Advisor(s)
Sue Feldman
Committee Member(s)
Greg Orewa
Jeremey Walker
M Thad Phillips
Ryan Allen
School
School of Health Professions
Document Type
Dissertation
Department (new version)
Administration/Health Services
Date of Award
9-11-2025
Abstract
Introduction: Many healthcare organizations have experienced cybersecurity related phishing email attacks, costing these organizations many thousands to many millions of dollars to release ransomed data to maintain patient care delivery and operations. Use of technology alone has proven to be insufficient, as most occurrences of data breaches are related to human behaviors. Background: Cybersecurity is a threat increasingly common to healthcare organizations, and it is gaining in both sophistication and complexity, aided by artificial intelligence. Healthcare organizations have adopted new technologies and increased the prevalence of cybersecurity training to develop a healthy cyber culture and construct a human firewall against phishing attacks and data breaches. Methods: To understand the potential for alternative methods of training on phishing awareness, an application was deployed using the Kaizen Education© platform to provide short, repeated bursts of phishing information on a convenience sample at UAB Health System. Data were collected and analyzed from use of the Kaizen application and KnowBe4 post-training simulation data. Results: Participants (n = 24) completed Kaizen training and KnowBe4 simulation testing, and data were explored for associations. The association between the amount of time spent in the Kaizen app and the average amount of time spent per question, as proxies for effort, and performance on a simulated phishing email was explored for associations and correlations. There were no statistically significant findings relative to effort and performance. Conclusion: Some participants performed well while spending less time in the app and a shorter average amount of time on the questions. It could be that the short, repeated bursts of information may actually require less time to elicit behavior change than longer training sessions. A more rigorous study design to include demographics and qualitative responses for volume and nature of interruptions, duties performed, and user experience is needed to understand behaviors toward emails.
ProQuest ID
Recommended Citation
Pena, Dalton E., "Reducing The Risk Of Phishing Attacks Through Providing Consistent Training Via The Kaizen Education Platform" (2025). All ETDs from UAB. 7422.
https://digitalcommons.library.uab.edu/etd-collection/7422