social media, and podcasts. These informal channels provide opportunities for IT professionals wishing to enhance employees’ anti-phishing awareness by better aligning the delivery of expert advice with employees’ current practices and desires. We provide four recommendations designed to embrace "guerrilla learning" by distributing anti-phishing educational resources across the workplace and workday in part to encourage the delivery of more accurate information in more informal and incidental ways, and greater dialogue between anti-phishing training instructors and learners.

著者
Anne Clara Tally
Indiana University, Bloomington, Indiana, United States
Jacob Abbott
Indiana University Bloomington, Bloomington, Indiana, United States
Ashley M. Bochner
Indiana University, Bloomington, Indiana, United States
Sanchari Das
University of Denver, Denver, Colorado, United States
Christena Nippert-Eng
Indiana University, Bloomington, Indiana, United States
論文URL

https://doi.org/10.1145/3544548.3580650

動画

会議: CHI 2023

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2023.acm.org/)

セッション: Security Awareness and Phishing

Hall C
6 件の発表
2023-04-25 01:35:00
2023-04-25 03:00:00