HomeSecurityPhishing training is forgotten after a few months

Phishing training is forgotten after a few months

Security and phishing awareness programs are forgotten very quickly and employees need to be retrained after about six months, according to a paper presented at the USENIX SOUPS security conference last month.

The purpose of the paper was to analyze the effectiveness of employee training on phishing over time.

Taking advantage of the fact that German public administration organizations must undergo mandatory training programs on phishing, academics from several German universities conducted a survey of 409 of the 2,200 employees of the state geoinformatics and state research service (SOGSS).

AgentTesla Trojan-phishing campaign-COVID-19

The researchers tested the effectiveness of phishing training over time, with periodic tests at regular intervals, to determine when employees would lose their ability to detect phishing messages.

The employees were divided into multiple groups and tested every four, six, eight, ten and twelve months, respectively, from the time they were trained in a phishing training program

The research team found that while study participants were able to correctly identify phishing emails even after four months of initial training, this was not the case from six months onwards, suggesting that companies should retrain their employees.

The researchers also created their own “reminders” to “replenish awareness and knowledge,” which they used to educate employees after their research – six and twelve months later.

“We developed four different programs,” the academics reported. “Four programs were distributed to four groups (one per group): (a) text, (b) video, (c) interactive examples, and (d) a short text.

“Twelve months after the seminar, we compared the knowledge retention of the four groups. Among the four different tests, the video and interactive examples performed the best, with their impact lasting at least six months after the training.”

The academics concluded that while training employees to detect phishing emails can help organizations prevent some attacks, this training should be cyclical, with repeated training sessions, ideally every six months, and using interactive examples or videos.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS