This study emulated unscheduled phishing e-mails over a long period of time by imitating the manner in which external hackers attacked a group of employees in a company. We then measured and analyzed the recipient's ability to identify and respond to phishing e-mails as training progressed. In addition, we analyzed the changes in participants' response behavior when changing the external control condition between the training. As a result of the analysis, it was confirmed that the training duration had a positive (+) relationship with the employees' ability to identify phishing e-mails and the infection rate, and more employees read emails and infected with phishing attacks using social issues and seasonal events. It was also confirmed that reinforcement of internal control policy on infected persons affects positively (+) on the phishing attack response behavior of employees. Based on these results, we would like to suggest the right training method for each organization to enhance the ability of employees to cope with phishing attacks.
CITATION STYLE
Yoon, D., Lee, K., & Lim, J. (2017). A Study on the Change of Capability and Behavior against Phishing Attack by Continuous Practical Simulation Training. Journal of the Korea Institute of Information Security and Cryptology, 27(2), 267–279. https://doi.org/10.13089/jkiisc.2017.27.2.267
Mendeley helps you to discover research relevant for your work.