Key Concepts
- Fishing: Mass email social engineering attempts to obtain information or interaction.
- Awareness: Knowledge about something requiring care, not just basic information.
- Dunning-Kruger Effect: Less competent individuals overestimate their abilities, while highly competent individuals may overestimate the abilities of others.
- Satisficing: Choosing a viable option that meets requirements instead of optimizing.
- Dual System of Thinking: Fast, automatic system vs. considered, conscious system.
- Heightened Awareness: Temporary increase in vigilance and recognition.
- Routine Concentrated Risk: Routines concentrating risk within specific time periods.
Introduction
The webinar, hosted by the Canadian Institute for Cyber Security, features Michael Joyce discussing the persistent threat of phishing. Michael, a researcher, practitioner, and host of the "Cyber Crimeology" podcast, brings his expertise in cyber security, psychology, and policy to the topic. He is the executive director of the Human Centric Cyber Security Partnership and an organizer of the Cyber Security Revolution Conference. His presentation is supported by Boseron Security.
Defining Key Terms
- Fishing: Defined specifically as a mass email attempting to get someone to provide information or interact with the email directly, distinguishing it from targeted attacks like spear phishing.
- Awareness: Explored etymologically, emphasizing its connection to knowledge requiring care and attention, rather than just a basic unit of information.
The Dunning-Kruger Effect and Specialization
Michael highlights the Dunning-Kruger effect, explaining how specialization can lead cyber security professionals to overestimate the understanding of non-experts. This can create a disconnect and make it difficult to understand why people fall for phishing scams.
The Temptation of Technological Solutions
The presentation cautions against relying solely on technology to solve social problems. Using the example of knives, a technology with a long history but still causing numerous injuries, Michael argues that some problems, like those in computer-mediated communications, may not be fully solvable with technology alone.
Harmonizing Human and Technology Solutions
Drawing parallels with health and safety practices, the presentation suggests integrating human and technology solutions:
- Elimination: Removing dangerous tools.
- Substitution: Replacing with safer technology.
- Engineering Controls: Adding safety features.
- Administrative Controls: Training and education.
- Personal Protective Equipment: Providing tools for individual safety.
Understanding Human Behavior
Five concepts from psychology and decision sciences are presented to explain human behavior in the context of cyber security:
- Humans Think Efficiently: Evolved to conserve energy, avoiding unnecessary cognitive effort.
- Humans Make Do (Satisficing): Choose viable options instead of optimizing.
- Dual System of Thinking: Fast, automatic system interacts with a considered, conscious system.
- Humans Learn Imperfectly: Learning is shaped by experiences and uses, not a perfect process.
- Humans Have Bodies: Physical conditions impact decision-making.
Data Analysis: Cyber Security Awareness Month
A Canadian study is presented to analyze the impact of Cyber Security Awareness Month (October) on phishing-related behaviors.
- Increased Activity: A 13% increase in phishing email simulations sent by organizations during October.
- Reduced Click Rate: Lower fishing click rates during October in 2023 and 2024.
- Increased Real Fishing Reports: More reports of actual phishing emails in October.
- Decreased Simulation Reporting: Fewer reports of phishing simulation emails during October.
Interpretation: Cyber Security Awareness Month is effective in raising awareness, but it may be a "heightened awareness" that decays over time. Reporting behavior may be affected by fatigue, with users opting for minimal effort (deleting/ignoring) rather than reporting.
Awareness Decay and Training Frequency
Analysis of the decay in awareness after training, focusing on those who clicked or reported phishing emails:
- Reporting Decay: Likelihood of reporting decreases over time. 98.4% at 0 days, dropping to 90% after 3 months, then declining rapidly.
- Clicking Increase: Likelihood of clicking increases over time. 3.5% at 0 days, increasing to 14% after 90 days.
Implications: Training frequency should be based on risk appetite. The presentation acknowledges that a 0% click rate is unlikely.
Time of Day and Day of Week Analysis
Analysis of when phishing emails are sent and clicked on:
- Email Distribution: Fishing simulation emails are sent relatively evenly across the week.
- Click Hotspot: A clear peak in clicks on Monday mornings around 8:00 a.m.
- Reporting Hotspot: A similar peak in reporting on Monday mornings around 8:00 a.m.
- Holiday Impact: Reporting and clicking significantly decrease on holiday Mondays.
Survival Analysis: Using survival analysis, the presentation shows that phishing emails sent on Friday, Saturday, and Sunday have different "survival" curves (time until clicked) than those sent on other days. This suggests routines impact when people interact with phishing emails.
Routine Concentrated Risk: The concept of "routine concentrated risk" is introduced, suggesting that routines concentrate risk within specific time periods.
Recommendations: Organizations can consider adjusting email delivery schedules, meeting policies, or other factors to mitigate the impact of concentrated risk.
Conclusion
The presentation concludes with three key takeaways:
- Different Types of Awareness: Distinguish between knowledge awareness and heightened awareness, recognizing the time limitation of the latter.
- Training Frequency Depends on Risk Appetite: Tune training frequency based on the organization's tolerance for risk.
- Routines Impact Risk: Be aware of how routines concentrate risk and make choices to mitigate it.
Michael Joyce encourages questions and provides contact information, thanking Boseron Security for their support.
AI summaries can miss context or contain errors. Check important details against the original video.





