{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T01:24:36Z","timestamp":1777944276530,"version":"3.51.4"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T00:00:00Z","timestamp":1759104000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100014013","name":"UK Research and Innovation","doi-asserted-by":"publisher","award":["EP\/L015463\/1"],"award-info":[{"award-number":["EP\/L015463\/1"]}],"id":[{"id":"10.13039\/100014013","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cogn Tech Work"],"published-print":{"date-parts":[[2026,3]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Managing unintentional insider threat (UIT)\u2014inadvertent mistakes and errors that cause cyber breaches\u2014remains a serious challenge to organisations and businesses. In previous work (Khan et al. in Cognit Technol Work 24:1\u201329, 2021) we developed a sociotechnical framework for UIT consisting of 45 elements arranged in six categories called \u2018pillars\u2019 (for e.g. technical cyber defences, user vulnerabilities, processes, knowledge sharing etc.). In the present paper we report the use of a web-based assessment tool that embodied this model and conducted a mixed methods study to examine its effectiveness as a tool for reflecting on these challenges and the consideration of future organisational responses. Senior leaders were invited to engage with the web-based assessment tool (hosted via a website) for a three-hour session to explore the application of the previously developed sociotechnical framework to identify where participants believed their organisation lay in terms of maturity. Attitudes were assessed through semantic scales and semi-structured interviews pre- and post-session that used the lens of Ajzen\u2019s Theory of Planned Behaviour to explore attitudes, subjective norms and perceived control around the cybersecurity issues identified. It was found that organisations view informal peer structures as beneficial and invest in individual development if it is relevant to the job function already being performed by individuals. Organisations also showed aspirations to continuously improve the state of their technical and sociotechnical defences through investing in people and better technologies. Potential areas for improvement of the assessment tool\u2019s inputs were also identified. We conclude that the web-based tool that was developed from the framework is an effective intervention to change planned behaviour for safeguarding against UIT. More broadly, the work demonstrates how an empirically derived framework for understanding human behaviour can be extended as a tool for reflection and determining future actions to improve organisational safety and security measures.<\/jats:p>","DOI":"10.1007\/s10111-025-00833-6","type":"journal-article","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T13:54:49Z","timestamp":1759154089000},"page":"113-133","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Reflective interventions for cybersecurity: insights from a sociotechnical framework application and assessment"],"prefix":"10.1007","volume":"28","author":[{"given":"Neeshe","family":"Khan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sarah","family":"Sharples","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert J.","family":"Houghton","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,29]]},"reference":[{"key":"833_CR1","doi-asserted-by":"publisher","DOI":"10.1080\/23742917.2018.1554985","author":"U Ani","year":"2018","unstructured":"Ani U, Daniel N, Oladipo F, Adewumi S (2018) Securing industrial control system environments: the missing piece. J Cyber Secur Technol. https:\/\/doi.org\/10.1080\/23742917.2018.1554985","journal-title":"J Cyber Secur Technol"},{"issue":"2","key":"833_CR2","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1016\/0749-5978(91)90020-T","volume":"50","author":"I Ajzen","year":"1991","unstructured":"Ajzen I (1991) The theory of planned behavior. Organ Behav Hum Decis Process 50(2):179\u2013211","journal-title":"Organ Behav Hum Decis Process"},{"issue":"3","key":"833_CR3","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1080\/00222216.1992.11969889","volume":"24","author":"I Ajzen","year":"1992","unstructured":"Ajzen I, Driver BL (1992) Application of the theory of planned behavior to leisure choice. J Leis Res 24(3):207\u2013224","journal-title":"J Leis Res"},{"issue":"2","key":"833_CR4","first-page":"215","volume":"15","author":"KL Ingram","year":"2000","unstructured":"Ingram KL, Cope JG, Harju BL, Wuensch KL (2000) Applying to graduate school: a test of the theory of planned behavior. J Soc Behav Personal 15(2):215","journal-title":"J Soc Behav Personal"},{"issue":"3","key":"833_CR5","doi-asserted-by":"publisher","first-page":"352","DOI":"10.5964\/ejop.v16i3.3107","volume":"16","author":"M Bosnjak","year":"2020","unstructured":"Bosnjak M, Ajzen I, Schmidt P (2020) The theory of planned behavior: selected recent advances and applications. Eur J Psychol 16(3):352","journal-title":"Eur J Psychol"},{"issue":"1","key":"833_CR6","first-page":"24","volume":"54","author":"J Brenner","year":"2007","unstructured":"Brenner J (2007) ISO 27001 risk management and compliance. Risk Manage 54(1):24\u201329","journal-title":"Risk Manage"},{"key":"833_CR7","doi-asserted-by":"publisher","unstructured":"Cappelli D, Desai A, Moore A, Shimeall T, Weaver E, Willke B (2007) Management and education of the risk of insider threat (MERIT): mitigating the risk of sabotage to employers information, systems, or networks. Carnegie Mellon University. https:\/\/doi.org\/10.1184\/R1\/6575231.v1","DOI":"10.1184\/R1\/6575231.v1"},{"key":"833_CR8","unstructured":"Cappelli D, Desai A, Moore A, Shimeall T, Weaver E, Willke B (2008) Management and Education of the Risk of Insider Threat (MERIT): System Dynamics Modeling of Computer System. Carnegie Mellon University, Pittsburgh. https:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?assetid=52324"},{"key":"833_CR9","doi-asserted-by":"publisher","DOI":"10.1184\/R1\/6585575.v1","author":"CERT Insider Threat Team","year":"2013","unstructured":"CERT Insider Threat Team (2013) Unintentional insider threats: a foundational study. Software Eng Inst. https:\/\/doi.org\/10.1184\/R1\/6585575.v1","journal-title":"Software Eng Inst"},{"key":"833_CR10","volume-title":"The discovery of grounded theory: strategies for qualitative research","author":"BG Glaser","year":"1967","unstructured":"Glaser BG, Strauss AL (1967) The discovery of grounded theory: strategies for qualitative research. Routledge, New York"},{"key":"833_CR11","doi-asserted-by":"publisher","DOI":"10.1080\/23742917.2019.1601889","author":"PL Goethals","year":"2019","unstructured":"Goethals PL, Hunt ME (2019) A review of scientific research in defensive cyberspace operation tools and technologies. J Cyber Secur Technol. https:\/\/doi.org\/10.1080\/23742917.2019.1601889","journal-title":"J Cyber Secur Technol"},{"key":"833_CR12","doi-asserted-by":"publisher","DOI":"10.5038\/1944-0472.4.2.2","author":"FL Greitzer","year":"2011","unstructured":"Greitzer FL, Hohimer RE (2011) Modeling human behavior to anticipate insider attacks. J Strateg Secur. https:\/\/doi.org\/10.5038\/1944-0472.4.2.2","journal-title":"J Strateg Secur"},{"key":"833_CR13","doi-asserted-by":"publisher","unstructured":"Greitzer F, Purl J, Leong YM, Becker DES (2018) SOFIT: sociotechnical and organizational factors for insider threat. In: 2018 IEEE security and privacy workshops. https:\/\/doi.org\/10.1109\/SPW.2018.00035","DOI":"10.1109\/SPW.2018.00035"},{"issue":"7","key":"833_CR14","doi-asserted-by":"publisher","first-page":"e00346","DOI":"10.1016\/j.heliyon.2017.e00346","volume":"3","author":"L Hadlington","year":"2017","unstructured":"Hadlington L (2017) Human factors in cybersecurity; examining the link between internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours. Heliyon 3(7):e00346","journal-title":"Heliyon"},{"key":"833_CR15","doi-asserted-by":"publisher","first-page":"46","DOI":"10.4018\/978-1-5225-4053-3.ch003","volume-title":"Psychological and behavioral examinations in cyber security","author":"L Hadlington","year":"2018","unstructured":"Hadlington L (2018) The \u201chuman factor\u201d in cybersecurity: exploring the accidental insider. In: McAlaney J, Frumkin LA, Benson V (eds) Psychological and behavioral examinations in cyber security. IGI Global, pp 46\u201363. https:\/\/doi.org\/10.4018\/978-1-5225-4053-3.ch003"},{"key":"833_CR17","first-page":"279","volume-title":"Resilient health care","author":"E Hollnagel","year":"2017","unstructured":"Hollnagel E (2017) Why is work-as-imagined different from work-as-done? Resilient health care, vol 2. CRC Press, Boca Raton, pp 279\u2013294"},{"key":"833_CR18","doi-asserted-by":"crossref","unstructured":"Huang, K., & Pearlson, K. (2019). For what technology can\u2019t fix: Building a model of organizational cybersecurity culture. In: Proceedings of the 52nd Hawaii International Conference on System Sciences","DOI":"10.24251\/HICSS.2019.769"},{"key":"833_CR19","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/LaTiCE.2014.22","volume":"2014","author":"NF Jumaat","year":"2014","unstructured":"Jumaat NF, Tasir Z (2014) Instructional scaffolding in online learning environment: a meta-analysis. Int Conf Teach Learn Comput Eng 2014:74\u201377. https:\/\/doi.org\/10.1109\/LaTiCE.2014.22","journal-title":"Int Conf Teach Learn Comput Eng"},{"issue":"3","key":"833_CR20","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1080\/10919392.2018.1484598","volume":"28","author":"S Kabanda","year":"2018","unstructured":"Kabanda S, Tanner M, Kent C (2018) Exploring SME cybersecurity practices in developing countries. J Organ Comput Electron Commer 28(3):269\u2013282","journal-title":"J Organ Comput Electron Commer"},{"key":"833_CR21","unstructured":"Keeney M, Kowalski E, Cappelli D, Moore A, Shimeall T, Rogers S (2005) Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors. National Threat Assessment CTR, Washington. https:\/\/apps.dtic.mil\/dtic\/tr\/fulltext\/u2\/a636653.pdf"},{"key":"833_CR22","first-page":"1","volume":"24","author":"N Khan","year":"2021","unstructured":"Khan N, Houghton RJ, Sharples S (2021) Understanding factors that influence unintentional insider threat: a framework to counteract unintentional risks. Cognit Technol Work 24:1\u201329","journal-title":"Cognit Technol Work"},{"key":"833_CR23","first-page":"77","volume":"426","author":"N King","year":"2012","unstructured":"King N (2012) Doing template analysis. Qualitat Organiz Res: Core Methods Curr Chall 426:77\u2013101","journal-title":"Qualitat Organiz Res: Core Methods Curr Chall"},{"key":"833_CR24","doi-asserted-by":"publisher","DOI":"10.1109\/21.31053","author":"GA Klein","year":"1989","unstructured":"Klein GA, Calderwood R, MacGregor D (1989) Critical decision method for eliciting knowledge. IEEE Trans Syst Man Cybern. https:\/\/doi.org\/10.1109\/21.31053","journal-title":"IEEE Trans Syst Man Cybern"},{"key":"833_CR25","doi-asserted-by":"crossref","unstructured":"Morel B (2011). Artificial intelligence and the future of cybersecurity. In: Proceedings of the 4th ACM workshop on Security and artificial intelligence. pp 93\u201398","DOI":"10.1145\/2046684.2046699"},{"key":"833_CR26","unstructured":"NCSC (2012) 10 steps to cyber security: Guidance on how organisations can protect themselves in cyberspace, including the 10 steps to cyber security. https:\/\/www.ncsc.gov.uk\/collection\/10-steps-to-cyber-security"},{"issue":"3","key":"833_CR27","doi-asserted-by":"publisher","first-page":"71","DOI":"10.2478\/hjbpa-2018-0024","volume":"9","author":"C Nobles","year":"2018","unstructured":"Nobles C (2018) Botching human factors in cybersecurity in business organizations. Holistica\u2013J Bus Public Adm 9(3):71\u201388","journal-title":"Holistica\u2013J Bus Public Adm"},{"key":"833_CR28","doi-asserted-by":"publisher","unstructured":"Nurse JRC, Buckley O, Legg PA, Goldsmith M, Creese S, Wright GRT, Whitty M (2014) Understanding insider threat: a framework for characterising attacks. In: 2014 IEEE security and privacy workshops. https:\/\/doi.org\/10.1109\/SPW.2014.38","DOI":"10.1109\/SPW.2014.38"},{"key":"833_CR29","doi-asserted-by":"crossref","unstructured":"Ponemon Institute LLC (2022a) Cost of a data breach, Report 2022. IBM Secur. July pp 1\u201355, . https:\/\/www.ibm.com\/uk-en\/security\/data-breach","DOI":"10.12968\/S1353-4858(22)70049-9"},{"key":"833_CR30","unstructured":"Ponemon Institute LLC (2022b) 2022 Cost of insider threats: global report. https:\/\/www.proofpoint.com\/uk\/resources\/threat-reports\/cost-of-insider-threats"},{"key":"833_CR32","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.87","author":"J Predd","year":"2008","unstructured":"Predd J, Pfleeger SL, Hunker J, Bulford C (2008) Insiders behaving badly. IEEE Secur Priv. https:\/\/doi.org\/10.1109\/MSP.2008.87","journal-title":"IEEE Secur Priv"},{"key":"833_CR33","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1983.6313160","author":"J Rasmussen","year":"1983","unstructured":"Rasmussen J (1983) Skills, rules, and knowledge; signals, signs, and symbols, and other distinctions in human performance models. IEEE Trans Syst Man Cybern. https:\/\/doi.org\/10.1109\/TSMC.1983.6313160","journal-title":"IEEE Trans Syst Man Cybern"},{"key":"833_CR34","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139062367","volume-title":"Human error","author":"J Reason","year":"1990","unstructured":"Reason J (1990) Human error. Cambridge University Press, Cambridge"},{"issue":"2","key":"833_CR35","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1037\/0022-3514.44.2.233","volume":"44","author":"DO Sears","year":"1983","unstructured":"Sears DO (1983) The person-positivity bias. J Pers Soc Psychol 44(2):233","journal-title":"J Pers Soc Psychol"},{"key":"833_CR36","doi-asserted-by":"publisher","DOI":"10.1037\/13620-005","volume-title":"Interpretative phenomenological analysis","author":"JA Smith","year":"2012","unstructured":"Smith JA, Shinebourne P (2012) Interpretative phenomenological analysis. American Psychological Association"},{"issue":"4","key":"833_CR37","doi-asserted-by":"publisher","first-page":"416","DOI":"10.2307\/800824","volume":"36","author":"JK Watters","year":"1989","unstructured":"Watters JK, Biernacki P (1989) Targeted sampling: options for the study of hidden populations. Social Problems 36(4):416\u2013430. https:\/\/doi.org\/10.2307\/800824","journal-title":"Social Problems"},{"key":"833_CR38","volume-title":"A human error approach to aviation accident analysis","author":"DA Wiegmann","year":"2003","unstructured":"Wiegmann DA, Shappell SA (2003) A human error approach to aviation accident analysis. Routledge"},{"key":"833_CR39","doi-asserted-by":"crossref","unstructured":"Liginlal D, Sim I,  Khansa L (2009  How significant is human error as a cause of privacy breaches? An empirical study and a framework for error management. computers & security 28(3-4), 215\u2013228.","DOI":"10.1016\/j.cose.2008.11.003"},{"key":"833_CR40","doi-asserted-by":"crossref","unstructured":"Legg PA., Buckley O, Goldsmith M, Creese S (2015) Automated insider threat detection system using user and role-based profile assessment. IEEE Systems Journal 11(2):503\u2013512.","DOI":"10.1109\/JSYST.2015.2438442"},{"key":"833_CR41","doi-asserted-by":"crossref","unstructured":"Rydell RJ,  McConnell AR (2006) Understanding implicit and explicit attitude change: a systems of reasoning analysis. Journal of personality and social psychology 91(6):995.","DOI":"10.1037\/0022-3514.91.6.995"},{"key":"833_CR42","unstructured":"Carnegie Mellon University, Software Engineering Institute's Digital Library. Carnegie Mellon's Software Engineering Institute, July 31, 2006. https:\/\/www.sei.cmu.edu\/library\/cert-research-2005-annual-report\/."},{"key":"833_CR43","unstructured":"Cappelli DM, Desai AG, Moore AP, Shimeall TJ, Weaver EA,  Willke BJ (2007) Management and Education of the Risk of Insider Threat (MERIT): mitigating the risk of sabotage to employers' information, systems, or networks."},{"key":"833_CR44","unstructured":"Cappelli DM, Desai AG, Moore AP, Shimeall TJ, Weaver EA., Willke BJ (2008) Management and education of the risk of insider threat (MERIT): System dynamics modeling of computer system sabotage. Carnegie-Mellon Univ Pittsburgh PA Software Engineering Inst."}],"container-title":["Cognition, Technology &amp; Work"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10111-025-00833-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10111-025-00833-6","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10111-025-00833-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T07:50:58Z","timestamp":1777708258000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10111-025-00833-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,29]]},"references-count":42,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["833"],"URL":"https:\/\/doi.org\/10.1007\/s10111-025-00833-6","relation":{},"ISSN":["1435-5558","1435-5566"],"issn-type":[{"value":"1435-5558","type":"print"},{"value":"1435-5566","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,29]]},"assertion":[{"value":"14 November 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 August 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 September 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}