Suppr超能文献

评估美国医疗体系内高风险员工强制参加网络钓鱼培训计划的效果。

Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system.

机构信息

Division of General Internal Medicine and Primary Care, Brigham and Women's Hospital, Boston, Massachusetts, USA.

Harvard Medical School, Boston, Massachusetts, USA.

出版信息

J Am Med Inform Assoc. 2019 Jun 1;26(6):547-552. doi: 10.1093/jamia/ocz005.

Abstract

OBJECTIVE

The study sought to understand the impact of a phishing training program on phishing click rates for employees at a single, anonymous US healthcare institution.

MATERIALS AND METHODS

We stratified our population into 2 groups: offenders and nonoffenders. Offenders were defined as those that had clicked on at least 5 simulated phishing emails and nonoffenders were those that had not. We calculated click rates for offenders and nonoffenders, before and after a mandatory training program for offenders was implemented.

RESULTS

A total of 5416 unique employees received all 20 campaigns during the intervention period; 772 clicked on at least 5 emails and were labeled offenders. Only 975 (17.9%) of our set clicked on 0 phishing emails over the course of the 20 campaigns; 3565 (65.3%) clicked on at least 2 emails. There was a decrease in click rates for each group over the 20 campaigns. The mandatory training program, initiated after campaign 15, did not have a substantial impact on click rates, and the offenders remained more likely to click on a phishing simulation.

DISCUSSION

Phishing is a common threat vector against hospital employees and an important cybersecurity risk to healthcare systems. Our work suggests that, under simulation, employee click rates decrease with repeated simulation, but a mandatory training program targeted at high-risk employees did not meaningfully decrease the click rates of this population.

CONCLUSIONS

Employee phishing click rates decrease over time, but a mandatory training program for the highest-risk employees did not decrease click rates when compared with lower-risk employees.

摘要

目的

本研究旨在了解针对美国某单一匿名医疗机构员工的网络钓鱼培训计划对网络钓鱼点击率的影响。

材料与方法

我们将研究人群分为两组:违规者和非违规者。违规者被定义为至少点击过 5 封模拟网络钓鱼电子邮件的人员,而非违规者则未点击过。在对违规者实施强制性培训计划之前和之后,我们计算了违规者和非违规者的点击率。

结果

在干预期间,共有 5416 名员工收到了所有 20 次活动的邮件;772 人点击了至少 5 封电子邮件,被标记为违规者。在 20 次活动期间,只有 975 名(17.9%)员工点击了 0 封网络钓鱼电子邮件;3565 名(65.3%)员工点击了至少 2 封电子邮件。随着 20 次活动的进行,每个组的点击率都有所下降。在第 15 次活动后启动的强制性培训计划对点击率没有显著影响,违规者仍然更有可能点击网络钓鱼模拟。

讨论

网络钓鱼是针对医院员工的常见威胁载体,也是医疗保健系统重要的网络安全风险。我们的工作表明,在模拟环境下,随着模拟次数的增加,员工的点击率会下降,但针对高风险员工的强制性培训计划并没有显著降低该人群的点击率。

结论

随着时间的推移,员工的网络钓鱼点击率会下降,但与低风险员工相比,针对最高风险员工的强制性培训计划并不能降低点击率。

相似文献

5
The role of cue utilization in the detection of phishing emails.线索利用在钓鱼邮件检测中的作用。
Appl Ergon. 2023 Jan;106:103887. doi: 10.1016/j.apergo.2022.103887. Epub 2022 Aug 26.
6
Phishing simulation exercise in a large hospital: A case study.大型医院中的网络钓鱼模拟演练:一项案例研究。
Digit Health. 2022 Mar 16;8:20552076221081716. doi: 10.1177/20552076221081716. eCollection 2022 Jan-Dec.

引用本文的文献

5
Phishing simulation exercise in a large hospital: A case study.大型医院中的网络钓鱼模拟演练:一项案例研究。
Digit Health. 2022 Mar 16;8:20552076221081716. doi: 10.1177/20552076221081716. eCollection 2022 Jan-Dec.
6
Hospitals' Cybersecurity Culture during the COVID-19 Crisis.新冠疫情危机期间医院的网络安全文化
Healthcare (Basel). 2021 Oct 7;9(10):1335. doi: 10.3390/healthcare9101335.

本文引用的文献

1
Threats to Information Security - Public Health Implications.信息安全威胁——对公共卫生的影响
N Engl J Med. 2017 Aug 24;377(8):707-709. doi: 10.1056/NEJMp1707212. Epub 2017 Jul 12.
3
Hospital Risk of Data Breaches.医院数据泄露风险。
JAMA Intern Med. 2017 Jun 1;177(6):878-880. doi: 10.1001/jamainternmed.2017.0336.
5

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验