Phish Derby: Shoring the Human Shield Through Gamified Phishing Attacks

被引:10
作者
Canham, Matthew [1 ]
Posey, Clay [2 ]
Constantino, Michael [3 ]
机构
[1] Beyond Layer Seven LLC, Oviedo, FL 32765 USA
[2] Brigham Young Univ, Marriott Sch Business, Informat Syst, Provo, UT 84602 USA
[3] Univ Cent Florida, Informat Secur Off, Orlando, FL 32816 USA
关键词
phishing; cybersecurity awareness training; gamification; NIST phish scale; protective stewards; repeat clickers; GOAL ORIENTATION; INDIVIDUAL-DIFFERENCES; GAMIFICATION; PERSONALITY; PERFORMANCE; MOTIVATION; TAXONOMY; IMPACT; MODEL;
D O I
10.3389/feduc.2021.807277
中图分类号
G40 [教育学];
学科分类号
040101 ; 120403 ;
摘要
To better understand employees' reporting behaviors in relation to phishing emails, we gamified the phishing security awareness training process by creating and conducting a month-long "Phish Derby" competition at a large university in the U.S. The university's Information Security Office challenged employees to prove they could detect phishing emails as part of the simulated phishing program currently in place. Employees volunteered to compete for prizes during this special event and were instructed to report suspicious emails as potential phishing attacks. Prior to the beginning of the competition, we collected demographics and data related to the concepts central to two theoretical foundations: the Big Five personality traits and goal orientation theory. We found several notable relationships between demographic variables and Phish Derby performance, which was operationalized from the number of phishing attacks reported and employee report speed. Several key findings emerged, including past performance on simulated phishing campaigns positively predicted Phish Derby performance; older participants performed better than their younger colleagues, but more educated participants performed poorer; and individuals who used a mix of PCs and Macs at work performed worse than those using a single platform. We also found that two of the Big Five personality dimensions, extraversion and agreeableness, were both associated with poorer performance in phishing detection and reporting. Likewise, individuals who were driven to perform well in the Phish Derby because they desired to learn from the experience (i.e., learning goal orientation) performed at a lower level than those driven by other goals. Interestingly, self-reported levels of computer skill and the perceived ability to detect phishing messages failed to exhibit a significant relationship with Phish Derby performance. We discuss these findings and describe how focusing on motivating the good in employee cyber behaviors is a necessary yet too often overlooked component in organizations whose training cyber cultures are rooted in employee click rates alone.
引用
收藏
页数:10
相关论文
共 55 条
  • [1] The impact of individual differences on influence strategies
    Alkis, Nurcan
    Temizel, Tugba Taskaya
    [J]. PERSONALITY AND INDIVIDUAL DIFFERENCES, 2015, 87 : 147 - 152
  • [2] Anawar S, 2019, J ENG SCI TECHNOL, V14, P2865
  • [3] Baxter R.J., 2017, Journal of Forensic Accounting Research, V10, P1, DOI [DOI 10.2308/JFAR-51725, 10.2308/jfar-51725]
  • [4] If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security
    Boss, Scott R.
    Kirsch, Laurie J.
    Angermeier, Ingo
    Shingler, Raymond A.
    Boss, R. Wayne
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (02) : 151 - 164
  • [5] Goal orientation and goal content as predictors of performance in a training program
    Brett, JF
    VandeWalle, D
    [J]. JOURNAL OF APPLIED PSYCHOLOGY, 1999, 84 (06) : 863 - 873
  • [6] The Adaptive Roles of Positive and Negative Emotions in Organizational Insiders' Security-Based Precaution Taking
    Burns, A. J.
    Roberts, Tom L.
    Posey, Clay
    Lowry, Paul Benjamin
    [J]. INFORMATION SYSTEMS RESEARCH, 2019, 30 (04) : 1228 - 1247
  • [7] Phishing for Long Tails: Examining Organizational Repeat Clickers and Protective Stewards
    Canham, Matthew
    Posey, Clay
    Strickland, Delainey
    Constantino, Michael
    [J]. SAGE OPEN, 2021, 11 (01):
  • [8] Going Spear Phishing: Exploring Embedded Training and Awareness
    Caputo, Deanna D.
    Pfleeger, Shari Lawrence
    Freeman, Jesse D.
    Johnson, M. Eric
    [J]. IEEE SECURITY & PRIVACY, 2014, 12 (01) : 28 - 38
  • [9] Intrinsic Motivation, Performance, and the Mediating Role of Mastery Goal Orientation: A Test of Self-Determination Theory
    Cerasoli, Christopher P.
    Ford, Michael T.
    [J]. JOURNAL OF PSYCHOLOGY, 2014, 148 (03) : 267 - 286
  • [10] CheckPoint, 2021, BIGG CYB SEC CHALL 2