{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:27:13Z","timestamp":1760059633797,"version":"build-2065373602"},"reference-count":24,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,6,27]],"date-time":"2025-06-27T00:00:00Z","timestamp":1750982400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>This study investigates the effectiveness of two cybersecurity awareness interventions\u2014phishing simulations and organized online training\u2014in enhancing end-user resilience to phishing attacks in a Croatian university setting. Three controlled phishing simulations and one targeted instructional module were executed across several organizational departments. This study assesses behavioral responses, compromise rates, and statistical associations with demographic variables, including age, department, and educational background. Despite educational instruction yielding a marginally reduced number of compromised users, statistical analysis revealed no meaningful difference between the two methods. The third phishing simulation, executed over a pre-holiday timeframe, demonstrated a significantly elevated compromising rate, underscoring the influence of temporal and organizational context on employee alertness. These findings highlight the shortcomings of standalone awareness assessments and stress the necessity for ongoing, contextualized, and integrated cybersecurity training approaches. The findings offer practical guidance for developing more effective phishing defense strategies within organizational environments.<\/jats:p>","DOI":"10.3390\/jcp5030038","type":"journal-article","created":{"date-parts":[[2025,6,27]],"date-time":"2025-06-27T05:29:58Z","timestamp":1751002198000},"page":"38","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating End-User Defensive Approaches Against Phishing Using Education and Simulated Attacks in a Croatian University"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5566-1581","authenticated-orcid":false,"given":"Zlatan","family":"Mori\u0107","sequence":"first","affiliation":[{"name":"Department of Cybersecurity and System Engineering, Algebra Bernays University, 10000 Zagreb, Croatia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8638-6044","authenticated-orcid":false,"given":"Vedran","family":"Daki\u0107","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity and System Engineering, Algebra Bernays University, 10000 Zagreb, Croatia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mladen","family":"Ple\u0107a\u0161","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity and System Engineering, Algebra Bernays University, 10000 Zagreb, Croatia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-0947-9655","authenticated-orcid":false,"given":"Ivana","family":"Ogrizek Bi\u0161kupi\u0107","sequence":"additional","affiliation":[{"name":"Department of Interdisciplinary Sciences, Algebra Bernays University, 10000 Zagreb, Croatia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,6,27]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Enhancing Phishing Awareness Strategy Through Embedded Learning Tools: A Simulation Approach","volume":"2","author":"Ahmad","year":"2023","journal-title":"Arch. Adv. Eng. Sci."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"103364","DOI":"10.1016\/j.cose.2023.103364","article-title":"Evaluating Organizational Phishing Awareness Training on an Enterprise Scale","volume":"132","author":"Hillman","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"K\u00e4vrestad, J., Hagberg, A., Nohlberg, M., Rambusch, J., Roos, R., and Furnell, S. (2022). Evaluation of Contextual and Game-Based Training for Phishing Detection. Future Internet, 14.","DOI":"10.3390\/fi14040104"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Jayakrishnan, G., Banahatti, V., and Lodha, S. (2022, January 28). PickMail: A Serious Game for Email Phishing Awareness Training. Proceedings of the 2022 Symposium on Usable Security, San Diego, CA, USA.","DOI":"10.14722\/usec.2022.23059"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Wen, Z.A., Lin, Z., Chen, R., and Andersen, E. (2019, January 4\u20139). What Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game. Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, Scotland, UK.","DOI":"10.1145\/3290605.3300338"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"100540","DOI":"10.1109\/ACCESS.2022.3207272","article-title":"Avoiding the Hook: Influential Factors of Phishing Awareness Training on Click-Rates and a Data-Driven Approach to Predict Email Difficulty Perception","volume":"10","author":"Sutter","year":"2022","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"103313","DOI":"10.1016\/j.cose.2023.103313","article-title":"Falling for Phishing Attempts: An Investigation of Individual Differences That Are Associated with Behavior in a Naturalistic Phishing Simulation","volume":"131","author":"Beu","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1663","DOI":"10.30574\/wjarr.2024.23.2.2538","article-title":"Evaluating the Effectiveness of Cybersecurity Awareness Programs in Reducing Phishing Attacks: A Qualitative Study","volume":"23","author":"Khan","year":"2024","journal-title":"World J. Adv. Res. Rev."},{"key":"ref_9","first-page":"802","article-title":"Simulated Phishing Attack and Embedded Training Campaign","volume":"62","author":"Yeoh","year":"2021","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Ciupe, A., and Orza, B. (2024, January 8\u201311). Reinforcing Cybersecurity Awareness through Simulated Phishing Attacks: Findings from an HEI Case Study. Proceedings of the 2024 IEEE Global Engineering Education Conference (EDUCON), Kos Island, Greece.","DOI":"10.1109\/EDUCON60312.2024.10578700"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Sirawongphatsara, P., Prachayagringkai, S., Pornpongtechavanich, P., Rompun, T., Chaowmak, K., Phanthuna, N., and Daengsi, T. (2023, January 20\u201321). Comparative Phishing Attack Simulations: A Case Study of Critical Information Infrastructure Organization Using Two Different Contents. Proceedings of the 2023 10th International Conference on Electrical Engineering, Computer Science and Informatics (EECSI), Palembang, Indonesia.","DOI":"10.1109\/EECSI59885.2023.10295679"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"McElwee, S., Murphy, G., and Shelton, P. (2018, January 19\u201322). Influencing Outcomes and Behaviors in Simulated Phishing Exercises. Proceedings of the SoutheastCon 2018, St. Petersburg, FL, USA.","DOI":"10.1109\/SECON.2018.8479109"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"361","DOI":"10.34190\/iccws.20.1.3366","article-title":"The Evolution of Phishing and Future Directions: A Review","volume":"20","author":"Osamor","year":"2025","journal-title":"iccws"},{"key":"ref_14","first-page":"45","article-title":"What the Phish! Effects of AI on Phishing Attacks and Defense","volume":"27","author":"Kumar","year":"2025","journal-title":"TAMU Cybersecur. J."},{"key":"ref_15","unstructured":"Heiding, F., Lermen, S., Kao, A., Schneier, B., and Vishwanath, A. (2024). Evaluating Large Language Models\u2019 Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects. arXiv."},{"key":"ref_16","unstructured":"Chen, F., Wu, T., Nguyen, V., Wang, S., Hu, H., Abuadbba, A., and Rudolph, C. (2024). Adapting to Cyber Threats: A Phishing Evolution Network (PEN) Framework for Phishing Generation and Analyzing Evolution Patterns using Large Language Models. arXiv."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Aljeaid, D., Alzhrani, A., Alrougi, M., and Almalki, O. (2020). Assessment of End-User Susceptibility to Cybersecurity Threats in Saudi Arabia by Simulating Phishing Attacks. Information, 11.","DOI":"10.3390\/info11120547"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Chatchalermpun, S., Wuttidittachotti, P., and Daengsi, T. (2020, January 18\u201319). Cybersecurity Drill Test Using Phishing Attack: A Pilot Study of a Large Financial Services Firm in Thailand. Proceedings of the 2020 IEEE 10th Symposium on Computer Applications & Industrial Electronics (ISCAIE), Penang, Malaysia.","DOI":"10.1109\/ISCAIE47305.2020.9108832"},{"key":"ref_19","first-page":"63","article-title":"Response to a Phishing Attack: Persuasion and Protection Motivation in an Organizational Context","volume":"30","author":"Taib","year":"2021","journal-title":"Inf. Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"4713","DOI":"10.22214\/ijraset.2024.61106","article-title":"Exploring Phishing Awareness and User Behavior: A Survey-Based Investigation","volume":"12","author":"Kudalkar","year":"2024","journal-title":"Int. J. Res. Appl. Sci. Eng. Technol."},{"key":"ref_21","unstructured":"Cranford, E.A., Lebiere, C., Rajivan, P., Aggarwal, P., and Gonzalez, C. (2019, January 19\u201322). Modeling Cognitive Dynamics in End-User Response to Phishing Emails. Proceedings of the 17th Annual Meeting of the International Conference on Cognitive Modelling, Montreal, QC, Canada."},{"key":"ref_22","unstructured":"Vishwanath, A. (2016). Blunting the Phisher\u2019s Spear: A Risk-Based Approach for Defining User Training and Awarding Administrative Privileges. Black Hat USA 2016, Black Hat. Available online: https:\/\/www.blackhat.com\/docs\/us-16\/materials\/us-16-Vishwanath-Blunting-The-Phishers-Spear-A-Risk-Based-Approach-For-Defining-User-Training-And-Awarding-Administrative-Privileges-wp.pdf."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"129","DOI":"10.29007\/dkdw","article-title":"A Cyber Attack Simulation for Teaching Cybersecurity","volume":"93","author":"Scherb","year":"2023","journal-title":"Epic. Ser. Comput."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"584","DOI":"10.1080\/0144929X.2011.632650","article-title":"Phishing for Phishing Awareness","volume":"32","author":"Jansson","year":"2013","journal-title":"Behav. Inf. Technol."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/38\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:59:49Z","timestamp":1760032789000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/38"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,27]]},"references-count":24,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030038"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030038","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,6,27]]}}}