• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

为何员工(仍然)会点击网络钓鱼链接:医院调查

Why Employees (Still) Click on Phishing Links: Investigation in Hospitals.

作者信息

Jalali Mohammad S, Bruckes Maike, Westmattelmann Daniel, Schewe Gerhard

机构信息

Massachusetts General Hospital Institute for Technology Assessment, Harvard Medical School, Boston, MA, United States.

Massachusetts Institute of Technology Sloan School of Management, Cambridge, MA, United States.

出版信息

J Med Internet Res. 2020 Jan 23;22(1):e16775. doi: 10.2196/16775.

DOI:10.2196/16775
PMID:32012071
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC7005690/
Abstract

BACKGROUND

Hospitals have been one of the major targets for phishing attacks. Despite efforts to improve information security compliance, hospitals still significantly suffer from such attacks, impacting the quality of care and the safety of patients.

OBJECTIVE

This study aimed to investigate why hospital employees decide to click on phishing emails by analyzing actual clicking data.

METHODS

We first gauged the factors that influence clicking behavior using the theory of planned behavior (TPB) and integrating trust theories. We then conducted a survey in hospitals and used structural equation modeling to investigate the components of compliance intention. We matched employees' survey results with their actual clicking data from phishing campaigns.

RESULTS

Our analysis (N=397) reveals that TPB factors (attitude, subjective norms, and perceived behavioral control), as well as collective felt trust and trust in information security technology, are positively related to compliance intention. However, compliance intention is not significantly related to compliance behavior. Only the level of employees' workload is positively associated with the likelihood of employees clicking on a phishing link.

CONCLUSIONS

This is one of the few studies in information security and decision making that observed compliance behavior by analyzing clicking data rather than using self-reported data. We show that, in the context of phishing emails, intention and compliance might not be as strongly linked as previously assumed; hence, hospitals must remain vigilant with vulnerabilities that cannot be easily managed. Importantly, given the significant association between workload and noncompliance behavior (ie, clicking on phishing links), hospitals should better manage employees' workload to increase information security. Our findings can help health care organizations augment employees' compliance with their cybersecurity policies and reduce the likelihood of clicking on phishing links.

摘要

背景

医院一直是网络钓鱼攻击的主要目标之一。尽管医院努力提高信息安全合规性,但仍深受此类攻击的严重影响,进而影响医疗质量和患者安全。

目的

本研究旨在通过分析实际点击数据,调查医院员工决定点击网络钓鱼邮件的原因。

方法

我们首先运用计划行为理论(TPB)并整合信任理论,来衡量影响点击行为的因素。然后在医院开展了一项调查,并使用结构方程模型来研究合规意图的组成部分。我们将员工的调查结果与他们在网络钓鱼活动中的实际点击数据进行了匹配。

结果

我们的分析(N = 397)表明,TPB因素(态度、主观规范和感知行为控制)以及集体感知信任和对信息安全技术的信任与合规意图呈正相关。然而,合规意图与合规行为并无显著关联。只有员工的工作量水平与员工点击网络钓鱼链接的可能性呈正相关。

结论

这是信息安全与决策领域中少数几项通过分析点击数据而非使用自我报告数据来观察合规行为的研究之一。我们表明,在网络钓鱼邮件的背景下,意图与合规之间的联系可能不像之前假设的那么紧密;因此,医院必须对难以管理的漏洞保持警惕。重要的是,鉴于工作量与违规行为(即点击网络钓鱼链接)之间存在显著关联,医院应更好地管理员工的工作量以提高信息安全。我们的研究结果可帮助医疗保健组织增强员工对其网络安全政策的合规性,并降低点击网络钓鱼链接的可能性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6d69/7005690/87f864989535/jmir_v22i1e16775_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6d69/7005690/edbc143ceea9/jmir_v22i1e16775_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6d69/7005690/87f864989535/jmir_v22i1e16775_fig2.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6d69/7005690/edbc143ceea9/jmir_v22i1e16775_fig1.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6d69/7005690/87f864989535/jmir_v22i1e16775_fig2.jpg

相似文献

1
Why Employees (Still) Click on Phishing Links: Investigation in Hospitals.为何员工(仍然)会点击网络钓鱼链接:医院调查
J Med Internet Res. 2020 Jan 23;22(1):e16775. doi: 10.2196/16775.
2
Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions.美国医疗机构中员工易受网络钓鱼攻击的评估。
JAMA Netw Open. 2019 Mar 1;2(3):e190393. doi: 10.1001/jamanetworkopen.2019.0393.
3
Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system.评估美国医疗体系内高风险员工强制参加网络钓鱼培训计划的效果。
J Am Med Inform Assoc. 2019 Jun 1;26(6):547-552. doi: 10.1093/jamia/ocz005.
4
The Role of Health Concerns in Phishing Susceptibility: Survey Design Study.健康担忧在网络钓鱼易感性中的作用:调查设计研究
J Med Internet Res. 2020 May 4;22(5):e18394. doi: 10.2196/18394.
5
Phishing in healthcare organisations: threats, mitigation and approaches.医疗保健机构中的网络钓鱼:威胁、缓解措施及应对方法。
BMJ Health Care Inform. 2019 Sep;26(1). doi: 10.1136/bmjhci-2019-100031.
6
Informing, simulating experience, or both: A field experiment on phishing risks.告知、模拟体验还是两者兼而有之:关于网络钓鱼风险的现场实验。
PLoS One. 2019 Dec 18;14(12):e0224216. doi: 10.1371/journal.pone.0224216. eCollection 2019.
7
An Investigation of Employees' Intention to Comply with Information Security System-A Mixed Approach Based on Regression Analysis and fsQCA.员工对信息安全系统遵从意愿的调查——基于回归分析和 fsQCA 的混合方法
Int J Environ Res Public Health. 2022 Nov 30;19(23):16038. doi: 10.3390/ijerph192316038.
8
Signal Detection Theory (SDT) Is Effective for Modeling User Behavior Toward Phishing and Spear-Phishing Attacks.信号检测理论(SDT)可有效用于对用户针对网络钓鱼和鱼叉式网络钓鱼攻击的行为进行建模。
Hum Factors. 2018 Dec;60(8):1179-1191. doi: 10.1177/0018720818789818. Epub 2018 Jul 31.
9
So Many Phish, So Little Time: Exploring Email Task Factors and Phishing Susceptibility.这么多网络钓鱼,时间太少了:探索电子邮件任务因素和网络钓鱼易感性。
Hum Factors. 2022 Dec;64(8):1379-1403. doi: 10.1177/0018720821999174. Epub 2021 Apr 9.
10
The Phishing Email Suspicion Test (PEST) a lab-based task for evaluating the cognitive mechanisms of phishing detection.钓鱼邮件怀疑测试(PEST)是一种基于实验室的任务,用于评估钓鱼检测的认知机制。
Behav Res Methods. 2021 Jun;53(3):1342-1352. doi: 10.3758/s13428-020-01495-0. Epub 2020 Oct 19.

引用本文的文献

1
Prompt injection attacks on vision language models in oncology.肿瘤学中针对视觉语言模型的提示注入攻击。
Nat Commun. 2025 Feb 1;16(1):1239. doi: 10.1038/s41467-024-55631-x.
2
Factors Influencing Telemedicine Adoption Among Health Care Professionals: Qualitative Interview Study.影响医疗保健专业人员采用远程医疗的因素:定性访谈研究
JMIR Form Res. 2025 Jan 27;9:e54777. doi: 10.2196/54777.
3
Legal implications for clinicians in cybersecurity incidents: A review.临床医生在网络安全事件中的法律责任:综述。

本文引用的文献

1
European Hospitals' Transition Toward Fully Electronic-Based Systems: Do Information Technology Security and Privacy Practices Follow?欧洲医院向全电子系统的转型:信息技术安全与隐私措施是否与之同步?
JMIR Med Inform. 2019 Mar 25;7(1):e11211. doi: 10.2196/11211.
2
Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system.评估美国医疗体系内高风险员工强制参加网络钓鱼培训计划的效果。
J Am Med Inform Assoc. 2019 Jun 1;26(6):547-552. doi: 10.1093/jamia/ocz005.
3
Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions.
Medicine (Baltimore). 2024 Sep 27;103(39):e39887. doi: 10.1097/MD.0000000000039887.
4
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study.网络卫生方法在提高医疗机构网络安全和数据隐私意识中的应用:概念研究。
J Med Internet Res. 2023 Jul 27;25:e41294. doi: 10.2196/41294.
5
The impact of lecture playback speeds on concentration and memory.讲座回放速度对注意力和记忆力的影响。
BMC Med Educ. 2023 Jul 18;23(1):515. doi: 10.1186/s12909-023-04491-y.
6
State-of-the-art session key generation on priority-based adaptive neural machine (PANM) in telemedicine.远程医疗中基于优先级的自适应神经网络(PANM)上的先进会话密钥生成
Neural Comput Appl. 2023;35(13):9517-9533. doi: 10.1007/s00521-022-08169-2. Epub 2023 Mar 22.
7
Information Security Behavior in Health Information Systems: A Review of Research Trends and Antecedent Factors.健康信息系统中的信息安全行为:研究趋势与先行因素综述
Healthcare (Basel). 2022 Dec 14;10(12):2531. doi: 10.3390/healthcare10122531.
8
Hospital cybersecurity risks and gaps: Review (for the non-cyber professional).医院网络安全风险与差距:综述(面向非网络专业人员)
Front Digit Health. 2022 Aug 11;4:862221. doi: 10.3389/fdgth.2022.862221. eCollection 2022.
9
The COVID-19 scamdemic: A survey of phishing attacks and their countermeasures during COVID-19.新冠疫情骗局:新冠疫情期间网络钓鱼攻击及其应对措施调查
IET Inf Secur. 2022 Sep;16(5):324-345. doi: 10.1049/ise2.12073. Epub 2022 Jul 4.
10
Phishing simulation exercise in a large hospital: A case study.大型医院中的网络钓鱼模拟演练:一项案例研究。
Digit Health. 2022 Mar 16;8:20552076221081716. doi: 10.1177/20552076221081716. eCollection 2022 Jan-Dec.
美国医疗机构中员工易受网络钓鱼攻击的评估。
JAMA Netw Open. 2019 Mar 1;2(3):e190393. doi: 10.1001/jamanetworkopen.2019.0393.
4
Health Care and Cybersecurity: Bibliometric Analysis of the Literature.医疗保健与网络安全:文献计量分析
J Med Internet Res. 2019 Feb 15;21(2):e12644. doi: 10.2196/12644.
5
EARS to cyber incidents in health care.医疗保健领域的网络事件。
J Am Med Inform Assoc. 2019 Jan 1;26(1):81-90. doi: 10.1093/jamia/ocy148.
6
Cybersecurity: Positive Changes Through Processes and Team Culture.网络安全:通过流程和团队文化实现积极变革。
Front Health Serv Manage. 2018 Fall;35(1):3-12. doi: 10.1097/HAP.0000000000000038.
7
Cybersecurity in healthcare: A narrative review of trends, threats and ways forward.医疗保健中的网络安全:趋势、威胁及未来发展方向的叙述性综述。
Maturitas. 2018 Jul;113:48-52. doi: 10.1016/j.maturitas.2018.04.008. Epub 2018 Apr 22.
8
Cybersecurity in Hospitals: A Systematic, Organizational Perspective.医院中的网络安全:系统的组织视角
J Med Internet Res. 2018 May 28;20(5):e10059. doi: 10.2196/10059.
9
Creative Persuasion: A Study on Adversarial Behaviors and Strategies in Phishing Attacks.创造性说服:网络钓鱼攻击中的对抗行为与策略研究
Front Psychol. 2018 Feb 21;9:135. doi: 10.3389/fpsyg.2018.00135. eCollection 2018.
10
Safeguarding Confidentiality in Electronic Health Records.保护电子健康记录中的机密性。
Camb Q Healthc Ethics. 2017 Apr;26(2):337-341. doi: 10.1017/S0963180116000931.