Paper Type
ERF
Abstract
Organizations increasingly rely on recurring phishing simulations to strengthen employees’ cybersecurity awareness. However, existing behavioral cybersecurity research largely adopts cross-sectional and between-person approaches, implicitly assuming that training effects accumulate linearly over time. This study theorizes that individuals dynamically transition across qualitatively distinct response states during repeated phishing exposure. Drawing on appraisal-based and affective perspectives, we conceptualize phishing simulation as a recurring intervention that differentially shapes risk interpretation accuracy and precautionary engagement across exposure cycles. We develop a typology of response states and theorize the mechanisms through which employees transition between these states over time. By introducing a within-person, state-transition perspective to cybersecurity training research, this study seeks a more dynamic understanding of behavioral adaptation and highlights the importance of modeling temporal trajectories in security awareness interventions.
Paper Number
1676
Recommended Citation
Wang, Ruilin and Motiwalla, Luvai F., "Interpreting Phishing Simulation: A Typology of Employee Behavioral Responses and Their Transformation Pathways" (2026). AMCIS 2026 Proceedings. 31.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/31
Interpreting Phishing Simulation: A Typology of Employee Behavioral Responses and Their Transformation Pathways
Organizations increasingly rely on recurring phishing simulations to strengthen employees’ cybersecurity awareness. However, existing behavioral cybersecurity research largely adopts cross-sectional and between-person approaches, implicitly assuming that training effects accumulate linearly over time. This study theorizes that individuals dynamically transition across qualitatively distinct response states during repeated phishing exposure. Drawing on appraisal-based and affective perspectives, we conceptualize phishing simulation as a recurring intervention that differentially shapes risk interpretation accuracy and precautionary engagement across exposure cycles. We develop a typology of response states and theorize the mechanisms through which employees transition between these states over time. By introducing a within-person, state-transition perspective to cybersecurity training research, this study seeks a more dynamic understanding of behavioral adaptation and highlights the importance of modeling temporal trajectories in security awareness interventions.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC