What Motivates and Discourages Employees in Phishing Interventions: An Exploration of Expectancy-Value Theory

Xiaowei Chen, Sophie Doublet, Anastasia Sergeeva, Gabriele Lenzini, Vincent Koenig, Verena Distler

Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference article in proceedingsScientificvertaisarvioitu

Abstrakti

Organizations adopt a combination of measures to defend against phishing attacks that pass through technical filters. However, employees' engagement with these countermeasures often does not meet security experts' expectations. To explore what motivates and discourages employees from engaging with user-oriented phishing interventions, we conducted seven focus groups with 34 employees at a European university, applying the Expectancy-Value Theory. Our study revealed a spectrum of factors influencing employees' engagement. The perceived value of phishing interventions influences employees' participation. Although the expectation of mitigation and fear of consequences can motivate employees, lack of feedback and communication, worries, and privacy concerns discourage them from reporting phishing emails. We found that the expectancy-value framework provides a unique lens for explaining how organizational culture, social roles, and the influence of colleagues and supervisors foster proactive responses to phishing attacks. We documented a range of improvements proposed by employees to phishing interventions. Our findings underscore the importance of enhancing utility value, prioritizing positive user experiences, and nurturing employees' motivations to engage them with phishing interventions.
AlkuperäiskieliEnglanti
OtsikkoProceedings of the Twentieth Symposium on Usable Privacy and Security (SOUPS 2024)
KustantajaUSENIX -The Advanced Computing Systems Association
Sivut487-506
ISBN (painettu)978-1-939133-42-7
TilaJulkaistu - 2024
OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
TapahtumaSymposium on Usable Privacy and Security - Philadelphia, Yhdysvallat
Kesto: 11 elok. 202414 elok. 2024
Konferenssinumero: 20

Conference

ConferenceSymposium on Usable Privacy and Security
Maa/AlueYhdysvallat
KaupunkiPhiladelphia
Ajanjakso11/08/202414/08/2024

Sormenjälki

Sukella tutkimusaiheisiin 'What Motivates and Discourages Employees in Phishing Interventions: An Exploration of Expectancy-Value Theory'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

Siteeraa tätä