Logo image
Informing, simulating experience, or both: A field experiment on phishing risks
Journal article   Open access   Peer reviewed

Informing, simulating experience, or both: A field experiment on phishing risks

Aurélien Baillon, Jeroen de Bruin, Aysil Emirmahmutoglu, Evelien van de Veer and Bram van Dijk
PLOS ONE, Vol.14(12)
18/12/2019

Abstract

"Cybersecurity cannot be ensured with mere technical solutions. Hackers often use fraudulent emails to simply ask people for their password to breach into organizations. This technique, called phishing, is a major threat for many organizations. A typical prevention measure is to inform employees but is there a better way to reduce phishing risks? Experience and feedback have often been claimed to be effective in helping people make better decisions. In a large field experiment involving more than 10,000 employees of a Dutch ministry, we tested the effect of information provision, simulated experience, and their combination to reduce the risks of falling into a phishing attack. Both approaches substantially reduced the proportion of employees giving away their password. Combining both interventions did not have a larger impact."
pdf
Informing-simulating-experience-or-bothDownloadView
Open Access CC BY V4.0
url
https://doi.org/10.1371/journal.pone.0224216View
Published (Version of record) Open

Metrics

5 File views/ downloads
11 Record Views

Details

InCites Highlights

These are selected metrics from InCites Benchmarking & Analytics tool, related to this contribution

Collaboration types
Domestic collaboration
Citation topics
4 Electrical Engineering, Electronics & Computer Science
4.187 Security Systems
4.187.1592 Cyber Defense
Web of Science research areas
Computer Science, Information Systems
Logo image