Yusuf Taoheed Abiodun, Sajjad Mahmood, Mahmood Niazi, Mohammad Alshayeb, Azzah A. AlGhamdi
{"title":"基于人为因素的网络安全准备模型","authors":"Yusuf Taoheed Abiodun, Sajjad Mahmood, Mahmood Niazi, Mohammad Alshayeb, Azzah A. AlGhamdi","doi":"10.1007/s13369-025-10349-w","DOIUrl":null,"url":null,"abstract":"<div><p>Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.</p></div>","PeriodicalId":54354,"journal":{"name":"Arabian Journal for Science and Engineering","volume":"50 19","pages":"16199 - 16219"},"PeriodicalIF":2.9000,"publicationDate":"2025-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Cybersecurity Readiness Model Based on Human Factors\",\"authors\":\"Yusuf Taoheed Abiodun, Sajjad Mahmood, Mahmood Niazi, Mohammad Alshayeb, Azzah A. AlGhamdi\",\"doi\":\"10.1007/s13369-025-10349-w\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.</p></div>\",\"PeriodicalId\":54354,\"journal\":{\"name\":\"Arabian Journal for Science and Engineering\",\"volume\":\"50 19\",\"pages\":\"16199 - 16219\"},\"PeriodicalIF\":2.9000,\"publicationDate\":\"2025-06-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Arabian Journal for Science and Engineering\",\"FirstCategoryId\":\"103\",\"ListUrlMain\":\"https://link.springer.com/article/10.1007/s13369-025-10349-w\",\"RegionNum\":4,\"RegionCategory\":\"综合性期刊\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"MULTIDISCIPLINARY SCIENCES\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Arabian Journal for Science and Engineering","FirstCategoryId":"103","ListUrlMain":"https://link.springer.com/article/10.1007/s13369-025-10349-w","RegionNum":4,"RegionCategory":"综合性期刊","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
Cybersecurity Readiness Model Based on Human Factors
Human error is one of the leading causes of data and security breaches, as cybersecurity attackers prey on psychological manipulations to push users into performing unwanted actions or providing information. Humans act as a weak link in cyberattacks, and as a result, organizations are prone to phishing, business email compromise, and malware types of cybersecurity attacks. In this study, we identify the human-centric barriers and success factors that influence an organization's readiness to handle cybersecurity threats. Moreover, we develop a readiness model to help organizations assess and implement security practices for cybersecurity from the human factor perspective. We conducted a multivocal literature review on 120 primary studies to identify human barriers, success factors, and best practices that positively influence cybersecurity. The results show that researchers consider trust, ignorance, and a lack of technological knowledge the significant obstacles, while industry practitioners point to a lack of technological knowledge, negligence, and impulsive or reckless behavior as the primary barriers. On the other hand, knowledge, proactive awareness, and cognitive ability are the most significant success factors from both researchers’ and industry practitioners’ perspectives. We mapped the identified barriers to the CyBOK cybersecurity knowledge areas. Next, we used the identified success factors to develop a cybersecurity readiness model. The readiness model was validated by applying it to a real-world scenario using the case studies approach. This paper provides a knowledge base to develop threat prevention strategies for human factors in cybersecurity and assist organizations in devising approaches to tackle pressing security issues.
期刊介绍:
King Fahd University of Petroleum & Minerals (KFUPM) partnered with Springer to publish the Arabian Journal for Science and Engineering (AJSE).
AJSE, which has been published by KFUPM since 1975, is a recognized national, regional and international journal that provides a great opportunity for the dissemination of research advances from the Kingdom of Saudi Arabia, MENA and the world.