The Influence of Human Factors on the Intention to Report Phishing Emails

Cybersecurity Training & AwarenessOnline Harassment & Counter-ToolsCybersecurity EngineersContent Governance & Platform Compliance Teams

Title of the Paper

The Influence of Human Factors on the Intention to Report Phishing Emails

Bibliographic Information

  • Subject Area: Cybersecurity behavior and phishing email reporting behavior
  • Keywords: Information security, human behavior, cybersecurity, organizational culture, phishing email reporting

Research Background and Problem

  • Identified Problem: Phishing attacks are a major cybersecurity threat, and the importance of reporting such attacks is increasing. However, the reporting rate remains low (typically below 10%). While existing studies have identified some human factors influencing phishing email reporting behavior, they lack a systematic and comprehensive theoretical framework.
  • Significance: Reporting phishing emails can serve as a rapid, crowd-sourced defense mechanism, helping to mitigate the damage caused by phishing attacks. Understanding human factors enables organizations to better design training programs and enhance employees' cybersecurity awareness.
  • Motivation and Related Work: Previous research has primarily focused on general cybersecurity behaviors or the negative impacts of such behaviors on organizations, with limited attention to specific phishing email reporting behaviors and the human factors influencing them. This paper aims to address this gap by integrating existing theories.

Solution

  • Proposed Approach: The authors developed a unified theoretical model to describe how human factors influence employees' phishing email reporting behavior. An empirical study was conducted using an online survey (n=284).
  • Innovations:
    • Established a comprehensive framework that includes both individual-level and organizational-level factors.
    • Combined OCBO (Organizational Citizenship Behavior toward the Organization), OCBI (Organizational Citizenship Behavior toward Individuals), personality traits (e.g., the "Big Five"), and beliefs for the first time.
    • Explored the differential impacts of human factors on general cybersecurity behavior versus specific email reporting behavior.
  • Implementation Steps:
    1. Identified influencing factors and theoretical frameworks through literature review.
    2. Formulated hypotheses and developed a unified model.
    3. Designed an online survey, collected participant data, and assessed their intentions to report phishing emails.
    4. Analyzed the data using linear regression models to validate the hypotheses.

Research Findings

  • Key Findings:
    • Self-efficacy, subjective norms, and altruism were significantly associated with phishing email reporting intentions.
    • Sportsmanship was negatively correlated with reporting intentions, suggesting that individuals with high sportsmanship might not perceive phishing emails as a serious issue.
    • Positive cybersecurity behaviors strongly supported phishing email reporting intentions, but certain personality traits, such as extraversion, had a greater influence on general cybersecurity behaviors rather than specific reporting behaviors.
  • Advantages Compared to Existing Solutions: By integrating human factors from both individual and organizational domains, the study proposed a more comprehensive theoretical framework, offering more detailed guidance for improving phishing email reporting rates.
  • Experimental or Evaluation Results: The model and hypotheses were validated using survey data and statistical methods. The adjusted R² values indicated that the model effectively explained the primary drivers of reporting intentions.
  • Limitations and Future Directions:
    • Limitations: The results were based on measuring intentions rather than actual reporting behavior; the sample was limited to the U.S. and skewed toward highly experienced users.
    • Future Directions: Expand the study to include more diverse demographic and cultural factors; explore how negative cybersecurity behaviors counteract reporting intentions.

Practical Implications

  • For Designing Training and Awareness Programs:
    • Focus on enhancing employees' self-efficacy, such as by demonstrating the reporting process to reduce uncertainty.
    • Emphasize altruism and team protection as core motivations for reporting to increase employee engagement.
    • For individuals with high sportsmanship, highlight the positive impact of reporting behavior, such as how it contributes to the organization's overall security improvement.
  • Organizational Culture Development:
    • Promote a sense of responsibility and teamwork as part of the organizational culture to encourage employees to proactively identify and report security threats.
    • Establish feedback mechanisms to show reporters the positive outcomes of their actions, thereby enhancing intrinsic motivation.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96363/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580985
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Cybersecurity Training & Awareness, Online Harassment & Counter-Tools
work
Professions
Cybersecurity Engineers, Content Governance & Platform Compliance Teams
article
Content Status
Full text indexed
hub
Related Papers
0 related papers