Human Factors in Cybersecurity The Impact of Security Awareness Training and Simulated Phishing on Reducing Phishing Susceptibility
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
The British University in Dubai
DOI
Abstract
Phishing remains one of the most persistent cybersecurity threats because it exploits human behaviour as well as technical weaknesses. Attackers often use urgency, authority, fear, trust and routine communication to persuade users to click unsafe links, open harmful attachments or respond to deceptive requests. This dissertation examines human factors in cybersecurity by focusing on the impact of security awareness training and simulated phishing-style email classification tasks on reducing phishing susceptibility. The study aimed to evaluate whether phishing awareness training helps participants identify suspicious emails and make safer email decisions. A small-scale mixed-methods design was used. Quantitative data were collected through participant profile questions, Likert-scale awareness items and pre-training and post-training email classification tasks. Participants classified realistic email examples as phishing, legitimate or unclear. Qualitative data were gathered through one open-ended question asking participants what they found useful from the training. The findings showed that participants became more cautious and were better able to recognise phishing cues after the awareness activity, particularly in security alerts, file-sharing links, account suspension warnings and urgent HR requests. However, reporting-confidence findings were limited by measurement constraints in the post-training Likert responses. Overall, the study supports combining technical controls with human-centred awareness training, realistic practice, feedback and non-punitive reporting systems. It concludes that employees and digital users should not be viewed only as vulnerabilities, but as an important defence layer when properly trained and supported.