Evaluating Employee Awareness and Response to Phishing Attacks in Financial Institutions in Saudi Arabia
No Thumbnail Available
Date
2026
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
Phishing is one of the most widespread forms of cybersecurity threat to financial institutions,
as it is not a technical flaw, but a human vulnerability. The research evaluates employee
awareness and response to phishing attacks in financial institutions in Saudi Arabia, which
represents a significant gap in the literature on the behavioural, cultural and organizational
aspects of the Saudi context. The quantitative approach was adopted whereby structured online
survey was administered to 147 employees working in commercial banks, Islamic banks, and
licensed financial service providers. The survey measured phishing knowledge, behavioural
responses, training effectiveness, and included scenario-based detection tasks. The results
indicate moderate to high awareness of phishing indicators at a theoretical level, but there are
important gaps in practical detection, especially of sophisticated and authority-based phishing.
Correlation analysis showed that job role affected phishing detection performance, especially
in the ability to distinguish between phishing and legitimate emails apart. IT/cybersecurity staff
showed the most balanced results, while finance/accounting staff also performed consistently,
although the sample size was small. Administrative, management, and customer service staff
showed larger gaps between the two tasks. Age did not show a clear linear relationship with
detection ability. Therefore, this research finds that just raising awareness is not sufficient, and
that financial institutions should have role-specific, continuous and culturally-sensitive training
programmes that can transform awareness into consistent and secure behaviour
Description
Keywords
Phishing, cybersecurity, financial institutions, employee awareness, Saudi Arabia, human vulnerability, social engineering, email fraud, cybersecurity threats, security awareness
