A Comparative Study of Cybersecurity Awareness on Phishing Among Employees from Different Departments in an Organization

Therdpong Daengsi, Pongpisit Wuttidittachotti, Phisit Pornpongtechavanich, Nathaporn Utakrit
{"title":"A Comparative Study of Cybersecurity Awareness on Phishing Among Employees from Different Departments in an Organization","authors":"Therdpong Daengsi, Pongpisit Wuttidittachotti, Phisit Pornpongtechavanich, Nathaporn Utakrit","doi":"10.1109/ICSCEE50312.2021.9498208","DOIUrl":null,"url":null,"abstract":"Cybersecurity is an important issue for people who usually use the Internet for their purposes (e.g., ecommerce) in this era of the COVID-19 pandemic. For cyberthreats, phishing, which can be sent via email, can harm information systems in the organization. However, the risks from this kind of threats can be reduced if the employees have cybersecurity awareness. To prove this hypothesis with Thai employees, this paper presents a comparative study of cybersecurity awareness enhancement associated with the employees who work in different departments within the same organization in Bangkok, Thailand. In this study, the first phishing attack simulation was conducted before providing knowledge and training in cybersecurity to the employees and attacking with the second simulation. After result collection and analysis, it has been found that there are significant differences in cybersecurity awareness level between Thai employees from technology-based departments (e.g., IT department) and social-based departments (e.g., HR department) within the same organization. Of course, the technology-based employees are the better. Furthermore, it has been found that the cybersecurity awareness level of Thai employees from the social-based department, which were poor when compared to the other one, was improved obviously after they were involved with the cybersecurity awareness enhancement processes.","PeriodicalId":252529,"journal":{"name":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","volume":"38 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCEE50312.2021.9498208","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Cybersecurity is an important issue for people who usually use the Internet for their purposes (e.g., ecommerce) in this era of the COVID-19 pandemic. For cyberthreats, phishing, which can be sent via email, can harm information systems in the organization. However, the risks from this kind of threats can be reduced if the employees have cybersecurity awareness. To prove this hypothesis with Thai employees, this paper presents a comparative study of cybersecurity awareness enhancement associated with the employees who work in different departments within the same organization in Bangkok, Thailand. In this study, the first phishing attack simulation was conducted before providing knowledge and training in cybersecurity to the employees and attacking with the second simulation. After result collection and analysis, it has been found that there are significant differences in cybersecurity awareness level between Thai employees from technology-based departments (e.g., IT department) and social-based departments (e.g., HR department) within the same organization. Of course, the technology-based employees are the better. Furthermore, it has been found that the cybersecurity awareness level of Thai employees from the social-based department, which were poor when compared to the other one, was improved obviously after they were involved with the cybersecurity awareness enhancement processes.
某企业不同部门员工网络钓鱼意识的比较研究
在COVID-19大流行的这个时代,对于通常使用互联网(例如电子商务)的人来说,网络安全是一个重要问题。对于网络威胁,可以通过电子邮件发送的网络钓鱼可能会损害组织中的信息系统。然而,如果员工有网络安全意识,这种威胁的风险是可以降低的。为了在泰国员工中证明这一假设,本文在泰国曼谷对同一组织内不同部门工作的员工进行了网络安全意识增强的比较研究。在本研究中,先进行第一次网络钓鱼攻击模拟,然后对员工进行网络安全知识和培训,再进行第二次模拟攻击。经过结果收集和分析,我们发现同一组织内来自技术型部门(如it部门)和社会型部门(如人力资源部门)的泰国员工在网络安全意识水平上存在显著差异。当然,技术型员工更好。此外,我们发现来自社会部门的泰国员工的网络安全意识水平在参与网络安全意识提升过程后明显提高,而社会部门员工的网络安全意识水平相对较差。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信