Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
Authors
Document Title
Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees’ Current Practices
Document Information
- Subject Area: Anti-phishing education and learning in workplace environments
- Keywords: phishing, anti-phishing training, informal learning, distributed learning, organizational security, human factors, workplace cybersecurity, qualitative research, IT departments, work environments
Research Background and Issues
- Identified Problems or Challenges: Among mid-career administrative office workers at two universities in the United States, less than 21% of participants had received formal anti-phishing training. Their primary knowledge sources were informal channels, such as social media and news stories. Many existing anti-phishing education methods fail to meet user needs and do not effectively enhance employees' ability to respond to phishing threats comprehensively.
- Significance: Phishing has become a growing global cybersecurity threat, with 91% of cyberattacks originating from phishing attempts. Strengthening employees' ability to identify and respond to phishing is crucial for improving organizational cybersecurity capabilities.
- Research Motivation and Related Work: Current research predominantly focuses on technical solutions and automated tools, with limited user-centered studies on how employees acquire and learn phishing-related knowledge. The motivation for this study is to explore the integration of informal learning models with workplace education to better address this threat.
Solution
- Proposed Solution:
- Combine formal training with informal learning to design distributed learning pathways tailored to users' current practices and needs.
- Utilize a "guerrilla learning" approach, leveraging distributed educational resources and unexpected learning moments to increase the dissemination of anti-phishing knowledge and user engagement.
- Provide customized recommendations and deliver high-quality educational content in diverse formats, including news stories, podcasts, and social media.
- Innovative Aspects:
- Integration of formal and informal learning channels, capitalizing on non-traditional educational spaces that users encounter daily.
- Drawing on the concept of guerrilla learning in education to spark user interest and reflection through unexpected methods, while encouraging active dialogue around educational content.
- Implementation Steps and Key Techniques: Based on participants' learning behaviors, strategies were proposed to improve anti-phishing education, including sending timely reminders, promoting diverse learning resources (e.g., podcasts, social media), designing intuitive user guides, and enhancing workplace training interactions.
Research Outcomes
- Specific Findings:
- The study revealed that mid-career office workers primarily learn about phishing through informal channels and most expressed a desire for more systematic training.
- An anti-phishing education method based on guerrilla learning principles was proposed to help organizations design more employee-friendly anti-phishing strategies.
- Advantages of Existing Solutions:
- Tailored educational content for non-cybersecurity expert users, effectively complementing existing formal training.
- Enhancing the appeal of learning materials, such as using storytelling and case studies to engage employees.
- Experimental or Evaluation Results: Among the 24 participants in the study, there was widespread positive feedback regarding diverse and distributed learning opportunities, emphasizing the importance and challenges of informal learning.
- Limitations and Future Directions:
- Limitations: The study focused on employees at two universities in the United States, with a small sample size that may not fully reflect the perspectives and needs of users in other industries and regions.
- Future Directions:
- Conduct large-scale surveys to validate the effectiveness of anti-phishing education methods for different user groups.
- Explore ways to optimize the accuracy of informal learning content and expand dissemination through broader media channels.
Conclusion and Recommendations
This study highlights the importance of a hybrid approach that combines formal and informal learning to improve employees' awareness and response capabilities regarding phishing threats. Four specific implementation recommendations for organizations are proposed: balancing the distribution of unexpected and routine information, sending timely reminders, diversifying learning resource formats, and fostering users' fundamental anti-phishing skills. These methods can enhance the quality of internal education within organizations and strengthen employees' resilience against phishing threats.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- Through what means do mid-career office workers primarily acquire anti-phishing knowledge?Category: Cybersecurity and Privacy LiteracySimilar questionsarrow_forward
- How can formal training and informal learning be combined to improve employees' ability to respond to phishing threats?Category: Cybersecurity and Privacy LiteracySimilar questionsarrow_forward
- How effective is guerrilla learning (non-traditional learning approaches) in anti-phishing education?Category: Cybersecurity and Privacy LiteracySimilar questionsarrow_forward
Practical Problems
1- Mid-career professionals generally lack systematic anti-phishing training and are vulnerable to cyber threats.Category: Cybersecurity and Privacy LiteracySimilar questionsarrow_forward
- 80%
From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms
CHI '26· Privacy by Design & User Control +2
- 67%
"It's Confusing, Insecure, and Messy" – Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector
CHI '26· Privacy Perception & Decision-Making +2
- 67%
Why Johnny Checks but Doesn’t Alert: Reporting as the Missing Step in Verifiable Internet Voting
CHI '26· Privacy by Design & User Control +2
- 60%
Field Evidence of the Effects of Privacy, Data Transparency, and Pro-social Appeals on COVID-19 App Attractiveness
CHI '22· Privacy by Design & User Control +1
- 60%
Self-Efficacy and Security Behavior: Results from a Systematic Review of Research Methods
CHI '24· Privacy Perception & Decision-Making +1
- 60%
A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations
CHI '25· Passwords & Authentication +1
- 60%
Small Talk, Big Impact: The Role of Everyday Conversations in Cybersecurity Practices
CHI '26· Privacy Perception & Decision-Making +1
Based on Jaccard similarity of research subtopics & professions (≥60%)