Skip to main navigation Skip to search Skip to main content

Can secure habits counter phishing? An exploration using a novel in-tray simulation

  • University of Bristol

Research output: Contribution to journalArticlepeer-review

Abstract

Cyber attacks are increasing in frequency year by year, presenting a substantial and growing threat to the security of organisations (Verizon, 2023). (Spear) phishing—or the practice of sending (targeted) fraudulent emails to employees—is one means by which cyber attackers attempt to infiltrate secure systems. These messages typically exploit vulnerabilities in human decision-making, aiming to elicit sensitive information or distribute malware via fraudulent emails. Although various factors including individual, cultural, environmental, and message-related factors are known to influence susceptibility to phishing emails, current understanding of the nature of their interplay remains severely limited (Williams et al., 2017a). Addressing this gap, the current study investigates the role of habit in the context of phishing susceptibility, leveraging data from the pilot launch of PhiT. This tool—a collaboration between the UK's National Protective Security Authority (NPSA), the authors, and other stakeholders—is a sophisticated browser-based simulated email client for ecologically-valid research and training on phishing. PhiT provides realistic scenarios for roles such as IT Specialist, HR Assistant, and Procurement Manager, and has extensive data-gathering capabilities, facilitating a nuanced exploration of email interaction patterns and their impact on phishing vulnerability. While engaging with emails in an automatic, habitual way can be detrimental to one's ability to spot phishing emails, the current study explores whether certain ‘good’ security habits, like consistently verifying sender email addresses, might offer protective benefits. We explore patterns in participants’ email interactions using Markov chains and k-medoids clustering. Our analysis indicates that individuals who reliably verify sender email addresses may be less likely to fall for phishing attacks. However, correlations between sender checks and phishing rates were significant only in the IT specialist scenario (τb(39)=−.444, p<0.001; Kendall, 1938), suggesting role-specific differences in the effectiveness of this security behaviour. The various critical implications of this finding for cybersecurity research and practice are discussed in the context of habit theory. Based on this, we suggest that future research should explore the possibility of ‘cue engineering’: making changes to the UI with the aim of facilitating habit formation by designing better cues.

Original languageEnglish
Article number105057
Number of pages18
JournalComputers and Security
Volume170
Early online date17 Jul 2026
DOIs
Publication statusE-pub ahead of print - 17 Jul 2026

Data Availability Statement

The authors do not have permission to share data.

Acknowledgements

We would like to thank the anonymous reviewers for their thoughtful and constructive feedback, which helped to clarify and improve the final manuscript.

Keywords

  • Cue engineering
  • Cybersecurity
  • Email security
  • Habit theory
  • Human-centred security
  • Markov chains
  • Phishing
  • Phishing prevention
  • Security habits
  • User behaviour analytics

ASJC Scopus subject areas

  • General Computer Science
  • Law

Fingerprint

Dive into the research topics of 'Can secure habits counter phishing? An exploration using a novel in-tray simulation'. Together they form a unique fingerprint.

Cite this