The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design Experiment

要旨

Organizations rely on phishing interventions to enhance employees' vigilance and safe responses to phishing emails that bypass technical solutions. While various resources are available to counteract phishing, studies emphasize the need for interactive and practical training approaches. To investigate the effectiveness of such an approach, we developed and delivered two anti-phishing trainings, group discussion and role-playing, at a European university. We conducted a pre-registered experiment (N = 105), incorporating repeated measures at three time points, a control group, and three in-situ phishing tests. Both trainings enhanced employees' anti-phishing self-efficacy and support-seeking intention in within-group analyses. Only the role-playing training significantly improved support-seeking intention when compared to the control group. Participants in both trainings reported more phishing tests and demonstrated heightened vigilance to phishing attacks compared to the control group. We discuss practical implications for evaluating and improving phishing interventions and promoting safe responses to phishing threats within organizations.

著者
Xiaowei Chen
University of Luxembourg, Esch-sur-Alzette, Luxembourg
Margault Sacré
Université du Luxembourg, Esch-sur-Alzette, Luxembourg
Gabriele Lenzini
SnT - Interdisciplinary Centre for Security, Reliability and Trust, University of Luxembourg, Luxembourg, Luxembourg
Samuel Greiff
University of Luxembourg, Esch-sur-Alzette, Luxembourg
Verena Distler
Bundeswehr University Muncih, Munich, Germany
Anastasia Sergeeva
University of Luxembourg, Esch-sur-Alzette, Luxembourg
論文URL

https://doi.org/10.1145/3613904.3641943

動画

会議: CHI 2024

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2024.acm.org/)

セッション: Security

317
5 件の発表
2024-05-15 01:00:00
2024-05-15 02:20:00