An RPA-powered Simulated Phishing Campaign Solution for Assessing Human Susceptibility

Fuente: Zenodo
Salvato in:
Dettagli Bibliografici
Autori principali: Papatsaroucha, Dimitra, Kapouranis, Dimitrios, Papachatzakis, Nikos, Markakis, Evangelos
Natura: Recurso digital
Lingua:inglese
Pubblicazione: Zenodo 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866902308595433472
author Papatsaroucha, Dimitra
Kapouranis, Dimitrios
Papachatzakis, Nikos
Markakis, Evangelos
author_facet Papatsaroucha, Dimitra
Kapouranis, Dimitrios
Papachatzakis, Nikos
Markakis, Evangelos
contents <p>The rise of social engineering attacks continues to pose a significant threat to individuals and organizations. In recent years, research has focused not only on developing effective cybersecurity defense strategies and mitigation approaches, but also on assessing an individual’s awareness of and susceptibility to such attack scenarios. Several approaches have been used, ranging from traditional methods, such as questionnaires de signed to evaluate cybersecurity risky behavior and susceptibility to persuasion, which constitute a rather more static way to assess human susceptibility, to more contemporary practices, such as Simulated Social Engineering Campaigns, involving Phishing Campaigns and similar techniques. Simulated Phishing Campaigns offer the advantage of proactively identifying human related susceptibility to phishing in a realistic manner, hence aid ing in the prevention of real-world cyberattacks before they occur. However, more often than not, they require human intervention, which can be time- and cost-consuming as well as prone to error. This paper proposes the use of Robotic Process Automation (RPA) to automate Simulated Phishing Campaigns and, thus, enhance their efficiency and effectiveness. The proposed solution includes a user interface and back-end logic that automates the process of sending phishing emails and enumerates recipients’ in teractions aiming at assessing phishing awareness. Furthermore, the proposed system is designed to be able to, eventually, also include the result of a persuasion susceptibility assessment with the aim to combine human vulnerability assessment approaches, co-present their results, and draw a more complete picture regarding an individual’s vulnerability. To assess the proposed system, a realistic use case scenario was employed to conduct an experiment in a lab environment demonstrating the potential offered by RPA technology in automating Simulated Phishing Campaigns and thus enhancing phishing awareness assessment strategies.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_15183053
institution Zenodo
language eng
publishDate 2025
publisher Zenodo
record_format zenodo
spellingShingle An RPA-powered Simulated Phishing Campaign Solution for Assessing Human Susceptibility
Papatsaroucha, Dimitra
Kapouranis, Dimitrios
Papachatzakis, Nikos
Markakis, Evangelos
human susceptibility
phishing
robotic process automation
cybersecurity
<p>The rise of social engineering attacks continues to pose a significant threat to individuals and organizations. In recent years, research has focused not only on developing effective cybersecurity defense strategies and mitigation approaches, but also on assessing an individual’s awareness of and susceptibility to such attack scenarios. Several approaches have been used, ranging from traditional methods, such as questionnaires de signed to evaluate cybersecurity risky behavior and susceptibility to persuasion, which constitute a rather more static way to assess human susceptibility, to more contemporary practices, such as Simulated Social Engineering Campaigns, involving Phishing Campaigns and similar techniques. Simulated Phishing Campaigns offer the advantage of proactively identifying human related susceptibility to phishing in a realistic manner, hence aid ing in the prevention of real-world cyberattacks before they occur. However, more often than not, they require human intervention, which can be time- and cost-consuming as well as prone to error. This paper proposes the use of Robotic Process Automation (RPA) to automate Simulated Phishing Campaigns and, thus, enhance their efficiency and effectiveness. The proposed solution includes a user interface and back-end logic that automates the process of sending phishing emails and enumerates recipients’ in teractions aiming at assessing phishing awareness. Furthermore, the proposed system is designed to be able to, eventually, also include the result of a persuasion susceptibility assessment with the aim to combine human vulnerability assessment approaches, co-present their results, and draw a more complete picture regarding an individual’s vulnerability. To assess the proposed system, a realistic use case scenario was employed to conduct an experiment in a lab environment demonstrating the potential offered by RPA technology in automating Simulated Phishing Campaigns and thus enhancing phishing awareness assessment strategies.</p>
title An RPA-powered Simulated Phishing Campaign Solution for Assessing Human Susceptibility
topic human susceptibility
phishing
robotic process automation
cybersecurity
url https://doi.org/10.5281/zenodo.15183053