Cybersecurity Training Programs Ineffective in Reducing Phishing Scams

A recent study conducted at the University of California, San Diego (UCSD) has found that large companies' cybersecurity training programs have little to no impact on reducing the risk of employees falling for phishing scams. The study evaluated the effectiveness of two different types of cybersecurity training during an eight-month randomized controlled experiment, involving 10 phishing email campaigns sent to over 19,500 employees at UCSD Health. Despite 20 years of research and development into malicious email filtering techniques, phishing remains the single largest source of successful cybersecurity breaches, with a 2023 IBM study identifying it as a 16% overall threat. The study's findings have significant implications for the healthcare sector, where targeted data breaches have reached record highs.

Key Takeaways:

  • The study found that there was no significant relationship between whether users had recently completed an annual, mandated cybersecurity training and the likelihood of falling for phishing emails.
  • Embedded phishing training, which involves sharing anti-phishing information after a user engages with a phishing email sent by their organization as a test, was found to have an extremely low effect in reducing the likelihood of clicking on phishing links.
  • The researchers note that one reason the trainings are not effective is that the majority of people do not engage with the embedded training materials, with 75% of users engaging with the embedded training materials for a minute or less, and one-third immediately closing the embedded training page without engaging with the material.
  • The study found that more employees fell for the phishing emails as time went on, with only 10% of employees clicking on a phishing link in the first month, and more than half clicking on at least one phishing link by the eighth month.
  • Some phishing emails were found to be considerably more effective than others, with 1.82% of recipients clicking on a link to update their Outlook password, but 30.8% clicked on a link that purported to be an update to UCSD Health's vacation policy.
  • The researchers recommend that organizations refocus their efforts to combat phishing on technical countermeasures, such as two-factor authentication and password managers that only work on correct domains.

Statistics:

  • 19,500 employees at UCSD Health participated in the study over an eight-month period.
  • 10 different types of phishing emails were sent to employees during the study.
  • Embedded phishing training only reduced the likelihood of clicking on phishing links by 2%.
  • 75% of users engaged with the embedded training materials for a minute or less.
  • One-third of users immediately closed the embedded training page without engaging with the material.
  • Only 1.82% of recipients clicked on a link to update their Outlook password, but 30.8% clicked on a link that purported to be an update to UCSD Health's vacation policy.
  • More than half of employees clicked on at least one phishing link by the eighth month of the study.
  • Phishing remains the single largest source of successful cybersecurity breaches, with a 2023 IBM study identifying it as a 16% overall threat.

Sources:

  • Researchers presented their findings at the Blackhat conference Aug. 2 to 7 in Las Vegas.
  • The team originally shared their work at the 46th IEEE Symposium on Security and Privacy in May in San Francisco.
  • Funding for the study was provided by the University of California Office of the President "Be Smart About Safety" program, U.S. National Science Foundation grant CNS-2152644, UCSD CSE Postdoctoral Fellows program, Irwin Mark and Joan Klein Jacobs Chair in Information and Computer Science, CSE Professorship in Internet Privacy and/or Internet Data Security, a generous gift from Google, and operational support from the UCSD Center for Networked Systems.