Cybersecurity Training Programs Fail to Prevent Phishing Scams: Study

A recent study conducted on the University of California San Diego Health campus found that cybersecurity training programs, including mandated annual training and embedded phishing exercises, do not significantly reduce the risk of employees falling for phishing scams. The study evaluated the effectiveness of two types of training during an eight-month, randomized controlled experiment involving 19,500 employees. The research team sent 10 different phishing email campaigns and found that there was no significant relationship between recent completion of cybersecurity training and the likelihood of falling for phishing emails. Embedded phishing training only reduced the likelihood of clicking on a phishing link by 2%.

Key Takeaways:

  • The study involved 19,500 employees at UC San Diego Health and sent 10 different phishing email campaigns over 8 months.
  • Researchers found no significant relationship between recent completion of cybersecurity training and the likelihood of falling for phishing emails.
  • Embedded phishing training reduced the likelihood of clicking on a phishing link by only 2%.
  • 75% of users engaged with the embedded training materials for a minute or less, while 1/3 immediately closed the embedded training page without engaging with the material.
  • The study found that some phishing emails were considerably more effective than others, with a 30.8% click rate on a link that purported to be an update to UC San Diego Health's vacation policy.
  • Researchers recommend that organizations refocus their efforts to combat phishing on technical countermeasures such as two-factor authentication and password managers.

Statistics:

  • 19,500 employees participated in the study.
  • 10 different phishing email campaigns were sent over 8 months.
  • 2% reduction in likelihood of clicking on a phishing link with embedded phishing training.
  • 75% of users engaged with the embedded training materials for a minute or less.
  • 1/3 of users immediately closed the embedded training page without engaging with the material.
  • 30.8% click rate on a phishing email that purported to be an update to UC San Diego Health's vacation policy.
  • 2-factor authentication and password managers recommended as effective technical countermeasures to combat phishing.

Sources:

  • https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams
  • 46th IEEE Symposium on Security and Privacy (May)
  • Blackhat conference (Aug. 2-7)