- Cybersecurity training for users less effective than expected.
- Majority of subjects ignored remedial training materials.
- Better-crafted messages more effective in duping victims.
Researchers from University College, San Diego have found that enterprise phishing training has barely any effect on its subjects. Ariana Mirian and Christian Dameff, the co-director of the U.C. San Diego Center for Healthcare Cybersecurity ran a study over eight months which tried four types of phishing training, and used 19,500 employees as their lab rats.
One of the problems that organisations experience, the report [PDF] explains, is that subjects don’t usually want to engage with training materials. When a user fell victim to a fake phishing email and clicked a rogue link, they were taken to a web page designed to inform and educate. However, time-on-page metrics showed that over half of all training sessions end inside ten seconds, and only a quarter of users formally complete any given training web page by clicking a final button. Those users who engaged with the training materials and fully completed it were 19% less likely to fall victim to an attack than others. Most users that failed the phishing test and landed on the training page clicked away so quickly that their page dwell times could not be measured.
Overall, the average improvement rate of falling victim to phishing across the nearly 20,000 subjects was only 1.7%.
Cybersecurity training’s effectiveness
Results from phishing simulations are difficult to measure, the researchers noted, as only an average of 10% of users will click a rogue link in a single simulated attack. However, over half (56%) of the subjects clicked a suspect link during the study’s eight months.
The team found that messages that are typical lures (such as a call for users to change their email passwords) were less successful in duping users. Announcements about changes to the organisation’s vacation policy and company dress code, however, fooled nearly a third of users. An email informing the user they’d received a speeding ticket led to a 20% failure rate.
Speaking at a security conference in Las Vegas last week, in which the paper’s cybersecurity training findings were presented, Mirian said, “Whoever controls the lures controls the failure rates,” suggesting that the more detailed and relevant the message, the more often are links clicked by users.
The team used a simulation platform from cybersecurity vendor Proofpoint, and collected anonymised information on whether a user read the simulated rogue email, clicked an embedded phishing link in it, completed the embedded training materials on test failure, and the amount of time spent on the training page they were taken to.
What the study reveals is that phishing training may well not work as well as its providers state, and that more research is required to discover the right ways to educate users. “Is all of this focus on training worth the outcome? Training barely works,” researcher Ariana Mirian said. There was little difference in results between the four different types of training the team presented, but with only that paltry 1.7% improvement from the best-performing training materials.
Measuring the success of any cybersecurity measure by lack of incidents is always problematic, of course. But few decision-makers would consider the cost of a new suite of cybersecurity software a good deal if it were only to improve cybersecurity resilience by less than 2%. User training has to remain as one method organisations can deploy to decrease their chances of cyber breach, but the research from U.C. San Diego suggests that much anti-phishing training is close to ineffective in its current forms.

Want to learn more about cybersecurity and the cloud from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London.
Explore other upcoming enterprise technology events and webinars powered by TechForge here.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.