Matthew L. Jensen

dblp:22/973 · DBLP profile ↗
← Back
4ranked-venue papers in the field
1as first author
3since 2021 · last 2025
0000-0001-8711-1827ORCID · corroborated

Domains — venue-derived; a paper can count in several

Knowledge Engineering, Semantic Web & Information Systems · 3 (1 first)Information Retrieval & Web Search · 1
YearPublicationVenuePosition
2025 The influence of affective processing on phishing susceptibility
abstract
The heightened sophistication of phishing attacks results in billions of dollars of financial losses, loss of intellectual property, and reputational damage to organisations. Past work examining determinants of phishing susceptibility has been dominated by cognitive theoretical perspectives. However, recent research has also revealed the importance of emotion in phishing susceptibility. This study expands our understanding of phishing susceptibility by adopting an affective lens. Using an integrative perspective of emotion, we build on the Affective Infusion Model (AIM) to predict the effects of valence, certainty, and arousal on phishing susceptibility. We pilot our manipulations (N = 241) and then test our hypotheses using a mock phishing experiment (N = 474) in which phishing messages are sent directly to participant inboxes. We demonstrate that messages inducing positive valence and low certainty result in higher phishing susceptibility. This study contributes to phishing literature by illuminating the critical role that emotion plays in altering recipients’ susceptibility in the processing of phishing messages and has implications for scholars, practitioners, and organisations.
Chuan (Annie) Tian, Matthew L. Jensen, Gregory Bott, Xin (Robert) Luo
Eur. J. Inf. Syst.2
2023 Learning not to take the bait: a longitudinal examination of digital training methods and overlearning on phishing susceptibility
abstract
As phishing becomes increasingly sophisticated and costly, interventions that improve and prolong resistance to attacks are needed. Previous research supported digital training as a method to reduce phishing susceptibility. However, the effects of training degrade with time. Therefore, we investigate overlearning as an approach that may increase skill retention through repetition and developing automaticity. We performed a longitudinal experiment crossing overlearning with anti-phishing digital training (rule-based, mindfulness, and control). Participants were tested using email identification tests (immediately following and 10 weeks after training) and mock phishing messages delivered to their inboxes (1 week and 8 weeks following training). Results showed that compared to rule-based training, mindfulness training resulted in significantly greater retention in terms of better email discrimination and less susceptibility to phishing attacks but similar levels of caution towards phishing after 2 months. Overlearning resulted in significantly less susceptibility to phishing attacks and more caution towards phishing compared to no overlearning but did not impact the digital training approaches. Even so, mindfulness was more beneficial compared to overlearning. Altogether, the results demonstrate the stability of the benefits of mindfulness training over time in terms of mitigating phishing susceptibility without influencing the chances of missing legitimate emails.
Christopher Nguyen, Matthew L. Jensen, Eric Day
Eur. J. Inf. Syst.2
2021 Using susceptibility claims to motivate behaviour change in IT security
abstract
Organisations face growing IT security risks with substantial consequences for missteps in business continuity, data loss, reputational harm, and future competitive advantage. To improve precaution-taking among organisation members, leaders frequently turn to susceptibility claims embedded in security education, training, and awareness (SETA) initiatives to motivate change. However, prior studies have produced mixed empirical results concerning the role of susceptibility in motivating precaution-taking. To deepen theorising about using susceptibility claims to change behaviour, we argue that threat characteristics (overt versus furtive attacks) shape individuals’ attitudes of the threat, and these attitudes subsequently anchor how individuals respond to new claims about the threats. We introduce social judgement theory (SJT) to argue that when individuals participate in SETA initiatives, susceptibility claims that are too distant from individuals’ existing attitudes will be ignored, while claims that are more proximal are more likely to be accepted and result in behaviour change. Using a longitudinal field experiment, we found that susceptibility claims motivated precaution taking against phishing (overt attack) but did not against password cracking (furtive attack). These results support SJT predictions and imply latitudes of acceptability and rejection into which susceptibility claims are placed. Implications for researchers, organisation leaders, and SETA developers are discussed.
Matthew L. Jensen, Alexandra Durcikova, Ryan T. Wright
Eur. J. Inf. Syst.1
2012 Using an elaboration likelihood approach to better understand the persuasiveness of website privacy assurance cues for online consumers
abstract
Abstract Privacy concerns can greatly hinder consumers' intentions to interact with a website. The success of a website therefore depends on its ability to improve consumers' perceptions of privacy assurance. Seals and assurance statements are mechanisms often used to increase this assurance; however, the findings of the extant literature regarding the effectiveness of these tools are mixed. We propose a model based on the elaboration likelihood model (ELM) that explains conditions under which privacy assurance is more or less effective, clarifying the contradictory findings in previous literature. We test our model in a free‐simulation online experiment, and the results of the analysis indicate that the inclusion of assurance statements and the combination, understanding, and assurance of seals influence privacy assurance. Privacy assurance is most effective when seals and statements are accompanied by the peripheral cues of website quality and brand image and when counter‐argumentation—through transaction risk—is minimized. Importantly, we show ELM to be an appropriate theoretical lens to explain the equivocal results in the literature. Finally, we suggest theoretical and practical implications.
Paul Benjamin Lowry, Greg D. Moody, Anthony Vance, Matthew L. Jensen, Jeffrey L. Jenkins, Taylor M. Wells
J. Assoc. Inf. Sci. Technol.4