Impact of information security training on recognition of phishing attacks: a case study of Vilnius Gediminas Technical University

1Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Phishing attack is a type of social engineering attack and often used as the initial stage of a larger campaign. It is dangerous as users might inadvertently reveal to the attackers personal data or sensitive corporate information. Therefore, inability to recognize and properly react to phishing attacks must be treated as one of the main security risks in the enterprise. In this paper, we present a methodology for evaluating employees' resistance to phishing attacks. We also analyze the changes to the situation after the employees participated in information security training. Experiments with employees of Vilnius Gediminas Technical University were carried out within a period of one year to gather information on how credulous they are to phishing attacks before and after security training. Results of the experiment reveal the benefit of security training, however there is still room for improvement and need to pay attention in the future.

Cite

CITATION STYLE

APA

Rastenis, J., Ramanauskaitė, S., Janulevičius, J., & Čenys, A. (2020). Impact of information security training on recognition of phishing attacks: a case study of Vilnius Gediminas Technical University. In Communications in Computer and Information Science (Vol. 1243 CCIS, pp. 311–324). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-57672-1_23

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free