
Why People Click, lessons from qualitative research
Keywords
Summary
157 words
Critical Evaluation
Value of the Information & Strength of the Argument
The talk provides valuable insights from a large real-world dataset, which is rare in this field. The argumentation is generally solid, with data supporting claims about training decay and the distinction between clicking and reporting. However, some interpretations are speculative, such as the reasons for the Monday morning peak, which the speakers admit did not match their hypothesis. The use of PMT is well-explained and adds theoretical grounding. The discussion of security fatigue is supported by data on click and report rates. Overall, the value is high for practitioners, but the scientific rigor is moderate due to the qualitative nature and potential biases in self-reported data.
Scientific Rigor, Source Quality, Title Accuracy
The speakers cite several sources, including the Ho et al. study from UCSD and the Hawthorne effect, but they do not provide specific citations for all claims. The data presented is from Beauceron’s own platform, which is a primary source but may have selection bias. The title accurately reflects the content. The talk is not peer-reviewed, but it is based on a large dataset and references established theories. The description includes links to relevant resources, such as HC2P and Beauceron, which add credibility. The Q&A section addresses common concerns and clarifies points. Overall, the scientific rigor is moderate, with a good balance of data and interpretation.
227 words
Title / Content Match
The title accurately reflects the content, which focuses on qualitative insights into why people click on phishing simulations.
Quality & Reliability
7/10
The talk is based on a large dataset (170k people, 15M simulations) and references academic concepts (PMT, Hawthorne effect), but the analysis is largely qualitative and the speakers are industry practitioners rather than academic researchers. The claims are generally supported by data, but some interpretations are speculative.
Chapters
- Welcome & Introductions
- What “cyber” really means: cybernetics, humans–technology–control
- Why humans matter in cyber defence
- Phishing 101
- Do phishing simulations work?
- Beauceron dataset: 1,300 orgs, 170k people, 15M simulations
- Training decay over time
- When people click
- Security fatigue
- Attitudes & risk
- Over‑trusting security tools doubles risk
- “Aggressive mimicry”
- Emotions & clicks
- Monday morning myth?
- Teach in the moment
- Why people clicked
- Habits, vigilance & better training design
- “Phishing tests = fire drills?”
- Q&A begins
- Q1: Why people still click after training
- Q2: Attitudes/beliefs that increase phishing vulnerability
- Q3: Fear‑based vs. empowerment‑based awareness campaigns
- Closing remarks
Cited Sources
- Cybercrimeology podcast — Michael Joyce's podcast discussing cybercrime science and research.
- Human-Centric Cybersecurity Partnership (HC2P) — Michael Joyce's organization, a transdisciplinary group researching human-centric cybersecurity.
- Canada's Smart Cybersecurity Network (SERENE-RISC) — Network for cybercrime and cybersecurity knowledge mobilization.
- Cybercrime prevention laboratory — Michael Joyce's research lab at the University of Montreal.
- Canadian Institute for Cybersecurity — Hosting institution and David Shipley's alma mater.
- CIC webinar introduction video — Video about the Canadian Institute for Cybersecurity.
Concurring Sources
- Ho et al. (UCSD) study on phishing training — Referenced in the talk as showing that some training methods are ineffective, but the talk argues that other methods can be effective.
Dissenting Sources
- Claims that security awareness training doesn't work — The speakers argue that such claims are oversimplified and not supported by all evidence.
External References
Contribution & Novelties
The talk provides unique qualitative insights from a large dataset on phishing behavior, specifically the distinction between clicking and reporting, and the decay of training effects over time. It also introduces Protection Motivation Theory as a framework for understanding user motivation, which is not commonly applied in cybersecurity. The emphasis on the need for interdisciplinary collaboration between social sciences and STEM is a valuable contribution.
Pour aller plus loin :
- Protection Motivation Theory — Foundational theory explaining how individuals are motivated to respond to threats.
- Hawthorne effect — Phenomenon where individuals modify behavior due to awareness of being observed.
- Phishing — Overview of phishing attacks and defenses.
107 words
Radar Profile
The radar profile shows high scores in quantity of information and fiability, reflecting the large dataset and credible sources. The technical level is moderate, indicating the content is accessible to a broad audience. The quality of information is good, but the qualitative nature and potential biases prevent a perfect score.
💬 No comments were provided for analysis.