Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices

Privacy Perception & Decision-MakingCybersecurity Training & AwarenessGovernment Officials & Civil ServantsPrivacy Policy Makers

Document Title

Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees’ Current Practices

Document Information

  • Subject Area: Anti-phishing education and learning in workplace environments
  • Keywords: phishing, anti-phishing training, informal learning, distributed learning, organizational security, human factors, workplace cybersecurity, qualitative research, IT departments, work environments

Research Background and Issues

  • Identified Problems or Challenges: Among mid-career administrative office workers at two universities in the United States, less than 21% of participants had received formal anti-phishing training. Their primary knowledge sources were informal channels, such as social media and news stories. Many existing anti-phishing education methods fail to meet user needs and do not effectively enhance employees' ability to respond to phishing threats comprehensively.
  • Significance: Phishing has become a growing global cybersecurity threat, with 91% of cyberattacks originating from phishing attempts. Strengthening employees' ability to identify and respond to phishing is crucial for improving organizational cybersecurity capabilities.
  • Research Motivation and Related Work: Current research predominantly focuses on technical solutions and automated tools, with limited user-centered studies on how employees acquire and learn phishing-related knowledge. The motivation for this study is to explore the integration of informal learning models with workplace education to better address this threat.

Solution

  • Proposed Solution:
    1. Combine formal training with informal learning to design distributed learning pathways tailored to users' current practices and needs.
    2. Utilize a "guerrilla learning" approach, leveraging distributed educational resources and unexpected learning moments to increase the dissemination of anti-phishing knowledge and user engagement.
    3. Provide customized recommendations and deliver high-quality educational content in diverse formats, including news stories, podcasts, and social media.
  • Innovative Aspects:
    • Integration of formal and informal learning channels, capitalizing on non-traditional educational spaces that users encounter daily.
    • Drawing on the concept of guerrilla learning in education to spark user interest and reflection through unexpected methods, while encouraging active dialogue around educational content.
  • Implementation Steps and Key Techniques: Based on participants' learning behaviors, strategies were proposed to improve anti-phishing education, including sending timely reminders, promoting diverse learning resources (e.g., podcasts, social media), designing intuitive user guides, and enhancing workplace training interactions.

Research Outcomes

  • Specific Findings:
    1. The study revealed that mid-career office workers primarily learn about phishing through informal channels and most expressed a desire for more systematic training.
    2. An anti-phishing education method based on guerrilla learning principles was proposed to help organizations design more employee-friendly anti-phishing strategies.
  • Advantages of Existing Solutions:
    • Tailored educational content for non-cybersecurity expert users, effectively complementing existing formal training.
    • Enhancing the appeal of learning materials, such as using storytelling and case studies to engage employees.
  • Experimental or Evaluation Results: Among the 24 participants in the study, there was widespread positive feedback regarding diverse and distributed learning opportunities, emphasizing the importance and challenges of informal learning.
  • Limitations and Future Directions:
    • Limitations: The study focused on employees at two universities in the United States, with a small sample size that may not fully reflect the perspectives and needs of users in other industries and regions.
    • Future Directions:
      1. Conduct large-scale surveys to validate the effectiveness of anti-phishing education methods for different user groups.
      2. Explore ways to optimize the accuracy of informal learning content and expand dissemination through broader media channels.

Conclusion and Recommendations

This study highlights the importance of a hybrid approach that combines formal and informal learning to improve employees' awareness and response capabilities regarding phishing threats. Four specific implementation recommendations for organizations are proposed: balancing the distribution of unexpected and routine information, sending timely reminders, diversifying learning resource formats, and fostering users' fundamental anti-phishing skills. These methods can enhance the quality of internal education within organizations and strengthen employees' resilience against phishing threats.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/95884/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580650
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
Privacy Perception & Decision-Making, Cybersecurity Training & Awareness
work
Professions
Government Officials & Civil Servants, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
7 related papers