Paper Type

ERF

Abstract

Organizations increasingly rely on recurring phishing simulations to strengthen employees’ cybersecurity awareness. However, existing behavioral cybersecurity research largely adopts cross-sectional and between-person approaches, implicitly assuming that training effects accumulate linearly over time. This study theorizes that individuals dynamically transition across qualitatively distinct response states during repeated phishing exposure. Drawing on appraisal-based and affective perspectives, we conceptualize phishing simulation as a recurring intervention that differentially shapes risk interpretation accuracy and precautionary engagement across exposure cycles. We develop a typology of response states and theorize the mechanisms through which employees transition between these states over time. By introducing a within-person, state-transition perspective to cybersecurity training research, this study seeks a more dynamic understanding of behavioral adaptation and highlights the importance of modeling temporal trajectories in security awareness interventions.

Paper Number

1676

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Interpreting Phishing Simulation: A Typology of Employee Behavioral Responses and Their Transformation Pathways

Organizations increasingly rely on recurring phishing simulations to strengthen employees’ cybersecurity awareness. However, existing behavioral cybersecurity research largely adopts cross-sectional and between-person approaches, implicitly assuming that training effects accumulate linearly over time. This study theorizes that individuals dynamically transition across qualitatively distinct response states during repeated phishing exposure. Drawing on appraisal-based and affective perspectives, we conceptualize phishing simulation as a recurring intervention that differentially shapes risk interpretation accuracy and precautionary engagement across exposure cycles. We develop a typology of response states and theorize the mechanisms through which employees transition between these states over time. By introducing a within-person, state-transition perspective to cybersecurity training research, this study seeks a more dynamic understanding of behavioral adaptation and highlights the importance of modeling temporal trajectories in security awareness interventions.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.