Intelligent Risk Prioritization for Phishing Mitigation: A Human-Factor-Aware Framework for Healthcare SOCs
Chia-Nan Wang1, Tsei-Hsuan Chen2,*, Syuan-Yun Wang3,*, Chung-Nan Cheng2
1 Department of Industrial Engineering and Management, National Kaohsiung University of Science and Technology, Kaohsiung, Taiwan
2 Department of Medical Information, Kaohsiung Armed Forces General Hospital, Kaohsiung, Taiwan
3 Department of Mechanical Engineering, National Cheng Kung University, Tainan, Taiwan
* Corresponding Author: Tsei-Hsuan Chen. Email:
; Syuan-Yun Wang. Email:
Computer Modeling in Engineering & Sciences https://doi.org/10.32604/cmes.2026.085454
Received 11 May 2026; Accepted 13 August 2026; Published online 28 August 2026
Abstract
In email-centric healthcare environments, social engineering attacks increasingly exploit human psychology, organizational trust relationships, and persuasive communication strategies to bypass conventional cybersecurity defenses. While existing email security controls are effective at blocking many malicious messages, they remain vulnerable to whitelist-failure scenarios in which compromised or seemingly legitimate communications evade detection and reach end users. Under limited analyst capacity and increasing alert volumes, the operational challenge is no longer solely identifying phishing emails but determining which socially engineered communications should be reviewed first. To address this problem, this study proposes a governance-oriented human-factor risk prioritization framework that operates as a post-detection decision-support layer rather than a traditional phishing-filtering mechanism. The proposed P×F framework integrates persuasion tactics (P) and persona-based message-framing factors (F) to model social engineering influence patterns and transform psychological manipulation cues into interpretable risk representations for Top-K (top-ranked K alerts) alert prioritization. Using Bayesian smoothing and Logistic Regression, the framework converts semantic indicators into auditable risk scores that support analyst attention allocation under constrained Security Operations Center (SOC) resources. The framework was evaluated using Enron and Nazario email corpora, Large Language Model (LLM)-generated phishing scenarios, and a real-world Hospital A proof-of-concept dataset. Experimental results achieved mean Receiver Operating Characteristic Area Under the Curve (ROC-AUC) values of 0.9829 under subject-only conditions and 0.9871 using full-text content, while maintaining robust performance under distribution shift with performance degradation below 0.06 AUC. In operational evaluation, the Top-100 prioritization mechanism achieved 0.95 precision across 10,463 real SOC emails. Compared with Bidirectional Encoder Representations from Transformers (BERT), which exhibited recall collapse (0.03) under limited-context conditions, the proposed framework demonstrated greater stability, interpretability, and operational suitability for alert triage. Unlike conventional phishing detection approaches that primarily emphasize content classification, the proposed framework models psychological manipulation mechanisms derived from persuasion theory and human-factor literature. It operationalizes these mechanisms as interpretable P×F human-factor indicators and validates the resulting governance-oriented risk prioritization framework using real hospital phishing emails.
Keywords
SOC alert prioritization; human-factor risk modeling; phishing mitigation; healthcare security operations; risk prioritization