{"id":{"repo_id":"buffalo","oai_identifier":"oai:ubir.buffalo.edu:10477/79522"},"canonical_url":"https://search.dev.ndltd.org/etd/buffalo/oai:ubir.buffalo.edu:10477/79522","repository":{"repo_id":"buffalo","name":"Buffalo","base_url":"https://ubir.buffalo.edu/oai/request"},"display":{"title":"Does Anti-phishing Training Protect Against Organizational Cyber Attacks?: An Empirical Assessment of Training Methods and Employee Readiness","abstract":"Ph.D.","abstract_html":"Ph.D.","abstract_has_math":false,"creators":["Harrison, Brynne"],"institution":"State University of New York at Buffalo","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Feeley, Thomas"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-05-07T16:16:30Z","date_published":"2019-05-07T16:16:30Z","updated_at":"2026-07-27T19:05:19Z","subjects":["communication","cyber security","online deception","SCAM"],"languages":["eng"],"rights":["Users of works found in University at Buffalo Institutional Repository (UBIR) are responsible for identifying and contacting the copyright owner for permission to reuse. University at Buffalo Libraries do not manage rights for copyright-protected works and cannot assist with permissions.","Copyright retained by author."],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/10477/79522","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Feeley, Thomas"]},{"key":"dc:creator","label":"Author","values":["Harrison, Brynne"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2019-05-07T16:16:30Z","2018","2018-07-23 14:21:30"]},{"key":"dc:publisher","label":"Institution","values":["State University of New York at Buffalo"]},{"key":"dc:type","label":"Dc Type","values":["Text","Dissertation"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["communication","cyber security","online deception","SCAM"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Users of works found in University at Buffalo Institutional Repository (UBIR) are responsible for identifying and contacting the copyright owner for permission to reuse. University at Buffalo Libraries do not manage rights for copyright-protected works and cannot assist with permissions.","Copyright retained by author."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/10477/79522"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Ph.D.","Phishing has become a preferred method among cyber criminals looking to gain access to confidential information. Although most businesses and governmental organizations provide employees with some sort of cyber security training, there is a lack of research examining whether such training methods work to actually reduce susceptibility to phishing—resulting in a sense of uncertainty surrounding a large portion of annual training dollars spent. Furthermore, while evidence suggests that the behavioral elements of the Susceptibility, Cognition, Automaticity Model (SCAM) provide the framework to predict susceptibility to phishing attacks, the current training methods being used in the workplace neglect to incorporate such information. The present study provides a thorough examination of the training methods that are currently used in organizational and governmental entities and empirically tests their ability to prepare employees for phishing attacks using a national, US-based wealth management firm. Results indicate that traditional cyber security training methods do not influence employee victimization to phishing attacks, nor do they actuate the SCAM. The author suggests and provides rationale for using the SCAM to develop a new, behavioral-based training program to better prepare employees for phishing attacks."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Does Anti-phishing Training Protect Against Organizational Cyber Attacks?: An Empirical Assessment of Training Methods and Employee Readiness"]}]}],"canonical_facts":{"dc:contributor":["Feeley, Thomas"],"dc:creator":["Harrison, Brynne"],"dc:date":["2019-05-07T16:16:30Z","2018","2018-07-23 14:21:30"],"dc:description":["Ph.D.","Phishing has become a preferred method among cyber criminals looking to gain access to confidential information. Although most businesses and governmental organizations provide employees with some sort of cyber security training, there is a lack of research examining whether such training methods work to actually reduce susceptibility to phishing—resulting in a sense of uncertainty surrounding a large portion of annual training dollars spent. Furthermore, while evidence suggests that the behavioral elements of the Susceptibility, Cognition, Automaticity Model (SCAM) provide the framework to predict susceptibility to phishing attacks, the current training methods being used in the workplace neglect to incorporate such information. The present study provides a thorough examination of the training methods that are currently used in organizational and governmental entities and empirically tests their ability to prepare employees for phishing attacks using a national, US-based wealth management firm. Results indicate that traditional cyber security training methods do not influence employee victimization to phishing attacks, nor do they actuate the SCAM. The author suggests and provides rationale for using the SCAM to develop a new, behavioral-based training program to better prepare employees for phishing attacks."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/10477/79522"],"dc:language":["eng"],"dc:publisher":["State University of New York at Buffalo"],"dc:rights":["Users of works found in University at Buffalo Institutional Repository (UBIR) are responsible for identifying and contacting the copyright owner for permission to reuse. University at Buffalo Libraries do not manage rights for copyright-protected works and cannot assist with permissions.","Copyright retained by author."],"dc:subject":["communication","cyber security","online deception","SCAM"],"dc:title":["Does Anti-phishing Training Protect Against Organizational Cyber Attacks?: An Empirical Assessment of Training Methods and Employee Readiness"],"dc:type":["Text","Dissertation"]},"updated_at":"2026-07-27T19:05:19Z"}