[ Download ]
Abstract
Phishing continues to be one of the most persistent cybersecurity
threats, with employees remaining the primary target of social engineering
attacks. Although phishing awareness training is widely implemented, limited
empirical evidence exists regarding its long-term effectiveness in real
organizational environments. This study investigates the impact of adaptive
phishing simulations on employee cybersecurity behavior using longitudinal data
collected from a multinational enterprise between 2023 and 2025. The dataset
comprises 20 phishing simulation campaigns conducted across five organizational
departments, enabling the examination of phishing click rates, credential
submission rates, departmental behavioral differences, and security awareness
improvement over time. The results demonstrate that repeated adaptive phishing
simulations significantly reduce phishing susceptibility, with the greatest
behavioral improvements observed in departments initially exhibiting the
highest risk levels. The findings further reveal that phishing vulnerability
varies across departments, supporting the need for risk-based and
department-specific awareness strategies rather than uniform training programs.
Based on the empirical evidence, this study proposes a Security Awareness
Maturity Model to evaluate the progression of organizational cybersecurity
behavior. The research contributes to the cybersecurity literature by providing
rare longitudinal evidence from a real enterprise setting and offers practical
guidance for designing adaptive phishing awareness programs that strengthen
employee resilience, cybersecurity governance, and organizational cyber
resilience.
JEL Classification: M15, M12, D83, L86.
Keywords: Adaptive Phishing Simulation, Cybersecurity Awareness, Social
Engineering, Longitudinal Study, Employee Security Behavior, Cyber Resilience.