information Article Assessment of End-User Susceptibility to Cybersecurity Threats in Saudi Arabia by Simulating Phishing Attacks Dania Aljeaid * , Amal Alzhrani , Mona Alrougi and Oroob Almalki Department of Information System, Faculty of Computing and Information Technology, KingAbdulaziz University, Jeddah 21551, Saudi Arabia;
[email protected] (A.A.);
[email protected] (M.A.);
[email protected] (O.A.) * Correspondence:
[email protected] Received: 8 October 2020; Accepted: 23 November 2020; Published: 25 November 2020 Abstract: Phishing attacks are cybersecurity threats that have become increasingly sophisticated. Phishing is a cyberattack that can be carried out using various approaches and techniques. Usually, an attacker uses trickery as well as fraudulent and disguised means to steal valuable personal information or to deceive the victim into running malicious code, thereby gaining access and controlling the victim’s systems. This study focuses on evaluating the level of cybersecurity knowledge and cyber awareness in Saudi Arabia. It is aimed at assessing end-user susceptibility through three phishing attack simulations. Furthermore, we elaborate on some of the concepts related to phishing attacks and review the steps required to launch such attacks. Subsequently, we briefly discuss the tools and techniques associated with each attack simulation. Finally, a comprehensive analysis is conducted to assess and evaluate the results. Keywords: cybersecurity; phishing attacks; attack simulation; cybersecurity awareness 1. Introduction The utilisation of information and communications technologies has led to unprecedented advances in our daily lives and resulted in an increase in the usage and production of electronic devices. As the real world has shifted into the cyber world, a growing number of uncertainties related to the use of the digital environment have occurred, posing new digital security threats and challenges.