• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • LOGIN
  • Law Office ManagerHOME
  • Book StoreBook Store
  • WebinarsWebinars
  • LOGIN
  • Manage Your Account
  •  
Law Office Manager

Law Office Manager

  • Hiring
  • Increasing profits
  • Technology
  • Billing
  • Managing staff
  • More! ⇩
    • Newsletter Archive
    • Time tracking
    • Client relations
    • Termination
    • Tool Box
    • Risk management
    • Recordkeeping
    • Cartoons
    • Reader tips
    • Purchasing & leasing
    • Marketing
    • Managing the office
    • Information security
    • Your career
    • Working with lawyers
    • Employee benefits
    • Compliance
    • Workplace Safety
  • Special Reports

Gone phishin’: CyLab researchers find our ability to spot phishing emails is far from perfect

October 7, 2016

Each year, tens of millions of phishing emails make it to your inbox, uncaught by your email client’s spam filter. Of those, millions more slide past our own judgment and are clicked and opened. A recent study out of Carnegie Mellon’s CyLab Security and Privacy Institute has revealed just how likely we are to take the bait.

“Despite the fact that people were generally cautious, their ability to detect phishing emails was poor enough to jeopardize computer systems,” says Casey Canfield, a CyLab researcher from Carnegie Mellon’s Department of Engineering and Public Policy.

Canfield’s study was recently published in the journal Human Factors. Those interested can test their own phishing email detection skills in this brief online quiz.

In the study, Canfield and her colleagues showed participants information about phishing before asking them to evaluate 38 different emails, half of which were legitimate and half were phishing. For each email, participants answered questions about whether the email was phishing, what action they would perform, their confidence in their choices, and the perceived consequences of falling for the email if it was phishing.

On average, participants were only able to correctly identify just over half of the phishing emails presented to them. Fortunately, participants displayed a little more caution when it came to their behavior: roughly three-quarters of the phishing links were left un-clicked.

“Some users were able to identify a vast majority of the phishing emails, but only because they were biased to think everything was a phishing attack,” Canfield says. “So they didn’t necessarily have a high ability to tell the difference between phishing and legitimate emails.”

What’s more, participants’ confidence levels were not always calibrated with their ability.

“When making decisions about phishing emails, people were more cautious when they were unconfident and perceived very negative consequences of opening a phishing email,” Canfield says. “Unfortunately, they were often overconfident so they would still fall for phishing attacks.”

Based on the results, the authors of the study suggest interventions such as providing users with feedback on their abilities and emphasizing the consequences of phishing attacks. One effective training method that companies commonly use, Canfield explains, is sending out fake phishing emails and teaching a user about phishing emails if they open the email. This training method, called “embedded training,” was originally developed by the CyLab Usable Privacy and Security Lab.

“It seems like those trainings may not always be making people better at telling the difference, but it’s probably making them more cautious,” Canfield says. “Helping people tell the difference may not be as useful as just encouraging them to be more cautious.”


Editor’s picks:

Are you still complacent about mobile security risks?


What Employees Need to Know About Cybersecurity


Cybercrime and 7 basic security measures your firm should take now


Filed Under: Topics, Information security, Risk management, Technology, articles Tagged With: Information security, Technology, Risk management

Primary Sidebar

Free Reports

    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying

Free Premium Reports

    • 7 Smart Cost-Cutting Strategies for Your Law Office
    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying
    • 7 Proven Ways to Make Your Billing and Collections More Profitable
    • 7 Simple, Proven Steps to Hiring the Right Staff
    • 7 Policies Every Law Office Should Have

Download Current Issue

Current Issue

Recent Headlines

8 Proven Ways to Totally Destroy Your Credibility as a Manager

How to Communicate New Raised Rates for 2026 to Your Clients

The Benefit of a Wind-Down Ritual

17 Proofreading Tips for the Law Office

Budgeting and Planning for Long-Term Stability

Your Career

8 Proven Ways to Totally Destroy Your Credibility as a Manager

The Benefit of a Wind-Down Ritual

17 Proofreading Tips for the Law Office

Top 10 Essential Skills Every Law Office Manager Needs to Succeed

How to Unplug from Work Over the Thanksgiving Holiday

Deliver Your Message

Footer

Return to the Top

Download the Current issue
Monthly Magazine Archive
Advertise in Law Office Manager
Download Media Kit

Become a Premium Member
Download a Sample Issue of LOM
Renew your Law Office Manager Membership
Manage Your Account
Contact Law Office Manager
About Law Office Manager
Terms & Conditions
Privacy Policy
Give Us Feedback


Copyright © 2025 Plain Language Media, LLLP • 1-888-729-2315