The role of optimism bias in susceptibility to phishing attacks in a financial services organisation

dc.contributor.advisorFlowerday, Stephen
dc.contributor.authorOwen, Morné
dc.date.accessioned2026-03-03T10:35:51Z
dc.date.issued31/3/2023
dc.description.abstractResearchers looking for ways to change the insecure behaviour that results in successful phishing have considered multiple possible reasons for such behaviour. Therefore, the purpose of this study is to understand the role of optimism bias (OB "“ defined as a cognitive bias), which characterises overly optimistic or unrealistic individuals, in order to ensure secure behaviour. Research is considered that has focused on issues such as personality traits, trust, attitude and information security awareness training (ISAT). We used a mixed methods design to investigate OB behaviour, building on a recontextualised version of the theory of planned behaviour to evaluate the influence that OB has on phishing susceptibility. To model the data, an analysis was performed on 226 survey responses (systematic random sampling method) from the employees of a financial services organisation using partial least squares (PLS) path modelling. To evaluate OB behaviour, we conducted an experiment consisting of three ISAT sessions and three simulated phishing attacks. After each phishing experiment, we conducted interviews to gain a better understanding of why people succumbed to the attacks. It was subsequently found that overly optimistic individuals are inclined to behave insecurely, while factors such as attitude and trust significantly influence the intention to behave securely. Our contribution to practice is to enhance the effectiveness of ISAT by identifying and addressing the OB weakness to deliver a more successful training outcome. Our contribution to theory enriches the Information Systems literature by evaluating the effect of a cognitive bias on phishing susceptibility and, through research, offering a contextual explanation of the resultant behaviour.
dc.description.degreeDoctoral theses
dc.description.degreePhD
dc.format.extent279 pages
dc.format.mimetypeapplication/pdf
dc.identifier.doihttps://doi.org/10.21504/10962/419257
dc.identifier.otherhttp://hdl.handle.net/10962/419257
dc.identifier.urihttps://researchrepository.ru.ac.za/handle/123456789/3692
dc.languageEnglish
dc.publisherRhodes University, Faculty of Commerce, Department of Information Systems
dc.rightsOwen, Morné
dc.subjectMixed methods research
dc.subjectPhishing
dc.subjectOptimism bias
dc.subjectInformation security
dc.subjectInformation storage and retrieval systems
dc.subjectFinancial services industry
dc.subjectRisk perception
dc.titleThe role of optimism bias in susceptibility to phishing attacks in a financial services organisation
dc.typeAcademic thesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
The_role_of_optimism_bias_in_susceptibility_to_phi_vital_71629.pdf
Size:
2.43 MB
Format:
Adobe Portable Document Format