Abstract
Cyber attacks are increasing in frequency year by year, presenting a substantial and growing threat to the security of organisations (Verizon, 2023). (Spear) phishing—or the practice of sending (targeted) fraudulent emails to employees—is one means by which cyber attackers attempt to infiltrate secure systems. These messages typically exploit vulnerabilities in human decision-making, aiming to elicit sensitive information or distribute malware via fraudulent emails. Although various factors including individual, cultural, environmental, and message-related factors are known to influence susceptibility to phishing emails, current understanding of the nature of their interplay remains severely limited (Williams et al., 2017a). Addressing this gap, the current study investigates the role of habit in the context of phishing susceptibility, leveraging data from the pilot launch of PhiT. This tool—a collaboration between the UK's National Protective Security Authority (NPSA), the authors, and other stakeholders—is a sophisticated browser-based simulated email client for ecologically-valid research and training on phishing. PhiT provides realistic scenarios for roles such as IT Specialist, HR Assistant, and Procurement Manager, and has extensive data-gathering capabilities, facilitating a nuanced exploration of email interaction patterns and their impact on phishing vulnerability. While engaging with emails in an automatic, habitual way can be detrimental to one's ability to spot phishing emails, the current study explores whether certain ‘good’ security habits, like consistently verifying sender email addresses, might offer protective benefits. We explore patterns in participants’ email interactions using Markov chains and k-medoids clustering. Our analysis indicates that individuals who reliably verify sender email addresses may be less likely to fall for phishing attacks. However, correlations between sender checks and phishing rates were significant only in the IT specialist scenario (τb(39)=−.444, p<0.001; Kendall, 1938), suggesting role-specific differences in the effectiveness of this security behaviour. The various critical implications of this finding for cybersecurity research and practice are discussed in the context of habit theory. Based on this, we suggest that future research should explore the possibility of ‘cue engineering’: making changes to the UI with the aim of facilitating habit formation by designing better cues.
| Original language | English |
|---|---|
| Article number | 105057 |
| Number of pages | 18 |
| Journal | Computers and Security |
| Volume | 170 |
| Early online date | 17 Jul 2026 |
| DOIs | |
| Publication status | E-pub ahead of print - 17 Jul 2026 |
Data Availability Statement
The authors do not have permission to share data.Acknowledgements
We would like to thank the anonymous reviewers for their thoughtful and constructive feedback, which helped to clarify and improve the final manuscript.Keywords
- Cue engineering
- Cybersecurity
- Email security
- Habit theory
- Human-centred security
- Markov chains
- Phishing
- Phishing prevention
- Security habits
- User behaviour analytics
ASJC Scopus subject areas
- General Computer Science
- Law
Fingerprint
Dive into the research topics of 'Can secure habits counter phishing? An exploration using a novel in-tray simulation'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS