BACKGROUND:Hospitals have been one of the major targets for phishing attacks. Despite efforts to improve information security compliance, hospitals still significantly suffer from such attacks, impacting the quality of care and the safety of patients. OBJECTIVE:This study aimed to investigate why hospital employees decide to click on phishing emails by analyzing actual clicking data. METHODS:We first gauged the factors that influence clicking behavior using the theory of planned behavior (TPB) and integrating trust theories. We then conducted a survey in hospitals and used structural equation modeling to investigate the components of compliance intention. We matched employees' survey results with their actual clicking data from phishing campaigns. RESULTS:Our analysis (N=397) reveals that TPB factors (attitude, subjective norms, and perceived behavioral control), as well as collective felt trust and trust in information security technology, are positively related to compliance intention. However, compliance intention is not significantly related to compliance behavior. Only the level of employees' workload is positively associated with the likelihood of employees clicking on a phishing link. CONCLUSIONS:This is one of the few studies in information security and decision making that observed compliance behavior by analyzing clicking data rather than using self-reported data. We show that, in the context of phishing emails, intention and compliance might not be as strongly linked as previously assumed; hence, hospitals must remain vigilant with vulnerabilities that cannot be easily managed. Importantly, given the significant association between workload and noncompliance behavior (ie, clicking on phishing links), hospitals should better manage employees' workload to increase information security. Our findings can help health care organizations augment employees' compliance with their cybersecurity policies and reduce the likelihood of clicking on phishing links.

译文

背景:医院已成为网络钓鱼攻击的主要目标之一。尽管努力改善信息安全合规性,但医院仍然遭受此类攻击的严重影响,从而影响了护理质量和患者的安全。
目的:本研究旨在通过分析实际点击数据来调查为什么医院员工决定点击网络钓鱼电子邮件。
方法:我们首先使用计划行为理论(TPB)并整合了信任理论,评估了影响点击行为的因素。然后,我们在医院进行了一项调查,并使用结构方程模型来研究合规意图的组成部分。我们将员工的调查结果与网络钓鱼活动中的实际点击数据进行了匹配。
结果:我们的分析(N = 397)表明,TPB因素(态度,主观规范和感知的行为控制)以及集体对信息安全技术的信任和信任与合规意图成正相关。但是,合规意图与合规行为没有显着关系。只有员工的工作量水平与员工点击网络钓鱼链接的可能性呈正相关。
结论:这是信息安全和决策研究中为数不多的研究之一,这些研究通过分析点击数据而不是使用自我报告的数据来观察合规性行为。我们表明,在网络钓鱼电子邮件的上下文中,意图和合规性可能不像以前所假设的那样紧密地联系在一起。因此,医院必须对无法轻易管理的漏洞保持警惕。重要的是,考虑到工作量和违规行为之间存在显着关联(即,单击网络钓鱼链接),医院应更好地管理员工的工作量以提高信息安全性。我们的发现可以帮助医疗保健组织提高员工对网络安全政策的遵从性,并减少点击网络钓鱼链接的可能性。

+1
+2
100研值 100研值 ¥99课程
检索文献一次
下载文献一次

去下载>

成功解锁2个技能,为你点赞

《SCI写作十大必备语法》
解决你的SCI语法难题!

技能熟练度+1

视频课《玩转文献检索》
让你成为检索达人!

恭喜完成新手挑战

手机微信扫一扫,添加好友领取

免费领《Endnote文献管理工具+教程》

微信扫码, 免费领取

手机登录

获取验证码
登录