ejecip Open Access Journal

European Journal of Emerging Cybersecurity and Information Protection

eISSN: Applied
Publication Frequency : 2 Issues per year.

  • Peer Reviewed & International Journal
Table of Content
Issues (Year-wise)
Loading…

Open Access iconOpen Access

ARTICLE

ASSESSING END-USER RESILIENCE TO PHISHING: A STUDY ON EDUCATIONAL INTERVENTIONS AND SIMULATED ATTACKS IN A CROATIAN UNIVERSITY

1 Department of Information and Communication Sciences, University of Zagreb, Croatia
2 Department of Information Systems, University of Split, Croatia

Citations: Loading…
ABSTRACT VIEWS: 75   |   FILE VIEWS: 30   |   PDF: 30   HTML: 0   OTHER: 0   |   TOTAL: 105
Views + Downloads (Last 90 days)
Cumulative % included

Abstract

Phishing remains a pervasive and evolving cybersecurity threat, consistently exploiting the human element as a primary vulnerability in organizational defenses. This comprehensive study investigates the efficacy of structured educational interventions combined with realistic simulated phishing attacks in bolstering end-user resilience against these threats within a prominent Croatian university. Employing a quasi-experimental design, the research involved a multi-phased approach comprising an initial baseline assessment, targeted educational modules, and subsequent simulated attacks. We meticulously analyzed behavioral responses, compromise rates, and their statistical associations with various demographic and contextual variables, including age, departmental affiliation, and professional qualifications. While individual interventions showed varying degrees of immediate impact, a critical finding emerged regarding the significant influence of temporal factors, particularly pre-holiday periods, on user susceptibility. These results underscore the inherent limitations of standalone awareness assessments and highlight the imperative for ongoing, highly contextualized, and integrated cybersecurity training methodologies. The findings offer practical guidance for academic institutions and other organizations seeking to develop more robust and adaptive phishing defense strategies that account for both human factors and environmental dynamics.


Keywords

Phishing, Cybersecurity, End-User Awareness, Simulated Attacks

References

1. Ahmad, B.M.; Ahmed, S.M.; Sylvanus, D.E. Enhancing Phishing Awareness Strategy Through Embedded Learning Tools: A Simulation Approach. Arch. Adv. Eng. Sci. 2023, 2, 1–14. [CrossRef]

2. Hillman, D.; Harel, Y.; Toch, E. Evaluating Organizational Phishing Awareness Training on an Enterprise Scale. Comput. Secur. 2023, 132, 103364. [CrossRef]

3. Kävrestad, J.; Hagberg, A.; Nohlberg, M.; Rambusch, J.; Roos, R.; Furnell, S. Evaluation of Contextual and Game-Based Training for Phishing Detection. Future Internet 2022, 14, 104. [CrossRef]

4. Jayakrishnan, G.; Banahatti, V.; Lodha, S. PickMail: A Serious Game for Email Phishing Awareness Training. In Proceedings of the 2022 Symposium on Usable Security, San Diego, CA, USA, 28 April 2022. [CrossRef]

5. Wen, Z.A.; Lin, Z.; Chen, R.; Andersen, E. What Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game. In Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, Scotland, UK, 4–9 May 2019; pp. 1–12. [CrossRef]


How to Cite

ASSESSING END-USER RESILIENCE TO PHISHING: A STUDY ON EDUCATIONAL INTERVENTIONS AND SIMULATED ATTACKS IN A CROATIAN UNIVERSITY. (2024). European Journal of Emerging Cybersecurity and Information Protection, 1(01), 44-56. https://parthenonfrontiers.com/index.php/ejecip/article/view/83

Share Link