Journal of Risk & Control

Adaptive Phishing Simulation and Longitudinal Employee Security Behavior: Evidence from a Global Enterprise

  • Pdf Icon [ Download ]
  • Times downloaded: 9
  • Abstract

     

    Phishing continues to be one of the most persistent cybersecurity threats, with employees remaining the primary target of social engineering attacks. Although phishing awareness training is widely implemented, limited empirical evidence exists regarding its long-term effectiveness in real organizational environments. This study investigates the impact of adaptive phishing simulations on employee cybersecurity behavior using longitudinal data collected from a multinational enterprise between 2023 and 2025. The dataset comprises 20 phishing simulation campaigns conducted across five organizational departments, enabling the examination of phishing click rates, credential submission rates, departmental behavioral differences, and security awareness improvement over time. The results demonstrate that repeated adaptive phishing simulations significantly reduce phishing susceptibility, with the greatest behavioral improvements observed in departments initially exhibiting the highest risk levels. The findings further reveal that phishing vulnerability varies across departments, supporting the need for risk-based and department-specific awareness strategies rather than uniform training programs. Based on the empirical evidence, this study proposes a Security Awareness Maturity Model to evaluate the progression of organizational cybersecurity behavior. The research contributes to the cybersecurity literature by providing rare longitudinal evidence from a real enterprise setting and offers practical guidance for designing adaptive phishing awareness programs that strengthen employee resilience, cybersecurity governance, and organizational cyber resilience.

     

    JEL Classification: M15, M12, D83, L86.

    Keywords: Adaptive Phishing Simulation, Cybersecurity Awareness, Social Engineering, Longitudinal Study, Employee Security Behavior, Cyber Resilience.