Why People Click, lessons from qualitative research

Why People Click, lessons from qualitative research

🎙 David Shipley & Michael Joyce 👥 1K 📅 December 12, 2025 ⏱ 57 min 👁 72 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

phishinghuman behaviorsecurity awarenesstraining decayprotection motivation theory

Summary

The webinar, hosted by the Canadian Institute for Cybersecurity, features David Shipley (CEO of Beauceron Security) and Michael Joyce (Executive Director of HC2P) discussing qualitative research on why people click on phishing simulations. They present data from Beauceron’s platform, covering 170,000 people and 15 million simulations across 1,300 organizations. Key findings include: training decay over time (click probability rises from 3.5% immediately after training to 95% after a year), the distinction between clicking and reporting behaviors, the impact of security fatigue (over-saturation reduces reporting), and the influence of attitudes (e.g., those who strongly disagree they are targets click 37% more). They introduce Protection Motivation Theory (PMT) as a framework for understanding user motivation. The talk emphasizes the need for social sciences and STEM collaboration in cybersecurity and challenges the notion that phishing simulations are ineffective, citing counter-evidence. They also discuss the importance of regular training (every 90 days) and the need for empowerment-based approaches over fear-based ones.

157 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights from a large real-world dataset, which is rare in this field. The argumentation is generally solid, with data supporting claims about training decay and the distinction between clicking and reporting. However, some interpretations are speculative, such as the reasons for the Monday morning peak, which the speakers admit did not match their hypothesis. The use of PMT is well-explained and adds theoretical grounding. The discussion of security fatigue is supported by data on click and report rates. Overall, the value is high for practitioners, but the scientific rigor is moderate due to the qualitative nature and potential biases in self-reported data.

Scientific Rigor, Source Quality, Title Accuracy

The speakers cite several sources, including the Ho et al. study from UCSD and the Hawthorne effect, but they do not provide specific citations for all claims. The data presented is from Beauceron’s own platform, which is a primary source but may have selection bias. The title accurately reflects the content. The talk is not peer-reviewed, but it is based on a large dataset and references established theories. The description includes links to relevant resources, such as HC2P and Beauceron, which add credibility. The Q&A section addresses common concerns and clarifies points. Overall, the scientific rigor is moderate, with a good balance of data and interpretation.

227 words

Title / Content Match

The title accurately reflects the content, which focuses on qualitative insights into why people click on phishing simulations.

Quality & Reliability

7/10

The talk is based on a large dataset (170k people, 15M simulations) and references academic concepts (PMT, Hawthorne effect), but the analysis is largely qualitative and the speakers are industry practitioners rather than academic researchers. The claims are generally supported by data, but some interpretations are speculative.

Chapters

Cited Sources

Concurring Sources

  • Ho et al. (UCSD) study on phishing training — Referenced in the talk as showing that some training methods are ineffective, but the talk argues that other methods can be effective.

Dissenting Sources

  • Claims that security awareness training doesn't work — The speakers argue that such claims are oversimplified and not supported by all evidence.

External References

Contribution & Novelties

The talk provides unique qualitative insights from a large dataset on phishing behavior, specifically the distinction between clicking and reporting, and the decay of training effects over time. It also introduces Protection Motivation Theory as a framework for understanding user motivation, which is not commonly applied in cybersecurity. The emphasis on the need for interdisciplinary collaboration between social sciences and STEM is a valuable contribution.

Pour aller plus loin :

  • Protection Motivation Theory — Foundational theory explaining how individuals are motivated to respond to threats.
  • Hawthorne effect — Phenomenon where individuals modify behavior due to awareness of being observed.
  • Phishing — Overview of phishing attacks and defenses.

107 words

Radar Profile

The radar profile shows high scores in quantity of information and fiability, reflecting the large dataset and credible sources. The technical level is moderate, indicating the content is accessible to a broad audience. The quality of information is good, but the qualitative nature and potential biases prevent a perfect score.

Reliability 7/10

💬 No comments were provided for analysis.