Mid Sweden University

miun.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Investigating Factors influencing Phishing Susceptibility Within an Organisation: An exploratory study on the individual, organisational and technological factors that drive risky behaviours in phishing email responses.
Mid Sweden University, Faculty of Science, Technology and Media, Department of Communication, Quality Management, and Information Systems (2023-).
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Certain individuals, despite working at the same organisation and having been exposed to the same training, are found through longitudinal phishing simulations to continuously click on, and fail to report, phishing emails. This study attempts to investigate the factors that contribute to phishing susceptibility and non-reporting within an organisation, including understanding the barriers to reporting. 14 participants were identified from one year of phishing simulation data and were selected based on either exhibiting ideal or non-ideal reporting behaviours. Participants performed an email identification task as well as a semi-structured follow-up interview. A grounded theory approach was leveraged to identify five key themes that may indicate phishing susceptibility: reportingawareness, technological capabilities, organisational factors, message processing, and cognitive factors. Findings indicate that employees who are on external contracts as well as have shorter tenures are likely to be more susceptible to phishing, primarily due to a lack of awareness of appropriate reporting processes. Further, participants were found to be unaware of methods on how to leverage message cues, such as the “link hover” function. This indicates the need for consistent education within an organisation pertaining to these topics. 

Place, publisher, year, edition, pages
2025. , p. 50
Keywords [en]
Phishing attacks; phishing susceptibility; human risk management; reporting; information security awareness; theory of planned behavior (TPB); grounded theory
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:miun:diva-55532OAI: oai:DiVA.org:miun-55532DiVA, id: diva2:1997794
Subject / course
Computer Science IF1
Supervisors
Examiners
Available from: 2025-09-15 Created: 2025-09-15 Last updated: 2025-09-25Bibliographically approved

Open Access in DiVA

No full text in DiVA

Search in DiVA

By author/editor
Fabreschi, Olivia
By organisation
Department of Communication, Quality Management, and Information Systems (2023-)
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 38 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf