Criterion Calibration: How Organizational Policy Shapes Employees’ Phishing Decision Thresholds @ 2026 Dewald Roode Information Security Workshop
Oct 9, 2026·
,,·
1 min read
Yuxiao (Rain) Luo, PhD
Adel Yazdanmehr
Jingguo Wang
Abstract
Organizations facing phishing threats need employees who can not only detect attacks but also calibrate their suspicion to the organization’s decision context. Drawing on signal detection theory (SDT), we distinguish detection sensitivity (d′) from the decision threshold, or response criterion (c). We theorize that organizational policies shape this criterion by altering employees’ perceived decision costs: security accountability increases suspicion, whereas productivity accountability restrains it. When organizations emphasize security accountability without comparable productivity accountability, employees may become overly suspicious, generating more false alarms and reducing decision effectiveness. We test this theory in a 2 × 2 experiment that independently manipulates a Security Performance Report and a Task Performance Report. Our study highlights an overlooked practical implication: effective phishing management should calibrate suspicion rather than maximize it.
Date
Oct 9, 2026 2:00 PM
Event
Location
Tucson, AZ, USA
903 E. 2nd Street, Tucson, 85719
Click on the Slides button above to view the slides.