Laura M. Bishop, Phoebe M. Asquith, Phillip L. Morgan
{"title":"The Employee Cybersecurity Awareness Framework","authors":"Laura M. Bishop, Phoebe M. Asquith, Phillip L. Morgan","doi":"10.1155/hbe2/1025045","DOIUrl":null,"url":null,"abstract":"<p>With cyberattack methods becoming increasingly sophisticated and end-users of targeted technology continuing to be the weakest link, it is crucial to develop more optimal ways to measure and better understand human cybersecurity behaviour risk. Across three studies, a tool consisting of a battery of established questionnaires and other measures to investigate employee cybersecurity vulnerability factors was tested and developed. Study 1 determined key correlating factors including security–self-efficacy, experience and involvement, awareness and organisational policy, with large effect sizes. A refined tool was deployed in Study 2 amongst a larger sample of employees within a multinational organisation. Exploratory factor analysis determined two latent factors—<i>cybersecurity awareness</i> and <i>psychological ownership</i>. However, 55% of variance within a regression model was explained by cybersecurity awareness alone. Study 3 included an even larger sample employed by multiple organisations—with cybersecurity awareness accounting for 60% of variance. We propose the employee cybersecurity awareness framework (ECAF) with cybersecurity awareness at its core and containing six underlying factors: threat appraisal, information security self-efficacy, information security awareness, information security attitude, information security operation policy and cybersecurity experience and involvement. The ECAF can be deployed by organisations to optimally measure employee cybersecurity risk factors and determine optimal interventions tailored to risk profiles.</p>","PeriodicalId":36408,"journal":{"name":"Human Behavior and Emerging Technologies","volume":"2025 1","pages":""},"PeriodicalIF":3.0000,"publicationDate":"2025-07-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1155/hbe2/1025045","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Human Behavior and Emerging Technologies","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1155/hbe2/1025045","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"PSYCHOLOGY, MULTIDISCIPLINARY","Score":null,"Total":0}
引用次数: 0
Abstract
With cyberattack methods becoming increasingly sophisticated and end-users of targeted technology continuing to be the weakest link, it is crucial to develop more optimal ways to measure and better understand human cybersecurity behaviour risk. Across three studies, a tool consisting of a battery of established questionnaires and other measures to investigate employee cybersecurity vulnerability factors was tested and developed. Study 1 determined key correlating factors including security–self-efficacy, experience and involvement, awareness and organisational policy, with large effect sizes. A refined tool was deployed in Study 2 amongst a larger sample of employees within a multinational organisation. Exploratory factor analysis determined two latent factors—cybersecurity awareness and psychological ownership. However, 55% of variance within a regression model was explained by cybersecurity awareness alone. Study 3 included an even larger sample employed by multiple organisations—with cybersecurity awareness accounting for 60% of variance. We propose the employee cybersecurity awareness framework (ECAF) with cybersecurity awareness at its core and containing six underlying factors: threat appraisal, information security self-efficacy, information security awareness, information security attitude, information security operation policy and cybersecurity experience and involvement. The ECAF can be deployed by organisations to optimally measure employee cybersecurity risk factors and determine optimal interventions tailored to risk profiles.
期刊介绍:
Human Behavior and Emerging Technologies is an interdisciplinary journal dedicated to publishing high-impact research that enhances understanding of the complex interactions between diverse human behavior and emerging digital technologies.