2020
DOI: 10.2196/16775
|View full text |Cite
|
Sign up to set email alerts
|

Why Employees (Still) Click on Phishing Links: An Investigation in Hospitals

Abstract: Background Hospitals have been one of the major targets for phishing attacks. Despite efforts to improve information security compliance, hospitals still significantly suffer from such attacks, impacting the quality of care and the safety of patients. Objective This study aimed to investigate why hospital employees decide to click on phishing emails by analyzing actual clicking data. Methods We first gauged … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4

Citation Types

0
42
0
3

Year Published

2020
2020
2023
2023

Publication Types

Select...
4
3

Relationship

1
6

Authors

Journals

citations
Cited by 67 publications
(64 citation statements)
references
References 72 publications
0
42
0
3
Order By: Relevance
“…Furthermore, health services staff often have limited previous experience with remote working and with planning for this change, which leaves the sector vulnerable to cyberattacks [ 9 , 14 , 19 ]. As health services make use of a variety of medical devices, interconnectivity and interoperability create issues as they are now being accessed from outside health services’ internal network perimeter.…”
Section: Resultsmentioning
confidence: 99%
See 3 more Smart Citations
“…Furthermore, health services staff often have limited previous experience with remote working and with planning for this change, which leaves the sector vulnerable to cyberattacks [ 9 , 14 , 19 ]. As health services make use of a variety of medical devices, interconnectivity and interoperability create issues as they are now being accessed from outside health services’ internal network perimeter.…”
Section: Resultsmentioning
confidence: 99%
“…As health services make use of a variety of medical devices, interconnectivity and interoperability create issues as they are now being accessed from outside health services’ internal network perimeter. The medium and mode of access creates problems as access to the sensitive parts of health services can be reached via unsecured network connections or unpatched systems by staff working remotely [ 19 ]. In addition, some medical devices use off-the-shelf software, such as commercial operating systems (eg, older versions of Windows).…”
Section: Resultsmentioning
confidence: 99%
See 2 more Smart Citations
“…Recent research in hospitals shows that among several personal characteristics and organizational conditions, employees’ workload had the strongest impact on the rate of clicking on phishing links. 5 While extensive emailing of announcements may be needed to keep employees up to date during the pandemic, it could unnecessarily add to workload, putting them at higher risk of clicking on phishing emails. Moreover, best-practice security behaviors must be followed—encrypting data, keeping software updated, running antivirus software, using 2-factor authentication, and following local cybersecurity regulations or recommendations.…”
mentioning
confidence: 99%