Article navigation
Purpose

This study aims to investigate the factors influencing employees’ decisions to report suspicious phishing e-mails in organizations, addressing the gap in understanding what motivates users to report and which types of e-mails are most likely to be reported.

Design/methodology/approach

In this study, the authors sample and interview n = 49 employees from the pool of phishing reporters at a European university. Interviewees are selected based on the sophistication of the e-mails they report, considering both contextual and technical dimensions. The authors cluster reporters according to their (emerging) reporting behavior and conduct semistructured interviews until thematic saturation is reached. Through thematic analysis, the authors identify 21 main themes that drive reporting.

Findings

The results indicate that the primary drivers for reporting suspicious e-mails are the desire to protect and help the organization and coworkers. Additional factors include a sense of responsibility, awareness of potential consequences and feelings of insecurity. Participants are more likely to report phishing e-mails that appear well-impersonated and with a believable pretexts, signaling user prowess in estimating the potential impact of phishing attacks.

Originality/value

This research offers a novel perspective on the complex interplay between motivations to report with a discussion in the broader theoretical context, as well as on the practical implications of the findings.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close Modal
Close Modal