Phishing and Credential-Based Cybersecurity Threats Among Remote Employees During the COVID-19 Pandemic in the United Kingdom

Authors

Keywords:

phishing, united kingdom, information security, cyber security

Abstract

The rapid transition to remote working during the COVID-19 pandemic substantially altered the cybersecurity exposure of organisations and employees. In the United Kingdom, employees increasingly depended on email, cloud applications, virtual private networks, remote-access platforms and digital collaboration systems for routine organisational activities. These changes expanded opportunities for phishing and credential-based attacks by increasing dependence on electronic communication while reducing face-to-face verification and conventional workplace security oversight. This paper examines phishing and credential-related threats affecting remote employees during the pandemic through a structured review of literature published between 2016 and 2020. Particular attention is given to social engineering, credential harvesting, employee susceptibility, time pressure, security awareness, organisational culture and remote authentication. The review demonstrates that phishing risk cannot be adequately explained by technical vulnerabilities alone. Attack success is influenced by the interaction between persuasive message characteristics, employee cognitive processes, organisational security practices and authentication architecture. A layered cybersecurity framework is proposed for UK organisations incorporating stronger identity controls, email protection, endpoint security, contextual security-awareness interventions and rapid incident reporting. The findings emphasise that effective protection of remote employees requires simultaneous technological and human-centred measures rather than reliance on conventional awareness training or perimeter security alone.

References

Aleroud, A. and Zhou, L. (2017) ‘Phishing environments, techniques, and countermeasures: A survey’, Computers & Security, 68, pp. 160–196.

Alshaikh, M. (2020) ‘Developing cybersecurity culture to influence employee behavior: A practice perspective’, Computers & Security, 98, 102003.

Bauer, S., Bernroider, E.W.N. and Chudzikowski, K. (2017) ‘Prevention is better than cure! Designing information security awareness programs to overcome users’ non-compliance with information security policies in banks’, Computers & Security, 68, pp. 145–159.

Chen, R., Gaia, J. and Rao, H.R. (2020) ‘An examination of the effect of recent phishing encounters on phishing susceptibility’, Decision Support Systems, 133, 113287.

Chowdhury, N.H., Adam, M.T.P. and Teubner, T. (2020) ‘Time pressure in human cybersecurity behavior: Theoretical framework and countermeasures’, Computers & Security, 97, 101963.

Da Veiga, A., Astakhova, L.V., Botha, A. and Herselman, M. (2020) ‘Defining organisational information security culture—Perspectives from academia and industry’, Computers & Security, 92, 101713.

De, R., Pandey, N. and Pal, A. (2020) ‘Impact of digital surge during COVID-19 pandemic: A viewpoint on research and practice’, International Journal of Information Management, 55, 102171.

Frauenstein, E.D. and Flowerday, S. (2020) ‘Susceptibility to phishing on social network sites: A personality information processing model’, Computers & Security, 94, 101862.

Goel, D. and Jain, A.K. (2018) ‘Mobile phishing attacks and defence mechanisms: State of art and open research challenges’, Computers & Security, 73, pp. 519–544.

Gratian, M., Bandi, S., Cukier, M., Dykstra, J. and Ginther, A. (2018) ‘Correlating human traits and cyber security behavior intentions’, Computers & Security, 73, pp. 345–358.

Han, J.Y., Kim, Y.J. and Kim, H. (2017) ‘An integrative model of information security policy compliance with psychological contract: Examining a bilateral perspective’, Computers & Security, 66, pp. 52–65.

Hooper, V. and Blunt, C. (2020) ‘Factors influencing the information security behaviour of IT employees’, Behaviour & Information Technology, 39(8), pp. 862–874.

House, D. and Raja, M. (2020) ‘Phishing: Message appraisal and the exploration of fear and self-confidence’, Behaviour & Information Technology, 39(11), pp. 1204–1224.

Karjalainen, M., Siponen, M. and Sarker, S. (2020) ‘Toward a stage theory of the development of employees’ information security behavior’, Computers & Security, 93, 101782.

Ki-Aries, D. and Faily, S. (2017) ‘Persona-centred information security awareness’, Computers & Security, 70, pp. 663–674.

Li, L., He, W., Xu, L., Ash, I., Anwar, M. and Yuan, X. (2019) ‘Investigating the impact of cybersecurity policy awareness on employees’ cybersecurity behavior’, International Journal of Information Management, 45, pp. 13–24.

Li, Y., Zhang, N. and Siponen, M. (2019) ‘Keeping secure to the end: A long-term perspective to understand employees’ consequence-delayed information security violation’, Behaviour & Information Technology, 38(5), pp. 435–453.

Menard, P., Warkentin, M. and Lowry, P.B. (2018) ‘The impact of collectivism and psychological ownership on protection motivation: A cross-cultural examination’, Computers & Security, 75, pp. 147–166.

Mouton, F., Leenen, L. and Venter, H.S. (2016) ‘Social engineering attack examples, templates and scenarios’, Computers & Security, 59, pp. 186–209.

Öğütçü, G., Testik, Ö.M. and Chouseinoglou, O. (2016) ‘Analysis of personal information security behavior and awareness’, Computers & Security, 56, pp. 83–93.

Papagiannidis, S., Harris, J. and Morton, D. (2020) ‘WHO led the digital transformation of your company? A reflection of IT related challenges during the pandemic’, International Journal of Information Management, 55, 102166.

Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A. and Zwaans, T. (2017) ‘The Human Aspects of Information Security Questionnaire (HAIS-Q): Two further validation studies’, Computers & Security, 66, pp. 40–51.

Parsons, K., Butavicius, M., Delfabbro, P. and Lillie, M. (2019) ‘Predicting susceptibility to social influence in phishing emails’, International Journal of Human-Computer Studies, 128, pp. 17–26.

Rajab, M. and Eydgahi, A. (2019) ‘Evaluating the explanatory power of theoretical frameworks on intention to comply with information security policies in higher education’, Computers & Security, 80, pp. 211–223.

Safa, N.S., Von Solms, R. and Furnell, S. (2016) ‘Information security policy compliance model in organizations’, Computers & Security, 56, pp. 70–82.

Wiley, A., McCormac, A. and Calic, D. (2020) ‘More than the individual: Examining the relationship between culture and Information Security Awareness’, Computers & Security, 88, 101640.

Downloads

Published

2021-04-15

Issue

Section

Articles