Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Cybersecurity Awareness Training Against Phishing and Ransomware Risk: A Systematic Literature Review
University of Skövde, School of Informatics.
2026 (English)Independent thesis Basic level (degree of Bachelor), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The financial gains associated with ransomware have made it a popular and serious cybersecurity threat, while organizations may have become more vulnerable to this type of attack due to their dependence on digital infrastructure. Ransomware’s association with phishing as a commonly used attack vector, which may require organizations to consider employee awareness training alongside technical security measures. Small and medium-sized enterprises (SMEs) can be more vulnerable to ransomware because of resource constraints and limited cybersecurity knowledge. That is why this thesis aims to investigate how cybersecurity awareness training can help SMEs in Europe to support employees in identifying and responding to phishing attempts in the context of ransomware risk. This was done through a systematic literature review, where previous research was retrieved from five different databases. This was done with a specified search term to find articles used to answer this thesis research question. The literature selection process resulted in 35 articles being included in the final review and analyzed with thematic coding. Findings from the analysis suggest that cybersecurity awareness training may help SMEs to support employees to identify and respond to phishing attempts. However, the findings suggest that awareness training may be more useful for SMEs when it is practical, continuous, and connected to employees’ daily tasks, reporting procedures, and incident response routines.

Place, publisher, year, edition, pages
2026. , p. 37
Keywords [en]
Ransomware, phishing, cybersecurity awareness training, SMEs, employee awareness
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:his:diva-26535OAI: oai:DiVA.org:his-26535DiVA, id: diva2:2073928
Subject / course
Informationsteknologi
Educational program
Network and Systems Administration
Supervisors
Examiners
Available from: 2026-06-17 Created: 2026-06-17 Last updated: 2026-06-17Bibliographically approved

Open Access in DiVA

fulltext(703 kB)333 downloads
File information
File name FULLTEXT01.pdfFile size 703 kBChecksum SHA-512
805eee27776b86f344d756ad9cb0337069daddac99c976101a985f354734e250f00540d3e2227e4fbc6bfacd7eee8608383a690124832f851df6029118111ef0
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 383 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf