ERIC Number: ED653538
Record Type: Non-Journal
Publication Date: 2024
Pages: 171
Abstractor: As Provided
ISBN: 979-8-3827-1578-0
ISSN: N/A
EISSN: N/A
A Research Study of Employee Perceptions on Identifying Phishing Attacks in Financial Organizations
Lili Ana
ProQuest LLC, Ed.D. Dissertation, University of Southern California
This dissertation addresses the problem of practice of the high rate of employees in financial organizations clicking on phishing links, positioning their companies at risk of a data incident or breach. The financial sector was the most breached industry in 2022 (Schwartz, 2022) and was impacted the most by malicious phishing emails (Trellix Advanced Research Center, 2022). This qualitative research study utilized an adapted Clark and Estes (2008) Gap Analysis conceptual framework to include expectations of knowledge construction (factual, conceptual, procedural, and metacognitive knowledge) (Krathwohl, 2002), motivation (self-efficacy) (Bandura, 2000) and (value) (Ambrose et al., 2010), and organizational influences (training, communication, and culture). Semi-structured interviews were conducted with 13 participants in August 2023. This research study explored safeguarding against phishing within organizational settings and contexts in which employees are susceptible to deception and exposed gaps in organizational influences through significant research findings that more training and awareness are needed for employees to successfully identify advanced phishing attacks. As the cyber threat landscape continues to be pervasive, companies utilize a myriad of information security frameworks for building their security programs; however, these frameworks only require that employees receive phishing training and do not address how to effectively train staff. This research study was conducted to serve as a resource for leaders in organizations by providing recommendations for developing a security-aware culture and effective training and communication that educates and motivates employees to identify phishing attacks and protect company and customer data. [The dissertation citations contained here are published with the permission of ProQuest LLC. Further reproduction is prohibited without permission. Copies of dissertations may be obtained by Telephone (800) 1-800-521-0600. Web page: http://bibliotheek.ehb.be:2222/en-US/products/dissertations/individuals.shtml.]
Descriptors: Employees, Employee Attitudes, Electronic Mail, Computer Security, Information Security, Identification, Banking, Risk, Behavior Problems, Knowledge Level, Training, Incidence
ProQuest LLC. 789 East Eisenhower Parkway, P.O. Box 1346, Ann Arbor, MI 48106. Tel: 800-521-0600; Web site: http://bibliotheek.ehb.be:2222/en-US/products/dissertations/individuals.shtml
Publication Type: Dissertations/Theses - Doctoral Dissertations
Education Level: N/A
Audience: N/A
Language: English
Sponsor: N/A
Authoring Institution: N/A
Grant or Contract Numbers: N/A