<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>The impact of short-term memory on phishing detection ability and password behaviour</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Joakim Kävrestad</string-name>
          <email>joakim.kavrestad@ju.se</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Muhammad Abbas Khan Abbasi</string-name>
          <email>muhammad.abbas.khan.abbasi@his.se</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Márton Tarczal</string-name>
          <email>tarczal.marton@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marcus Nohlberg</string-name>
          <email>marcus.nohlberg@his.se</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>School of Engineering, Jönköping University</institution>
          ,
          <country country="SE">Sweden</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>School of Informatics, University of Skövde</institution>
          ,
          <country country="SE">Sweden</country>
        </aff>
      </contrib-group>
      <fpage>160</fpage>
      <lpage>173</lpage>
      <abstract>
        <p>Cybersecurity is a socio-technical discipline which is dependent on the interplay between users and devices, and the organizations where this interplay takes place. Previous research has shown that the interplay between users and devices is highly afected by the cognitive abilities of users. This is prominent in cybersecurity, which requires users to make security-aware decisions when, for instance, reading emails and decide which emails are legitimate and which emails constitute phishing. Research further suggests that decision-making is dependent on memory ability, which is the focus of this research. In this study, we investigate the impact of short-term memory on phishing detection ability and password behaviour. A web survey was used to collect quantitative data from a large sample of respondents. The survey was distributed on social media platforms and 93 participants completed the survey. The results indicate a positive correlation between short-term memory scores and both password detection ability and password behavior.</p>
      </abstract>
      <kwd-group>
        <kwd>cybersecurity</kwd>
        <kwd>behaviour</kwd>
        <kwd>memory</kwd>
        <kwd>phishing</kwd>
        <kwd>password</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        OECD describes that the world is becoming more digital at a rapid pace [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. As a natural
consequence, cybercrime continues to steadily increase [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Consequently, individuals and
organizations must find ways to protect themselves from cybercriminals. Such protection
involves both technical, organizational, and user-oriented methods, called controls. Technical
controls include firewalls and authentication procedures that control what devices and control
what users can and cannot do. Organizational controls include policies and strategies, and
user-oriented controls aim to support users towards secure behavior through, for instance,
training. The present research focuses on user-oriented cybersecurity, and the rationale is that
the current research reflects that user behavior is extensively exploited by cybercriminals [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ].
One example is phishing where an attacker attempts to trick users into doing something users
should not do using email. Phishing can be used to trick a user into installing ransomware,
CEUR
CEUR
Workshop
Proceedings
      </p>
      <p>ceur-ws.org
ISSN1613-0073
giving up sensitive information, etc. Another example is exploiting poor password habits to
gain access to a system. This can include, for example, guessing user passwords in hope that a
user selected a weak password.</p>
      <p>
        Cybersecurity can be seen as a sociotechnical system that is dependent on technology, users,
and the organization. As described by Mumford (2006), a socio-technical approach does not
only assume that a system consists of technology, users and an organization, but emphasizes
that the interplay between those entities is crucial for the success of the system [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. In the
context of cybersecurity, it is crucial to have a strategic plan, supported by relevant technology
and based on the needs of users and organizations. Consider, for instance, user authentication,
which is paramount to ensure that only authorized users can access digital resources [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. An
efective authentication system needs to ensure that users can access the resources they need
and nothing more, in a timely manner. This requires a strategic plan that outlines the resources
that should be made available and to what user groups. Then, technical measures to realize
the plan are needed. Finally, users should be educated on how and why to eficiently use the
system. For the system to be successful, all those parts must be aligned. Should the plan be too
vague, technical implementation becomes dificult. If the technical implementation is dificult
to use, the user will struggle to use it correctly [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Indeed, a socio-technical approach is argued
to lead to increased stakeholder value and user acceptance of technology [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        The management teams or IT departments are usually in charge of the technical and
organizational security aspects, while the users are expected to take on a large responsibility by
selecting secure passwords, avoiding phishing, etc. It is well-known that it is dificult to get
users to use tools, features, and procedures designed to ensure cybersecurity. Consequently, the
usability of such tools has been the focus of much research, and it is evident that the usability of
tools, features, and procedures is a factor that determines which tools and features users decide
to adopt or not [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref9">9, 10, 11, 12</xref>
        ]. Furthermore, recent studies describe cognitive workload and
fatigue as possible inhibitors of secure behavior [
        <xref ref-type="bibr" rid="ref13 ref14">13, 14</xref>
        ]. The rationale is that activities such
as password creation or phishing detection require reasoning, planning, memory, etc., which
demands cognitive resources from the user. When these resources are depleted, users’ ability to
engage in secure behavior is reduced [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>
        The purpose of the present study is to investigate how the ability of users to detect phishing
and adopt strong passwords is impacted by short-term memory capacity. Short-term memory
is, in this paper, defined as a persons ability to recall information recently presented to them.
Phishing and password, while only a subset of user responsibilities were selected in this research,
as they are exploited very frequently by cybercriminals [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Although diferent cognitive
functions have been discussed in the cybersecurity domain [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], this research is focused on
short-term memory. The rationale is that short-term memory has been found to influence
decision making, which is believed to be important for cybersecurity behavior [
        <xref ref-type="bibr" rid="ref17">17, 18</xref>
        ]. The
purpose of this research is to be an initial study on how cybersecurity behavior is impacted by
cognitive abilities.
      </p>
      <p>Data were obtained using an online survey that measured the participant’s ability to identify
phishing emails, password behavior, and short-term memory. The results indicate a positive
correlation between short-term memory scores and both phishing detection ability and password
behaviour. To the best of our knowledge, this is the first study that explicitly measures the
impact of short-term memory capacity on cybersecurity behavior. Although the sample size in
this study (n = 93) is a limitation, it is a first step that researchers can build on in continued
investigations into how cybersecurity behavior is afected by cognitive abilities.</p>
      <p>The next section will describe the research methodology used for this research. Then, the
results of the survey will be presented before they are discussed and concluded with suggestions
for future work.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Methodology</title>
      <p>With the purpose of collecting quantitative data from a large sample of respondents, a web-based
survey was used. The following section will, in turn, discuss the hypotheses developed in this
research, describe how the survey was developed and distributed, and how the collected data
were analyzed.</p>
      <sec id="sec-2-1">
        <title>2.1. Hypothesis development</title>
        <p>
          Recent research describes password behavior and phishing as two key areas of user behavior
with respect to cybersecurity [19, 20]. Industry reports provide a similar view, where phishing
is commonly discussed as the most common cyberattack [
          <xref ref-type="bibr" rid="ref16">16, 21, 22</xref>
          ]. Likewise, exploiting
weak passwords is a common practice used by attackers seeking to gain unauthorized access
to computer systems [23, 24]. Consequently, password behavior and phishing are two critical
areas of investigation.
        </p>
        <p>
          There are several previous studies which suggest that cognitive abilities have an impact on
cybersecurity behavior [
          <xref ref-type="bibr" rid="ref13 ref14">13, 14</xref>
          ]. Cognitive ability includes the ability of a person to reason,
plan, solve problems, etc. [25]. It also afects a person’s memory and ability to concentrate [ 26].
This research has chosen to focus on short-term memory with the motivation that it afects a
person’s memory [18].
        </p>
        <p>Given the justification above, two sets of hypotheses were developed. The first hypothesis
and corresponding null hypothesis are:</p>
        <p>H1: A person with higher memory ability will display a better ability to identify
phishing emails.</p>
        <p>H1null: Memory ability is not associated with the ability to detect phishing emails.
The second hypothesis and corresponding null hypothesis are:</p>
        <p>H2: A person with higher memory ability will display better password behavior.</p>
        <p>H2null: Memory ability is not associated with password behaviour.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Instrumentation</title>
        <p>A survey was developed for this research and consisted of four blocks of questions each
containing five questions:
• Block 1: Questions about the participants’ background.
• Block 2: Questions measuring the participants’ ability to identify phishing.
• Block 3: Questions measuring the participants’ password behavior.</p>
        <p>• Block 4: Question measuring the participants’ short-term memory.</p>
        <p>The questions in block one, which intended to introduce the survey with a few demographic
questions, appeared to the participants in a fixed order. Blocks two to four were presented in
ifxed order, but the question order within those blocks was randomized to minimize question
order bias [27].</p>
        <p>In block 2, each question displayed an email and the participants were asked to decide if it
was legitimate or phishing. The survey was designed so that participants could hover over
links to display link targets and interact with the email as they would in a webmail client.
An example is provided in Figure 1. All emails were phishing and the five phishing scenarios
included an email regarding a SWEDBANK transaction alert redirecting to a malicious link, a
Netflix account-related email with a malicious link, an iCloud account storage issue email with
a malicious link, the University finance ofice email regarding payment of a fee containing a
malicious attachment, and a Firefox account login alert with a malicious link. Te were selected
to represent phishing of medium dificulty.</p>
        <p>In Block 3, the questions were presented as account registration forms to the following five
websites:
• Citibank
• Google
• Instagram
• LinkedIn
• 7-eleven</p>
        <p>For each question, participants were asked to pick the password that was closest to the one
they would personally create for the website in question. An example question is provided in
Figure 2. The participants could choose from the following passwords:
• 1YellowCatCrossedTheRoad?
• aZtG@497$/#
• KYbeR1&amp;
• 1986March8!
• Password123!</p>
        <p>The first two passwords are considered secure in this research since they are suficiently long
and/or complex [28]. The other passwords are considered insecure because they are too short
or easy to guess.</p>
        <p>Block four intended to measure the participants’ short-term memory by presenting five
questions about what the participants had experienced during block 3. This approach mimics
a free recall test which is a popular measurement of explicit memory [29]. The survey was
developed by the research team and validated in a pilot test intending to ensure that participants
interpreted the survey in the intended way and that all participants interpreted the survey in the
same way [30]. During the pilot, nine participants were asked to do the survey monitored by a
member of the research team and asked to speak out their thoughts. The survey was updated
following insights from the pilot.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3. Execution</title>
        <p>The survey was anonymous and was preceded by an informed consent form. Ethical approval
was not necessary for this research according to Swedish regulations [31]. The online survey
platform Limesurvey was used to conduct the survey1.The survey was distributed using social
media platforms.</p>
      </sec>
      <sec id="sec-2-4">
        <title>2.4. Data Analysis</title>
        <p>The gathered data was analyzed using SPSS version 27. Responses to demographic questions
are presented to provide an overview of the data sample. The questions in blocks two to four
are used to create index variables that are used for further analysis. Each question had correct
and incorrect response options. Each participants index variable was computed as the number
of correct answers within each block.</p>
        <p>Index variables were used to test the established hypotheses using correlation tests.
Correlation tests measure the correlation between two variables and return a value between 1 and -1.
A positive value indicates a positive correlation, while a negative value indicates a negative
correlation [32]. Pearson’s rank correlation was used for variables with normal distribution, and
Spearman’s rho was used in other cases [32, 33]. Normality was assessed using the Shapiro-Wilk
test [34]. In this study, the conventional 5% significance level was used.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Results and Analysis</title>
      <p>A link to the survey was distributed on social media platforms and 93 participants completed
the survey. This section will provide an overview of the characteristics of the sample before
describing the responses to the questionnaire. It ends with testing of the established hypotheses.</p>
      <sec id="sec-3-1">
        <title>3.1. Sample characteristics</title>
        <p>Out of the 93 respondents 45 identified as female while 48 identified as male. 53 respondents
lived in Pakistan, 21 lived in Sweden, and the remaining 19 were spread between another ten
countries. As seen in Table 1, the age distribution in the sample is skewed toward younger
adults with only a handful of respondents over the age of 45.</p>
        <p>Participants were asked to rate their own IT competence by selecting one of four levels of
competence. Most of the participants rate themselves as good IT users, as seen in Table 2 which
also presents the description of the levels as presented to the participants.</p>
        <p>Skill level
Below Average user - I always have problems with IT, and always seek
help from someone in IT matters
Average user - I often have problems with IT, and feel that I need help
with things that others can do on their own
Expert user - I use IT without any larger problems, but need help
timeto-time
Professional - Works within, has a degree within, or studies within IT</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Descriptives</title>
        <p>Following the demographic questions, the participants received five emails and asked if the email
was legitimate or not. The five phishing scenarios included an email regarding a SWEDBANK
transaction alert redirecting to a malicious link, a Netflix account-related email with a malicious
link, an iCloud account storage issue email with a malicious link, the University finance ofice
email regarding payment of a fee containing a malicious attachment, and a Firefox account
login alert with a malicious link. Table 3 shows how many participants who correctly identified
each email as phishing.</p>
        <p>Furthermore, an index variable reflecting how many correct answers each participant had
was computed. As seen in Figure 3, only 10 (11%) participants correctly classified all emails as
phishing, and the median result was two correct responses.</p>
        <p>The participants were then presented with diferent account registration pages and asked
to pick which password, out of five provided examples, most closely resembled one that they
would choose for a new account on the website in question. Two passwords were considered
strong and three were considered weak. Table 4 lists the included websites and the number of
participants who selected one of the strong passwords for each website.</p>
        <p>An index variable was created and reflects the number of secure passwords each participant
selected. The median value was 2 and, as shown in Figure 4, the data demonstrate that a large
number of participants selected only good (n=19(20%)), or only bad (n=26(31%)). However,
48 (52%) participants selected diferent passwords for diferent sites, suggesting that they are
selecting passwords based on how important they think it is to keep the respective accounts
secure.</p>
        <p>Finally, participants were asked five questions about the previous questions in the survey.
The purpose of these questions was to see how much of the survey the participants remembered.
The number of correct responses was collected in an index variable that is the measure of the
short-term memory of the participants used in the remaining analysis. An overview of the
results is presented in Figure 5.</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Hypothesis testing</title>
        <p>The last step in the analysis was to test the hypotheses previously developed to test for
correlations between short-term memory and the ability to identify phishing and password behavior.
The index variables were subjected to Shapiro-Wilks normality test, which suggested that the
data do not follow a normal distribution. Consequently, Pearson’s rank correlation was not
appropriate to use and Spearman’s rho was used instead.</p>
        <p>The correlation between short-term memory and the ability to identify phishing was first
tested. Spearman’s rho returned a correlation coeficient of .238, and a p-value of .022. Thus,
the tests show a statistically significant correlation between the variables and the following
hypothesis is supported by the data:</p>
        <p>H1: A person with higher memory ability will display a better ability to identify
phishing emails.</p>
        <p>The correlation between short-term memory and password behavior was then tested.
Spearman’s rho returned a correlation coeficient of .207, and a p-value of .046. Thus, the tests show
a statistically significant correlation between the variables and the following hypothesis is
supported by the data:</p>
        <p>H2: A person with higher memory ability will display better password behavior</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions and Future Work</title>
      <p>This research aimed to investigate whether the ability of users to detect phishing and adopt
strong passwords is impacted by short-term memory capacity. Data was collected using an
online survey, and subjected to statistical analysis that showed a correlation between the ability
of users to detect phishing and short-term memory capacity as well as password behavior
and short-term memory. It could be seen that the correlation coeficients, while significant,
were around 0.2 which signifies quite weak correlations [ 32]. In light of previous research, this
is quite unsurprising. Both phishing detection ability and password behavior are afected by
numerous factors such as previous training [35], the use of other security functions [36], and risk
perception [37]. However, this research suggests that short-term memory is a predictor of the
ability to identify phishing and password behavior. This information can, for example, be useful
in developing tailored cybersecurity awareness eforts and policies. For instance, care could be
taken to evaluate policies from a memory-requirement perspective. One could perhaps limit
how password behavior is impacted by memory by allowing for passphrases without complexity
requirements or implement multi-factor authentication and allow for simpler password. Such
an approach has been suggested to improve users password behaviour in previous research
[38].</p>
      <p>In addition to the results discussed in the previous paragraph, this paper provides data about
users’ ability to detect phishing and password behavior. Looking at the participants’ ability to
detect phishing, presented in Figure 1, it can be seen that only ten out of 93 participants correctly
classified the five emails presented as phishing. In fact, the mean result was two correctly
identified phishing emails out of five, which means that the median participant was tricked in
three out of five attempts. Consequently, this paper adds to the existing body of research which
states that users struggle to correctly identify phishing [39]. A possible limitation, however, of
the study design is that the participants are presented with constructed phishing emails rather
than faced with actual phishing attempts as part of their daily life. In a real life situation, it
is likely that a lot of phishing is simply not relevant to the recipient and therefore discarded
as spam. In example, a user who is not a LinkedIn user would not be likely to be tricked by a
LinkedIn related phishing attempt. The results of this research reflects the participants ability
to detect phishing when forced to do that for every email included in the study and should be
interpreted as such.</p>
      <p>The common approach to phishing detection has historically been training and awareness
[40]. Training does, however, only focus on improving one socio-technical dimension, the
user. A socio-technical approach to phishing detection should perhaps also consider how
organizational and technical aspects can be changed to help users detect phishing, possibly
with better results. Organizational culture has, fro instance, been associated with cybersecurity
behaviour in the past [41]. The results regarding password behavior suggest that there are three
groups of users; one group that always creates strong passwords, one group that never creates
strong passwords, and one group that uses diferent levels of password strength for diferent
accounts.</p>
      <p>The purpose of this research was to be a first step in the investigation of how user cognitive
abilities impact cybersecurity behavior. The main limitation in this work comes from the data
sample, which was acquired using social media and was of a limited size (93 participants), and
the results should be interpreted with this in mind. The rationale for this sampling method
was that sampling using social media is easy and cost eficient. Nevertheless, the results in this
research motivate further research in the area. Such research could be survey-based and then
include larger samples gathered using non-probability sampling techniques. Future research
could also look at other aspects of cybersecurity behavior and / or other cognitive abilities.
efect of working memory load on decision-making, Journal of Cognitive Psychology 27
(2015) 27–36.
[18] J. A. Dykstra, S. R. Orr, Acting in the unknown: the cynefin framework for managing
cybersecurity risk in dynamic decision making, in: 2016 International Conference on
Cyber Conflict (CyCon US), IEEE, 2016, pp. 1–6.
[19] A. A. Moustafa, A. Bello, A. Maurushat, The role of user behaviour in improving cyber
security management, Frontiers in Psychology 12 (2021) 561011.
[20] F. B. Fatokun, Z. A. Long, S. Hamid, J. O. Fatokun, C. I. Eke, A. Norman, Gamifying
cybersecurity knowledge to promote good cybersecurity behaviour, Journal of Computing
Technologies and Creative Content (JTec) 7 (2022) 25–34.
[21] techopedia, 50+ Cybersecurity Statistics for 2023 You Need to Know – Where, Who What
is Targeted, 2023. URL: https://www.techopedia.com/cybersecurity-statistics.
[22] CompTIA, Top 50 Cybersecurity Statistics, Figures and Facts, 2023. URL: https://connect.</p>
      <p>comptia.org/blog/cyber-security-stats-facts.
[23] D. O. Dastane, The efect of bad password habits on personal data breach, International</p>
      <p>Journal of Emerging Trends in Engineering Research 8 (2020).
[24] onelogin, Six Types of Password Attacks How to Stop Them, 2023. URL: https://www.</p>
      <p>onelogin.com/learn/6-types-password-attacks.
[25] M. Karwowski, J. C. Kaufman, The creative self: Efect of beliefs, self-eficacy, mindset,
and identity, Academic Press, 2017.
[26] K. Oberauer, H.-M. Süß, R. Schulze, O. Wilhelm, W. W. Wittmann, Working memory
capacity—facets of a cognitive ability construct, Personality and individual diferences 29
(2000) 1017–1045.
[27] D. J. Mingay, M. T. Greenwell, Memory bias and response-order efects, Journal of Oficial</p>
      <p>Statistics 5 (1989) 253–263.
[28] L. A. Loos, M. E. Crosby, Cognition and predictors of password selection and usability, in:
Augmented Cognition: Users and Contexts: 12th International Conference, AC 2018, Held
as Part of HCI International 2018, Las Vegas, NV, USA, July 15-20, 2018, Proceedings, Part
II, Springer, 2018, pp. 117–132.
[29] H. L. Roediger, J. D. Karpicke, Learning and memory, in: K. Kempf-Leonard (Ed.),
Encyclopedia of Social Measurement, Elsevier, New York, 2005, pp. 479–486. URL: https:
//www.sciencedirect.com/science/article/pii/B0123693985005405. doi:https://doi.org/
10.1016/B0- 12- 369398- 5/00540- 5.
[30] N. H. Chowdhury, M. T. Adam, G. Skinner, The impact of time pressure on cybersecurity
behaviour: a systematic literature review, Behaviour &amp; Information Technology 38 (2019)
1290–1308.
[31] S. R. Council, Good Research Practice, 2017. URL: https://www.vr.se/english/analysis/
reports/our-reports/2017-08-31-good-research-practice.html.
[32] H. Akoglu, User’s guide to correlation coeficients, Turkish journal of emergency medicine
18 (2018) 91–93.
[33] M.-T. Puth, M. Neuhäuser, G. D. Ruxton, Efective use of spearman’s and kendall’s
correlation coeficients for association between two measured traits, Animal Behaviour 102
(2015) 77–84. URL: https://www.sciencedirect.com/science/article/pii/S0003347215000196.
doi:https://doi.org/10.1016/j.anbehav.2015.01.010.
[34] K. R. Das, A. Imon, A brief review of tests for normality, American Journal of Theoretical
and Applied Statistics 5 (2016) 5–12.
[35] K. Singh, P. Aggarwal, P. Rajivan, C. Gonzalez, Training to detect phishing emails: Efects
of the frequency of experienced phishing emails, in: Proceedings of the human factors and
ergonomics society annual meeting, volume 63, SAGE Publications Sage CA: Los Angeles,
CA, 2019, pp. 453–457.
[36] J. Kävrestad, J. Zaxmy, M. Nohlberg, Analyzing the usage of character groups and keyboard
patterns in password creation, Information &amp; Computer Security (2020).
[37] K. Parsons, A. McCormac, M. Butavicius, L. Ferguson, Human factors and information
security: individual, culture and security environment, Technical Report, 2010.
[38] J. Kävrestad, M. Lennartsson, M. Birath, M. Nohlberg, Constructing secure and memorable
passwords, Information &amp; Computer Security 28 (2020) 701–717.
[39] M. Alsharnouby, F. Alaca, S. Chiasson, Why phishing still works: User strategies for
combating phishing attacks, International Journal of Human-Computer Studies 82 (2015)
69–82.
[40] B. Reinheimer, L. Aldag, P. Mayer, M. Mossano, R. Duezguen, B. Lofthouse, T. Von
Landesberger, M. Volkamer, An investigation of phishing awareness and education over time:
When and how to best remind users, in: Sixteenth Symposium on Usable Privacy and
Security (SOUPS 2020), 2020, pp. 259–284.
[41] G. Bansal, Got phished! role of top management support in creating phishing safe
organizations, MWAIS 2018 Proceedings 6 (2018).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>OECD</surname>
          </string-name>
          , Hows Life in the Digital Age?,
          <year>2019</year>
          . URL: https://www.oecd-ilibrary.org/content/ publication/9789264311800-en.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <source>[2] CyberEdge, 10th annual Cyberthreat Defense Report</source>
          ,
          <year>2023</year>
          . URL: https://cyber-edge.com/ cdr/.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.</given-names>
            <surname>Chaudhary</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Gkioulos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Katsikas</surname>
          </string-name>
          ,
          <article-title>Developing metrics to assess the efectiveness of cybersecurity awareness program</article-title>
          ,
          <source>Journal of Cybersecurity</source>
          <volume>8</volume>
          (
          <year>2022</year>
          )
          <article-title>tyac006</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Zwilling</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Klien</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Lesjak</surname>
          </string-name>
          , Ł. Wiechetek,
          <string-name>
            <given-names>F.</given-names>
            <surname>Cetin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. N.</given-names>
            <surname>Basim</surname>
          </string-name>
          ,
          <article-title>Cyber security awareness, knowledge and behavior: A comparative study</article-title>
          ,
          <source>Journal of Computer Information Systems</source>
          <volume>62</volume>
          (
          <year>2022</year>
          )
          <fpage>82</fpage>
          -
          <lpage>97</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>E. Mumford,</surname>
          </string-name>
          <article-title>The story of socio-technical design: Reflections on its successes, failures and potential</article-title>
          ,
          <source>Information systems journal 16</source>
          (
          <year>2006</year>
          )
          <fpage>317</fpage>
          -
          <lpage>342</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>C. P.</given-names>
            <surname>Pfleeger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. L.</given-names>
            <surname>Pfleeger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Margulies</surname>
          </string-name>
          , Security in computing, fith edition ed.,
          <string-name>
            <surname>Prentice</surname>
            <given-names>Hall</given-names>
          </string-name>
          , Upper Saddle River, NJ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. L.</given-names>
            <surname>Durity</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Huh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <article-title>Designing password policies for strength and usability</article-title>
          ,
          <source>ACM Transactions on Information and System Security (TISSEC) 18</source>
          (
          <year>2016</year>
          )
          <fpage>1</fpage>
          -
          <lpage>34</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>G.</given-names>
            <surname>Baxter</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Sommerville</surname>
          </string-name>
          ,
          <article-title>Socio-technical systems: From design methods to systems engineering, Interacting with computers 23 (</article-title>
          <year>2011</year>
          )
          <fpage>4</fpage>
          -
          <lpage>17</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>R.</given-names>
            <surname>Bhagavatula</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Iacovino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Kywe</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Savvides</surname>
          </string-name>
          ,
          <article-title>Biometric authentication on iphone and android: Usability, perceptions, and influences on adoption</article-title>
          .,
          <source>in: USEC'15: Workshop on Usable Security</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Whitten</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Tygar</surname>
          </string-name>
          ,
          <article-title>Why johnny can't encrypt: A usability evaluation of pgp 5.0</article-title>
          ., in: USENIX Security Symposium, volume
          <volume>348</volume>
          ,
          <year>1999</year>
          , pp.
          <fpage>169</fpage>
          -
          <lpage>184</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>B.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Sadeh</surname>
          </string-name>
          ,
          <article-title>Reconciling mobile app privacy and usability on smartphones: Could user privacy profiles help?</article-title>
          ,
          <source>in: Proceedings of the 23rd international conference on World wide web</source>
          ,
          <year>2014</year>
          , pp.
          <fpage>201</fpage>
          -
          <lpage>212</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>K. M. Ramokapane</surname>
            ,
            <given-names>A. C.</given-names>
          </string-name>
          <string-name>
            <surname>Mazeli</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Rashid</surname>
          </string-name>
          , Skip, skip, skip, accept!!
          <article-title>!: A study on the usability of smartphone manufacturer provided default features and user privacy</article-title>
          ,
          <source>Proceedings on Privacy Enhancing Technologies</source>
          <year>2019</year>
          (
          <year>2019</year>
          )
          <fpage>209</fpage>
          -
          <lpage>227</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>R.</given-names>
            <surname>Gutzwiller</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dykstra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Payne</surname>
          </string-name>
          ,
          <article-title>Gaps and opportunities in situational awareness for cybersecurity</article-title>
          ,
          <source>Digital Threats: Research and Practice</source>
          <volume>1</volume>
          (
          <year>2020</year>
          )
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Reeves</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Delfabbro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Calic</surname>
          </string-name>
          ,
          <article-title>Encouraging employee engagement with cybersecurity: How to tackle cyber fatigue</article-title>
          ,
          <source>SAGE Open 11</source>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>A.-M. Horcher</surname>
            ,
            <given-names>G. P.</given-names>
          </string-name>
          <string-name>
            <surname>Tejay</surname>
          </string-name>
          ,
          <article-title>Building a better password: The role of cognitive load in information security training</article-title>
          ,
          <source>in: 2009 IEEE International Conference on Intelligence and Security Informatics</source>
          , IEEE,
          <year>2009</year>
          , pp.
          <fpage>113</fpage>
          -
          <lpage>118</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sfakianakis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Douligeris</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Marinos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lourenço</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Raghimi</surname>
          </string-name>
          ,
          <source>ENISA Threat Landscape Report</source>
          <year>2018</year>
          : 15
          <string-name>
            <given-names>Top</given-names>
            <surname>Cyberthreats</surname>
          </string-name>
          and Trends,
          <string-name>
            <surname>ENISA</surname>
          </string-name>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>M. R.</given-names>
            <surname>Hatfield-Eldred</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. L.</given-names>
            <surname>Skeel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. P.</given-names>
            <surname>Reilly</surname>
          </string-name>
          ,
          <article-title>Is it random or impulsive responding? the</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>