Human Factor in Cybersecurity: Behavioral Insights into Phishing and Social Engineering Attacks

Sudha Rani Pujari, Mahmood Afzal Hussain · Nanotechnology Perceptions · 2024

In this paper, we explore the role of human behavior in cybersecurity by looking at phishing and social engineering as an example. It will explore the role that psychological and behavioral factors play as vulnerabilities and what may be done to reduce the risk of human error. The methodology used in the study is a systematic review involving existing literature from empirical studies, case analysis, and theoretical frameworks. Part of this research integrates human factors in cybersecurity by integrating findings from psychology, information technology, and organizational behavior on human factors in cybersecurity. Results from the study demonstrate that phishing and social engineering succeed due to cognitive biases, low awareness, and lack of training. It also identifies effective countermeasures: Minimum susceptibility can be reduced through tailored training programs, behavioral nudges, and technical interventions. The research shows that behavioral insights have to be included in the cybersecurity strategy. This increases the organization's overall security posture across all systems, and the value comes from designing interventions to address human vulnerabilities. From a social perspective, the outcomes accentuate the need for broad training and identification battles in people and networks of people. In this study, we offer a novel, interdisciplinary view of human factors in cybersecurity. This book aims to connect the dots between behavioral science and cybersecurity practice, providing action-oriented findings to researchers, practitioners, and practitioners who want the human element out of cyber risk.

Read the paper · More papers on PaperTik