Proceedings 2019 Workshop on Usable Security 2019
DOI: 10.14722/usec.2019.23028
|View full text |Cite
|
Sign up to set email alerts
|

A Phish Scale: Rating Human Phishing Message Detection Difficulty

Abstract: As organizations continue to invest in phishing awareness training programs, many Chief Information Security Officers (CISOs) are concerned when their training exercise click rates are high or variable, as they must justify training budgets to those who question the efficacy of training when click rates are not declining. We argue that click rates should be expected to vary based on the difficulty of the phishing email for a target audience. Past research has shown that when the premise of a phishing email ali… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
14
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
4
1

Relationship

0
10

Authors

Journals

citations
Cited by 20 publications
(14 citation statements)
references
References 27 publications
0
14
0
Order By: Relevance
“… 36 , 37 More work is required to understand the relative persuasiveness of different targeted messages as well as the relative difficulty in detection. 42 …”
Section: Discussion and Lessons Learntmentioning
confidence: 99%
“… 36 , 37 More work is required to understand the relative persuasiveness of different targeted messages as well as the relative difficulty in detection. 42 …”
Section: Discussion and Lessons Learntmentioning
confidence: 99%
“…e literature [22] focuses more on the human impact on the phishing emails. Steves et al [23] built the previous research to construct a phishing scale, which is a phishing tool that utilizes premise to its information retrieval. e former analyzes the user's area of interest in phishing messages, and the latter indicates the attack elements contained in phishing attacks.…”
Section: Related Researchmentioning
confidence: 99%
“…If controls focus on how employees treat URLs in emails, some staff may find it more difficult than others to identify particular kinds of malicious email [99]. A reporting point for malicious emails can then be valuable, or support for when staff are uncertain.…”
Section: Step 3 Identifying Linkages Between Negative and Positive Be...mentioning
confidence: 99%