elib
DLR-Header
DLR-Logo -> http://www.dlr.de
DLR Portal Home | Imprint | Privacy Policy | Accessibility | Contact | Deutsch
Fontsize: [-] Text [+]

What Makes Phishing Simulation Campaigns (Un)Acceptable? A Vignette Experiment

Schwab, Jasmin and Nussbaum, Alexander and Sergeeva, Anastasia and Alt, Florian and Distler, Verena (2025) What Makes Phishing Simulation Campaigns (Un)Acceptable? A Vignette Experiment. In: Network and Distributed System Security Symposium, NDSS 2025. Symposium on Usable Security and Privacy (USEC) 2025, 2025-02-24 - 2025-02-28, San Diego, California. doi: 10.14722/usec.2025.23010. ISBN 979-8-9919276-5-9.

[img] PDF
1MB

Official URL: https://www.ndss-symposium.org/ndss-paper/auto-draft-586/

Abstract

Organizations depend on their employees’ long-term cooperation to help protect the organization from cybersecurity threats. Phishing attacks are the entry point for harmful followup attacks. The acceptance of training measures is thus crucial. Many organizations use simulated phishing campaigns to train employees to adopt secure behaviors. We conducted a preregistered vignette experiment (N=793), investigating the factors that make a simulated phishing campaign seem (un)acceptable, and their influence on employees’ intention to manipulate the campaign. In the experiment, we varied whether employees gave prior consent, whether the phishing email promised a financial incentive and the consequences for employees who clicked on the phishing link. We found that employees’ prior consent positively affected the acceptance of a simulated phishing campaign. The consequences of “employee interview” and “termination of the work contract” negatively affected acceptance. We found no statistically significant effects of consent, monetary incentive, and consequences on manipulation probability. Our results shed light on the factors influencing the acceptance of simulated phishing campaigns. Based on our findings, we recommend that organizations prioritize obtaining informed consent from employees before including them in simulated phishing campaigns and that they clearly describe their consequences. Organizations should carefully evaluate the acceptance of simulated phishing campaigns and consider alternative anti-phishing measures.

Item URL in elib:https://elib.dlr.de/211498/
Document Type:Conference or Workshop Item (Speech)
Title:What Makes Phishing Simulation Campaigns (Un)Acceptable? A Vignette Experiment
Authors:
AuthorsInstitution or Email of AuthorsAuthor's ORCID iDORCID Put Code
Schwab, Jasminjasmin.schwab (at) dlr.dehttps://orcid.org/0000-0003-1750-0688183503251
Nussbaum, Alexanderalexander.nussbaum (at) unibw.deUNSPECIFIEDUNSPECIFIED
Sergeeva, Anastasiaanastasia.sergeeva (at) uni.luUNSPECIFIEDUNSPECIFIED
Alt, Florianflorian.alt (at) ifi.lmu.deUNSPECIFIEDUNSPECIFIED
Distler, Verenaverena.distler (at) aalto.fiUNSPECIFIEDUNSPECIFIED
Date:24 February 2025
Journal or Publication Title:Network and Distributed System Security Symposium, NDSS 2025
Refereed publication:Yes
Open Access:Yes
Gold Open Access:No
In SCOPUS:No
In ISI Web of Science:No
DOI:10.14722/usec.2025.23010
ISBN:979-8-9919276-5-9
Status:Published
Keywords:Phishing, Simulated Phishing Campaigns, Acceptance, Vignette Experiment
Event Title:Symposium on Usable Security and Privacy (USEC) 2025
Event Location:San Diego, California
Event Type:international Conference
Event Start Date:24 February 2025
Event End Date:28 February 2025
HGF - Research field:other
HGF - Program:other
HGF - Program Themes:other
DLR - Research area:no assignment
DLR - Program:no assignment
DLR - Research theme (Project):no assignment
Location: Rhein-Sieg-Kreis
Institutes and Institutions:Institute for the Protection of Terrestrial Infrastructures > Digital Twins of Infrastructures
Institute for the Protection of Terrestrial Infrastructures
Deposited By: Schwab, Jasmin
Deposited On:06 May 2025 08:21
Last Modified:06 May 2025 08:21

Repository Staff Only: item control page

Browse
Search
Help & Contact
Information
OpenAIRE Validator logo electronic library is running on EPrints 3.3.12
Website and database design: Copyright © German Aerospace Center (DLR). All rights reserved.