Phishing simulations are essential for enhancing cybersecurity awareness and preparedness among university staff and students. These simulations provide a practical approach to identifying vulnerabilities, educating users about phishing tactics, and fostering a culture of vigilance against cyber threats. Various factors influence the difficulty of identifying phishing emails, mainly when the messages are highly deceptive. This study conducted an email phishing simulation as part of an annual training program at a major university in Thailand. A total of 14,020 participants were involved, including 4,916 staff members and 9,104 students. The results revealed that emails offering benefits aligned with the recipients’ interests were more deceptive and, consequently, more effective than the previous year’s simulation. Specifically, 14.62% of the participants opened a general phishing email, with 1.34% providing their information. In contrast, 27.46% of the participants opened the phishing email for a more customised and deceptive email, and 3.53% submitted their information.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Evaluating the Effectiveness of Customised Phishing Simulations in Enhancing Cybersecurity Awareness at a University in Thailand

  • Damrongsak Naparat,
  • Opas Muensaen,
  • Worajak Chaikaew

摘要

Phishing simulations are essential for enhancing cybersecurity awareness and preparedness among university staff and students. These simulations provide a practical approach to identifying vulnerabilities, educating users about phishing tactics, and fostering a culture of vigilance against cyber threats. Various factors influence the difficulty of identifying phishing emails, mainly when the messages are highly deceptive. This study conducted an email phishing simulation as part of an annual training program at a major university in Thailand. A total of 14,020 participants were involved, including 4,916 staff members and 9,104 students. The results revealed that emails offering benefits aligned with the recipients’ interests were more deceptive and, consequently, more effective than the previous year’s simulation. Specifically, 14.62% of the participants opened a general phishing email, with 1.34% providing their information. In contrast, 27.46% of the participants opened the phishing email for a more customised and deceptive email, and 3.53% submitted their information.