"It may take ages": understanding human-centred lateral phishing attack detection in organisations

Neeranjan Chitare, Lynne Coventry, James Nicholson

Research output: Chapter in Book/Report/Conference proceedingConference contribution

3 Citations (Scopus)
161 Downloads (Pure)

Abstract

Lateral phishing attacks can be devastating for users and organisational IT teams as these originate from legitimate, but compromised, email accounts that benefit from the implicit trust between sender and recipients. In this paper, we begin to explore the human-centred space of lateral phishing attacks through interviews with 5 security practitioners and 17 employees from the UK and India. We report how security practitioners predominantly rely on employees to alert them to compromised accounts, and how this can create a delay during which the attack can continue. Our interviews with employees, on the other hand, found that individuals may not be reliable; they struggled to detect slight changes to messages, and over-relied on markers that cannot identify lateral attacks. We discuss the symbiotic relationship between security practitioners and employees for combatting lateral phishing attacks within organisations, and present recommendations for improving resistance to these attacks.

Original languageEnglish
Title of host publicationEuroUSEC '23
Subtitle of host publicationproceedings of the 2023 European Symposium on Usable Security
Place of PublicationNew York
PublisherAssociation for Computing Machinery (ACM)
Pages344-355
Number of pages12
ISBN (Electronic)9798400708145
DOIs
Publication statusPublished - 16 Oct 2023
EventThe 2023 European Symposium on Usable Security - Copenhagen, Denmark
Duration: 16 Oct 202317 Oct 2023
https://eurousec23.itu.dk/

Conference

ConferenceThe 2023 European Symposium on Usable Security
Abbreviated titleEuroUSEC 2023
Country/TerritoryDenmark
CityCopenhagen
Period16/10/2317/10/23
Internet address

Keywords

  • Organisations
  • Lateral phishing
  • Phishing
  • Reporting
  • Cybersecurity practitioners

Fingerprint

Dive into the research topics of '"It may take ages": understanding human-centred lateral phishing attack detection in organisations'. Together they form a unique fingerprint.

Cite this