{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:41:45Z","timestamp":1785512505086,"version":"3.56.0"},"reference-count":141,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2024,10,10]],"date-time":"2024-10-10T00:00:00Z","timestamp":1728518400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,1,10]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Cyber security advice is a broad church: it is thematically expansive, comprising expert texts, user-generated data consumed by individual users via informal learning and much in-between. While there is evidence that cyber security news articles play a role in disseminating cyber security advice, the nature and extent of that role are not clear. We present a corpus of cyber security advice generated from mainstream news articles. The work was driven by two research objectives. The first objective was to ascertain what kind of actionable advice is being disseminated; the second was to explore ways of determining the efficacy potential of news-mediated security advice. The results show an increase in the generation of cyber security news articles, together with increases in vocabulary complexity and reading difficulty. We argue that these could present challenges for vulnerable users. We believe that this corpus and the accompanying analysis have the potential to inform future efforts to quantify and improve the efficacy potential of security advice dissemination.<\/jats:p>","DOI":"10.1093\/iwc\/iwae048","type":"journal-article","created":{"date-parts":[[2024,9,20]],"date-time":"2024-09-20T15:21:35Z","timestamp":1726845695000},"page":"30-48","source":"Crossref","is-referenced-by-count":5,"title":["The Efficacy Potential of Cyber Security Advice as Presented in News Articles"],"prefix":"10.1093","volume":"37","author":[{"given":"Mark","family":"Quinlan","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Oxford , Wolfson Building, Parks Road, Oxford, OX1 3QD ,","place":["United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aaron","family":"Ceross","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Oxford , Wolfson Building, Parks Road, Oxford, OX1 3QD ,","place":["United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrew","family":"Simpson","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Oxford , Wolfson Building, Parks Road, Oxford, OX1 3QD ,","place":["United Kingdom"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2024,10,10]]},"reference":[{"key":"2025091002162419000_ref1","doi-asserted-by":"publisher","first-page":"65","DOI":"10.13052\/jcsm2245-1439.414","article-title":"Cyber-security and the internet of things: vulnerabilities, threats, intruders and attacks","volume":"4","author":"Abomhara","year":"2015","journal-title":"J. Cyber Secur. Mobil."},{"key":"2025091002162419000_ref2","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1007\/978-3-031-17604-3_3","article-title":"Security ontologies: A systematic literature review","volume-title":"International Conference on Enterprise Design, Operations, and Computing","author":"Adach","year":"2022"},{"key":"2025091002162419000_ref3","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/322796.322806","article-title":"Users are not the enemy","volume":"42","author":"Adams","year":"1999","journal-title":"Commun. ACM"},{"key":"2025091002162419000_ref4","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1007\/978-3-642-69746-3_2","article-title":"From intentions to actions: A theory of planned behavior","volume-title":"Action Control","author":"Ajzen","year":"1985"},{"key":"2025091002162419000_ref5","first-page":"288","article-title":"Threats of online social networks","volume":"9","author":"Al Hasib","year":"2009","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"2025091002162419000_ref6","first-page":"499","article-title":"Cyber-security incidents: a review cases in cyber-physical systems","volume":"9","author":"Al-Mhiqani","year":"2018","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"2025091002162419000_ref7","doi-asserted-by":"crossref","first-page":"287","DOI":"10.1007\/978-3-319-58460-7_19","article-title":"Identifying changes in the cyber-security threat landscape using the LDA-web topic modelling data search engine","volume-title":"Human Aspects of Information Security, Privacy and Trust","author":"Al Moubayed","year":"2017"},{"key":"2025091002162419000_ref8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3389684","article-title":"Time-based gap analysis of cyber-security trends in academic and digital media","volume":"11","author":"Alagheband","year":"2020","journal-title":"ACM Trans. Manag. Inform. Syst."},{"key":"2025091002162419000_ref9","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1901.02672","volume-title":"International Conference on Cyber Security for Sustainable Society","author":"Bada","year":"2015"},{"key":"2025091002162419000_ref10","first-page":"158","volume-title":"Self-efficacy: The Exercise of Control","author":"Bandura","year":"1999"},{"key":"2025091002162419000_ref11","doi-asserted-by":"publisher","DOI":"10.5210\/fm.v11i9.1394","article-title":"A privacy paradox: Social networking in the United States","volume":"11","author":"Barnes","year":"2006","journal-title":"First Monday"},{"key":"2025091002162419000_ref12","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MC.2017.62","article-title":"Botnets and internet of things security","volume":"50","author":"Bertino","year":"2017","journal-title":"IEEE Comput."},{"key":"2025091002162419000_ref13","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1016\/j.obhdp.2006.07.001","article-title":"Advice taking and decision-making: An integrative literature review, and implications for the organizational sciences","volume":"101","author":"Bonaccio","year":"2006","journal-title":"Organ. Behav. Hum. Decis. Process."},{"key":"2025091002162419000_ref14","doi-asserted-by":"publisher","first-page":"340","DOI":"10.1177\/1948550612455931","article-title":"Misplaced confidences: Privacy and the control paradox","volume":"4","author":"Brandimarte","year":"2013","journal-title":"Soc. Psychol. Personal. Sci."},{"key":"2025091002162419000_ref15","doi-asserted-by":"publisher","DOI":"10.2196\/jmir.3100","article-title":"ehealth literacy and health behaviors affecting modern college students: A pilot study of issues identified by the american college health association","volume":"19","author":"Britt","year":"2017","journal-title":"J. Med. Int. Res."},{"key":"2025091002162419000_ref16","first-page":"100","article-title":"Connecting informal and formal learning experiences in the age of participatory media","volume":"8","author":"Bull","year":"2008","journal-title":"Contemp. Issues Technol. Teach. Educ."},{"key":"2025091002162419000_ref17","first-page":"131","article-title":"Towards detection of botnet communication through social media by monitoring user activity","volume-title":"International Conference on Information Systems Security","author":"Burghouwt","year":"2011"},{"key":"2025091002162419000_ref18","first-page":"26","article-title":"Perceptions of internet threats: Behavioral intent to click again","volume-title":"Proceedings of the 27th Annual Conference of the Society for Industrial and Organizational Psychology","author":"Byrne","year":"2012"},{"key":"2025091002162419000_ref19","doi-asserted-by":"crossref","first-page":"497","DOI":"10.1016\/B978-0-12-803843-7.00033-8","article-title":"Security education, training, and awareness","volume-title":"Computer and Information Security Handbook","author":"Caballero","year":"2017"},{"key":"2025091002162419000_ref20","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(13)70062-9","article-title":"Plugging the cyber-security skills gap","volume":"2013","author":"Caldwell","year":"2013","journal-title":"Comput. Fraud Secur."},{"key":"2025091002162419000_ref21","doi-asserted-by":"publisher","first-page":"1775","DOI":"10.1016\/j.neucom.2008.06.011","article-title":"A density-based method for adaptive LDA model selection","volume":"72","author":"Cao","year":"2009","journal-title":"Neurocomputing"},{"key":"2025091002162419000_ref22","first-page":"1","article-title":"Network security and anomaly detection with big-dama, a big data analytics framework","volume-title":"The 2017 IEEE 6th Int. Conf. on Cloud Networking (CloudNet)","author":"Casas","year":"2017"},{"key":"2025091002162419000_ref23","first-page":"2","article-title":"The economic impact of cyber-attacks","volume-title":"Congressional Research Service Documents, CRS RL32331","author":"Cashell","year":"2004"},{"key":"2025091002162419000_ref24","doi-asserted-by":"publisher","first-page":"1687","DOI":"10.1287\/mnsc.1100.1228","article-title":"An experimental test of advice and social learning","volume":"56","author":"\u00c7elen","year":"2010","journal-title":"Manag. Sci."},{"key":"2025091002162419000_ref25","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/s10683-010-9257-1","article-title":"Sustaining cooperation in laboratory public goods experiments: a selective survey of the literature","volume":"14","author":"Chaudhuri","year":"2011","journal-title":"Exp. Econ."},{"key":"2025091002162419000_ref26","doi-asserted-by":"publisher","first-page":"1165","DOI":"10.2307\/41703503","article-title":"Business intelligence and analytics: From big data to big impact","volume":"36","author":"Chen","year":"2012","journal-title":"Manag. Inform. Syst. Q."},{"key":"2025091002162419000_ref27","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1037\/h0076540","article-title":"A computer readability formula designed for machine scoring","volume":"60","author":"Coleman","year":"1975","journal-title":"J. Appl. Psychol."},{"key":"2025091002162419000_ref28","doi-asserted-by":"publisher","first-page":"444","DOI":"10.1111\/j.1468-0009.2010.00608.x","article-title":"Knowledge exchange processes in organizations and policy arenas: a narrative systematic review of the literature","volume":"88","author":"Contandriopoulos","year":"2010","journal-title":"Milbank Q."},{"key":"2025091002162419000_ref29","volume-title":"Governing with the News: The News Media as a Political Institution","author":"Cook","year":"1998"},{"key":"2025091002162419000_ref30","first-page":"1","article-title":"Breaking! A typology of security and privacy news and how it\u2019s shared","volume-title":"Proc. of the 2018 CHI Conf. on Human Factors in Computing Systems","author":"Das","year":"2018"},{"key":"2025091002162419000_ref31","doi-asserted-by":"crossref","first-page":"5578","DOI":"10.3390\/su13105578","article-title":"Smart city ontologies and their applications: A systematic literature review","volume":"13","author":"De Nicola","year":"2021","journal-title":"Sustainability"},{"key":"2025091002162419000_ref32","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1002\/(SICI)1097-4571(199009)41:6\u2216(\u2329\u2216)391::AID-ASI1\u2216(\u232a\u2216)3.0.CO;2-9","article-title":"Indexing by latent semantic analysis","volume":"41","author":"Deerwester","year":"1990","journal-title":"J. Amer. Soc. inform. Sci."},{"key":"2025091002162419000_ref33","doi-asserted-by":"publisher","first-page":"61","DOI":"10.3166\/dn.17.1.61-84","article-title":"Accurate and effective latent concept modeling for ad hoc information retrieval","volume":"17","author":"Deveaud","year":"2014","journal-title":"Doc. Numer."},{"key":"2025091002162419000_ref34","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1017\/iop.2018.3","article-title":"The looming cyber-security crisis and what it means for the practice of industrial and organizational psychology","volume":"11","author":"Dreibelbis","year":"2018","journal-title":"Industr. Organ. Psychol."},{"key":"2025091002162419000_ref35","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1016\/j.physa.2010.09.034","article-title":"Online social networks\u2014paradise of computer viruses","volume":"390","author":"Fan","year":"2011","journal-title":"Phys. A Stat. Mech. Appl."},{"key":"2025091002162419000_ref36","article-title":"Flesch-Kincaid readability test","volume":"26","author":"Flesch","year":"2007","journal-title":"Retrieved"},{"key":"2025091002162419000_ref37","first-page":"97","article-title":"Do or do not, there is no try: user engagement may not improve security outcomes","volume-title":"Twelfth Symposium on Usable Privacy and Security (SOUPS)","author":"Forget","year":"2016"},{"key":"2025091002162419000_ref38","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1109\/TSE.2017.2782813","article-title":"The good, the bad and the ugly: a study of security decisions in a cyber-physical systems game","volume":"45","author":"Frey","year":"2017","journal-title":"IEEE Trans. Softw. Eng."},{"key":"2025091002162419000_ref39","first-page":"79","article-title":"The effect of entertainment media on mental models of computer security","author":"Fulton","year":"2019","journal-title":"In Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS)"},{"key":"2025091002162419000_ref40","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1093\/iwc\/iwad035","article-title":"Usable cybersecurity: a contradiction in terms?","volume":"36","author":"Furnell","year":"2024","journal-title":"Interact. Comput."},{"key":"2025091002162419000_ref41","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1016\/S1361-3723(09)70139-3","article-title":"Recognising and addressing \u2018security fatigue\u2019","volume":"2009","author":"Furnell","year":"2009","journal-title":"Comput. Fraud Secur."},{"key":"2025091002162419000_ref42","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1017\/S0022381609990910","article-title":"The politics of threat: How terrorism news shapes foreign policy attitudes","volume":"72","author":"Gadarian","year":"2010","journal-title":"J. Politics"},{"key":"2025091002162419000_ref43","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1002\/hrdq.3920090205","article-title":"Informal learning in corporate workplaces","volume":"9","author":"Garrick","year":"1998","journal-title":"Hum. Resour. Dev. Q."},{"key":"2025091002162419000_ref44","first-page":"121","article-title":"Summarizing text documents: Sentence selection and evaluation metrics","volume-title":"Proc. of the 22nd Annual Int. ACM SIGIR Conf. on Research and Development in Information Retrieval","author":"Goldstein","year":"1999"},{"key":"2025091002162419000_ref45","first-page":"1745","article-title":"Identifying modes of user engagement with online news and their relationship to information gain in text","volume-title":"Proc. of the 2018 World Wide Web Conf.","author":"Grinberg","year":"2018"},{"key":"2025091002162419000_ref46","first-page":"122","article-title":"A critical view on cis controls","volume-title":"The 16th Int. Conf. on Telecommunications (ConTEL)","author":"Gro\u0161","year":"2021"},{"key":"2025091002162419000_ref47","article-title":"Regulations and brain drain: Evidence from wall street star analysts\u2019 career choices","author":"Guan","year":"2018"},{"key":"2025091002162419000_ref48","first-page":"318","article-title":"Cultural and psychological factors in cyber-security","volume-title":"Proc. of the 18th Int. Conf. on Information Integration and Web-based Applications and Services","author":"Halevi","year":"2016"},{"key":"2025091002162419000_ref49","first-page":"595","article-title":"Inducing domain-specific sentiment lexicons from unlabeled corpora","volume-title":"Proc. of the 2016 Conf. on Empirical Methods in Natural Language Processing, volume 2016","author":"Hamilton","year":"2016"},{"key":"2025091002162419000_ref50","first-page":"411","article-title":"\u201dIt\u2019s scary it\u2019s confusing it\u2019s dull\u201d: How cyber-security advocates overcome negative perceptions of security","volume-title":"The 14th Symposium on Usable Privacy and Security (SOUPS)","author":"Haney","year":"2018"},{"key":"2025091002162419000_ref51","volume-title":"Information Retrieval, Computational and Theoretical Aspects","author":"Heaps","year":"1978"},{"key":"2025091002162419000_ref52","doi-asserted-by":"publisher","first-page":"53","DOI":"10.17083\/ijsg.v3i1.107","article-title":"Game based cyber security training: are serious games suitable for cyber security training?","volume":"3","author":"Hendrix","year":"2016","journal-title":"Int. J. Serious Games"},{"key":"2025091002162419000_ref53","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1145\/1719030.1719050","article-title":"So long, and no thanks for the externalities: The rational rejection of security advice by users","volume-title":"Proc. of the 2009 Workshop on New Security Paradigms Workshop, NSPW \u201909","author":"Herley","year":"2009"},{"key":"2025091002162419000_ref54","article-title":"US patent 9,021,590: Spyware detection mechanism","author":"Cormac","year":"2015"},{"key":"2025091002162419000_ref55","first-page":"1","article-title":"The importance of a security, education, training and awareness program, November 2005","volume":"27601","author":"Hight","year":"2005","journal-title":"Security"},{"key":"2025091002162419000_ref56","doi-asserted-by":"publisher","first-page":"1796","DOI":"10.1016\/j.ins.2009.01.028","article-title":"What users see\u2013structures in search engine results pages","volume":"179","author":"H\u00f6chst\u00f6tter","year":"2009","journal-title":"Inform. Sci."},{"key":"2025091002162419000_ref57","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1109\/SP.2012.23","article-title":"The psychology of security for the home computer user","volume-title":"The2012 IEEE Symp. on Security and Privacy","author":"Howe","year":"2012"},{"key":"2025091002162419000_ref58","doi-asserted-by":"publisher","first-page":"3171","DOI":"10.1007\/s13369-019-04319-2","article-title":"Cyber-security threats and vulnerabilities: a systematic mapping study","volume":"45","author":"Humayun","year":"2020","journal-title":"Arab. J. Sci. Eng."},{"key":"2025091002162419000_ref59","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1016\/j.jksues.2016.04.002","article-title":"A survey on sentiment analysis challenges","volume":"30","author":"Hussein","year":"2018","journal-title":"J. King Saud Univ. Eng. Sci."},{"key":"2025091002162419000_ref60","first-page":"327","article-title":"\u201d...no one can hack my mind\u201d: Comparing expert and non-expert security practices","volume-title":"The 11th Symp. on Usable Privacy and Security (SOUPS)","author":"Ion","year":"2015"},{"key":"2025091002162419000_ref61","doi-asserted-by":"publisher","first-page":"973","DOI":"10.1016\/j.jcss.2014.02.005","article-title":"A survey of emerging threats in cyber-security","volume":"80","author":"Jang-Jaccard","year":"2014","journal-title":"J. Comput. Syst. Sci."},{"key":"2025091002162419000_ref62","first-page":"491","article-title":"Efficacy of news sentiment for stock market prediction","volume-title":"The 2019 Int. Conf. on Machine Learning, Big Data, Cloud and Parallel Computing (COMITCon)","author":"Kalra","year":"2019"},{"key":"2025091002162419000_ref63","doi-asserted-by":"crossref","first-page":"202","DOI":"10.1145\/1498759.1498827","article-title":"Predicting the readability of short web summaries","author":"Kanungo","year":"2009","journal-title":"In Proc. of the 2nd ACM Int. Conf. on Web Search and Data Mining"},{"key":"2025091002162419000_ref64","volume-title":"Ontology Engineering","author":"Kendall","year":"2019"},{"key":"2025091002162419000_ref65","first-page":"5","article-title":"La cryptographie militaire","volume":"IX","author":"Kerckhoffs","year":"1883","journal-title":"Journal des Sciences Militaires"},{"key":"2025091002162419000_ref66","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2017\/9780317","article-title":"Readability assessment of online patient education material on congestive heart failure","volume":"2017","author":"Kher","year":"2017","journal-title":"Adv. Prev. Med."},{"key":"2025091002162419000_ref67","article-title":"Installing fear: A Canadian legal and policy analysis of using, developing, and selling smartphone spyware and stalkerware applications","author":"Khoo","year":"2019"},{"key":"2025091002162419000_ref68","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1016\/j.infsof.2015.11.001","article-title":"Protocol of a systematic mapping study for domain-specific languages","volume":"71","author":"Kosar","year":"2016","journal-title":"J. Inform. Softw. Technol."},{"key":"2025091002162419000_ref69","doi-asserted-by":"publisher","first-page":"591","DOI":"10.1016\/j.jebo.2005.03.010","article-title":"How effective is advice from interested parties? An experimental test using a pure coordination game","volume":"62","author":"Kuang","year":"2007","journal-title":"J. Econ. Behav. Organ."},{"key":"2025091002162419000_ref70","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1145\/1047671.1047705","article-title":"Privacy and trust issues with invisible computers","volume":"48","author":"Lahlou","year":"2005","journal-title":"Commun. of the ACM"},{"key":"2025091002162419000_ref71","first-page":"37","article-title":"The structure and function of communication in society","volume-title":"The Communication of Ideas","author":"Lasswell","year":"1948"},{"key":"2025091002162419000_ref72","first-page":"65","article-title":"The cyber-doom effect: The impact of fear appeals in the us cyber-security debate","volume-title":"The 8th International Conference on Cyber Conflict (CyCon)","author":"Lawson","year":"2016"},{"key":"2025091002162419000_ref73","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1016\/j.cose.2016.02.004","article-title":"Understanding information security stress: Focusing on the type of information security compliance activity","volume":"59","author":"Lee","year":"2016","journal-title":"Comput. Secur."},{"key":"2025091002162419000_ref74","first-page":"286","article-title":"What data should i protect? recommender and planning support for data security analysts","volume-title":"Proc. of the 24th Int. Conf. on Intelligent User Interfaces","author":"Li","year":"2019"},{"key":"2025091002162419000_ref75","first-page":"121","article-title":"Understanding characteristics of biased sentences in news articles","volume-title":"CIKM Workshops","author":"Lim","year":"2018"},{"key":"2025091002162419000_ref76","doi-asserted-by":"publisher","first-page":"507","DOI":"10.24908\/ss.v18i4.13235","article-title":"Tor and the city: MSA-level correlates of interest in anonymous web browsing","volume":"18","author":"Lindner","year":"2020","journal-title":"Surveill. Soc."},{"key":"2025091002162419000_ref77","first-page":"926","article-title":"Identifying digital threats in a hacker web forum","volume-title":"Proc. of the 2015 IEEE\/ACM Int. Conf. on Advances in Social Networks Analysis and Mining 2015","author":"Macdonald","year":"2015"},{"key":"2025091002162419000_ref78","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-1-4419-6868-5_1","article-title":"Self-efficacy theory","volume-title":"Self-Efficacy, Adaptation, and Adjustment","author":"Maddux","year":"1995"},{"key":"2025091002162419000_ref79","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1108\/13665620310504783","article-title":"The interrelationships between informal and formal learning","volume":"15","author":"Malcolm","year":"2003","journal-title":"J. Workplace Learn."},{"key":"2025091002162419000_ref80","doi-asserted-by":"publisher","first-page":"457","DOI":"10.1016\/j.jfineco.2007.02.001","article-title":"Are small investors naive about incentives?","volume":"85","author":"Malmendier","year":"2007","journal-title":"J. Fin. Econ."},{"key":"2025091002162419000_ref81","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1080\/17530350.2013.772070","article-title":"Scraping the social? issues in live social research","volume":"6","author":"Marres","year":"2013","journal-title":"J. Cult. Econ."},{"key":"2025091002162419000_ref82","first-page":"639","article-title":"Smog grading\u2014a new readability formula","volume":"12","author":"Laughlin","year":"1969","journal-title":"J. Read."},{"key":"2025091002162419000_ref83","doi-asserted-by":"publisher","first-page":"176","DOI":"10.1086\/267990","article-title":"The agenda-setting function of mass media","volume":"36","author":"McCombs","year":"1972","journal-title":"Public Opin. Q."},{"key":"2025091002162419000_ref84","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1177\/1075547009359797","article-title":"The rise of the knowledge broker","volume":"32","author":"Meyer","year":"2010","journal-title":"Sci. Commun."},{"key":"2025091002162419000_ref85","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1016\/j.cose.2016.08.001","article-title":"Modelling cyber-security experts\u2019 decision making processes using aggregation operators","volume":"62","author":"Miller","year":"2016","journal-title":"Comput. Secur."},{"key":"2025091002162419000_ref86","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1111\/j.1745-6606.2009.01148.x","article-title":"Toward an understanding of the online consumer\u2019s risky behavior and protection practices","volume":"43","author":"Milne","year":"2009","journal-title":"J. Consumer Affairs"},{"key":"2025091002162419000_ref87","doi-asserted-by":"crossref","first-page":"62","DOI":"10.1145\/2897586.2897610","article-title":"Are easily usable security libraries possible and how should experts work together to create them?","volume-title":"Proc. of the 9th Int. Workshop on Cooperative and Human Aspects of Software Engineering","author":"Mindermann","year":"2016"},{"key":"2025091002162419000_ref88","first-page":"1","article-title":"\u201dIf it\u2019s important it will be a headline\u201d cyber-security information seeking in older adults","volume-title":"Proc. of the 2019 CHI Conf. on Human Factors in Computing Systems","author":"Nicholson","year":"2019"},{"key":"2025091002162419000_ref89","first-page":"123","article-title":"\u201dIf it\u2019s urgent or it is stopping me from doing something, then i might just go straight at it\u201d: a study into home data security decisions","volume-title":"Int. Conf. on Human Aspects of Information Security, Privacy, and Trust","author":"Nthala","year":"2017"},{"key":"2025091002162419000_ref90","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.4734","volume-title":"Foundations of a Security Policy for Use of the National Research and Educational Network","author":"Oldehoeft","year":"1992"},{"key":"2025091002162419000_ref91","first-page":"248","article-title":"Learning in social action: The informal and social learning dimensions of circumstantial and lifelong activists","volume":"51","author":"Ollis","year":"2011","journal-title":"Aust. J. Adult Learn."},{"key":"2025091002162419000_ref92","first-page":"26","article-title":"Towards a human factors ontology for cyber security","volume":"2015","author":"Oltramari","year":"2015","journal-title":"STIDS"},{"key":"2025091002162419000_ref93","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.jet.2004.08.005","article-title":"Professional advice","volume":"126","author":"Ottaviani","year":"2006","journal-title":"J. Econ. Theory"},{"key":"2025091002162419000_ref94","doi-asserted-by":"publisher","first-page":"149","DOI":"10.29214\/damis.2012.31.1.007","article-title":"An analysis on training curriculum for educating information security experts","volume":"31","author":"Park","year":"2012","journal-title":"Manag. Inform. Syst. Rev."},{"key":"2025091002162419000_ref95","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1016\/j.cose.2011.12.010","article-title":"Leveraging behavioral science to mitigate cyber-security risk","volume":"31","author":"Pfleeger","year":"2012","journal-title":"Comput. Secur."},{"key":"2025091002162419000_ref96","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1515\/jhsem-2014-0035","article-title":"From weakest link to security hero: Transforming staff security behavior","volume":"11","author":"Pfleeger","year":"2014","journal-title":"J. Homel. Secur. Emerg. Manag."},{"key":"2025091002162419000_ref97","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2021.105542","article-title":"Defence against the dark artefacts: Smart home cyber crimes and cyber-security standards","volume":"42","author":"Piasecki","year":"2021","journal-title":"Comput. Law Secur. Rev."},{"key":"2025091002162419000_ref98","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1108\/00330330610681286","article-title":"An algorithm for suffix stripping","volume":"40","author":"Porter","year":"2006","journal-title":"Program"},{"key":"2025091002162419000_ref99","doi-asserted-by":"publisher","first-page":"tyv008","DOI":"10.1093\/cybsec\/tyv008","article-title":"Identifying patterns in informal sources of security information","volume":"1","author":"Rader","year":"2015","journal-title":"J. Cyber Secur."},{"key":"2025091002162419000_ref100","first-page":"6","article-title":"Stories as informal lessons about security","volume-title":"Proc. of the 8th Symp. on Usable Privacy and Security","author":"Rader","year":"2012"},{"key":"2025091002162419000_ref101","first-page":"666","article-title":"How I learned to be secure: A census-representative survey of security advice sources and behavior","volume-title":"Proc. of the 2016 ACM SIGSAC Conf. on Computer and Communications Security, CCS \u201916","author":"Redmiles","year":"2016"},{"key":"2025091002162419000_ref102","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1109\/SP.2019.00014","article-title":"How well do my results generalize? Comparing security and privacy survey results from mturk, web, and telephone samples","volume-title":"The 2019 IEEE Symp. on Security and Privacy (SP)","author":"Redmiles","year":"2019"},{"key":"2025091002162419000_ref103","first-page":"272","article-title":"I think they\u2019re trying to tell me something: Advice sources and selection for digital security","volume-title":"The IEEE Symp. on Security and Privacy (SP)","author":"Redmiles","year":"2016"},{"key":"2025091002162419000_ref104","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1109\/MSP.2017.3681050","article-title":"152 simple steps to stay safe online: Security advice for non-tech-savvy users","volume":"15","author":"Reeder","year":"2017","journal-title":"IEEE Secur. Privacy"},{"key":"2025091002162419000_ref105","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1145\/3368860.3368864","article-title":"Cyber-security fear appeals: Unexpectedly complicated","author":"Renaud","year":"2019","journal-title":"In Proc. of the New Security Paradigms Workshop"},{"key":"2025091002162419000_ref106","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1001\/jama.1994.03520020045012","article-title":"Effects of peer review and editing on the readability of articles published in annals of internal medicine","volume":"272","author":"Roberts","year":"1994","journal-title":"JAMA"},{"key":"2025091002162419000_ref107","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1016\/j.cose.2006.10.008","article-title":"Organisational security culture: Extending the end-user perspective","volume":"26","author":"Ruighaver","year":"2007","journal-title":"Comput. Secur."},{"key":"2025091002162419000_ref108","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1080\/19331681.2019.1616646","article-title":"Updating the Wassenaar debate once again: Surveillance, intrusion software, and ambiguity","volume":"16","author":"Ruohonen","year":"2019","journal-title":"J. Inform. Technol. Politics"},{"key":"2025091002162419000_ref109","first-page":"211","article-title":"Weighing context and trade-offs: How suburban adults selected their online security posture","author":"Ruoti","year":"2017","journal-title":"In Proc. of the 13th Symp. on Usable Privacy and Security (SOUPS)"},{"key":"2025091002162419000_ref110","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1006\/jvbe.1996.0026","article-title":"Proactive socialization and behavioral self-management","volume":"48","author":"Saks","year":"1996","journal-title":"J. Vocat. Behav."},{"key":"2025091002162419000_ref111","first-page":"5034","article-title":"Extracting rich semantic information about cyber-security events","volume-title":"The 2019 IEEE International Conference on Big Data (Big Data)","author":"Satyapanich","year":"2019"},{"key":"2025091002162419000_ref112","doi-asserted-by":"publisher","first-page":"53","DOI":"10.15394\/jdfsl.2017.1476","article-title":"Towards a more representative definition of cyber-security","volume":"12","author":"Schatz","year":"2017","journal-title":"J. Digit. Forensics Secur. Law"},{"key":"2025091002162419000_ref113","article-title":"Towards a response to ransomware: Examining digital capabilities of the Wannacry attack","volume":"210","author":"Schirrmacher","year":"2018","journal-title":"In PACIS"},{"key":"2025091002162419000_ref114","doi-asserted-by":"publisher","first-page":"196","DOI":"10.1257\/000282803321947047","article-title":"Decision making with naive advice","volume":"93","author":"Schotter","year":"2003","journal-title":"Amer. Econ. Rev."},{"key":"2025091002162419000_ref115","article-title":"Automated readability index","author":"Senter","year":"1967"},{"key":"2025091002162419000_ref116","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1016\/j.chb.2015.01.046","article-title":"Online safety begins with you and me: Convincing internet users to protect themselves","volume":"48","author":"Shillair","year":"2015","journal-title":"Comput. Hum. Behav."},{"key":"2025091002162419000_ref117","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1080\/13523260.2019.1670006","article-title":"Cyber-noir: Cyber-security and popular culture","volume":"41","author":"Shires","year":"2020","journal-title":"Contemp. Secur. Policy"},{"key":"2025091002162419000_ref118","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1108\/14684520410543670","article-title":"Cybercriminal impacts on online business and consumer confidence","volume":"28","author":"Smith","year":"2004","journal-title":"Online Inform. Rev."},{"key":"2025091002162419000_ref119","doi-asserted-by":"publisher","first-page":"749","DOI":"10.1111\/bjet.12451","article-title":"Attributes of digital natives as predictors of information literacy in higher education","volume":"48","author":"\u0160orgo","year":"2017","journal-title":"Brit. J. Educ. Technol."},{"key":"2025091002162419000_ref120","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/978-3-319-15618-7_13","article-title":"A security ontology for security requirements elicitation","volume-title":"Engineering Secure Software and Systems: 7th Int. Symp., ESSoS 2015, Milan, Italy, March 4-6, 2015. Proceedings 7","author":"Souag","year":"2015"},{"key":"2025091002162419000_ref121","first-page":"686","article-title":"Android security issues and solutions","volume-title":"The 2017 Int. Conf. on Innovative Mechanisms for Industry Applications (ICIMIA)","author":"Sowndarajan","year":"2017"},{"key":"2025091002162419000_ref122","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1109\/MITP.2016.84","article-title":"Security fatigue","volume":"18","author":"Stanton","year":"2016","journal-title":"IT Professional"},{"key":"2025091002162419000_ref123","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1177\/1368430207081541","article-title":"Effects of experience and advice on process and performance in negotiations","volume":"10","author":"Steinel","year":"2007","journal-title":"Group Process. Intergroup Relat."},{"key":"2025091002162419000_ref124","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1016\/0001-8791(87)90037-6","article-title":"Self-efficacy expectations and coping with career-related events","volume":"31","author":"Stumpf","year":"1987","journal-title":"J. Vocat. Behav."},{"key":"2025091002162419000_ref125","volume-title":"The Victorians Since 1901: Histories, Representations and Revisions","author":"Taylor","year":"2004"},{"key":"2025091002162419000_ref126","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MITP.2018.2881373","article-title":"Challenges and the way forward","volume":"21","author":"Cyber-security in social media","year":"2019","journal-title":"IT Professional"},{"key":"2025091002162419000_ref127","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1109\/MC.2019.2954075","article-title":"Is usable security an oxymoron?","volume":"53","author":"Theofanos","year":"2020","journal-title":"IEEE Comput."},{"key":"2025091002162419000_ref128","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/S1363-4127(01)00304-1","article-title":"Risk assessment","volume":"6","author":"Tregear","year":"2001","journal-title":"Information Security Technical Report"},{"key":"2025091002162419000_ref129","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1145\/3233347.3233379","article-title":"Using deep learning model for network scanning detection","volume-title":"Proc. of the 4th Int. Conf. on Frontiers of Educational Technologies","author":"Viet","year":"2018"},{"key":"2025091002162419000_ref130","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","article-title":"From information security to cyber-security","volume":"38","author":"von Solms","year":"2013","journal-title":"Comput. Secur."},{"key":"2025091002162419000_ref131","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/978-3-319-96451-5_1","article-title":"Automatic generation of cyber architectures optimized for security, cost, and mission performance: A nature-inspired approach","volume-title":"Advances in Nature-Inspired Computing and Applications","author":"Wagner","year":"2019"},{"key":"2025091002162419000_ref132","first-page":"1242","article-title":"Targeted online password guessing: An underestimated threat","volume-title":"Proc. of the 2016 ACM SIGSAC Conf. on Computer and Communications Security","author":"Wang","year":"2016"},{"key":"2025091002162419000_ref133","first-page":"97","article-title":"A network gene-based framework for detecting advanced persistent threats","volume-title":"The 2014 Ninth Int. Conf. on P2P, Parallel, Grid, Cloud and Internet Computing","author":"Wang","year":"2014"},{"key":"2025091002162419000_ref134","doi-asserted-by":"publisher","first-page":"781","DOI":"10.1080\/02684527.2012.708530","article-title":"Cyber-security: A pre-history","volume":"27","author":"Warner","year":"2012","journal-title":"Intell. Natl. Secur."},{"key":"2025091002162419000_ref135","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/BF00993988","article-title":"What is an expert?","volume":"14","author":"Weinstein","year":"1993","journal-title":"Theoret. Med."},{"key":"2025091002162419000_ref136","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1017\/CBO9780511803932","article-title":"Communities of practice: Learning as a social system","volume":"9","author":"Wenger","year":"1998","journal-title":"Syst. Thinker"},{"key":"2025091002162419000_ref137","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1145\/1330311.1330320","article-title":"The psychology of security","volume":"51","author":"West","year":"2008","journal-title":"Commun. ACM"},{"key":"2025091002162419000_ref138","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1089\/cyber.2014.1502","article-title":"The role of psychology in enhancing cyber-security","volume":"17","author":"Wiederhold","year":"2014","journal-title":"Cyberpsychol. Behav. Soc. Netw."},{"key":"2025091002162419000_ref139","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13174-017-0059-y","article-title":"Mapping the coverage of security controls in cyber insurance proposal forms","volume":"8","author":"Woods","year":"2017","journal-title":"J. Internet Serv. Appl."},{"key":"2025091002162419000_ref140","doi-asserted-by":"publisher","DOI":"10.2196\/18936","article-title":"Peer-to-peer contact tracing: Development of a privacy-preserving smartphone app","volume":"8","author":"Yasaka","year":"2020","journal-title":"JMIR mHealth and uHealth"},{"key":"2025091002162419000_ref141","doi-asserted-by":"publisher","first-page":"746","DOI":"10.1177\/1932296818763634","article-title":"Standards for medical device cyber-security in 2018","author":"Yuan","year":"2018"}],"container-title":["Interacting with Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/iwc\/article-pdf\/37\/1\/30\/61115673\/iwae048.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/iwc\/article-pdf\/37\/1\/30\/61115673\/iwae048.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T06:16:43Z","timestamp":1757485003000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/iwc\/article\/37\/1\/30\/7816689"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,10]]},"references-count":141,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2024,10,10]]},"published-print":{"date-parts":[[2025,1,10]]}},"URL":"https:\/\/doi.org\/10.1093\/iwc\/iwae048","relation":{},"ISSN":["0953-5438","1873-7951"],"issn-type":[{"value":"0953-5438","type":"print"},{"value":"1873-7951","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2025,1]]},"published":{"date-parts":[[2024,10,10]]}}}