Pith. sign in

REVIEW 4 major objections 6 minor 299 references

MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity

T0 review · 4 major / 6 minor · reviewed 2026-08-03 · deepseek-v4-flash

Pith's one-line read Human cybersecurity failure is a system of 50 interacting factors whose 295 documented pairwise linkages fold into twelve recurring causal mechanisms.

desk verdict A genuinely useful synthesis of human-factor evidence in cybersecurity, but the causal architecture claims overreach the association-level data they actually collected. read the letter →

arxiv 2512.18303 v2 pith:BG6DYCGC submitted 2025-12-20 cs.CR cs.HC

classification cs.CRcs.HC
keywords humanfactorscybersecuritysocialengineeringphishingsusceptibilityCABmodelriskassessmentpsychometricinstrumentsinteractionmechanisms
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper sets out to replace the fragmented view of human vulnerability in cybersecurity with a single integrated map. It claims that 50 human factors—cognitive, emotional, behavioral, personality, demographic, and organizational—are not isolated traits but nodes in a dense network, and that the 295 pairwise interactions documented from the literature condense into twelve recurring mechanisms (for example, stress and fatigue forming a self-reinforcing bottleneck, and habitual repetition bypassing analytical attention). The paper further claims this network can be measured with 99 validated psychometric instruments and operationalized through risk-diagnosis scenarios, so that targeted interventions become possible where previous single-threat reviews offered only generic awareness training. A sympathetic reader would care because, if the framework holds, it gives security practitioners a common vocabulary and a concrete toolset for diagnosing why specific users or teams fail and which intervention point is most likely to interrupt the failure.

What carries the argument

The central carrying object is the hierarchical Causal Pathway Architecture: Layer 1 modulators (internal personality/demographics and external social/organizational context) set baseline thresholds; Layer 2 direct factors (the CAB triad of cognitive, emotional, behavioral states) are the proximal engine; Layer 3 is threat-specific susceptibility. The twelve interaction mechanisms—named archetypes such as the Cognitive-Emotional Bottleneck, the Habitual Autopilot Loop, and the Silence Loop—are the distillation of the 295-edge interaction network and function as the framework's explanation for how modulators and direct factors jointly produce insecure outcomes. A secondary mechanism is the se

What would settle it

Run a prospective study in a single organization: measure neuroticism, stress, cognitive fatigue, impulsivity, and shame at baseline; log every phishing click and misconfiguration for a year; then test whether the predicted moderation patterns appear—e.g., stress should amplify the fatigue-to-click link, and this amplification should weaken when communication/shame barriers are removed. If those conditional links do not show up, the twelve mechanisms reduce to a taxonomy of associations.

Watch

Extended reading notes

Core claim

MORPHEUS is proposed as a three-layer 'Causal Pathway Architecture': distal modulators (personality, demographics, social/organizational context) set the baseline; proximal direct factors in the Cognition–Affect–Behavior triad—cognitive biases, fatigue, fear, stress, impulsivity, habits—are the immediate drivers of the security action; and the behavioral outcome is susceptibility to specific threats (phishing, SMishing, spear-phishing, malware download, password management, misconfiguration), ignited by external adversarial triggers such as time pressure or persuasive tactics. On the paper's own terms, its core discovery is that this architecture is empirically grounded: 295 documented inter

Load-bearing premise

The load-bearing premise is that associations gathered from many separate studies can be read as causal pathways: Section 6 explicitly warns that unless a source establishes a causal link, interactions should be treated as statistical associations, and Section 8 concedes that the framework has not yet undergone longitudinal ecological validation—so the twelve mechanisms are hypotheses about how factors drive one another, not established causes.

Editorial extensions

If this is right

  • Security interventions should stop targeting isolated traits and instead target mechanisms—for example, breaking the habitual autopilot loop with contextual friction or breaking the silence loop by removing shame from reporting.
  • Because the same factor can be protective or risky depending on the mechanism (agreeableness aids policy compliance but invites social engineering), a one-size-fits-all training approach is predicted to underperform targeted, context-filtered interventions.
  • Risk diagnosis becomes a three-step operational procedure: filter the 50-factor map by threat and context, measure the active subset with the 99 validated instruments, then analyze feedback loops among measured factors before choosing an intervention.
  • An organization can use the framework as a monitoring protocol: repeated measurement of the same factors over time gives a concrete way to evaluate whether a security awareness program is changing vulnerability, not just attitudes.
  • The framework predicts that individual predictors of phishing susceptibility will keep looking weak unless they are studied in interaction; the unit of analysis should be the mechanism, not the isolated factor.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • My read: the abstract's '302 empirical interactions (82.8% architecture-compliant)' appears nowhere in the body, which consistently reports 295 interactions; the headline number should be reconciled against the released dataset before it is cited as a validation statistic.
  • My inference: the twelve mechanisms are testable moderator hypotheses; for example, the Cognitive-Emotional Bottleneck predicts that experimentally increasing cognitive fatigue will raise phishing click-through only when stress is also elevated, a prediction a factorial experiment could check directly.
  • My inference: the factor-to-threat table plus the interaction network could be turned into a quantitative human-risk scoring instrument—weight factors by their documented interaction degree and mechanism membership—giving organizations a reproducible per-threat risk score rather than a qualitative vignette.
  • My inference: the framework's strict separation of adversarial triggers from human factors implies a concrete design resource the paper lists as future work: a trigger-to-factor lookup table that red teams could use to choose which social-engineering tactic is most likely to ignite a given user profile.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper introduces MORPHEUS, a framework that consolidates 50 human factors associated with six cyberthreats, maps pairwise interactions among these factors, distills the resulting network into twelve 'key interaction mechanisms,' and provides an inventory of 99 psychometric instruments. The framework is built around a Cognition-Affect-Behavior (CAB) core with distal modulators categorized via Attribution Theory. The central contribution is claimed to be a hierarchical 'Causal Pathway Architecture' that reveals how cognitive, affective, and behavioral processes jointly shape security outcomes. The authors report a systematic scoping review augmented by AI-assisted screening with human-in-the-loop validation, and they present operational scenarios to illustrate the framework's applicability to risk diagnosis, intervention design, and monitoring.

Significance. If the central claims hold, MORPHEUS would be a significant contribution: it is unusually explicit about its review methodology, reporting inclusion criteria, Cohen's kappa (0.70, 0.76, 0.85), a 9.2% AI hallucination rate, and a three-step validation pipeline. The compilation of 50 factors, 295 interactions, and 99 measurement tools offers a potentially valuable reference map for human-centric cybersecurity. The twelve interaction mechanisms, if they were derived reproducibly and validated, could help researchers and practitioners move beyond single-threat, single-factor analyses. The paper also makes data and protocols available in a public repository, which supports transparency and replicability. However, the load-bearing claims of causal architecture and 'architecture compliance' are not adequately supported by the evidence presented, and there are unresolved inconsistencies between the abstract and the body. The current version therefore does not yet establish the framework's validity as a causal model.

major comments (4)
  1. [Abstract vs Section 6] The abstract claims '302 empirical interactions (82.8% architecture-compliant)' while Section 6 and Figure 1 report 295 interactions. More importantly, the 82.8% compliance statistic does not appear anywhere in the methodology (Section 3) or results. This number cannot be audited or reproduced. The authors should reconcile the discrepancy and either provide a definition, computation, and validation of 'architecture-compliant' in the body, or remove the claim from the abstract.
  2. [§6 and §4.1.3] There is a direct tension between the explicit caveat in Section 6 that 'unless a specific causal link is established by the source, these interactions should be interpreted as statistical associations' and the framework's presentation as an 'Operational Causal System' (Section 4.1.3) with the twelve mechanisms described as 'recurring causal patterns.' The current evidence base cannot support unqualified causal pathway claims. The authors should either temper the causal language throughout, or provide explicit criteria and supporting evidence for which interactions and mechanisms are causal as opposed to associative.
  3. [§4.1.2 and §4.1.3] The classification of factors into Direct Factors and Modulators is justified a priori from the CAB/Attribution architecture, and this same architecture is then used to interpret the interaction data. If the 82.8% compliance figure (abstract) is computed by checking interactions against this a priori classification, it is circular and carries no evidential weight. To avoid circularity, the authors need an independent, pre-registered coding protocol for compliance judgments, with inter-rater reliability reported for those judgments, or an explicit demonstration that the classification was not used to guide the interaction coding.
  4. [§6, Key Interaction Mechanisms] The twelve key interaction mechanisms are described as 'distilled' from the network of 295 interactions, but no reproducible method (e.g., clustering, network analysis, or formal induction) is specified. It is therefore unclear whether these mechanisms are data-driven regularities or researcher-selected archetypes. The authors should describe the extraction procedure in detail, or clearly label the mechanisms as interpretive syntheses rather than empirical findings, and indicate which sources support each mechanism.
minor comments (6)
  1. [Abstract] The interaction count discrepancy (302 vs 295) should be resolved in the final version. Also, the phrase 'distilling them into 12 recurring interaction mechanisms' overstates what can be inferred from the presented analysis.
  2. [§3.2.1] The prompts used for AI-assisted retrieval are said to be reported in 'Appendix 4', but the appendix list is not visible in the manuscript. Please ensure the prompts and full audit trail are included in the supplementary material.
  3. [Table 2] The inventory is titled '100% validated instruments,' but 'Standard Demographic Questionnaire' is not a validated psychometric instrument. Please either remove it from the validated list or clarify that demographic variables are typically measured with self-report items rather than validated scales.
  4. [§8.2 and §8.3] Mechanism numbers are inconsistent in the vignettes (e.g., Scenario B references 'Mechanism 6' for the Habitual Autopilot Loop, but in Section 6 the Habitual Autopilot Loop is Mechanism 9; Scenario C references 'Mechanism 6' for the Trust and Bias Overconfidence Trap, but that is Mechanism 7 in Section 6).
  5. [§5.1] The sentence 'The analysis is grounded in an extensive review of 50 studies' appears to be a typo; the review covered 99 publications. Please correct.
  6. [§5.3] The reference '[103]' is used for a study on password reuse, but the same citation number is also used elsewhere for other works; please check the reference numbering consistency.

Circularity Check

1 steps flagged · score 6.0 of 10

The headline 82.8% architecture-compliance statistic is not auditable and risks being definitional: the Causal Pathway Architecture is the same CAB/Attribution classification used to label factors, so the central mechanistic validation reduces to the authors' own coding.

  1. self definitional [Abstract; Section 4.1.1; Section 4.1.3; Section 6, Mechanism 1]
    "Systematically mapping 302 empirical interactions (82.8% architecture-compliant), we reveal how cognitive, affective, and behavioral processes jointly shape security outcomes... [Sec. 4.1.1] We classify factors belonging to the Cognitive, Emotional, and Behavioral dimensions as Direct Factors. [Sec. 6] Our analysis validates the hierarchical architecture of MORPHEUS, demonstrating that factors in Layer 1 (Modulators) actively dictate the operational baseline for Layer 2 (Direct Factors)."

    The architecture itself is constructed by assigning each factor to Layer 1 (Personality, Demographic, Social/Organizational) or Layer 2 (Cognitive, Emotional, Behavioral) using the CAB model and Attribution Theory. An interaction is 'architecture-compliant' exactly when it runs from the pre-assigned modulator layer to the pre-assigned direct layer. The 82.8% figure appears only in the abstract, with no coding rule, no pre-registration, and no inter-rater reliability for compliance judgments in Section 3 or Section 6. Therefore the statistic does not independently validate the architecture; it restates the authors' own a priori classification of the corpus, and Mechanism 1 then cites that same conformity as evidence.

full rationale

The paper has substantial independent empirical content: the 50-factor taxonomy, the 295-interaction corpus, and the 99-instrument inventory are drawn from external studies through a documented, human-validated screening process. Those components are not circular. The circularity is concentrated in the abstract's claim that the Causal Pathway Architecture is validated by 82.8% architecture compliance. Since the architecture is defined by the same CAB/Attribution dimensional classification used to label factors as Direct or Modulator, and since the compliance metric is never defined or audited in the body, the headline quantitative support reduces to the authors' own classification. Section 6 further states the interactions should be interpreted as statistical associations unless the source establishes causality, while the mechanisms are described as recurring causal patterns; this is an evidentiary gap rather than a definitional circle, but it compounds the problem. Because the central architectural validation reduces by construction to the classification, the score is 6; the taxonomy and instrument inventory themselves are not circular.

Assumptions & free parameters 3 free parameters · 5 assumptions · 3 invented entities

MORPHEUS has no numeric fitted parameters; its free parameters are categorical: the dimension assignments, the Direct/Modulator split, and the twelve mechanisms, all chosen by hand and then used to characterize the same corpus (e.g., the abstract's architecture-compliance statistic). The axioms are the borrowed psychological theories (CAB, Attribution Theory), the coverage assumption of a Google Scholar-only search, and the repurposing of instruments without security-context validation. The invented entities are conceptual (the architecture, the mechanisms, the trigger taxonomy) rather than physical, and none has independent empirical evidence in this paper.

free parameters (3)
  • Factor-to-dimension assignment
    Each of the 50 factors is assigned to exactly one of six dimensions; Section 4.1 notes overlaps (Risk attitude, Stress) and assigns 'the most relevant dimension as representative' by hand. The taxonomy depends on these choices.
  • Direct vs. Modulator split
    CAB-core factors are labeled Direct; Personality, Demographic, and Social/Organizational factors are labeled Modulators (Section 4.1). This split is the target of the abstract's '82.8% architecture-compliant' claim and is assumed, not derived.
  • Twelve Key Interaction Mechanisms
    Section 6 describes the mechanisms as 'representative archetypes' distilled by the authors from the same 295-interaction corpus. The selection, grouping, and naming are researcher choices, not outputs of a formal clustering or any quantitative criterion.
assumptions (5)
  • domain assumption The CAB model (Cognition-Affect-Behavior) is a valid decomposition of security-relevant psychological processing.
    Section 4.1.1 builds the Direct Factors core on Breckler [55]; no cybersecurity-context validation is given beyond citation.
  • domain assumption Heider's Attribution Theory's internal/external locus distinction maps cleanly onto Personality+Demographic (internal) vs. Social/Organizational (external) modulators.
    Section 4.1.2 asserts the mapping; the paper itself notes that demographic factors 'functionally differ' from other internal traits, weakening the clean mapping.
  • domain assumption Statistical associations from heterogeneous studies can support pathway/causal language.
    Section 6 explicitly says interactions are statistical associations unless the source establishes causality, yet the framework is named 'Causal Pathway Architecture' and the mechanisms are presented as recurring causal patterns.
  • domain assumption Google Scholar plus snowballing provides sufficient coverage of the human-factors literature for the six threats.
    Section 3.1.1 and 3.1.4; the single-engine limitation is acknowledged, and the 50-factor set is bounded by this coverage decision, compounded by excluding papers already covered by prior reviews.
  • domain assumption The 99 instruments remain valid when repurposed for cybersecurity measurement.
    Section 7 compiles instruments validated in their home domains (clinical psychology, marketing) and offers no re-validation in security contexts (e.g., OCI for compulsiveness, FQ for fear, CSII from consumer research).
invented entities (3)
  • MORPHEUS framework architecture (concentric layers, Causal Pathway Architecture)
    purpose: Organize the 50 factors, 295 interactions, 99 measurement tools, and 8 scenarios into one operational framework.
    The architecture is constructed in Sections 1 and 4; the paper states it has not undergone longitudinal ecological validation (Section 8.9). The only quantitative support, the abstract's '82.8% architecture-compliant' claim, does not appear in the body.
  • Twelve Key Interaction Mechanisms
    purpose: Distill the 295-interaction network into recurring causal archetypes (e.g., Cognitive-Emotional Bottleneck, Silence Loop, Habitual Autopilot).
    Section 6: they are 'representative archetypes' distilled from the dataset itself, with no independent out-of-sample check or empirical test.
  • Adversarial Triggers category (persuasion principles, time pressure, deceptive UI)
    purpose: Demarcate external stimuli from internal human factors to sharpen risk diagnosis.
    Section 4.2 introduces the trichotomy as a conceptual distinction; the paper's future-work section says systematic mapping of triggers to factors is still pending.

how reviews work

0 comments
Cite this review

Pith. "Pith review of MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity." pith.science (2026). https://pith.science/paper/BG6DYCGC

@misc{pith2026251218303,
  author       = {Pith},
  title        = {Pith review of: MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/BG6DYCGC}},
  note         = {Machine review of arXiv:2512.18303}
}
read the original abstract

Despite technical advancements, the human factor remains cybersecurity's most exploited vulnerability. Current research acknowledges this but remains fragmented, treating vulnerabilities as isolated, static traits. To address this, we introduce MORPHEUS, a holistic framework conceptualizing human-centric security as a dynamic, interconnected system. Grounded in the Cognition-Affect-Behavior (CAB) model and Attribution Theory, MORPHEUS consolidates 50 human factors influencing susceptibility to major cyberthreats (e.g., phishing, malware, password management, and misconfigurations). Beyond mere identification, the framework introduces a hierarchical Causal Pathway Architecture. Systematically mapping 302 empirical interactions (82.8% architecture-compliant), we reveal how cognitive, affective, and behavioral processes jointly shape security outcomes, distilling them into 12 recurring interaction mechanisms. MORPHEUS further links theory to practice through an inventory of 99 validated psychometric instruments for empirical assessment. We illustrate its applicability through in-depth operational scenarios for risk diagnosis and targeted interventions. Overall, MORPHEUS provides a comprehensive theoretical foundation for advancing human-centered cybersecurity.

Figures

Figures reproduced from arXiv: 2512.18303 by the authors.

Figure 1
Figure 1. High-level overview of the MORPHEUS Framework. The central hub organizes 𝑛 = 50 human factors across six dimensions (Cognitive, Affective, Behavioral, Personality, Demographic, Social/Organizational), distinguishing between proximal Direct Factors (aligned with the internal CAB triad: Cognition, Affect, Behavior) and distal Modulators. The core is connected to four operational layers: (Top) mapping of factors to spe… view at source ↗
Figure 2
Figure 2. The Causal Pathway Architecture of MORPHEUS. The framework distinguishes between distal [PITH_FULL_IMAGE:figures/full_fig_p014_2.png] view at source ↗
Figure 3
Figure 3. Summary of the interactions among the demographic human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p068_3.png] view at source ↗
Figures from the paper (5 more)
Figure 4
Figure 4. Figure 4: Summary of the interactions among the personality traits human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p070_4.png]
Figure 5
Figure 5. Figure 5: Summary of the interactions among the cognitive human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p072_5.png]
Figure 6
Figure 6. Figure 6: Summary of the interactions among the emotional human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p075_6.png]
Figure 7
Figure 7. Figure 7: Summary of the interactions among the behavioral human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p077_7.png]
Figure 8
Figure 8. Figure 8: Summary of the interactions among the social and organizational human factors and the other ones. [PITH_FULL_IMAGE:figures/full_fig_p078_8.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

299 extracted references · 162 canonical work pages

  1. [1]

    Mohamed Abdelhamid. 2020. The Role of Health Concerns in Phishing Susceptibility: Survey Design Study.J Med Internet Res22, 5 (4 5 2020), e18394. doi:10.2196/18394

  2. [2]

    Sherly Abraham and InduShobha Chengalur-Smith. 2010. An overview of social engineering malware: Trends, tactics, and implications.Technology in Society32, 3 (2010), 183–196. doi:10.1016/j.techsoc.2010.07.001

  3. [3]

    Hossein Abroshan, Jan Devos, Geert Poels, and Eric Laermans. 2021. COVID-19 and Phishing: Effects of Human Emotions, Behavior, and Demographics on the Success of Phishing Attempts During the Pandemic.IEEE Access9 (2021), 121916–121929. doi:10.1109/ACCESS.2021.3109091

  4. [4]

    Hossein Abroshan, Jan Devos, Geert Poels, and Eric Laermans. 2021. Phishing Happens Beyond Technology: The Effects of Human Behaviors and Demographics on Each Step of a Phishing Process.IEEE Access9 (2021), 44928–44949. doi:10.1109/ACCESS.2021.3066383

  5. [5]

    Ibrahim Abuelezz, Mohamed Barhamgi, Saeed Alshakhsi, et al. 2025. How do gender and age similarities with a potential social engineer influence one’s trust and willingness to take security risks?International Journal of Information Security24 (2025), 44. doi:10.1007/s10207-024-00954-5

  6. [6]

    Mitchell Ackerley, Ben Morrison, Kate Ingrey, Mark Wiggins, Piers Bayl-Smith, and Natalie Morrison. 2022. Errors, Irregularities, and Misdirection: Cue Utilisation and Cognitive Reflection in the Diagnosis of Phishing Emails.Australasian Journal of Information Systems26 (May 2022), 21 pages. doi:10.3127/ajis.v26i0.3615

  7. [7]

    Akshay Aggarwal and Shashi Kant Srivastava. 2024. Exploring eustress and fear: A new perspective on protection motivation in information security policy compliance within the financial sector.Computers & Security142 (2024), 103857. doi:10.1016/j.cose.2024.103857

  8. [8]

    Fawad Ahmad. 2020. Personality traits as predictor of cognitive biases: moderating role of risk-attitude.Qualitative Research in Financial Markets12, 4 (06 2020), 465–484. arXiv:https://www.emerald.com/qrfm/article-pdf/12/4/465/2869722/qrfm-10-2019-0123.pdf doi:10.1108/QRFM-10-2019-0123

Show all 299 references
  1. [9]

    Icek Ajzen. 1991. The theory of planned behavior.Organizational behavior and human decision processes50, 2 (Dec 1991), 179–211. doi:10.1016/0749- 5978(91)90020-T

  2. [10]

    Kurt, Necmettin Sezgin, and Muhittin Bayram

    Mehmet Akin, Muhammed B. Kurt, Necmettin Sezgin, and Muhittin Bayram. 2008. Estimating vigilance level by using EEG and EMG signals. Neural Computing and Applications17, 3 (01 Jun 2008), 227–236. doi:10.1007/s00521-007-0117-7

  3. [11]

    Al-Darwish and Pilsung Choe

    Ahmed I. Al-Darwish and Pilsung Choe. 2019. A Framework of Information Security Integrated with Human Factors. InHCI for Cybersecurity, Privacy and Trust: First International Conference, HCI-CPT 2019, Held as Part of the 21st HCI International Conference, HCII 2019, Orlando, F...

  4. [12]

    Al-Karaki, Amjad Gawanmeh, and Sanaa El-Yassami

    Jamal N. Al-Karaki, Amjad Gawanmeh, and Sanaa El-Yassami. 2022. GoSafe: On the practical characterization of the overall security posture of an organization information system using smart auditing and ranking.Journal of King Saud University - Computer and Information Sciences3...

  5. [13]

    Ahmed Aleroud, Emad Abu-Shanab, Ahmad Al-Aiad, and Yazan Alshboul. 2020. An examination of susceptibility to spear phishing cyber attacks in non-English speaking communities.Journal of Information Security and Applications55 (2020), 102614. doi:10.1016/j.jisa.2020.102614

  6. [14]

    Mohamad Alhaddad, Masnizah Mohd, Faizan Qamar, and Mohsin Imam. 2023. Study of Student Personality Trait on Spear-Phishing Susceptibility Behavior.International Journal of Advanced Computer Science and Applications14 (01 2023). doi:10.14569/IJACSA.2023.0140571

  7. [15]

    Mathias Allemand, Daniel Zimprich, and Arne A. J. Hendriks. 2008. Age differences in five personality domains across the life span.Developmental Psychology44, 3 (2008), 758–770. doi:10.1037/0012-1649.44.3.758

  8. [16]

    Natalie J Allen and John P Meyer. 1990. The measurement and antecedents of affective, continuance and normative commitment to the organization. Journal of occupational psychology63, 1 (1990), 1–18

  9. [17]

    Kenneth Allendoerfer, Shantanu Pai, et al. 2005. Human Factors Considerations for Passwords and Other User Identification Techniques—Part 1: Literature Review and Analysis. https://rosap.ntl.bts.gov/view/dot/71678/dot_71678_DS1.pdf

  10. [18]

    Jonathan Allsop and Rob Gray. 2014. Flying under pressure: Effects of anxiety on attention and gaze behavior in aviation.Journal of Applied Research in Memory and Cognition3, 2 (June 2014), 63–71. doi:10.1016/j.jarmac.2014.04.010

  11. [19]

    Hossam Almahasneh, Weng-Tink Chooi, Nidal Kamel, and Aamir Saeed Malik. 2014. Deep in thought while driving: An EEG study on drivers’ cognitive distraction.Transportation Research Part F: Traffic Psychology and Behaviour26 (2014), 218–226. doi:10.1016/j.trf.2014.08.001

  12. [20]

    Zafer Alqarni, Abdullah Algarni, and Yue Xu. 2016. Toward Predicting Susceptibility to Phishing Victimization on Facebook. In2016 IEEE International Conference on Services Computing (SCC). IEEE, New York, NY, USA, 419–426. doi:10.1109/SCC.2016.61

  13. [21]

    Carlos Alós-Ferrer, Michele Garagnani, and Sabine Hügelschäfer. 2016. Cognitive Reflection, Decision Biases, and Response Times.Frontiers in PsychologyVolume 7 - 2016 (2016), 21 pages. doi:10.3389/fpsyg.2016.01402

  14. [22]

    Amin et al

    Basheer E. Amin et al. 2024. Technostress Impact on Educator Productivity: Gender Differences in Jordan’s Higher Education.Electronic Journal of e-Learning22, 8 (2024), 60–75. doi:10.34190/ejel.22.8.3608

  15. [23]

    Brock Kirwan, Jeffrey L

    Bonnie Brinton Anderson, C. Brock Kirwan, Jeffrey L. Jenkins, David Eargle, Seth Howard, and Anthony Vance. 2015. How Polymorphic Warnings Reduce Habituation in the Brain: Insights from an fMRI Study. InProceedings of the 33rd Annual ACM Conference on Human Factors in Computin...

  16. [24]

    Valentine

    Bernice Andrews, Mingyi Qian, and John D. Valentine. 2002. Predicting depressive symptoms with a new measure of shame: The Experience of Shame Scale.British Journal of Clinical Psychology41, 1 (2002), 29–42. arXiv:https://bpspsychub.onlinelibrary.wiley.com/doi/pdf/10.1348/0144...

  17. [25]

    Mohd Anwar, Wu He, Ivan Ash, Xiaohong Yuan, Ling Li, and Li Xu. 2017. Gender difference and employees’ cybersecurity behaviors.Computers in Human Behavior69 (2017), 437–443. doi:10.1016/j.chb.2016.12.040

  18. [26]

    Nalin Asanka Gamagedara Arachchilage and Steve Love. 2014. Security awareness of computer users: A phishing threat avoidance perspective. Computers in Human Behavior38 (2014), 304–312. doi:10.1016/j.chb.2014.05.046

  19. [27]

    Andrade, and Milton Macas

    David Arévalo, Daniel Valarezo, William Fuertes, Maria Fernanda Cazares, Ricardo O. Andrade, and Milton Macas. 2023. Human and Cognitive Factors involved in Phishing Detection: A Literature Review. InProceedings of the 2023 Congress in Computer Science, Computer Engineering, &...

  20. [28]

    Ibrahim Arpaci and Ersin Ateş. 2022. Development of the cybercrime awareness scale (CAS): a validity and reliability study in a Turkish sample.Online Information Review47, 4 (09 2022), 633–643. arXiv:https://www.emerald.com/oir/article-pdf/47/4/633/2117459/oir-01-2022-0023.pdf...

  21. [29]

    Sutin, Martina Luchetti, Yannick Stephan, Oliver Schilling, Hans-Werner Wahl, Gabriel Olaru, and Antonio Terracciano

    Damaris Aschwanden, Mathias Allemand, Matthias Kliegel, Angelina R. Sutin, Martina Luchetti, Yannick Stephan, Oliver Schilling, Hans-Werner Wahl, Gabriel Olaru, and Antonio Terracciano. 2025. Longitudinal associations between personality traits and cognitive complaints in midl...

  22. [30]

    Capa, Nicolas Silvestrini, James Steele, Sabrina Ravel, and Benjamin Pageaux

    Michel Audiffren, Rémi L. Capa, Nicolas Silvestrini, James Steele, Sabrina Ravel, and Benjamin Pageaux. 2023. Editorial: Effort-based decision-making and cognitive fatigue.Frontiers in NeuroscienceVolume 17 - 2023 (2023), 4 pages. doi:10.3389/fnins.2023.1230022

  23. [31]

    Mitja D Back, Albrecht CP Küfner, Michael Dufner, Tanja M Gerlach, John F Rauthmann, and Jaap JA Denissen. 2013. Narcissistic admiration and rivalry: disentangling the bright and dark sides of narcissism.Journal of personality and social psychology105, 6 (2013), 1013. doi:10.1...

  24. [32]

    Nour Mohammad Bakhshani. 2014. Impulsivity: A Predisposition Toward Risky Behaviors.International journal of high risk behaviors & addiction3 (06 2014), e20428. doi:10.5812/ijhrba.20428

  25. [33]

    Baldwin, John R

    Kim M. Baldwin, John R. Baldwin, and Thomas Ewald. 2006. The Relationship among Shame, Guilt, and Self-Efficacy.American Journal of Psychotherapy60, 1 (2006), 1–21. doi:10.1176/appi.psychotherapy.2006.60.1.1

  26. [34]

    Barlow, Kristen K

    David H. Barlow, Kristen K. Ellard, Shannon Sauer-Zavala, Jacqueline R. Bullis, and Jenna R. Carl. 2014. The Origins of Neuroticism.Perspectives on Psychological Science9, 5 (2014), 481–496. arXiv:https://doi.org/10.1177/1745691614544528 doi:10.1177/1745691614544528 PMID: 26186755

  27. [35]

    Mathias Basner and David F. Dinges. 2011. Maximizing Sensitivity of the Psychomotor Vigilance Test (PVT) to Sleep Loss.Sleep34, 5 (05 2011), 581–591. arXiv:https://academic.oup.com/sleep/article-pdf/34/5/581/13665943/aasm.34.5.581.pdf doi:10.1093/sleep/34.5.581

  28. [36]

    Beck, Norman Epstein, Gary Brown, and Robert Steer

    Aaron T. Beck, Norman Epstein, Gary Brown, and Robert Steer. 1988. Beck Anxiety Inventory. doi:10.1037/t02025-000 [Database record]. APA PsycTests

  29. [37]

    Tom Beckers, Dirk Hermans, Iris Lange, Laura Luyten, Sara Scheveneels, and Bram Vervliet. 2023. Understanding clinical fear and anxiety through the lens of human fear conditioning.Nature Reviews Psychology2, 4 (2023), 233–245. doi:10.1038/s44159-023-00156-1

  30. [38]

    Zinaida Benenson, Freya Gassmann, and Robert Landwirth. 2017. Unpacking Spear Phishing Susceptibility. InProceedings of the Financial Cryptography and Data Security Workshops Malta. Springer, Cham, Switzerland, 610–627. doi:10.1007/978-3-319-70278-0_39

  31. [39]

    Chris Berka, Daniel J Levendowski, Michelle N Lumicao, Alan Yau, Gene Davis, Vladimir T Zivkovic, Richard E Olmstead, Patrice D Tremoulet, and Patrick L Craven. 2007. EEG correlates of task engagement and mental workload in vigilance, learning, and memory tasks.A viation, spac...

  32. [40]

    Vincent Berthet. 2021. The Measurement of Individual Differences in Cognitive Biases: A Review and Improvement.Frontiers in PsychologyVolume 12 - 2021 (2021), 12 pages. doi:10.3389/fpsyg.2021.630177

  33. [41]

    Shadi Beshai, Keith S Dobson, Claudi LH Bockting, and Leanne Quigley. 2011. Relapse and recurrence prevention in depression: current research and future prospects.Clinical psychology review31, 8 (2011), 1349–1360

  34. [42]

    Sonia J. Bishop. 2009. Trait anxiety and impoverished prefrontal control of attention.Nature Neuroscience12, 1 (January 2009), 92–98. doi:10.1038/ nn.2242

  35. [43]

    Ann-Renée Blais and Elke U Weber. 2006. A Domain-Specific Risk-Taking (DOSPERT) Scale for Adult Populations.Judgment and Decision making 1, 1 (February 2006), 33–47. doi:10.1017/S1930297500000334

  36. [44]

    Ann-Renee Blais and Elke U. Weber. 2006. Domain-Specific Risk-Taking Scale (DOSPERT). doi:10.1037/t13084-000 [Database record]. APA PsycTests

  37. [45]

    Jim Blythe, Jean Camp, and Vaibhav Garg. 2011. Targeted risk communication for computer security. InProceedings of the 16th International Conference on Intelligent User Interfaces(Palo Alto, CA, USA)(IUI ’11). Association for Computing Machinery, New York, NY, USA, 295–298. do...

  38. [46]

    Bodala, Nida I

    Indu P. Bodala, Nida I. Abbasi, Yu Sun, Anastasios Bezerianos, Hasan Al-Nashash, and Nitish V. Thakor. 2017. Measuring vigilance decrement using computer vision assisted eye tracking in dynamic naturalistic environments. In39th Annual International Conference of the IEEE Engin...

  39. [47]

    Henk Boer and Erwin R. Seydel. 1996. Protection motivation theory. InPredicting Health Behaviour: Research and Practice with Social Cognition Models, Mark Conner and Paul Norman (Eds.). Open University Press, Maidenhead, UK, 95–120

  40. [48]

    Tim Bogg and Brent W Roberts. 2013. The case for conscientiousness: Evidence and implications for a personality trait marker of health and longevity.Annals of Behavioral Medicine45, 3 (2013), 278–288

  41. [49]

    Botvinick, Todd S

    Matthew M. Botvinick, Todd S. Braver, Deanna M. Barch, Cameron S. Carter, and Jonathan D. Cohen. 2001. Conflict monitoring and cognitive control.Psychological Review108, 3 (2001), 624–652. doi:10.1037/0033-295X.108.3.624 Manuscript submitted to ACM MORPHEUS: A Multidimensional...

  42. [50]

    Alain Bouche, Bénédicte Poulin-Charronnat, and Romuald Lepers. 2025. Mental fatigue in older adults: A narrative review of subjective, behavioral, neurophysiological, and physical changes.Archives of Gerontology and Geriatrics138 (2025), 105950. doi:10.1016/j.archger.2025.105950

  43. [51]

    Dusica Bozovic, Maja Racic, and Natasa Ivkovic. 2013. Salivary cortisol levels as a biological marker of stress reaction.Medical Archives (Sarajevo, Bosnia and Herzegovina)67, 5 (2013), 374–377. doi:10.5455/medarh.2013.67.374-377

  44. [52]

    Brandt, C

    N.D. Brandt, C. Savage, B.W. Roberts, J. Baumert, and J. Wagner. 2022. Who do you trust? The role of level and change in trust and personality across young to middle adulthood for political interest and voting intentions.Journal of Research in Personality101 (2022), 104288. do...

  45. [53]

    Dawn Branley-Bell, Lynne Coventry, Matt Dixon, Adam Joinson, and Pam Briggs. 2022. Exploring Age and Gender Differences in ICT Cybersecurity Behaviour.Human Behavior and Emerging Technologies2022, 1 (2022), 2693080. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1155/2022/26...

  46. [54]

    Pablo Brañas-Garza, Praveen Kujal, and Balint Lenkei. 2019. Cognitive reflection test: Whom, how, when.Journal of Behavioral and Experimental Economics82 (2019), 101455. doi:10.1016/j.socec.2019.101455

  47. [55]

    Steven Breckler. 1985. Empirical validation of affect, behavior, and cognition as distinct components of attitude. Journal of Personality and Social Psychology, 47, 1191-1205.Journal of personality and social psychology47 (01 1985), 1191–205. doi:10.1037//0022-3514.47.6.1191

  48. [56]

    Linda Brennan and Wayne Binney. 2010. Fear, guilt, and shame appeals in social marketing.Journal of Business Research63, 2 (2010), 140–146. doi:10.1016/j.jbusres.2009.02.006 Advances in spreadsheet and database training

  49. [57]

    Broadbent, P

    Donald E. Broadbent, P. F. Cooper, Paul FitzGerald, and Katharine R. Parkes. 1982. The cognitive failures questionnaire (CFQ) and its correlates. British Journal of Clinical Psychology21, 1 (1982), 1–16. doi:10.1111/j.2044-8260.1982.tb01421.x

  50. [58]

    Kirk Warren Brown and Richard M. Ryan. 2003. Mindful Attention Awareness Scale (MAAS). doi:10.1037/t04259-000 [Database record]. APA PsycTests

  51. [59]

    Parker, and Baruch Fischhoff

    Wändi Bruine de Bruin, Andrew M. Parker, and Baruch Fischhoff. 2007. Individual differences in adult decision-making competence.Journal of Personality and Social Psychology92, 5 (2007), 938–956. doi:10.1037/0022-3514.92.5.938

  52. [60]

    2016.Cyber Situational A wareness Testing

    Joel Brynielsson, Ulrik Franke, and Stefan Varga. 2016.Cyber Situational A wareness Testing. Springer International Publishing, Cham, 209–233. doi:10.1007/978-3-319-38930-1_12

  53. [61]

    Buckley, D

    J. Buckley, D. Lottridge, J.G. Murphy, and P.M. Corballis. 2023. Indicators of employee phishing email behaviours: Intuition, elaboration, attention, and email typology.International Journal of Human-Computer Studies172 (2023), 102996. doi:10.1016/j.ijhcs.2023.102996

  54. [62]

    Yohanes Budiarto and Avin Fadilla Helmi. 2021. Shame and self-esteem: A meta-analysis.Europe’s journal of psychology17, 2 (2021), 131. doi:10.5964/ejop.2115

  55. [63]

    Sanja Budimir, Johnny R. J. Fontaine, Nathalie M. A. Huijts, Antal Haans, George Loukas, and Etienne B. Roesch. 2021. Emotional Reactions to Cybersecurity Breach Situations: Scenario-Based Survey Study.Journal of Medical Internet Research23, 5 (2021), e24879. doi:10.2196/24879

  56. [64]

    Jan-Willem Bullee, Lorena Montoya, Marianne Junger, and Pieter Hartel. 2017. Spear phishing in organisations explained.Information & Computer Security25, 5 (2017), 593–613. doi:10.1108/ICS-03-2017-0009

  57. [65]

    A. J. Burns, M. Eric Johnson, and Deanna D. Caputo. 2019. Spear phishing in a barrel: Insights from a targeted phishing campaign.Journal of Organizational Computing and Electronic Commerce29, 1 (2019), 24–39. arXiv:https://doi.org/10.1080/10919392.2019.1552745 doi:10.1080/1091...

  58. [66]

    Marcus Butavicius, Kathryn Parsons, Malcolm Pattinson, and Agata McCormac. 2015. Breaching the Human Firewall: Social Engineering in Phishing and Spear-Phishing Emails. InProceedings of the Australasian Conference on Information Systems (ACIS 2015). Australasian Association fo...

  59. [67]

    Marcus Butavicius, Ronnie Taib, and Simon J. Han. 2022. Why people keep falling for phishing scams: The effects of time pressure and deception cues on the detection of phishing emails.Computers & Security123 (2022), 102937. doi:10.1016/j.cose.2022.102937

  60. [68]

    Keith Campbell, Adam S

    W. Keith Campbell, Adam S. Goodie, and Joshua D. Foster. 2004. Narcissism, confidence, and risk attitude.Journal of Behavioral Decision Making 17, 4 (2004), 297–311. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1002/bdm.475 doi:10.1002/bdm.475

  61. [69]

    Canfield, Baruch Fischhoff, and Alex Davis

    Caitlin I. Canfield, Baruch Fischhoff, and Alex Davis. 2019. Correction to: Better beware: comparing metacognition for phishing and legitimate emails.Metacognition and Learning14 (2019), 363. doi:10.1007/s11409-019-09205-8

  62. [70]

    R Nicholas Carleton, MA Peter J Norton, and Gordon JG Asmundson. 2007. Fearing the unknown: A short version of the Intolerance of Uncertainty Scale.Journal of anxiety disorders21, 1 (2007), 105–117. doi:10.1016/j.janxdis.2006.03.014

  63. [71]

    Shelly Chaiken. 1980. Heuristic versus systematic information processing and the use of source versus message cues in persuasion.Journal of Personality and Social Psychology39 (1980), 752–766. Issue 5. doi:10.1037/0022-3514.39.5.752

  64. [72]

    Li Chen, Zhi Xie, Jia Zhen, and Kai Dong. 2022. The Impact of Challenge Information Security Stress on Information Security Policy Compliance: The Mediating Roles of Emotions.Psychology Research and Behavior Management15 (2022), 1177–1191. doi:10.2147/PRBM.S359277

  65. [73]

    Wei Lee Yuan Chen. 2024. Towards More Secure Interactions: Understanding User Experience and Behaviour in the NFT Domain. InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems(Honolulu, HI, USA)(CHI EA ’24). Association for Computing Machinery, New Y...

  66. [74]

    Xiaowei Chen, Sophie Doublet, Anastasia Sergeeva, Gabriele Lenzini, Vincent Koenig, and Verena Distler. 2024. What motivates and discourages employees in phishing interventions: an exploration of expectancy-value theory. InProceedings of the Twentieth USENIX Conference on Usab...

  67. [75]

    Xiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff, Verena Distler, and Anastasia Sergeeva. 2024. The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design Experiment. InP...

  68. [76]

    Lijiao Cheng, Ying Li, Wenli Li, Eric Holm, and Qingguo Zhai. 2013. Understanding the violation of IS security policy in organizations: An integrated model based on social control and deterrence theory.Computers & Security39 (2013), 447–459. doi:10.1016/j.cose.2013.09.009

  69. [77]

    Carriere, and Daniel Smilek

    James Allan Cheyne, Jonathan S.A. Carriere, and Daniel Smilek. 2006. Absent-mindedness: Lapses of conscious awareness and everyday cognitive failures.Consciousness and Cognition15, 3 (2006), 578–592. doi:10.1016/j.concog.2005.11.009

  70. [78]

    Heeyoung Choi, Sangun Park, and Juyoung Kang. 2024. Enhancing Participatory Security Culture in Public Institutions: An Analysis of Organizational Employees’ Security Threat Recognition Processes.IEEE Access12 (2024), 47543–47558. doi:10.1109/ACCESS.2024.3383311

  71. [79]

    Yee-Yin Choong. 2014. A Cognitive-Behavioral Framework of User Password Management Lifecycle. InHuman Aspects of Information Security, Privacy, and Trust, Theo Tryfonas and Ioannis Askoxylakis (Eds.). Springer International Publishing, Cham, 127–137

  72. [80]

    Frank Kun-Yueh Chou, Abbott Po-Shun Chen, and Vincent Cheng-Lung Lo. 2021. Mindless Response or Mindful Interpretation: Examining the Effect of Message Influence on Phishing Susceptibility.Sustainability13, 4 (2021), 25 pages. doi:10.3390/su13041651

  73. [81]

    Chowdhury, Marc T.P

    Noman H. Chowdhury, Marc T.P. Adam, and Timm Teubner. 2020. Time pressure in human cybersecurity behavior: Theoretical framework and countermeasures.Computers & Security97 (2020), 101963. doi:10.1016/j.cose.2020.101963

  74. [82]

    1993.Influence: Science and Practice

    Robert Cialdini. 1993.Influence: Science and Practice. HarperCollins College Publishers, New York, NY, US

  75. [83]

    Robert Cialdini and Noah Goldstein. 2004. Social Influence: Compliance and Conformity.Annual review of psychology55 (02 2004), 591–621. doi:10.1146/annurev.psych.55.090902.142015

  76. [84]

    Cialdini, Carl A

    Robert B. Cialdini, Carl A. Kallgren, and Raymond R. Reno. 1991. A Focus Theory of Normative Conduct: A Theoretical Refinement and Reevaluation of the Role of Norms in Human Behavior. InAdvances in Experimental Social Psychology, Mark P. Zanna (Ed.). Vol. 24. Academic Press, S...

  77. [85]

    2025.Rapporto Clusit 2025 sulla sicurezza ICT in Italia (Aggiornamento di Ottobre)

    Clusit. 2025.Rapporto Clusit 2025 sulla sicurezza ICT in Italia (Aggiornamento di Ottobre). Technical Report. Associazione Italiana per la Sicurezza Informatica, Milano. https://clusit.it/rapporto-clusit/ Analisi specifica degli attacchi in Italia nel primo semestre 2025

  78. [86]

    Sheldon Cohen, Tom Kamarck, and Robin Mermelstein. 1983. A Global Measure of Perceived Stress.Journal of Health and Social Behavior24, 4 (1983), 385–396. doi:10.2307/2136404

  79. [87]

    Sheldon Cohen, Tom Kamarck, and Robin Mermelstein. 1983. Perceived Stress Scale [Database record]. doi:10.1037/t02889-000

  80. [88]

    Steven Cook, Luca Giommoni, Nicolas Trajtenberg Pareja, Michael Levi, and Matthew L Williams. 2022. Fear of Economic Cyber- crime Across Europe: A Multilevel Application of Routine Activity Theory.The British Journal of Criminology63, 2 (05 2022), 384–406. arXiv:https://academ...

  81. [89]

    2017.A codebook for experimental research: The nifty nine indicators v1

    KP Coopamootoo and T Groß. 2017.A codebook for experimental research: The nifty nine indicators v1. Technical Report. 0. Technical Report TR-1514, Newcastle University

  82. [90]

    Un-Equal Online Safety?

    Kovila P.L. Coopamootoo and Magdalene Ng. 2023. "Un-Equal Online Safety?" A Gender Analysis of Security and Privacy Protection Advice and Behaviour Patterns. In32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 5611–5628. https: //www.usenix....

  83. [91]

    Kovila P. L. Coopamootoo and Thomas Groß. 2016.Evidence-Based Methods for Privacy and Identity Management. Springer International Publishing, Cham, 105–121. doi:10.1007/978-3-319-55783-0_9

  84. [92]

    Costa, Paul T

    Jr. Costa, Paul T. and Robert R. McCrae. 2008. The Revised NEO Personality Inventory (NEO-PI-R). InThe SAGE Handbook of Personality Theory and Assessment, Gregory J. Boyle, Gerald Matthews, and Donald H. Saklofske (Eds.). Vol. 2. Sage Publications, Inc., Thousand Oaks, CA, 179...

  85. [93]

    Costa, Paul T., Antonio Terracciano, and Robert R

    Jr. Costa, Paul T., Antonio Terracciano, and Robert R. McCrae. 2001. Gender differences in personality traits across cultures: Robust and surprising findings.Journal of Personality and Social Psychology81, 2 (2001), 322–331. doi:10.1037/0022-3514.81.2.322

  86. [94]

    Paul Costa and R.R. McCrae. 1999. A five-factor theory of personality.The Five-Factor Model of Personality: Theoretical Perspectives2 (01 1999), 51–87

  87. [95]

    Coutlee, Craig S

    Christopher G. Coutlee, Craig S. Politzer, Rick H. Hoyle, and Scott A. Huettel. 2014. An Abbreviated Impulsiveness Scale constructed through confirmatory factor analysis of the Barratt Impulsiveness Scale Version 11.Archives of Scientific Psychology2, 1 (2014), 1–12. doi:10.10...

  88. [96]

    Lorrie Faith Cranor. 2008. A framework for reasoning about the human in the loop. InProceedings of the 1st Conference on Usability, Psychology, and Security(San Francisco, California)(UPSEC’08). USENIX Association, USA, Article 1, 15 pages

  89. [97]

    Giuseppe Craparo, Raffaele Messina, Saverio Severino, Serena Fasciano, Vincenzo Cannella, Alessio Gori, Maria Cacioppo, and Roberto Baiocco

  90. [98]

    James Croft, Jessica Grisham, Andrew Perfors, and Brett Hayes. 2021. Risking Everything in Obsessive–Compulsive Disorder: An Analogue Decision-Making Study.Journal of Psychopathology and Behavioral Assessment44 (11 2021), 364–375. doi:10.1007/s10862-021-09901-3

  91. [99]

    Dámaris Cuadrado, Inmaculada Otero, Alexandra Martínez, Tania París, and Silvia Moscoso. 2024. Predicting technostress: The Big Five model of personality and subjective well-being.PLOS ONE19, 11 (11 2024), 1–18. doi:10.1371/journal.pone.0313247 Manuscript submitted to ACM MORP...

  92. [100]

    Curtis, Prashanth Rajivan, Daniel N

    Shelby R. Curtis, Prashanth Rajivan, Daniel N. Jones, and Cleotilde Gonzalez. 2018. Phishing attempts among the dark triad: Patterns of attack and vulnerability.Computers in Human Behavior87 (2018), 174–182. doi:10.1016/j.chb.2018.05.037

  93. [101]

    Brian Cusack and Kolade Adedokun. 2018. The impact of personality traits on user’s susceptibility to social engineering attacks. InProceedings of the 16th Australian Information Security Management Conference. Edith Cowan University, Perth, Australia, 83–89. doi:10.25958/5c528ffa66693

  94. [102]

    Therdpong Daengsi, Phisit Pornpongtechavanich, and Pongpisit Wuttidittachotti. 2022. Cybersecurity Awareness Enhancement: A Study of the Effects of Age and Gender of Thai Employees Associated with Phishing Attacks.Education and Information Technologies27, 4 (May 2022), 4729–47...

  95. [103]

    Anupam Das, Joseph Bonneau, Matthew Caesar, Nikita Borisov, and Xiaofeng Wang. 2014. The Tangled Web of Password Reuse. InProceedings of the Network and Distributed System Security Symposium (NDSS 2014). Internet Society, San Diego, CA, USA, 15 pages. doi:10.14722/ndss.2014.23357

  96. [104]

    Dabbish, and Jason I

    Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, and Jason I. Hong. 2014. The Effect of Social Influence on Security Sensitivity. In10th Symposium On Usable Privacy and Security (SOUPS 2014). USENIX Association, Menlo Park, CA, 143–157. https://www.usenix.org/conference/ so...

  97. [105]

    Davis, Gordon L

    Richard A. Davis, Gordon L. Flett, and Avi Besser. 2002. Validation of a New Scale for Measuring Problematic Internet Use: Implications for Pre-employment Screening.CyberPsychology & Behavior5, 4 (2002), 331–345. doi:10.1089/109493102760275581

  98. [106]

    Jessica Dawson and Robert Thomson. 2018. The Future Cybersecurity Workforce: Going Beyond Technical Skills for Successful Cyber Performance. Frontiers in PsychologyVolume 9 - 2018 (2018), 12 pages. doi:10.3389/fpsyg.2018.00744

  99. [107]

    Marco De Bona and Federica Paci. 2020. A real world study on employees’ susceptibility to phishing attacks. InProceedings of the 15th International Conference on A vailability, Reliability and Security(Virtual Event, Ireland)(ARES ’20). Association for Computing Machinery, New...

  100. [108]

    de Vries

    Reinout E. de Vries. 2013. The 24-item Brief HEXACO Inventory (BHI).Journal of Research in Personality47, 6 (2013), 871–880. doi:10.1016/j.jrp. 2013.09.003

  101. [109]

    Paul L de Zwart, Bertus F Jeronimus, and Peter de Jonge. 2019. Empirical evidence for definitions of episode, remission, recovery, relapse and recurrence in depression: a systematic review.Epidemiology and psychiatric sciences28, 5 (2019), 544–562. doi:10.1017/S2045796018000227

  102. [110]

    Ana Teresa Delso-Vicente, Laura Diaz-Marcos, Oscar Aguado-Tevar, et al. 2025. Factors influencing employee compliance with information security policies: a systematic literature review of behavioral and technological aspects in cybersecurity.Future Business Journal11 (2025), 2...

  103. [111]

    Ferro, Andrea Marrella, Tiziana Catarci, and Maria Francesca Costabile

    Giuseppe Desolda, Lauren S. Ferro, Andrea Marrella, Tiziana Catarci, and Maria Francesca Costabile. 2021. Human Factors in Phishing Attacks: A Systematic Literature Review.ACM Comput. Surv.54, 8, Article 173 (Oct. 2021), 35 pages. doi:10.1145/3469886

  104. [112]

    Colin G. DeYoung. 2015. Cybernetic Big Five Theory.Journal of Research in Personality56 (2015), 33–58. doi:10.1016/j.jrp.2014.07.004 Integrative Theories of Personality

  105. [113]

    Pierluigi Diotaiuti, Stefania Mancone, Stefano Corrado, Alfredo De Risio, Elisa Cavicchiolo, Laura Girelli, and Andrea Chirico. 2022. Internet addiction in young adults: The role of impulsivity and codependency.Frontiers in PsychiatryVolume 13 - 2022 (2022), 13 pages. doi:10.3...

  106. [114]

    Verena Distler. 2023. The Influence of Context on Response to Spear-Phishing Attacks: an In-Situ Deception Study. InProceedings of the 2023 CHI Conference on Human Factors in Computing Systems. Association for Computing Machinery, Hamburg, Germany, 1–18. doi:10.1145/3544548.35...

  107. [115]

    Jie Dong, Tingwei Xiao, Qiuyue Xu, Fei Liang, Simeng Gu, Fushun Wang, and Jason H. Huang. 2022. Anxious Personality Traits: Perspectives from Basic Emotions and Neurotransmitters.Brain Sciences12, 9 (2022), 16 pages. doi:10.3390/brainsci12091141

  108. [116]

    Wen Dong, Hui Tang, Shan Wu, et al. 2024. The effect of social anxiety on teenagers’ internet addiction: the mediating role of loneliness and coping styles.BMC Psychiatry24 (2024), 395. doi:10.1186/s12888-024-05854-5

  109. [117]

    Downs, Mandy Holbrook, and Lorrie Faith Cranor

    Julie S. Downs, Mandy Holbrook, and Lorrie Faith Cranor. 2007. Behavioral response to phishing risk. InProceedings of the Anti-Phishing Working Groups 2nd Annual ECrime Researchers Summit(Pittsburgh, Pennsylvania, USA)(eCrime ’07). Association for Computing Machinery, New York...

  110. [118]

    Gordon Dupont. 1997. The dirty dozen errors in maintenance. InThe 11th symposium on human factors in maintenance and inspection: Human error in aviation maintenance. Transport Canada, Vancouver, Canada, 1–12

  111. [119]

    Sergiu Eftimie, Radu Moinescu, and Ciprian Răcuciu. 2022. Spear-Phishing Susceptibility Stemming From Personality Traits.IEEE Access10 (2022), 73548–73561. doi:10.1109/ACCESS.2022.3190009

  112. [120]

    Serge Egelman and Eyal Peer. 2015. Scaling the Security Wall: Developing a Security Behavior Intentions Scale (SeBIS). InProceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems(Seoul, Republic of Korea)(CHI ’15). ACM, New York, NY, USA, 2873—-2882. ...

  113. [121]

    Robert Eisenberger, Robin Huntington, Steven Hutchison, and Debora Sowa. 1986. Perceived organizational support.Journal of Applied psychology 71, 3 (1986), 500–507. doi:10.1037/0021-9010.71.3.500

  114. [122]

    Mica R. Endsley. 1995. Measurement of Situation Awareness in Dynamic Systems.Human Factors37, 1 (1995), 65–84. arXiv:https://doi.org/10.1518/001872095779049499 doi:10.1518/001872095779049499

  115. [123]

    2025.ENISA Threat Landscape 2025

    European Union Agency for Cybersecurity (ENISA). 2025.ENISA Threat Landscape 2025. Technical Report. ENISA. https://www.enisa.europa.eu/ publications/enisa-threat-landscape-2025 Identifica Social Engineering e Malware come minacce top per l’UE. Manuscript submitted to ACM 46 D...

  116. [124]

    Michael Fagan, Yusuf Albayram, Mohammad Maifi Khan, and Ross Buck. 2017. An investigation into users’ considerations towards using password managers.Hum.-Centric Comput. Inf. Sci.7, 1, Article 93 (Dec. 2017), 20 pages. doi:10.1186/s13673-017-0093-6

  117. [125]

    Li fang Zhang. 2006. Thinking styles and the big five personality traits revisited.Personality and Individual Differences40, 6 (2006), 1177–1187. doi:10.1016/j.paid.2005.10.011

  118. [126]

    Sahar Farshadkhah, Craig Van Slyke, and Bryan Fuller. 2021. Onlooker effect and affective responses in information security violation mitigation. Computers & Security100 (2021), 102082. doi:10.1016/j.cose.2020.102082

  119. [127]

    F B Fatokun, S Hamid, A Norman, and J O Fatokun. 2019. The Impact of Age, Gender, and Educational level on the Cybersecurity Behaviors of Tertiary Institution Students: An Empirical investigation on Malaysian Universities.Journal of Physics: Conference Series1339, 1 (dec 2019)...

  120. [128]

    Ana Ferreira, Lynne Coventry, and Gabriele Lenzini. 2015. Principles of persuasion in social engineering and their use in phishing. InInternational Conference on Human Aspects of Information Security, Privacy, and Trust. Springer, Cham, Switzerland, 36–47

  121. [129]

    John Fleenor. 2023. Big five personality traits. InThe SAGE Encyclopedia of Leadership Studies. Vol. 2. SAGE Publications, Inc., Thousand Oaks, CA, US. doi:10.4135/9781071840801.n24

  122. [130]

    Edna B Foa, Jonathan D Huppert, Susanne Leiberg, Robert Langner, Rafael Kichic, Greg Hajcak, and Paul M Salkovskis. 2002. The Obsessive- Compulsive Inventory: development and validation of a short version.Psychological assessment14, 4 (2002), 485–496. doi:10.1037/1040-3590.14.4.485

  123. [131]

    Edwin Donald Frauenstein and Stephen Flowerday. 2020. Susceptibility to phishing on social network sites: A personality information processing model.Computers & Security94 (2020), 101862. doi:10.1016/j.cose.2020.101862

  124. [132]

    Shane Frederick. 2005. Cognitive Reflection and Decision Making.Journal of Economic Perspectives19, 4 (December 2005), 25–42. doi:10.1257/ 089533005775196732

  125. [133]

    Carlo Galli, Anna V Gavrilova, and Elena Calciolari. 2025. Large Language Models in Systematic Review Screening: Opportunities, Challenges, and Methodological Considerations.Information16, 5 (2025), 378

  126. [134]

    Luigi Gallo, Danilo Gentile, Saverio Ruggiero, Alessio Botta, and Giorgio Ventre. 2024. The human factor in phishing: Collecting and analyzing user behavior when reading emails.Computers & Security139 (2024), 103671. doi:10.1016/j.cose.2023.103671

  127. [135]

    Malgorzata Gambin and Carla Sharp. 2018. The relations between empathy, guilt, shame and depression in inpatient adolescents.Journal of Affective Disorders241 (2018), 381–387. doi:10.1016/j.jad.2018.08.068

  128. [136]

    Benjamin Gardner, Charles Abraham, Phillippa Lally, and Gert-Jan de Bruijn. 2012. Towards parsimony in habit measurement: Testing the convergent and predictive validity of an automaticity subscale of the Self-Report Habit Index.International Journal of Behavioral Nutrition and...

  129. [137]

    Yan Ge, Li Lu, Xinyue Cui, Zhe Chen, and Weina Qu. 2021. How personal characteristics impact phishing susceptibility: The mediating role of mail processing.Applied Ergonomics97 (2021), 103526. doi:10.1016/j.apergo.2021.103526

  130. [138]

    Grayer, Robin J

    Heather Getha-Taylor, Misty J. Grayer, Robin J. Kempf, and Rosemary O’Leary. 2019. Collaborating in the Absence of Trust? What Collaborative Governance Theory and Practice Can Learn From the Literatures of Conflict Resolution, Psychology, and Law.The American Review of Public ...

  131. [139]

    Chiara Ghislieri, Valentina Dolce, Domenico Sanseverino, Sophie Wodociag, Anne-Marie Vonthron, Émilie Vayre, Marianna Giunchi, and Monica Molino. 2022. Might insecurity and use of ICT enhance internet addiction and exhaust people? A study in two European countries during emerg...

  132. [140]

    Zohreh Gholami Doborjeh, Maryam G Doborjeh, and Nikola Kasabov. 2018. Attentional Bias Pattern Recognition in Spiking Neural Networks from Spatio-Temporal EEG Data.Cognitive Computation10, 1 (Feb. 2018), 35–48. doi:10.1007/s12559-017-9517-x

  133. [141]

    Natalie Glover, Joshua D Miller, Donald R Lynam, Cristina Crego, and Thomas A Widiger. 2012. The five-factor narcissism inventory: A five-factor measure of narcissistic personality traits.Journal of personality assessment94, 5 (2012), 500–512. doi:10.1080/00223891.2012.670680

  134. [142]

    Goldberg, John A

    Lewis R. Goldberg, John A. Johnson, Herbert W. Eber, Robert Hogan, Michael C. Ashton, C. Robert Cloninger, and Harrison G. Gough. 2006. The international personality item pool and the future of public-domain personality measures.Journal of Research in Personality40, 1 (2006), ...

  135. [143]

    Grafsgaard, Joseph B

    Joseph F. Grafsgaard, Joseph B. Wiggins, Kristy Elizabeth Boyer, Eric N. Wiebe, and James C. Lester. 2013. Automatically Recognizing Facial Indicators of Frustration: A Learning-centric Analysis. InHumaine Association Conference on Affective Computing and Intelligent Interacti...

  136. [144]

    2003.A Multi-Level Defense Against Social Engineering

    David Gragg. 2003.A Multi-Level Defense Against Social Engineering. SANS Reading Room White Paper. SANS Institute. https://www.sans.org/white- papers/920/ Accessed: 2024-05-22

  137. [145]

    Margaret Gratian, Sruthi Bandi, Michel Cukier, Josiah Dykstra, and Amy Ginther. 2018. Correlating human traits and cyber security behavior intentions.Computers & Security73 (2018), 345–358. doi:10.1016/j.cose.2017.11.015

  138. [146]

    William Graziano, Lauri Jensen-Campbell, and John Finch. 1997. The Self as a Mediator Between Personality and Adjustment.Journal of Personality and Social Psychology73 (08 1997), 392–404. doi:10.1037/0022-3514.73.2.392

  139. [147]

    Francesco Greco, Giuseppe Desolda, Paolo Buono, and Antonio Piccinno. 2025. Enhancing Phishing Defenses: The Impact of Timing and Explanations in Warnings for Email Clients.Computer Standards & Interfaces93 (2025), 103982. doi:10.1016/j.csi.2025.103982

  140. [148]

    Green and Priya Dozier

    Marcus L. Green and Priya Dozier. 2023. Understanding Human Factors of Cybersecurity: Drivers of Insider Threats. In2023 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE, Venice, Italy, 111–116. doi:10.1109/CSR57506.2023.10224926 Manuscript submitted ...

  141. [149]

    Frank L Greitzer, Wanru Li, Kathryn B Laskey, James Lee, and Justin Purl. 2021. Experimental investigation of technical and human factors related to phishing susceptibility.ACM Transactions on Social Computing4, 2 (2021), 1–48. doi:10.1145/3461672

  142. [150]

    Thomas Groß. 2021. Validity and Reliability of the Scale Internet Users’ Information Privacy Concerns (IUIPC). InProceedings on Privacy Enhancing Technologies. Sciendo, Warsaw, Poland, 235–258. doi:10.2478/popets-2021-0026

  143. [151]

    Ashish Gupta, Shreya Sinha, Harsh Kumar Singh, and Bharat Bhushan. 2023. Vulnerability Assessment of Security Breach and Deadly Threat in Cloud Computing Environment. In2023 IEEE 15th International Conference on Computational Intelligence and Communication Networks (CICN). IEE...

  144. [152]

    Gustafsod

    Per E. Gustafsod. 1998. Gender Differences in Risk Perception: Theoretical and Methodological Perspectives.Risk Analysis18, 6 (1998), 805–811. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1111/j.1539-6924.1998.tb01123.x doi:10.1111/j.1539-6924.1998.tb01123.x

  145. [153]

    Lee Hadlington. 2017. Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours.Heliyon3, 7 (2017), e00346. doi:10.1016/j.heliyon.2017.e00346

  146. [154]

    Lee Hadlington. 2018. Employees attitude towards cyber security and risky online behaviours: An empirical assessment in the United Kingdom. International Journal of Cyber Criminology12 (01 2018), 269–281. doi:10.5281/zenodo.1467909

  147. [155]

    Lee Hadlington and Karen Murphy. 2018. Is Media Multitasking Good for Cybersecurity? Exploring the Relationship Between Media Multitasking and Everyday Cognitive Failures on Self-Reported Risky Cybersecurity Behaviors.Cyberpsychology, Behavior, and Social Networking21, 3 (2018...

  148. [156]

    Lee Hadlington and Kathryn Parsons. 2017. Can Cyberloafing and Internet Addiction Affect Organizational Information Security?Cyberpsychology, Behavior, and Social Networking20, 9 (2017), 567–571. doi:10.1089/cyber.2017.0239 PMID: 28872364

  149. [157]

    Katherine Hamilton, Shin-I Shih, and Susan Mohammed. 2016. The development and validation of the rational and intuitive decision styles scale. Journal of personality assessment98, 5 (2016), 523–535

  150. [158]

    Eko Yon Handri, Dana Indra Sensuse, and Sofian Lusa. 2024. Examining Cybersecurity Culture: Trends and Success Factors.Journal of Internet Services and Information Security14, 3 (2024), 330–352. doi:10.58346/JISIS.2024.I3.020

  151. [159]

    Neil Harrington. 2005. The Frustration Discomfort Scale: development and psychometric properties.Clinical Psychology & Psychotherapy12, 5 (2005), 374–387. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1002/cpp.465 doi:10.1002/cpp.465

  152. [160]

    Mark Harris and Steven Furnell. 2012. Routes to security compliance: be good or be shamed?Computer Fraud & Security2012, 12 (2012), 12–20. doi:10.1016/S1361-3723(12)70122-7

  153. [161]

    Hart and Lowell E

    Sandra G. Hart and Lowell E. Staveland. 1988. Development of NASA-TLX (Task Load Index): Results of Empirical and Theoretical Research. InHuman Mental Workload, Peter A. Hancock and Najmedin Meshkati (Eds.). Advances in Psychology, Vol. 52. North-Holland, Amsterdam, Netherland...

  154. [162]

    Lambert, and Braden T

    William Hart, Joshua T. Lambert, and Braden T. Hall. 2025. Phishing in the Dark: Dark Personality is Associated with Phishing Susceptibility Due to Decreased Social Awareness.The Journal of Psychology0, 0 (2025), 1–18. doi:10.1080/00223980.2025.2538176 PMID: 40753471

  155. [163]

    S Mahmudul Hasan, Che Wei Tu, Endadul Hoque, Omar Chowdhury, and Sze Yiu Chau. 2025. SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-Fi. InProceedings of the 2025 CHI Conference on Human Factors in Computing Systems (CHI ’25). Association for Computin...

  156. [164]

    1958.The psychology of interpersonal relations

    Fritz Heider. 1958.The psychology of interpersonal relations. John Wiley & Sons Inc., Hoboken, NJ, US. doi:10.1037/10628-000

  157. [165]

    Heinssen, Carol R

    Robert K. Heinssen, Carol R. Glass, and Luanne A. Knight. 1987. Assessing computer anxiety: Development and validation of the Computer Anxiety Rating Scale.Computers in Human Behavior3, 1 (1987), 49–59. doi:10.1016/0747-5632(87)90010-0

  158. [166]

    Hengen and Georg W

    Kristina M. Hengen and Georg W. Alpers. 2021. Stress Makes the Difference: Social Stress and Social Anxiety in Decision-Making Under Uncertainty. Frontiers in PsychologyVolume 12 - 2021 (2021), 16 pages. doi:10.3389/fpsyg.2021.578293

  159. [167]

    Raghav Rao

    Tejaswini Herath and H. Raghav Rao. 2009. Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness.Decision Support Systems47, 2 (2009), 154–165. doi:10.1016/j.dss.2009.02.005

  160. [168]

    Tejaswini Herath and Han Reichgelt Rao. 2009. Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems18, 2 (2009), 106–125. doi:10.1057/ejis.2009.6

  161. [169]

    Herman, Hugo D

    Aleksandra M. Herman, Hugo D. Critchley, and Theodora Duka. 2018. Risk-Taking and Impulsivity: The Role of Mood States and Interoception. Frontiers in PsychologyVolume 9 - 2018 (2018), 11 pages. doi:10.3389/fpsyg.2018.01625

  162. [170]

    Krzysztof Herman, Leon Ciechanowski, and Aleksandra Przegalińska. 2021. Emotional Well-Being in Urban Wilderness: Assessing States of Calmness and Alertness in Informal Green Spaces (IGSs) with Muse—Portable EEG Headband.Sustainability13, 4 (2021), 21 pages. doi:10.3390/su13042212

  163. [171]

    Hickman Jr., Grant A

    Ronald L. Hickman Jr., Grant A. Pignatiello, and Sadia Tahir. 2018. Evaluation of the Decisional Fatigue Scale Among Surrogate Decision Makers of the Critically Ill.Western Journal of Nursing Research40, 2 (2018), 191–208. doi:10.1177/0193945917723828 PMID: 28805132

  164. [172]

    David Yau-Fai Ho, Wai Fu, and Siu Man Ng. 2004. Guilt, shame and embarrassment: Revelations of face and self.Culture & Psychology10, 1 (2004), 64–84. doi:10.1177/1354067X04044166

  165. [173]

    Susan Homack and Cynthia A Riccio. 2006. Conners’ continuous performance test (; CCPT-II).Journal of Attention Disorders9, 3 (2006), 556–558. doi:10.1177/1087054705283578

  166. [174]

    Wilson Cheong Hin Hong, ChunYang Chi, Jia Liu, YunFeng Zhang, Vivian Ngan-Lin Lei, and XiaoShu Xu. 2023. The influence of social education level on cybersecurity awareness and behaviour: a comparative study of university students and working graduates.Education and Information...

  167. [175]

    Xiyuan Hou, Yisi Liu, Olga Sourina, Yun Rui Eileen Tan, Lipo Wang, and Wolfgang Mueller-Wittig. 2015. EEG Based Stress Monitoring. In2015 IEEE International Conference on Systems, Man, and Cybernetics. IEEE, New York, NY, US, 3110–3115. doi:10.1109/SMC.2015.540

  168. [176]

    Deanna House and M. K. Raja. 2020. Phishing: message appraisal and the exploration of fear and self-confidence.Behaviour & Information Technology39, 11 (2020), 1204–1224. doi:10.1080/0144929X.2019.1657180

  169. [177]

    Qing Hu, Tamara Dinev, and Dale Cooke. 2012. Managing employee compliance with information security policies: the critical role of top management and organizational culture.Decision Sciences43, 4 (2012), 615–659. doi:10.1111/j.1540-5915.2012.00361.x

  170. [178]

    Farid Huseynov and Busra Ozdenizci Kose. 2024. Using machine learning algorithms to predict individuals’ tendency to be victim of social engineering attacks.Information Development40, 2 (2024), 298–318. doi:10.1177/02666669221116336

  171. [179]

    Hutton and Roy F

    Debra G. Hutton and Roy F. Baumeister. 1992. Self-Awareness and Attitude Change: Seeing Oneself on the Central Route to Persuasion.Personality and Social Psychology Bulletin18, 1 (1992), 68–75. doi:10.1177/0146167292181010

  172. [180]

    Yujong Hwang and Dan J. Kim. 2007. Customer self-service systems: The effects of perceived Web quality with service contents on enjoyment, anxiety, and e-trust.Decision Support Systems43, 3 (2007), 746–760. doi:10.1016/j.dss.2006.12.008 Integrated Decision Support

  173. [181]

    Princely Ifinedo. 2014. Information systems security policy compliance: An empirical study of the effects of socialisation, influence, and cognition. Information & Management51, 1 (2014), 69–79. doi:10.1016/j.im.2013.10.001

  174. [182]

    Inglesant and M

    Philip G. Inglesant and M. Angela Sasse. 2010. The true cost of unusable password policies: password use in the wild. InProceedings of the SIGCHI Conference on Human Factors in Computing Systems(Atlanta, Georgia, USA)(CHI ’10). Association for Computing Machinery, New York, NY...

  175. [183]

    Goudriaan, Simon Vlies, Naomi A

    Konstantinos Ioannidis, Roxanne Hook, Anna E. Goudriaan, Simon Vlies, Naomi A. Fineberg, Jon E. Grant, and Samuel R. Chamberlain. 2019. Cognitive deficits in problematic internet use: meta-analysis of 40 studies.British Journal of Psychiatry215, 5 (2019), 639–646. doi:10.1192/...

  176. [184]

    No one Can Hack My Mind

    Iulia Ion, Rob Reeder, and Sunny Consolvo. 2015. “...No one Can Hack My Mind”: Comparing Expert and Non-Expert Security Practices. InEleventh Symposium On Usable Privacy and Security (SOUPS 2015). USENIX Association, Ottawa, 327–346. https://www.usenix.org/conference/soups2015...

  177. [185]

    Nurse, and Arnau Erola

    Cristian Iuga, Jason R. Nurse, and Arnau Erola. 2016. Baiting the hook: factors impacting susceptibility to phishing attacks.Hum.-Centric Comput. Inf. Sci.6, 1, Article 65 (Dec. 2016), 20 pages. doi:10.1186/s13673-016-0065-2

  178. [186]

    Lennart Jaeger and Andreas Eckhardt. 2021. Eyes wide open: The role of situational information security awareness for security-related behaviour. Information Systems Journal31, 3 (2021), 429–472. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1111/isj.12317 doi:10.1111/isj.12317

  179. [187]

    Mohammad S Jalali, Maike Bruckes, Daniel Westmattelmann, and Gerhard Schewe. 2020. Why Employees (Still) Click on Phishing Links: Investigation in Hospitals.J Med Internet Res22, 1 (23 Jan 2020), e16775. doi:10.2196/16775

  180. [188]

    Daniel Jampen, Gürkan Gür, Thomas Sutter, and Bernhard Tellenbach. 2020. Don’t click: towards an effective anti-phishing training. A comparative literature review.Hum.-Centric Comput. Inf. Sci.10, 1 (Aug. 2020), 41 pages. doi:10.1186/s13673-020-00237-7

  181. [189]

    Jurjen Jansen and Paul van Schaik. 2018. Persuading end users to act cautiously online: a fear appeals study on phishing.Information and Computer Security26, 3 (07 2018), 264–276. arXiv:https://www.emerald.com/ics/article-pdf/26/3/264/1314148/ics-03-2018-0038.pdf doi:10.1108/I...

  182. [190]

    Jurjen Jansen and Paul van Schaik. 2019. The design and evaluation of a theory-based intervention to promote security behaviour against phishing. International Journal of Human-Computer Studies123 (2019), 40–55. doi:10.1016/j.ijhcs.2018.10.004

  183. [191]

    Matthew L Jensen, Michael Dinger, Ryan T Wright, and Jason Bennett Thatcher. 2017. Training to mitigate phishing attacks using mindfulness techniques.Journal of Management Information Systems34, 2 (2017), 597–626

  184. [192]

    Jeronimus and Odilia M

    Bertus F. Jeronimus and Odilia M. Laceulle. 2017.Frustration. Springer International Publishing, Cham, 1–5. doi:10.1007/978-3-319-28099-8_815-1

  185. [193]

    Robert Jervis. 1968. Hypotheses on Misperception.World Politics20, 3 (1968), 454–479. http://www.jstor.org/stable/2009777

  186. [194]

    Lin, and En Man Wang

    Hongzhi Jia, Chin J. Lin, and En Man Wang. 2022. Effects of mental fatigue on risk preference and feedback processing in risk decision-making. Scientific Reports12, 1 (2022), 10695. doi:10.1038/s41598-022-14682-0

  187. [195]

    Bisantz, and Colin G

    Jiun-Yin Jian, Ann M. Bisantz, and Colin G. Drury. 2000. Foundations for an Empirically Determined Scale of Trust in Automated Systems. International Journal of Cognitive Ergonomics4, 1 (2000), 53–71. doi:10.1207/S15327566IJCE0401_04

  188. [196]

    Oliver P. John, E. M. Donahue, and R. L. Kentle. 1991. Big Five Inventory (BFI) [Database record]. doi:10.1037/t07550-000

  189. [197]

    Chacko Eapen Jojo and Jeyavel Sundaramoorthy. 2022. Personality traits associated with Internet addiction among college students in South India. Cogent Education9, 1 (2022), 2142455. doi:10.1080/2331186X.2022.2142455

  190. [198]

    Jones and Delroy L

    Daniel N. Jones and Delroy L. Paulhus. 2011. The role of impulsivity in the Dark Triad of personality.Personality and Individual Differences51, 5 (2011), 679–682. doi:10.1016/j.paid.2011.04.011

  191. [199]

    2011.Thinking, Fast and Slow

    Daniel Kahneman. 2011.Thinking, Fast and Slow. Farrar, Straus and Giroux, New York

  192. [200]

    Kalsher and K

    M. Kalsher and K. Williams. 2006. Behavioral Compliance: Theory, Methodology, and Results. InHandbook of Warnings. Lawrence Erlbaum Associates, Mahwah, NJ, USA, 313–331

  193. [201]

    Jordan Howell, David Maimon, and Tamar Berenblum

    Eden Kamar, C. Jordan Howell, David Maimon, and Tamar Berenblum. 2023. The Moderating Role of Thoughtfully Reflective Decision-Making on the Relationship between Information Security Messages and SMiShing Victimization: An Experiment.Justice Quarterly40, 6 (2023), 837–858. doi...

  194. [202]

    Martin Karlsson, Fredrik Karlsson, Joachim Åström, and Thomas Denk. 2021. The effect of perceived organizational culture on employees’ information security compliance.Information and Computer Security30, 3 (2021), 382–401. doi:10.1108/ICS-06-2021-0073 Manuscript submitted to A...

  195. [203]

    Sonja C Kassenboehmer, Felix Leung, and Stefanie Schurer. 2018. University education and non-cognitive skill development.Oxford Economic Papers70, 2 (03 2018), 538–562. doi:10.1093/oep/gpy002

  196. [204]

    Borst, Marieke K

    Ioanna Katidioti, Jelmer P. Borst, Marieke K. van Vugt, and Niels A. Taatgen. 2016. Interrupt me: External interruptions are less disruptive than self-interruptions.Computers in Human Behavior63 (2016), 906–915. doi:10.1016/j.chb.2016.06.037

  197. [205]

    Rateb Katmah, Fares Al-Shargie, Usman Tariq, Fabio Babiloni, Fadwa Al-Mughairbi, and Hasan Al-Nashash. 2021. A Review on Mental Stress Assessment Methods Using EEG Signals.Sensors21, 15 (2021), 26 pages. doi:10.3390/s21155043

  198. [206]

    Ahmet Rıfat Kayiş, Seydi Ahmet Satici, Muhammet Fatih Yilmaz, Didem Şimşek, Esra Ceyhan, and Fuad Bakioğlu. 2016. Big five-personality trait and internet addiction: A meta-analytic review.Computers in Human Behavior63 (2016), 35–40. doi:10.1016/j.chb.2016.05.012

  199. [207]

    Jinjing Ke, Ming Zhang, Xiaowei Luo, and Jiayu Chen. 2021. Monitoring distraction of construction workers caused by noise using a wearable Electroencephalography (EEG) device.Automation in Construction125 (2021), 103598. doi:10.1016/j.autcon.2021.103598

  200. [208]

    John F Kelly, Bettina B Hoeppner, Karen A Urbanoski, and Valerie Slaymaker. 2011. Predicting relapse among young adults: Psychometric validation of the advanced warning of relapse (AWARE) scale.Addictive behaviors36, 10 (2011), 987–993

  201. [209]

    Kennison and Eric Chan-Tin

    Shelia M. Kennison and Eric Chan-Tin. 2020. Taking Risks With Cybersecurity: Using Knowledge and Personal Characteristics to Predict Self-Reported Cybersecurity Behaviors.Frontiers in PsychologyVolume 11 - 2020 (2020), 9 pages. doi:10.3389/fpsyg.2020.546546

  202. [210]

    Kalam Khadka and Abu Barkat Ullah. 2025. Human factors in cybersecurity: an interdisciplinary review and framework proposal.International Journal of Information Security24, 3 (April 2025), 13 pages. doi:10.1007/s10207-025-01032-0

  203. [211]

    Griffiths

    Kagan Kircaburun and Mark D. Griffiths. 2018. The dark side of internet: Preliminary evidence for the associations of dark personality traits with specific online activities and problematic internet use.Journal of Behavioral Addictions7, 4 (2018), 993 – 1003. doi:10.1556/2006....

  204. [212]

    Jan Klütsch, Julia Schwab, Christian Böffel, et al. 2024. Friend or phisher: how known senders and fear of missing out affect young adults’ phishing susceptibility on social media.Humanities and Social Sciences Communications11 (2024), 1145. doi:10.1057/s41599-024-03412-8

  205. [213]

    Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, and Serge Egelman

    Saranga Komanduri, Richard Shay, Patrick Gage Kelley, Michelle L. Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, and Serge Egelman. 2011. Of passwords and people: measuring the effect of password-composition policies. InProceedings of the SIGCHI Conference on Huma...

  206. [214]

    Kramer, Tom R

    Roderick M. Kramer, Tom R. Tyler, Larry L. Cummings, and Philip Bromiley. 1996. The Organizational Trust Inventory (OTI): Development and Validation. InThe Organizational Trust Inventory (OTI): Development and Validation. SAGE Publications, Inc., Thousand Oaks, CA, 302–330. do...

  207. [215]

    Goedele Krekels and Mario Pandelaere. 2015. Dispositional greed.Personality and Individual Differences74 (2015), 225–230. doi:10.1016/j.paid.2014. 10.036

  208. [216]

    Justin Kruger and David Dunning. 1999. Unskilled and unaware of it: How difficulties in recognizing one’s own incompetence lead to inflated self-assessments.Journal of Personality and Social Psychology77, 6 (1999), 1121–1134. doi:10.1037/0022-3514.77.6.1121

  209. [217]

    Lauren B Krupp, Nicholas G LaRocca, Joanne Muir-Nash, and Alfred D Steinberg. 1989. The fatigue severity scale: application to patients with multiple sclerosis and systemic lupus erythematosus.Archives of neurology46, 10 (1989), 1121–1123

  210. [218]

    Jitender Kumar and Neha Prince. 0. Overconfidence Bias in Investment Decisions: A Systematic Mapping of Literature and Future Research Topics. FIIB Business Review0, 0 (0), 23197145231174344. doi:10.1177/23197145231174344

  211. [219]

    Yogesh Kumar and Om P. Dhakar. 2025. Rise of netholicism: A comprehensive review of internet addiction among today’s youth.Journal of Education and Health Promotion14, 1 (2025), 32. doi:10.4103/jehp.jehp_394_24

  212. [220]

    Andrea Kusec, Fionnuala Murphy, Polly Peers, and Tom Manly. 2024. Measuring Intolerance of Uncertainty After Acquired Brain Injury: Factor Structure, Reliability, and Validity of the Intolerance of Uncertainty Scale–12.Assessment31 (06 2024), 794–811. doi:10.1177/10731911231182693

  213. [221]

    Youngsun Kwak, Seyoung Lee, Amanda Damiano, and Arun Vishwanath. 2020. Why do users not report spear phishing emails?Telematics and Informatics48 (2020), 101343. doi:10.1016/j.tele.2020.101343

  214. [222]

    Lambie, Jaimie Stickl Haugen, and Saundra M

    Glenn W. Lambie, Jaimie Stickl Haugen, and Saundra M. Tabet. 2022. Development and initial validation of the multidimensional dispositional greed assessment (MDGA) with adults.Cogent Psychology9, 1 (2022), 2019654. arXiv:https://doi.org/10.1080/23311908.2021.2019654 doi:10.108...

  215. [223]

    Lay and Henri C

    Clarry H. Lay and Henri C. Schouwenburg. 1993. Trait procrastination, time management, and academic behavior.Journal of Social Behavior & Personality8, 4 (1993), 647–662. https://psycnet.apa.org/record/1994-23368-001

  216. [224]

    Anh Son Le, Tatsuya Suzuki, and Hirofumi Aoki. 2020. Evaluating driver cognitive distraction by eye tracking: From simulator to driving. Transportation Research Interdisciplinary Perspectives4 (2020), 100087. doi:10.1016/j.trip.2019.100087

  217. [225]

    Johannes Leder, Philipp Chapkovski, Astrid Schütz, Thomas Lauer, and Özgür Gürerk. 2024. Background uncertainty does not increase risk aversion in decision making.Scientific Reports14, 1 (2024), 25899. doi:10.1038/s41598-024-73650-y

  218. [226]

    Hwansoo Lee, Siew Fan Wong, Jungjoo Oh, and Younghoon Chang. 2019. Information privacy concerns and demographic characteristics: Data from a Korean media panel survey.Government Information Quarterly36, 2 (2019), 294–303. doi:10.1016/j.giq.2019.01.002

  219. [227]

    Ji Yoon Lee, Su Mi Park, Yeon Jin Kim, Dai Jin Kim, Sam-Wook Choi, Jun Soo Kwon, and Jung-Seok Choi. 2017. Resting-state EEG activity related to impulsivity in gambling disorder.Journal of behavioral addictions6, 3 (2017), 387–395. doi:10.1556/2006.6.2017.055 Manuscript submit...

  220. [228]

    Yi Yong Lee, Chin Lay Gan, and Tze Wei Liew. 2022. Phishing victimization among Malaysian young adults: cyber routine activities theory and attitude in information sharing online.The Journal of Adult Protection24, 3-4 (08 2022), 179–194. arXiv:https://www.emerald.com/jap/artic...

  221. [229]

    Yi Yong Lee, Chin Lay Gan, and Tze Wei Liew. 2023. Thwarting Instant Messaging Phishing Attacks: The Role of Self-Efficacy and the Mediating Effect of Attitude towards Online Sharing of Personal Information.International Journal of Environmental Research and Public Health20, 4...

  222. [230]

    Ângela Leite, Susana Cardoso, and Ana Paula Monteiro. 2023. Dark Personality Traits and Online Behaviors: Portuguese Versions of Cyberstalking, Online Harassment, Flaming and Trolling Scales.International Journal of Environmental Research and Public Health20, 12 (2023), 22 pag...

  223. [231]

    C. W. Lejuez, J. P. Read, C. W. Kahler, J. B. Richards, S. E. Ramsey, G. L. Stuart, D. R. Strong, and R. A. Brown. 2002. Evaluation of a behavioral measure of risk taking: The Balloon Analogue Risk Task (BART).Journal of Experimental Psychology: Applied8, 2 (2002), 75–84. doi:...

  224. [232]

    Burton Leslie. 2025. Gender, Anxiety and Personality.Global Journal of Health Science17 (06 2025), 19–19. doi:10.5539/gjhs.v17n4p19

  225. [233]

    Fernandez

    Fanny Lalonde Lévesque, Sonia Chiasson, Anil Somayaji, and José M. Fernandez. 2018. Technological and Human Factors of Malware Attacks: A Computer Security Clinical Trial Approach.ACM Trans. Priv. Secur.21, 4, Article 18 (July 2018), 30 pages. doi:10.1145/3210311

  226. [234]

    Timothy R. Levine. 2014. Truth-Default Theory (TDT): A Theory of Human Deception and Deception Detection.Journal of Language and Social Psychology33, 4 (2014), 378–392. doi:10.1177/0261927X14535916

  227. [235]

    Ling Li, Li Xu, and Wu He. 2022. The effects of antecedents and mediating factors on cybersecurity protection behavior.Computers in Human Behavior Reports5 (2022), 100165. doi:10.1016/j.chbr.2021.100165

  228. [236]

    Wei Li, Siliu Chen, Zhibing Xiao, Dandan Li, Chenyu Lv, Shuyue Zhang, Ofir Turel, and Qinghua He. 2023. Risk aversion in risk-taking tasks: Combined effects of feedback attributes and cognitive reflection ability.Brain and Behavior13, 5 (2023), e2957. doi:10.1002/brb3.2957

  229. [237]

    Wenqin Li, Rongmin Liu, Linhui Sun, Zigu Guo, and Jie Gao. 2022. An Investigation of Employees’ Intention to Comply with Information Security System—A Mixed Approach Based on Regression Analysis and fsQCA.International Journal of Environmental Research and Public Health19, 23 ...

  230. [238]

    Weiwei Li, Haixia Wang, Xiaofei Xie, and Jian Li. 2019. Neural mediation of greed personality trait on economic risk-taking.eLife8 (apr 2019), e45093. doi:10.7554/eLife.45093

  231. [239]

    Yuhui Li, Zhaoxing Huang, Yenchun Jim Wu, and Zhiqiang Wang. 2019. Exploring How Personality Affects Privacy Control Behavior on Social Networking Sites.Frontiers in PsychologyVolume 10 - 2019 (2019), 9 pages. doi:10.3389/fpsyg.2019.01771

  232. [240]

    Judith-Lisa Lieberum, Markus Toews, Maria-Inti Metzendorf, Felix Heilmeyer, Waldemar Siemens, Christian Haverkamp, Daniel Böhringer, Joerg J Meerpohl, and Angelika Eisele-Metzger. 2025. Large language models for conducting systematic reviews: on the rise, but not yet ready for...

  233. [241]

    Capecci, Donovan M

    Tian Lin, Daniel E. Capecci, Donovan M. Ellis, Harold A. Rocha, Sandeep Dommaraju, Daniela S. Oliveira, and Natalie C. Ebner. 2019. Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content.ACM Trans. Comput.-Hum. Interact.26, 5, Article ...

  234. [242]

    Liu, Tianyi Zhang, and Percy Liang

    Nelson F. Liu, Tianyi Zhang, and Percy Liang. 2023. Evaluating Verifiability in Generative Search Engines. arXiv:2304.09848 [cs.CL] https: //arxiv.org/abs/2304.09848

  235. [243]

    S. H. Lovibond and P. F. Lovibond. 1995. Depression Anxiety Stress Scales (DASS–21, DASS–42). doi:10.1037/t01004-000 [Database record]. APA PsycTests

  236. [244]

    Bernd Löwe, Oliver Decker, Stefanie Müller, Elmar Brähler, Dieter Schellberg, Wolfgang Herzog, and Philipp Yorck Herzberg. 2008. Validation and standardization of the Generalized Anxiety Disorder Screener (GAD-7) in the general population.Medical care46, 3 (2008), 266–274. doi...

  237. [245]

    Raquel Lozano-Blasco, Alberto Quilez Robres, and Alberto Soto Sánchez. 2022. Internet addiction in young adults: A meta-analysis and systematic review.Computers in Human Behavior130 (2022), 107201. doi:10.1016/j.chb.2022.107201

  238. [246]

    Steven G. Ludeke. 2014. Truth and fiction in the association between Openness and education: The role of biased responding.Learning and Individual Differences35 (2014), 137–141. doi:10.1016/j.lindif.2014.07.008

  239. [247]

    Pablo López-Aguilar, Carlota Urruela, Edgar Batista, Juvenal Machin, and Agusti Solanas. 2025. Phishing vulnerability and personality traits: Insights from a systematic review.Computers in Human Behavior Reports20 (2025), 100784. doi:10.1016/j.chbr.2025.100784

  240. [248]

    Michele Maasberg, Craig Van Slyke, Selwyn Ellis, and Nicole Beebe. 2020. The dark triad and insider threats in cyber security.Commun. ACM63, 12 (Nov. 2020), 64–80. doi:10.1145/3408864

  241. [249]

    Mackworth

    Norman H. Mackworth. 1948. Mackworth Clock Test (MCT) [Database record]. doi:10.1037/t65905-000

  242. [250]

    Thomas Madsen. 2018. The conception of laziness and the characterisation of others as lazy.Human Arenas1, 3 (2018), 288–304. doi:10.1007/s42087- 018-0018-6

  243. [251]

    Ratul Mahajan, David Wetherall, and Tom Anderson. 2002. Understanding BGP misconfiguration.SIGCOMM Comput. Commun. Rev.32, 4 (Aug. 2002), 3–16. doi:10.1145/964725.633027

  244. [252]

    Christian Maier, Sven Laumer, Jakob Wirth, and Tim Weitzel. 2019. Technostress and the hierarchical levels of personality: a two-wave study with multiple data samples.European Journal of Information Systems28, 5 (2019), 496–522. doi:10.1080/0960085X.2019.1614739 Manuscript sub...

  245. [253]

    Klara Malinakova, Jana Furstova, Michal Kalman, and Radek Trnka. 2020. A Psychometric Evaluation of the Guilt and Shame Experience Scale (GSES) on a Representative Adolescent Sample: A Low Differentiation between Guilt and Shame.International Journal of Environmental Research ...

  246. [254]

    Salvatore Manfredi, Mariano Ceccato, Giada Sciarretta, and Silvio Ranise. 2021. Do Security Reports Meet Usability? Lessons Learned from Using Actionable Mitigations for Patching TLS Misconfigurations. InProceedings of the 16th International Conference on A vailability, Reliab...

  247. [255]

    Salvatore Manfredi, Mariano Ceccato, Giada Sciarretta, Silvio Ranise, et al. 2022. Empirical Validation on the Usability of Security Reports for Patching TLS Misconfigurations: User-and Case-Studies on Actionable Mitigations.J. Wirel. Mob. Networks Ubiquitous Comput. Dependabl...

  248. [256]

    Tianxin Mao, Weigang Pan, Yingying Zhu, Jian Yang, Qiaoling Dong, and Guofu Zhou. 2018. Self-control mediates the relationship between personality trait and impulsivity.Personality and Individual Differences129 (2018), 70–75. doi:10.1016/j.paid.2018.03.013

  249. [257]

    Maricutoiu

    Laurentiu P. Maricutoiu. 2014. A Meta-analysis on the Antecedents and Consequences of Computer Anxiety.Procedia - Social and Behavioral Sciences127 (2014), 311–315. doi:10.1016/j.sbspro.2014.03.262 The International Conference PSYCHOLOGY AND THE REALITIES OF THE CONTEMPORARY W...

  250. [258]

    Ioana Andreea Marin, Pavlo Burda, Nicola Zannone, and Luca Allodi. 2023. The Influence of Human Factors on the Intention to Report Phishing Emails. InProceedings of the 2023 CHI Conference on Human Factors in Computing Systems(Hamburg, Germany)(CHI ’23). Association for Comput...

  251. [259]

    Marks and A.M

    I.M. Marks and A.M. Mathews. 1979. Brief standard self-rating for phobic patients.Behaviour Research and Therapy17, 3 (1979), 263–267. doi:10.1016/0005-7967(79)90041-X

  252. [260]

    2019.2019 Global Cyber Risk Perception Survey

    Marsh & McLennan Companies and Microsoft. 2019.2019 Global Cyber Risk Perception Survey. Technical Report. Marsh & McLennan Companies and Microsoft. https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2019/09/marsh-microsoft-2019-global-cyber-risk-perception- surv...

  253. [261]

    Marsick and Karen E

    Victoria J. Marsick and Karen E. Watkins. 2003. Demonstrating the Value of an Organization’s Learning Culture: The Dimensions of the Learning Organization Questionnaire.Advances in Developing Human Resources5, 2 (2003), 132–151. doi:10.1177/1523422303005002002

  254. [262]

    Marijn Martens, Ralf De Wolf, and Lieven De Marez. 2019. Investigating and comparing the predictors of the intention towards taking security measures against malware, scams and cybercrime in general.Computers in Human Behavior92 (2019), 139–150. doi:10.1016/j.chb.2018.11.002

  255. [263]

    Eleonora Marzilli, Luca Cerniglia, Giulia Ballarotto, and Silvia Cimino. 2020. Internet Addiction among Young Adult University Students: The Complex Interplay between Family Functioning, Impulsivity, Depression, and Anxiety.International Journal of Environmental Research and P...

  256. [264]

    Mason, Caroline Stevenson, and Fleur Freedman

    Oliver J. Mason, Caroline Stevenson, and Fleur Freedman. 2014. Ever-present threats from information technology: the Cyber-Paranoia and Fear Scale.Frontiers in PsychologyVolume 5 - 2014 (2014), 6 pages. doi:10.3389/fpsyg.2014.01298

  257. [265]

    Mayer, James H

    Roger C. Mayer, James H. Davis, and F. David Schoorman. 1995. An Integrative Model of Organizational Trust.The Academy of Management Review20, 3 (1995), 709–734. doi:10.2307/258792

  258. [266]

    McAllister

    Daniel J. McAllister. 1995. Affect- and Cognition-Based Trust as Foundations for Interpersonal Cooperation in Organizations.Academy of management journal38, 1 (1995), 24–59. doi:10.2307/256727

  259. [267]

    Agata McCormac, Marcus Zwaans, Martin Parsons, Nigel Butavicius, and Kirsten Pattinson. 2017. Individual differences and information security awareness.Computers in Human Behavior69 (2017), 151–156. doi:10.1016/j.chb.2016.11.065

  260. [268]

    Tanya McGill and Nik Thompson. 2018. Gender Differences in Information Security Perceptions and Behaviour. InProceedings of the Australasian Conference on Information Systems (ACIS 2018). UTS ePRESS, Sydney, Australia, 1–10. doi:10.5130/acis2018.co

  261. [269]

    McIntire, R

    Lindsey K. McIntire, R. Andy McKinley, Chuck Goodyear, and John P. McIntire. 2014. Detection of vigilance performance using eye blinks.Applied Ergonomics45, 2, Part B (2014), 354–362. doi:10.1016/j.apergo.2013.04.020

  262. [270]

    Harrison McKnight, Michelle Carter, and Paul Clay. 2009. TRUST IN TECHNOLOGY: Development of a Set of Constructs and Measures. InDIGIT 2009 Proceedings. Australasian Association for Information Systems, Melbourne, Australia, 10 pages. https://aisel.aisnet.org/digit2009/10

  263. [271]

    Gert-Jan Meerkerk, Regina Eijnden, Ad Vermulst, and Henk Garretsen. 2009. The Compulsive Internet Use Scale (CIUS): Some psychometric properties.Cyberpsychology & behavior : the impact of the Internet, multimedia and virtual reality on behavior and society12 (02 2009), 1–6. do...

  264. [272]

    Xue Meng, Yuan Pan, and Chaoping Li. 2024. Portraits of procrastinators: A meta-analysis of personality and procrastination.Personality and Individual Differences218 (2024), 112490. doi:10.1016/j.paid.2023.112490

  265. [273]

    Stephanie M Merritt, Alicia Ako-Brew, William J Bryant, Amy Staley, Michael McKenna, Austin Leone, and Lei Shirase. 2019. Automation-induced complacency potential: Development and validation of a new scale.Frontiers in psychology10 (2019), 225. doi:10.3389/fpsyg.2019.00225

  266. [274]

    2025.Microsoft Digital Defense Report 2025

    Microsoft. 2025.Microsoft Digital Defense Report 2025. Technical Report. Microsoft Corporation. https://www.microsoft.com/en-us/corporate- responsibility/cybersecurity/microsoft-digital-defense-report-2025/ Focus su password spray, MFA fatigue e minacce state-sponsored

  267. [275]

    Vigneswara Ilavarasan

    Shweta Mittal and P. Vigneswara Ilavarasan. 2019. Demographic Factors in Cyber Security: An Empirical Study. InDigital Transformation for a Sustainable Society in the 21st Century, Ilias O. Pappas, Patrick Mikalef, Yogesh K. Dwivedi, Letizia Jaccheri, John Krogstie, and Matti ...

  268. [276]

    Mizrak, H

    F. Mizrak, H. G. Demirel, O. Yaşar, et al. 2025. Digital detox: exploring the impact of cybersecurity fatigue on employee productivity and mental health.Discover Mental Health5 (2025), 25. doi:10.1007/s44192-025-00149-x

  269. [277]

    David Modic, Ross Anderson, and Jussi Palomäki. 2018. We Will Make You Like Our Research: The Development of a Susceptibility-to-Persuasion (StP-II) Scale.PLOS One13, 3 (2018), e0194119. doi:10.1371/journal.pone.0194119

  270. [278]

    David M Monetti, Mark A Whatley, Kerry T Hinkle, Kerry T Cunningham, Jennifer E Breneiser, and Rhea Kisling. 2011. A Factor Analytic Study of the Internet Usage Scale.Journal of Research in Education21, 2 (2011), 14–23

  271. [279]

    Moody, Dennis F

    Gregory D. Moody, Dennis F. Galletta, and Brian Kimball Dunn. 2017. Which phish get caught? An exploratory study of individuals’ susceptibility to phishing.European Journal of Information Systems26, 6 (2017), 564–584. doi:10.1057/s41303-017-0058-x

  272. [280]

    Moore and Allen D

    Andrew P. Moore and Allen D. Householder. 2019. Multi-method Modeling and Analysis of the Cybersecurity Vulnerability Management Ecosystem. InProceedings of the 39th International Conference of the System Dynamics Society. System Dynamics Society, Albuquerque, NM, USA,

  273. [281]

    Yair Morad, Hadas Lemberg, Nehemiah Yofe, and Yaron Dagan. 2000. Pupillography as an objective indicator of fatigue.Current Eye Research21, 1 (2000), 535–542. doi:10.1076/0271-3683(200007)2111-ZFT535 PMID: 11035533

  274. [282]

    https://www.sei.cmu.edu/documents/581/2019_019_001_550437.pdf

  275. [283]

    Vincent Murday, Kévin Campos-Moinier, François Osiurak, and Lionel Brunel. 2021. Extraversion level predicts perceived benefits from social resources and tool use.Scientific Reports11, 1 (10 Jun 2021), 12260. doi:10.1038/s41598-021-91298-w

  276. [284]

    Gareth Mott, Sarah Turner, Jason R C Nurse, Nandita Pattnaik, Jamie MacColl, Pia Huesch, and James Sullivan. 2024. ‘There was a bit of PTSD every time I walked through the office door’: Ransomware harms and the factors that influence the victim organization’s experience. Journ...

  277. [285]

    Magreth Mushi and Rudra Dutta. 2018. Human factors in network reliability engineering.Journal of Network and Systems Management26, 3 (2018), 686–722. doi:10.1007/s10922-017-9440-1

  278. [286]

    Murphy, Peter A

    Sara A. Murphy, Peter A. Fisher, and Chet Robie. 2021. International comparison of gender differences in the five-factor model of personality: An investigation across 105 countries.Journal of Research in Personality90 (2021), 104047. doi:10.1016/j.jrp.2020.104047

  279. [287]

    Mwim, Jabu Mtsweni, and Bester Chimbo

    Emilia N. Mwim, Jabu Mtsweni, and Bester Chimbo. 2023. Conceptual Mapping of the Cybersecurity Culture to Human Factor Domain Framework. InAdvances in Information and Communication, Kohei Arai (Ed.). Springer Nature Switzerland, Cham, 729–742

  280. [288]

    Musuva, Katherine W

    Paula M.W. Musuva, Katherine W. Getao, and Christopher K. Chepken. 2019. A new approach to modelling the effects of cognitive processing and threat detection on phishing susceptibility.Comput. Hum. Behav.94, C (May 2019), 154–175. doi:10.1016/j.chb.2018.12.036

  281. [289]

    Netemeyer, William O

    Richard G. Netemeyer, William O. Bearden, and Jesse E. Teel. 1992. Consumer susceptibility to interpersonal influence and attributional sensitivity. Psychology & Marketing9, 5 (1992), 379–394. arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1002/mar.4220090504 doi:10.1002/mar...

  282. [290]

    Kyle Nash, Jordy Leota, and Albert Tran. 2021. Neural processes in antecedent anxiety modulate risk-taking behavior.Scientific Reports11 (2021),

  283. [291]

    Matipa Ricky Ngandu, Gardner Mwansa, and Ziyanda Mkabe. 2025. Strengthening cybersecurity in a government department by addressing password management challenges and human factor vulnerabilities.Discover Computing28, 1 (2025), 148. doi:10.1007/s10791-025-09659-2

  284. [292]

    Ngo, Alex R

    Fawn T. Ngo, Alex R. Piquero, Jennifer LaPrade, and Bao Duong. 2020. Victimization in Cyberspace: Is It How Long We Spend Online, What We Do Online, or What We Post Online?Criminal Justice Review45, 4 (2020), 430–451. doi:10.1177/0734016820934175

  285. [293]

    Ajaya Neupane, Nitesh Saxena, Jose Omar Maximo, and Rajesh Kana. 2016. Neural Markers of Cybersecurity: An fMRI Study of Phishing and Malware Warnings.IEEE Transactions on Information Forensics and Security11, 9 (2016), 1970–1983. doi:10.1109/TIFS.2016.2566265

  286. [295]

    Nigel Nicholson, Emma Soane, Mark Fenton-O’Creevy, and Paul Willman. 2005. Personality and domain-specific risk taking.Journal of Risk Research8, 2 (2005), 157–176. doi:10.1080/1366987032000123856

  287. [296]

    Binh Huu Nguyen and Huong Nguyen Quynh Le. 2024. Investigation on information security awareness based on KAB model: the moderat- ing role of age and education level.Information and Computer Security32, 5 (03 2024), 598–612. arXiv:https://www.emerald.com/ics/article- pdf/32/5/...

  288. [297]

    Greenshaw, and Vincent I.O

    Izu Nwachukwu, Nnamdi Nkire, Reham Shalaby, Marianne Hrabok, Wesley Vuong, April Gusnowski, Shireen Surood, Liana Urichuk, Andrew J. Greenshaw, and Vincent I.O. Agyapong. 2020. COVID-19 Pandemic: Age-Related Differences in Measures of Stress, Anxiety and Depression in Canada.I...

  289. [299]

    Sokratis Nifakos, Krishna Chandramouli, Charoula Konstantina Nikolaou, Panagiotis Papachristou, Sabine Koch, Emmanouil Panaousis, and Stefano Bonacina. 2021. Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.Sensors21, 15 (2021),...

  290. [2014]

    doi:10.4103/0253-7176.135386

    The relationships between self-efficacy, internet addiction and shame.Indian Journal of Psychological Medicine36, 3 (2014), 304–307. doi:10.4103/0253-7176.135386

  291. [2637]

    doi:10.1038/s41598-021-82229-w

Pith tools

Reviewed August 3, 2026 · model on record in the stance chip above.