Evaluating the Effectiveness of Customised Phishing Simulations in Enhancing Cybersecurity Awareness at a University in Thailand
摘要
Phishing simulations are essential for enhancing cybersecurity awareness and preparedness among university staff and students. These simulations provide a practical approach to identifying vulnerabilities, educating users about phishing tactics, and fostering a culture of vigilance against cyber threats. Various factors influence the difficulty of identifying phishing emails, mainly when the messages are highly deceptive. This study conducted an email phishing simulation as part of an annual training program at a major university in Thailand. A total of 14,020 participants were involved, including 4,916 staff members and 9,104 students. The results revealed that emails offering benefits aligned with the recipients’ interests were more deceptive and, consequently, more effective than the previous year’s simulation. Specifically, 14.62% of the participants opened a general phishing email, with 1.34% providing their information. In contrast, 27.46% of the participants opened the phishing email for a more customised and deceptive email, and 3.53% submitted their information.