Logo image
Falling and failing (to learn): Evidence from a nation-wide cybersecurity field experiment with SMEs
Journal article   Open access   Peer reviewed

Falling and failing (to learn): Evidence from a nation-wide cybersecurity field experiment with SMEs

David Gonzalez-Jimenez, Francesco Capozza, Thomas Dirkmaat, Evelien van de Veer, Amber van Druten and Aurélien Baillon
Journal of Economic Behavior and Organization
01/02/2025

Abstract

Field experiment Replication Phishing drill Prevention Patience Risk attitude
Prior experiences are crucial in shaping risk prevention behavior. Previous studies have shown that experiencing a simulated phishing attack (a “phishing drill”) reduces the likelihood of clicking on unsafe links and disclosing one’s password. In a large field experiment involving 670 small and medium-sized enterprises (SMEs) and their 33,000 employees, we examined the impact of experience on individuals’ ability to detect cyber-security threats, and whether this effect persisted over several months. We collected data at both the company and individual levels, including risk preference, time preference, and trust. Our findings indicate only a non-systematic, short-term effect of previous phishing emails on clicking behavior. A cluster of individuals with greater patience, trust, and risk seeking was more likely to click on phishing links in the first place but then also more likely to benefit from phishing drills.
pdf
Falling and failingDownloadView
Open Access CC BY V4.0
url
https://doi.org/10.1016/j.jebo.2024.106868View
Published (Version of record) Open

Metrics

5 File views/ downloads
47 Record Views

Details

InCites Highlights

These are selected metrics from InCites Benchmarking & Analytics tool, related to this contribution

Collaboration types
Domestic collaboration
International collaboration
Citation topics
6 Social Sciences
6.185 Communication
6.185.1644 Digital Privacy
Web of Science research areas
Economics
Logo image