Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system

Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system
复制标题

DOI:
10.1093/jamia/ocz005
复制
发表时间:
2019-06-01
影响因子:
6.4
通讯作者:
Landman, Adam
Landman, Adam
中科院分区:
管理学2区
文献类型:
--
作者:
Gordon, William J.;Wright, Adam;Landman, Adam

文献摘要

被引文献

相似文献

目的:这项研究旨在了解网络钓鱼培训计划对网络钓鱼点击率的影响,员工在一个单一的,匿名的美国healthcare institution.Materials和方法:我们将我们的人口分为2组:罪犯和nonofficials。罪犯被定义为那些点击了至少5个模拟钓鱼电子邮件和非罪犯是那些没有。我们计算点击率罪犯和非罪犯,之前和之后的强制性培训计划罪犯implemented.Results:共有5416独特的员工收到所有20个活动在干预期间,772点击至少5封电子邮件,并标记罪犯。只有975(17.9%)的人在20次活动中点击了0封钓鱼邮件; 3565(65.3%)点击了至少2封邮件。在20个广告系列中,每个群体的点击率都有所下降。在第15次战役后启动的强制性培训计划对点击率没有产生实质性影响,犯罪者仍然更有可能点击网络钓鱼模拟。讨论:网络钓鱼是针对医院员工的常见威胁媒介,也是医疗系统的重要网络安全风险。我们的工作表明,在模拟下,员工点击率随着重复模拟而下降,但针对高风险员工的强制性培训计划并没有显著降低这一population.Conclusions的点击率:员工钓鱼点击率随着时间的推移而下降,但与低风险员工相比,针对最高风险员工的强制性培训计划并没有降低点击率。
Objective: The study sought to understand the impact of a phishing training program on phishing click rates for employees at a single, anonymous US healthcare institution.Materials and Methods: We stratified our population into 2 groups: offenders and nonoffenders. Offenders were defined as those that had clicked on at least 5 simulated phishing emails and nonoffenders were those that had not. We calculated click rates for offenders and nonoffenders, before and after a mandatory training program for offenders was implemented.Results: A total of 5416 unique employees received all 20 campaigns during the intervention period; 772 clicked on at least 5 emails and were labeled offenders. Only 975 (17.9%) of our set clicked on 0 phishing emails over the course of the 20 campaigns; 3565 (65.3%) clicked on at least 2 emails. There was a decrease in click rates for each group over the 20 campaigns. The mandatory training program, initiated after campaign 15, did not have a substantial impact on click rates, and the offenders remained more likely to click on a phishing simulation.Discussion: Phishing is a common threat vector against hospital employees and an important cybersecurity risk to healthcare systems. Our work suggests that, under simulation, employee click rates decrease with repeated simulation, but a mandatory training program targeted at high-risk employees did not meaningfully decrease the click rates of this population.Conclusions: Employee phishing click rates decrease over time, but a mandatory training program for the highest-risk employees did not decrease click rates when compared with lower-risk employees.