Understanding Phishing Reporting Motivations in Organizations
Article Content
- •Low reporting rates can indicate employee hesitation or lack of perceived value in reporting.
- •Primary motivators for reporting phishing emails include a desire to protect the organization and coworkers.
- •Improving the reporting process can enhance employee engagement and security culture.
Recent studies highlight the challenges organizations face in encouraging employees to report phishing emails. A 2024 study indicated that factors such as low perceived value and privacy concerns hinder reporting. SoSafe's Adaptive Defence Playbook revealed that 42% of security professionals believe reporting mistakes is limited, with 23% citing fear of consequences as a barrier. The research from a European university identified 21 themes influencing reporting behavior, emphasizing the desire to protect the organization and coworkers as primary motivators. Employees are more likely to report well-impersonated emails, showcasing their ability to assess phishing threats. Understanding these motivations can help improve reporting processes and enhance organizational security culture.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…