O3.04.5Decay of trained phishing vigilancedesignresearch

Vigilance gained from security education decays with time and fatigue

Aliases: vigilance decay · phishing training forgetting · phishing training decay

What it is

Decay of trained phishing vigilance means that cue memory and checking behavior gained after instruction can weaken with time, repeated messages, task load, and alert fatigue. Improvement on one exercise is not a permanent personal trait. As attacks and work context change, an old checklist may also lose diagnostic value.

Why it happens

Training adds security inspection to ordinary work, but checking has little immediate reward and competes with speed and responsiveness. Repeating similar simulations can teach recognition of a training template rather than transfer to real attacks; frequent low-quality tests can produce disregard or resentment. Spacing, contextual fit, feedback timing, and a punitive climate all affect retention and reporting.

Studying it

In an approved longitudinal design, present simulations with calibrated difficulty and context at several post-training intervals. Compare recognition, independent verification, reporting, false alarms, and response time. Rotate attack forms and use held-out contexts to test transfer rather than template familiarity. Record workload and message exposure; avoid shame boards and punitive harm, and do not optimize click reduction alone.

Where it stops holding

Decay has no fixed rate. Short timely reinforcement, peer norms, and usable reporting can improve retention. Experienced roles and salient incidents may establish durable habits, though fatigue still matters. Training can support comprehension and reporting, but it is neither a permanent patch nor evidence that users should own interception. Technical and process controls remain necessary.

Applying it

  • Use spaced, role-relevant, changing micro-exercises with feedback on the decision evidence and safer action, not merely who answered incorrectly.
  • Interpret results by message difficulty, recipient context, and time interval rather than ranking raw click rates across unlike exercises.
  • Monitor reporting, false alarms, independent verification, and fatigue feedback, adjusting cadence and format when benefits decline.
  • Feed training findings into filtering, provenance, and business-process teams to remove recurring system conditions that invite error.

Related

  • Same group: O3.04.6 Limited human defense · O3.04.7 Contextual warning
  • Adjacent: O3.05 Security-warning fatigue and disregard
  • Search terms: phishing training decay · security vigilance · spaced security training

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O3.04.5