Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Understanding the role of phishing and weak password policies in cybersecurity breaches: Human factors and mitigation strategies
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This research examines human behaviour leading to breaches in cybersecurity, specifically phishing exploitation and weak passwords, as they exist in organizations. The study considers the role of cybersecurity awareness and training on employee behaviours. Analysis of a self-reported survey shows that while employees generally showed awareness of cyber risks, some lacked the skills to act securely at work, such as not reporting phishing emails or mishandling sensitive email content. The research highlights the importance of ongoing cybersecurity training as well as actions of the organizations to clarify a security policy to guide employee behaviour. The data used to support the findings were self-reported, and recognizing the limited sample size prior to developing firm conclusions about the results is necessary. Future research questions could explore the influence of individual psychological and social factors (for example, depression, optimism, and overconfidence) on employee behaviour, or influence the development of secure practices within workplace behaviour. 

Place, publisher, year, edition, pages
2025. , p. iv, 36
Keywords [en]
Information security, information security awareness, human security behaviour, phishing attacks, password policy
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-25318OAI: oai:DiVA.org:his-25318DiVA, id: diva2:1973708
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-06-19 Created: 2025-06-19 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(2526 kB)154 downloads
File information
File name FULLTEXT01.pdfFile size 2526 kBChecksum SHA-512
13dd9bcbd11c96c937910bdc937b203aad5566c36580e796ba6a889815371a41b1c7c114273fdd24afe603cce218a4d880ebdd98fbf9a103b71ca1baa2a5e49e
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 154 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 456 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf