Phishing Susceptibility and Protective Security Behaviors in Higher Education: Evidence for Organizational Cybersecurity Resilience
DOI:
https://doi.org/10.14738/abr.1410.12262Keywords:
behavioral risk management, cybersecurity resilience, higher education, organizational security, phishing simulation, reporting behaviorAbstract
Phishing creates organizational risk because a single user action can expose credentials, systems, and institutional information. This study examined event-level responses to a university-wide simulated phishing campaign involving 700 participants, including 600 students and 100 staff members. Outcomes included message reading, link clicking, credential submission, deletion, forwarding, and phishing reporting. The message was read by 296 participants (42.3%), clicked by 35 (5.0%), and followed by credential submission among 21 participants (3.0%). Of the 35 participants who clicked, 21 (60.0%) supplied credentials. Student and staff click rates were similar, at 5.2% and 4.0%, respectively, and the difference was not statistically significant. Credential-submission rates were 3.3% for students and 1.0% for staff, but this difference was also not statistically significant. Staff members were substantially more likely to delete and report the simulated message. These findings indicate that organizational phishing resilience should not be evaluated solely through click avoidance. Initial susceptibility and protective response are distinct dimensions of behavioral risk. Institutions should use multidimensional measures that distinguish clicking, credential disclosure, reporting, and other response behaviors. For managers, the results support role-sensitive interventions, accessible reporting mechanisms, and event-level security governance practices.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Chandra Dhimal, Stephanie Schwartz, Michael Douglas

This work is licensed under a Creative Commons Attribution 4.0 International License.
