Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Phishing in the Workplace: Organizational Practices, Culture and Phishing Vulnerability
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In today's digitally dependent workplaces, phishing attacks are a persistent and damaging cybersecurity threat. Phishing involves fraudulent attempts to obtain sensitive information, such as login credentials or financial details, by acting as a trustworthy entity, often through email. These attacks exploit human vulnerabilities through deceptive tactics, often resulting in significant financial and reputational damage to organizations. Despite advances in technical defenses, the role of organizational practices such as leadership, communication, structure, and culture in influencing phishing susceptibility among employees remains underexplored. The research question for the study is: “How do the organizational practices structure, leadership, communication and culture affect employees' vulnerability and susceptibility to phishing attacks?”.

Using a qualitative case study approach focusing on Söderberg & Partners, a prominent Swedish financial services organization, the research is conducted using data collected through semi-structured interviews with representative informants. The data is analyzed using thematic analysis to uncover patterns and insights into organizational practices and their impact on phishing defenses.

The findings indicated that a flat organizational structure and a supportive communication culture facilitate information sharing and timely reporting of phishing incidents. Leadership that emphasizes awareness and security-conscious norms strengthens employee preparedness. However, gaps in personalized training and fear of repercussions for reporting phishing attempts persist, highlighting areas for improvement.

This research underscores the interrelated role of organizational practices in mitigating phishing risk, and provides practical insights for developing a resilient cybersecurity culture in organizations.

Place, publisher, year, edition, pages
2025.
Keywords [en]
Phishing, Social engineering, Cybersecurity, Organizational practices, Case study.
National Category
Other Computer and Information Science
Identifiers
URN: urn:nbn:se:su:diva-242790OAI: oai:DiVA.org:su-242790DiVA, id: diva2:1955722
Available from: 2025-04-30 Created: 2025-04-30

Open Access in DiVA

fulltext(1577 kB)15 downloads
File information
File name FULLTEXT01.pdfFile size 1577 kBChecksum SHA-512
a20a0987e1e021800a38919271f25f4fcd2f2a28d40a6158da9a7acb9dd3d0498107db829361e0214d2a1045843165f3db8608874a7f963ab46300e96d0cff1f
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Prüzelius, GustavGyllner, Theodor
By organisation
Department of Computer and Systems Sciences
Other Computer and Information Science

Search outside of DiVA

GoogleGoogle Scholar
Total: 15 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 31 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf