Daengsi Therdpong, Pornpongtechavanich Phisit, Wuttidittachotti Pongpisit
Department of Sustainable Industrial Management Engineering, Faculty of Engineering, Rajamangala University of Technology Phra Nakhon (North Bangkok Center), Bangkok, Thailand.
Department of Information Technology, Faculty of Industry and Technology, Rajamangala University of Technology Rattanakosin (Wang Klai Kangwon Campus), Hua Hin, Prachuap Khiri Khan, Thailand.
Educ Inf Technol (Dordr). 2022;27(4):4729-4752. doi: 10.1007/s10639-021-10806-7. Epub 2021 Nov 15.
Cybersecurity is crucial at present because cyber threats (e.g., phishing) have become a very common occurrence in everyday life. A literature review showed that there are no studies based on cybersecurity awareness which involved a large number of Thai users. Thus, this research focused on the cybersecurity awareness of approximately 20,000 nationwide employees in a large financial institution in Thailand. The study consisted of three phases, a first phishing attack, knowledge transfer through a mixed-approach and a second phishing attack with different content. After data validation and analysis of the results, it was found that the level of cybersecurity awareness of employees improved significantly. The number of employees who opened the phishing email decreased by 71.5%. Therefore, this approach could be applied to cybersecurity enhancement in other organizations and other sectors/industries. Also, it was found that gender played a significant role in cybersecurity awareness within the Thai cybersecurity ecosystem since Thai female employees were found to have a higher level of cybersecurity awareness than male employees. Furthermore, it was found that the different generations of Thai employees (Generations Y and X and Baby Boomers) did not affect cybersecurity awareness.
目前,网络安全至关重要,因为网络威胁(如网络钓鱼)在日常生活中已变得非常普遍。一项文献综述表明,尚无基于网络安全意识且涉及大量泰国用户的研究。因此,本研究聚焦于泰国一家大型金融机构中约2万名全国范围内的员工的网络安全意识。该研究包括三个阶段:首次网络钓鱼攻击、通过混合方法进行知识传授以及内容不同的第二次网络钓鱼攻击。在对结果进行数据验证和分析后,发现员工的网络安全意识水平有显著提高。打开网络钓鱼电子邮件的员工数量减少了71.5%。因此,这种方法可应用于其他组织和其他部门/行业的网络安全增强。此外,研究发现,在泰国的网络安全生态系统中,性别在网络安全意识方面起着重要作用,因为泰国女性员工的网络安全意识水平高于男性员工。此外,还发现泰国不同代的员工(Y世代、X世代和婴儿潮一代)对网络安全意识没有影响。