{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T00:20:43Z","timestamp":1781137243394,"version":"3.54.1"},"reference-count":150,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2024,8,21]],"date-time":"2024-08-21T00:00:00Z","timestamp":1724198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Cybercrime is currently rapidly developing, requiring an increased demand for information security knowledge. Attackers are becoming more sophisticated and complex in their assault tactics. Employees are a focal point since humans remain the \u2018weakest link\u2019 and are vital to prevention. This research investigates what cognitive and internal factors influence information security awareness (ISA) among employees, through quantitative empirical research using a survey conducted at a Dutch financial insurance firm. The research question of \u201cHow and to what extent do cognitive and internal factors contribute to information security awareness (ISA)?\u201d has been answered, using the theory of situation awareness as the theoretical lens. The constructs of Security Complexity, Information Security Goals (InfoSec Goals), and SETA Programs (security education, training, and awareness) significantly contribute to ISA. The most important research recommendations are to seek novel explaining variables for ISA, further investigate the roots of Security Complexity and what influences InfoSec Goals, and venture into qualitative and experimental research methodologies to seek more depth. The practical recommendations are to minimize the complexity of (1) information security topics (e.g., by contextualizing it more for specific employee groups) and (2) integrate these simplifications in various SETA methods (e.g., gamification and online training).<\/jats:p>","DOI":"10.3390\/info15080505","type":"journal-article","created":{"date-parts":[[2024,8,23]],"date-time":"2024-08-23T12:53:19Z","timestamp":1724417599000},"page":"505","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Information Security Awareness in the Insurance Sector: Cognitive and Internal Factors and Combined Recommendations"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-3310-3270","authenticated-orcid":false,"given":"Morgan","family":"Djotaroeno","sequence":"first","affiliation":[{"name":"Consultant Process & Information Management, Dux Group, 3011 TA Rotterdam, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5804-109X","authenticated-orcid":false,"given":"Erik","family":"Beulen","sequence":"additional","affiliation":[{"name":"Management Sciences and Marketing, The University of Manchester, Manchester M15 6PB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100031","DOI":"10.1016\/j.csa.2023.100031","article-title":"Cyber security: State of the art, challenges and future directions","volume":"2","author":"Admass","year":"2023","journal-title":"Cyber Secur. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.54060\/a2zjournals.jase.42","article-title":"Cyber Security Threats and Countermeasures in Digital Age","volume":"4","author":"Thakur","year":"2024","journal-title":"J. Appl. Sci. Educ. (JASE)"},{"key":"ref_3","unstructured":"Gartner (2024). Top Trends in Cybersecurity for 2024, Gartner. Available online: https:\/\/www.gartner.com\/en\/cybersecurity\/trends\/cybersecurity-trends."},{"key":"ref_4","first-page":"234","article-title":"Working from Home: Cybersecurity in the Age of Covid-19","volume":"21","author":"Borkovich","year":"2020","journal-title":"Issues Inf. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/MITP.2020.2988330","article-title":"IT risk and resilience\u2014Cybersecurity response to COVID-19","volume":"22","author":"Weil","year":"2020","journal-title":"IT Prof."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1016\/j.dcan.2022.06.005","article-title":"COVID-19 pandemic and the cyberthreat landscape: Research challenges and opportunities","volume":"9","author":"Saleous","year":"2023","journal-title":"Digit. Commun. Netw."},{"key":"ref_7","unstructured":"Gartner (2022). Top Trends in Cybersecurity 2022, Gartner."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Almansoori, A., Al-Emran, M., and Shaalan, K. (2023). Exploring the Frontiers of Cybersecurity Behaviour: A Systematic Review of Studies and Theories. Appl. Sci., 13.","DOI":"10.3390\/app13095700"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bowen, B.M., Devarajan, R., and Stolfo, S. (2011, January 15\u201317). Measuring the human factor of cyber security. Proceedings of the 2011 IEEE International Conference on Technologies for Homeland Security (HST), Waltham, MA, USA.","DOI":"10.1109\/THS.2011.6107876"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1145\/3424282","article-title":"Assessing the moderating effect of security technologies on employees compliance with cybersecurity control procedures","volume":"12","author":"Onumo","year":"2021","journal-title":"ACM Trans. Manag. Inf. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"681","DOI":"10.1016\/j.im.2018.11.003","article-title":"Information security breaches and IT security investments: Impacts on competitors","volume":"56","author":"Jeong","year":"2019","journal-title":"Inf. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"102258","DOI":"10.1016\/j.techsoc.2023.102258","article-title":"A systematic review of multi perspectives on human cybersecurity behaviour","volume":"73","author":"Alsharida","year":"2023","journal-title":"Technol. Soc."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1396","DOI":"10.1111\/isj.12460","article-title":"\u2018What a waste of time\u2019: An examination of cybersecurity legitimacy","volume":"33","author":"Cram","year":"2023","journal-title":"Inf. Syst. J."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"103741","DOI":"10.1016\/j.cose.2024.103741","article-title":"A typology of cybersecurity behaviour among knowledge workers","volume":"140","author":"Baltuttis","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1108\/09685220010371394","article-title":"A conceptual foundation for organizational information security awareness","volume":"8","author":"Siponen","year":"2000","journal-title":"Inf. Manag. Comput. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"100542","DOI":"10.1016\/j.ijcip.2022.100542","article-title":"Cyber-attacks detection in industrial systems using artificial intelligence-driven methods","volume":"38","author":"Wang","year":"2022","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1108\/ICS-08-2022-0133","article-title":"Critical success factors for Security Education, Training and Awareness (SETA) programme effectiveness: An empirical comparison of practitioner perspectives","volume":"32","author":"Alyami","year":"2024","journal-title":"Inf. Comput. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Aldawood, S., and Skinner, G. (2019). Reviewing Cyber Security Social Engineering Training and Awareness Programs\u2014Pitfalls and Ongoing Issues. Future Internet, 11.","DOI":"10.3390\/fi11030073"},{"key":"ref_19","first-page":"345","article-title":"Security Awareness: The First Step in Information Security Compliance Behaviour","volume":"61","author":"Hwang","year":"2021","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"463","DOI":"10.1108\/ICS-08-2022-0139","article-title":"A systematic literature review of how cybersecurity-related behaviour has been assessed","volume":"31","author":"Katsikas","year":"2023","journal-title":"Inf. Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1016\/j.procs.2023.01.267","article-title":"Impact of Cyber-Attacks on the Financial Institutions","volume":"219","author":"Kiss","year":"2023","journal-title":"Procedia Comput. Sci."},{"key":"ref_22","first-page":"43","article-title":"Safeguarding FinTech: Elevating Employee Cybersecurity Awareness in Financial Sector","volume":"12","author":"Kuraku","year":"2023","journal-title":"Int. J. Appl. Inf. Syst. (IJAIS)"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"e08671","DOI":"10.1016\/j.heliyon.2023.e14234","article-title":"A systematic literature review of cybersecurity scales assessing information security awareness","volume":"9","author":"Rohan","year":"2023","journal-title":"Heliyon"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1080\/0960085X.2021.1978344","article-title":"Beyond Technical Measures: A Value-Focused Thinking Appraisal of Strategic Drivers in Improving Information Security Policy Compliance","volume":"31","author":"Donalds","year":"2021","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"523","DOI":"10.2307\/25750690","article-title":"Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness","volume":"34","author":"Bulgurcu","year":"2010","journal-title":"MIS Q."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1043","DOI":"10.1287\/isre.2021.1014","article-title":"Understanding Inconsistent Employee Compliance with Information Security Policies through the Lens of the Extended Parallel Process Model","volume":"32","author":"Chen","year":"2021","journal-title":"Inf. Syst. Res."},{"key":"ref_27","unstructured":"Fertig, T., Sch\u00fctz, A.E., and Weber, K. (2020, January 15\u201317). Current Issues of Metrics for Information Security Awareness. Proceedings of the 28th European Conference on Information Systems (ECIS), An AIS Conference, Online."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"723","DOI":"10.1080\/07421222.2020.1790187","article-title":"The effectiveness of abstract versus concrete fear appeals in information security","volume":"37","author":"Schuetz","year":"2020","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"732","DOI":"10.1080\/07421222.2021.1962601","article-title":"Protecting against threats to information security: An attitudinal ambivalence perspective","volume":"38","author":"Ng","year":"2021","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"525","DOI":"10.25300\/MISQ\/2019\/15117","article-title":"Seeing the Forest and the Trees: A Meta-Analysis of the Antecedents to Information Security Policy Compliance","volume":"43","author":"Cram","year":"2019","journal-title":"MIS Q."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"101693","DOI":"10.1016\/j.jsis.2021.101693","article-title":"Information systems security research agenda: Exploring the gap between research and practice","volume":"30","author":"Dhillon","year":"2021","journal-title":"J. Strateg. Inf. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"174","DOI":"10.1108\/ITP-11-2021-0849","article-title":"Information security awareness maturity: Conceptual and practical aspects in Hungarian organizations","volume":"36","author":"Ko","year":"2023","journal-title":"Inf. Technol. People"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"317","DOI":"10.25300\/MISQ\/2022\/15713","article-title":"Where is IT in Information Security? The Interrelationship among IT Investment, Security Awareness, and Data Breaches","volume":"47","author":"Li","year":"2023","journal-title":"MIS Q."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1007\/s10257-022-00575-2","article-title":"Moving Beyond Cyber Security Awareness and Training to Engendering Security Knowledge Sharing","volume":"21","author":"Alahmari","year":"2023","journal-title":"Inf. Syst. E-Bus. Manag."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1016\/j.procs.2015.12.151","article-title":"Information Security Awareness at the Knowledge-Based Institution: Its Antecedents and Measures","volume":"72","author":"Ahlan","year":"2015","journal-title":"Procedia Comput. Sci."},{"key":"ref_36","unstructured":"Haeussinger, F., and Kranz, J. (2017, January 5\u201310). Antecedents of employees\u2019 information security awareness: Review, synthesis, and directions for future research. Proceedings of the 25th European Conference on Information Systems (ECIS), Guimar\u00e3es, Portugal."},{"key":"ref_37","first-page":"311","article-title":"Leadership styles and information security compliance behaviour: The mediator effect of information security awareness","volume":"5","author":"Humaidi","year":"2015","journal-title":"Int. J. Inf. Educ. Technol."},{"key":"ref_38","unstructured":"Al-Omari, A., El-Gayar, O., and Deokar, A. (2012, January 9\u201312). Information security policy compliance: The role of information security awareness. Proceedings of the Eighteenth Americas Conference on Information Systems, Seattle, WA, USA."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Al-Omari, A., El-Gayar, O., and Deokar, A. (2012, January 4\u20137). Security policy compliance: User acceptance perspective. Proceedings of the 2012 45th Hawaii International Conference on System Sciences, Maui, HI, USA.","DOI":"10.1109\/HICSS.2012.516"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1287\/isre.1070.0160","article-title":"User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach","volume":"20","author":"Hovav","year":"2009","journal-title":"Inf. Syst. Res."},{"key":"ref_41","first-page":"2","article-title":"Information Security Awareness and Information Security Practices of Internet Users in Bolivia: A Socio-Cognitive View","volume":"6","author":"Guzman","year":"2014","journal-title":"RELCASI"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"429","DOI":"10.1111\/isj.12317","article-title":"Eyes wide open: The role of situational information security awareness for security-related behaviour","volume":"31","author":"Jaeger","year":"2021","journal-title":"Inf. Syst. J."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"102152","DOI":"10.1016\/j.ijinfomgt.2020.102152","article-title":"Motivating information security policy compliance: The critical role of supervisor-subordinate guanxi and organizational commitment","volume":"54","author":"Liu","year":"2020","journal-title":"Int. J. Inf. Manag."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"107376","DOI":"10.1016\/j.chb.2022.107376","article-title":"Exploring the factors that influence the cybersecurity behaviors of young adults","volume":"136","author":"Alanazi","year":"2022","journal-title":"J. Comput. Hum. Behav."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"101640","DOI":"10.1016\/j.cose.2019.101640","article-title":"More Than the Individual: Examining the Relationship Between Culture and Information Security Awareness","volume":"88","author":"Wiley","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"377","DOI":"10.1016\/0167-4048(95)97088-R","article-title":"Deficiencies of the traditional approach to information security and the requirements for a new methodology","volume":"14","author":"Hitchings","year":"1995","journal-title":"Comput. Secur."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1016\/j.cose.2012.09.010","article-title":"Future directions for behavioural information security research","volume":"32","author":"Crossler","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1145\/3210530.3210538","article-title":"Definition and multidimensionality of security awareness: Close encounters of the second order","volume":"49","author":"Hanus","year":"2018","journal-title":"ACM SIGMIS Database DATABASE Adv. Inf. Syst."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1186\/s42400-020-00050-w","article-title":"Review and insight on the behavioural aspects of cybersecurity","volume":"3","author":"Caulkins","year":"2020","journal-title":"Cybersecurity"},{"key":"ref_50","first-page":"276","article-title":"Behavioral information security: An overview, results, and research agenda","volume":"12","author":"Stanton","year":"2015","journal-title":"Hum. Comput. Interact. Manag. Inf. Syst."},{"key":"ref_51","first-page":"18","article-title":"K Woon, I.; Kankanhalli, A. Perceptions of Information Security in the Workplace: Linking Information Security Climate to Compliant Behavior","volume":"1","author":"Chan","year":"2005","journal-title":"J. Inf. Priv. Secur."},{"key":"ref_52","unstructured":"Johnston, A.C., Wech, B., Jack, E., and Beavers, M. (, January 15\u201318). Reigning in the Remote Employee: Applying Social Learning Theory to Explain Information Security Policy Compliance Attitudes. Proceedings of the AMCIS 2010."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Duzenci, D., Kitapci, H., and Gok, M.S. (2023). The Role of Decision-Making Styles in Shaping Cybersecurity Compliance Behavior. Appl. Sci., 13.","DOI":"10.3390\/app13158731"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1057\/ejis.2010.72","article-title":"The influence of the informal social learning environment in information security awareness programs","volume":"20","author":"Warkentin","year":"2011","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"1770","DOI":"10.1016\/j.tele.2018.05.005","article-title":"Impact of Employees\u2019 Demographic Characteristics on the Awareness and Compliance of Information Security Policy in Organizations","volume":"35","author":"Chua","year":"2018","journal-title":"Telematics Inf."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Luo, X.R., Li, H., Hu, Q., and Xu, H. (2020). Why Individual Employees Commit Malicious Computer Abuse: A Routine Activity Theory Perspective. J. Assoc. Inf. Syst., 21.","DOI":"10.17705\/1jais.00646"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"576","DOI":"10.1108\/ICS-05-2022-0087","article-title":"Cyber Suraksha: A Card Game for Smartphone Security Awareness","volume":"31","author":"Shah","year":"2023","journal-title":"Inf. Comput. Secur."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"47543","DOI":"10.1109\/ACCESS.2024.3383311","article-title":"Enhancing Participatory Security Culture in Public Institutions: An Analysis of Organizational Employees\u2019 Security Threat Recognition Processes","volume":"12","author":"Choi","year":"2024","journal-title":"IEEE Access"},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Lebek, B., Uffen, J., Breitner, M.H., Neumann, M., and Hohler, B. (2013, January 7-10). Employees\u2019 Information Security Awareness and Behavior: A Literature Review. Proceedings of the 2013 46th Hawaii International Conference on System Sciences, Wailea, HI, USA.","DOI":"10.1109\/HICSS.2013.192"},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.cose.2016.01.004","article-title":"Shaping intention to resist social engineering through transformational leadership, information security culture and awareness","volume":"59","author":"Ekstedt","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"285","DOI":"10.25300\/MISQ\/2018\/13853","article-title":"Toward a Unified Model of Information Security Policy Compliance","volume":"42","author":"Moody","year":"2018","journal-title":"MIS Q."},{"key":"ref_62","unstructured":"Hutchinson, G., and Ophoff, J. (2019, January 15). A descriptive review and classification of organizational information security awareness research. Proceedings of the 18th International Information Security Conference 2019, Johannesburg, South Africa."},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.procs.2021.01.103","article-title":"The role of employees\u2019 information security awareness on the intention to resist social engineering","volume":"181","author":"Grassegger","year":"2021","journal-title":"Procedia Comput. Sci."},{"key":"ref_64","unstructured":"Jaeger, L., and Eckhardt, A. (2017, January 5\u201310). Making cues salient: The Role of Security Awareness in shaping Threat and Coping Appraisals. Proceedings of the 25th European Conference on Information Systems (ECIS) 2017, Guimar\u00e3es, Portugal. Available online: https:\/\/aisel.aisnet.org\/ecis2017_rip\/5."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1016\/j.cose.2018.08.007","article-title":"The Impact of Security Awareness on Information Technology Professionals\u2019 Behavior","volume":"79","author":"Torten","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/j.ijinfomgt.2018.10.017","article-title":"Investigating the impact of cybersecurity policy awareness on employees\u2019 cybersecurity behaviour","volume":"45","author":"Li","year":"2019","journal-title":"Int. J. Inf. Manag."},{"key":"ref_67","first-page":"752","article-title":"Security Education, Training, and Awareness Programs: Literature Review","volume":"62","author":"Hu","year":"2021","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_68","unstructured":"Bandura, A., and Walters, R.H. (1977). Social Learning Theory, Englewood Cliffs."},{"key":"ref_69","first-page":"1","article-title":"Moderating Effect of Self-Efficacy in the Relationship Between Knowledge, Attitude and Environment Behavior of Cybersecurity Awareness","volume":"18","author":"Zainal","year":"2022","journal-title":"Asian Social Science."},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Ormond, D., Warkentin, M., and Crossler, R.E. (2019). Integrating Cognition with an Affective Lens to Better Understand Information Security Policy Compliance. J. Assoc. Inf. Syst., 20.","DOI":"10.17705\/1jais.00586"},{"key":"ref_71","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1080\/0960085X.2020.1793696","article-title":"Using susceptibility claims to motivate behaviour change in IT security","volume":"30","author":"Jensen","year":"2021","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1007\/s10799-022-00362-y","article-title":"The Role of Collectivism and Moderating Effect of IT Proficiency on Intention to Disclose Protected Health Information","volume":"24","author":"Park","year":"2023","journal-title":"Inf. Technol. Manag."},{"key":"ref_73","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/j.compedu.2008.06.011","article-title":"The Impact of Information Richness on Information Security Awareness Training Effectiveness","volume":"52","author":"Shaw","year":"2009","journal-title":"Comput. Educ."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"256","DOI":"10.1108\/MRR-04-2013-0085","article-title":"Information security awareness and behaviour: A theory-based literature review","volume":"37","author":"Lebek","year":"2014","journal-title":"Manag. Res. Rev."},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1518\/001872095779049543","article-title":"Toward a theory of situation awareness in dynamic systems","volume":"37","author":"Endsley","year":"1995","journal-title":"J. Hum. Factors Ergon. Soc."},{"key":"ref_76","doi-asserted-by":"crossref","first-page":"1443","DOI":"10.1111\/j.1365-2648.2012.05989.x","article-title":"Nurses\u2019 use of situation awareness in decision-making: An integrative review","volume":"68","author":"Stubbings","year":"2012","journal-title":"J. Adv. Nurs."},{"key":"ref_77","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2014.06.008","article-title":"Cyber situational awareness\u2013a systematic review of the literature","volume":"46","author":"Franke","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_78","doi-asserted-by":"crossref","unstructured":"Renaud, J., and Ophoff, J. (2021). A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs. Organizational Cybersecurity Journal: Practice, Process and People. Organ. Cybersecur. J. Pract. Process People.","DOI":"10.1108\/OCJ-03-2021-0004"},{"key":"ref_79","unstructured":"Tianfield, H. (2016, January 5\u20137). Towards integrating a task allocation mechanism into a cyber security situation awareness system. Proceedings of the Cyber and Information Security Research Conference (CISRC) 2016, Oak Ridge, TN, USA."},{"key":"ref_80","doi-asserted-by":"crossref","unstructured":"Alshboul, Y., and Streff, K. (2017, January 28\u201330). Beyond cybersecurity awareness: Antecedents and satisfaction. Proceedings of the 2017 International Conference on Software and e-Business, Hong Kong, China.","DOI":"10.1145\/3178212.3178218"},{"key":"ref_81","doi-asserted-by":"crossref","unstructured":"Jaeger, L. (2018, January 3\u20136). Information security awareness: Literature review and integrative framework. Proceedings of the 51st Hawaii International Conference on System Sciences, Hilton Waikoloa Village, HI, USA.","DOI":"10.24251\/HICSS.2018.593"},{"key":"ref_82","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1145\/3130515.3130519","article-title":"From information security awareness to reasoned compliant action: Analyzing information security policy compliance in a large banking organization","volume":"48","author":"Bauer","year":"2017","journal-title":"ACM SIGMIS Database DATABASE Adv. Inf. Syst."},{"key":"ref_83","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1016\/j.chb.2016.11.065","article-title":"Individual differences and Information Security Awareness","volume":"69","author":"McCormac","year":"2017","journal-title":"Comput. Hum. Behav."},{"key":"ref_84","first-page":"354","article-title":"Proposing a user-centric and context-aware conceptual model for enhancing cybersecurity behaviour","volume":"40","author":"Flowerday","year":"2021","journal-title":"Behav. Inf. Technol."},{"key":"ref_85","doi-asserted-by":"crossref","first-page":"197","DOI":"10.1108\/ICS-04-2023-0063","article-title":"Informational inequality: The role of resources and attributes in information security awareness","volume":"32","author":"Lyon","year":"2024","journal-title":"Inf. Comput. Secur."},{"key":"ref_86","doi-asserted-by":"crossref","first-page":"128","DOI":"10.1016\/j.cose.2015.04.006","article-title":"Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs","volume":"52","author":"Tsohou","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_87","doi-asserted-by":"crossref","unstructured":"Endsley, M.R. (1988). Design and evaluation for situation awareness enhancement. Proceedings of the Human Factors Society Annual Meeting, Sage Publications.","DOI":"10.1177\/154193128803200221"},{"key":"ref_88","doi-asserted-by":"crossref","first-page":"125140","DOI":"10.1109\/ACCESS.2020.3007867","article-title":"Factors related to cyber security behaviour","volume":"8","author":"Putnik","year":"2020","journal-title":"IEEE Access"},{"key":"ref_89","doi-asserted-by":"crossref","first-page":"103386","DOI":"10.1016\/j.cose.2023.103386","article-title":"Understanding Extra-Role Security Behaviors: An Integration of the Self-Determination Theory and Construal Level Theory","volume":"132","author":"Frank","year":"2023","journal-title":"Computers & Security"},{"key":"ref_90","unstructured":"Peltier, T.R. (2005). Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management, CRC Press."},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Amankwa, E., Loock, M., and Kritzinger, E. (2014, January 8\u201310). A conceptual analysis of information security education, information security training and information security awareness definitions. Proceedings of the 9th International Conference for Internet Technology and Secured Transactions (ICITST-2014), London, UK.","DOI":"10.1109\/ICITST.2014.7038814"},{"key":"ref_92","first-page":"8","article-title":"Understanding information security awareness: A systematic literature review","volume":"49","author":"Tsohou","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_93","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1016\/j.istr.2010.05.002","article-title":"The positive outcomes of information security awareness training in companies\u2014A case study","volume":"14","author":"Eren","year":"2009","journal-title":"Inf. Secur. Tech. Rep."},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1007\/s10796-019-09977-z","article-title":"The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence","volume":"23","author":"Kweon","year":"2021","journal-title":"Inf. Syst. Front."},{"key":"ref_95","doi-asserted-by":"crossref","unstructured":"Sikolia, D., Biros, D., and Zhang, T. (2023). How Effective Are SETA Programs Anyway: Learning and Forgetting in Security Awareness Training. J. Cybersecurity Educ. Res. Pract., 2023.","DOI":"10.32727\/8.2023.13"},{"key":"ref_96","doi-asserted-by":"crossref","first-page":"132132","DOI":"10.1109\/ACCESS.2022.3230286","article-title":"Assessment of the impact of information security awareness training methods on knowledge, attitude, and behaviour","volume":"10","author":"Alkhazi","year":"2022","journal-title":"IEEE Access"},{"key":"ref_97","first-page":"12","article-title":"A Systematic Review of Multimedia Tools for Cybersecurity Awareness and Education","volume":"54","author":"Chiasson","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"ref_98","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1080\/07421222.2019.1705512","article-title":"Using design-science based gamification to improve organizational security training and compliance","volume":"37","author":"Silic","year":"2020","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_99","doi-asserted-by":"crossref","first-page":"669","DOI":"10.1080\/0960085X.2020.1797546","article-title":"Choose your own training adventure: Designing a gamified SETA artefact for improving information security and privacy through interactive storytelling","volume":"29","author":"Dincelli","year":"2020","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_100","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/S1353-4858(21)00040-4","article-title":"Gamification\u2014Can it be applied to security awareness training?","volume":"4","author":"Emm","year":"2021","journal-title":"Netw. Secur."},{"key":"ref_101","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1080\/0144929X.2012.708787","article-title":"User preference of cyber security awareness delivery methods","volume":"33","author":"Abawajy","year":"2014","journal-title":"Behav. Inf. Technol."},{"key":"ref_102","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.cose.2014.03.003","article-title":"An exploratory investigation of message-person congruence in information security awareness campaigns","volume":"43","author":"Kajzer","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_103","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1016\/j.dss.2018.02.009","article-title":"Exploring the Influence of Flow and Psychological Ownership on Security Education, Training and Awareness Effectiveness and Security Compliance","volume":"108","author":"Yoo","year":"2018","journal-title":"Decis. Support Syst."},{"key":"ref_104","doi-asserted-by":"crossref","first-page":"757","DOI":"10.2307\/25750704","article-title":"Improving employees\u2019 compliance through information systems security training: An action research study","volume":"34","author":"Puhakainen","year":"2010","journal-title":"MIS Q."},{"key":"ref_105","doi-asserted-by":"crossref","first-page":"3163","DOI":"10.3390\/su12083163","article-title":"Organizational information security management for sustainable information systems: An unethical employee information security behaviour perspective","volume":"12","author":"Chu","year":"2020","journal-title":"Sustainability"},{"key":"ref_106","doi-asserted-by":"crossref","first-page":"286","DOI":"10.1109\/TPC.2014.2374011","article-title":"A path to successful management of employee security compliance: An empirical study of information security climate","volume":"57","author":"Goo","year":"2014","journal-title":"IEEE Trans. Prof. Commun."},{"key":"ref_107","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1080\/0960085X.2021.1927866","article-title":"Enhancing users\u2019 security engagement through cultivating commitment: The role of psychological needs fulfilment","volume":"32","author":"Davis","year":"2023","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_108","doi-asserted-by":"crossref","first-page":"1","DOI":"10.36941\/ajis-2023-0151","article-title":"Organizational Determinants and Compliance Behaviour to Shape Information Security Plan","volume":"12","author":"Cavallari","year":"2023","journal-title":"Acad. J. Interdiscip. Stud."},{"key":"ref_109","doi-asserted-by":"crossref","first-page":"103968","DOI":"10.1016\/j.im.2024.103968","article-title":"Fostering Information Security Compliance as Organizational Citizenship Behavior","volume":"61","author":"Vedadi","year":"2024","journal-title":"Inf. Manage."},{"key":"ref_110","doi-asserted-by":"crossref","unstructured":"Price, W., Price, T., Tenan, M., Head, J., Maslin, W., and LaFiandra, M. (2016, January 15\u201318). Acute Stress Causes Overconfidence in Situation Awareness. Proceedings of the 2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA), San Diego, CA, USA.","DOI":"10.1109\/COGSIMA.2016.7497778"},{"key":"ref_111","first-page":"463","article-title":"The effect of resilience and job stress on information security awareness","volume":"26","author":"McCormac","year":"2018","journal-title":"Inf. Comput. Secur."},{"key":"ref_112","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1016\/j.cose.2016.02.004","article-title":"Understanding information security stress: Focusing on the type of information security compliance activity","volume":"59","author":"Lee","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_113","doi-asserted-by":"crossref","first-page":"103151","DOI":"10.1016\/j.im.2019.02.006","article-title":"Predicting employee information security policy compliance on a daily basis: The interplay of security-related stress, emotions, and neutralization","volume":"56","author":"Teh","year":"2019","journal-title":"Inf. Manag."},{"key":"ref_114","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1111\/isj.12319","article-title":"When enough is enough: Investigating the antecedents and consequences of information security fatigue","volume":"31","author":"Cram","year":"2021","journal-title":"Inf. Syst. J."},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"285","DOI":"10.2753\/MIS0742-1222310210","article-title":"Understanding employee responses to stressful information security requirements: A coping perspective","volume":"31","author":"Herath","year":"2014","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_116","doi-asserted-by":"crossref","first-page":"2339","DOI":"10.1080\/01605682.2022.2147030","article-title":"Increasing situation awareness in healthcare through real-time simulation","volume":"74","author":"Harper","year":"2023","journal-title":"J. Oper. Res. Society"},{"key":"ref_117","unstructured":"Bolger, C., Brummel, B., Aurigemma, S., Moore, T., and Baskin, M. (2023, January 29\u201330). Information security awareness: Identifying gaps in current measurement tools. Proceedings of the 22nd Annual Security Conference (ASC), Las Vegas, NV, USA."},{"key":"ref_118","unstructured":"Bui, T.X. (2023). Do SETA Interventions Change Security Behavior? A Literature Review. Proceedings of the 56th Annual Hawaii International Conference on System Sciences (HICSS 2023), University of Hawaii, M\u0101noa."},{"key":"ref_119","unstructured":"Hart, C. (1998). Doing a Literature Review: Releasing the Social Science Research Imagination, Sage."},{"key":"ref_120","doi-asserted-by":"crossref","first-page":"2577","DOI":"10.1007\/s11846-022-00588-8","article-title":"Literature reviews as independent studies: Guidelines for academic practice","volume":"16","author":"Kraus","year":"2022","journal-title":"Rev. Manag. Sci."},{"key":"ref_121","unstructured":"Letts, L., Wilkins, S., Law, M.C., Stewart, D.A., Bosch, J., and Westmorland, M.G. (2007). Guidelines for Critical Review Form\u2014Qualitative Studies (Version 2.0), McMaster University Occupational Therapy Evidence-Based Practice Research Group."},{"key":"ref_122","unstructured":"Roscoe, J.T. (1975). Fundamental Research Statistics for the Behavioural Sciences, Holt, Rinehart & Winston. [2nd ed.]."},{"key":"ref_123","first-page":"133","article-title":"Students\u2019 cybersecurity awareness at a private tertiary educational institution","volume":"20","author":"Chandarman","year":"2017","journal-title":"Afr. J. Inf. Commun."},{"key":"ref_124","doi-asserted-by":"crossref","first-page":"1240","DOI":"10.1287\/isre.2020.0941","article-title":"The Influence of Professional Subculture on Information Security Policy Violations: A Field Study in a Healthcare Context","volume":"31","author":"Sarkar","year":"2020","journal-title":"Inf. Syst. Res."},{"key":"ref_125","unstructured":"Forthofer, R.N., Lee, E.S., and Hernandez, M. (2006). Biostatistics: A Guide to Design, Analysis and Discovery, Elsevier."},{"key":"ref_126","unstructured":"Salmer\u00f3n, R., Garc\u00eda, C., and Garc\u00eda, J. (2020). Overcoming the inconsistences of the variance inflation factor: A redefined VIF and a test to detect statistical troubling multicollinearity. arXiv."},{"key":"ref_127","doi-asserted-by":"crossref","first-page":"347","DOI":"10.1016\/B978-0-08-044894-7.01353-1","article-title":"Nonparametric Statistical Methods","volume":"3","author":"Sijtsma","year":"2010","journal-title":"Int. Encycl. Educ."},{"key":"ref_128","doi-asserted-by":"crossref","unstructured":"Tinsley, H.E.A., and Brown, S.D. (2000). Confirmatory Factor Analysis. Handbook of Applied Multivariate Statistics and Mathematical Modeling, Academic Press.","DOI":"10.1016\/B978-012691360-6\/50002-1"},{"key":"ref_129","unstructured":"Hancock, G.R., and Mueller, R.O. (2006). Exploratory or confirmatory factor analysis?. The Reviewer\u2019s Guide to Quantitative Methods in the Social Sciences, Routledge."},{"key":"ref_130","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1177\/002224378101800104","article-title":"Evaluating structural equation models with unobservable variables and measurement error","volume":"18","author":"Fornell","year":"1981","journal-title":"J. Mark. Res."},{"key":"ref_131","unstructured":"Hair, J.F., Anderson, R.E., Tatham, R.L., and Black, W.C. (2003). Multivariate Data Analysis, Prentice Hall. [5th ed.]."},{"key":"ref_132","doi-asserted-by":"crossref","unstructured":"Field, A. (2005). Discovering Statistics Using SPSS, Sage Publications.","DOI":"10.53841\/bpspag.2005.1.56.31"},{"key":"ref_133","unstructured":"Kutner, M.H., Nachtsheim, C.J., Neter, J., and Li, W. (2004). Applied Linear Regression Models, McGraw-Hill Irwin. [4th ed.]."},{"key":"ref_134","doi-asserted-by":"crossref","first-page":"673","DOI":"10.1007\/s11135-006-9018-6","article-title":"A caution regarding rules of thumb for variance inflation factors","volume":"41","year":"2007","journal-title":"Qual. Quant."},{"key":"ref_135","doi-asserted-by":"crossref","unstructured":"Borenstein, M., Hedges, L.V., Higgins, J.P., and Rothstein, H.R. (2021). Introduction to Meta-Analysis, John Wiley & Sons.","DOI":"10.1002\/9781119558378"},{"key":"ref_136","unstructured":"Cisco (2022, April 14). The Top Cybersecurity Threats in 2022. Available online: https:\/\/umbrella.cisco.com\/blog\/top-cybersecurity-threats-2022."},{"key":"ref_137","doi-asserted-by":"crossref","unstructured":"Chen, H., Hai, Y., Tu, L., and Fan, J. (2023). Not All Information Security-Related Stresses Are Equal: The Effects of Challenge and Hindrance Stresses on Employees\u2019 Compliance with Information Security Policies. Behav. Inf. Technol., 1\u201316.","DOI":"10.1080\/0144929X.2023.2295950"},{"key":"ref_138","first-page":"254","article-title":"Unconscious on their own ignorance: Overconfidence in information security","volume":"50","author":"Ament","year":"2017","journal-title":"J. Inf. Sci."},{"key":"ref_139","doi-asserted-by":"crossref","first-page":"790","DOI":"10.1111\/isj.12424","article-title":"The effects of knowledge mechanisms on employees\u2019 information security threat construal","volume":"33","author":"Mady","year":"2023","journal-title":"Inf. Syst. J."},{"key":"ref_140","doi-asserted-by":"crossref","first-page":"195","DOI":"10.5539\/gjhs.v8n7p195","article-title":"The relationship between organizational culture and organizational commitment in Zahedan University of Medical Sciences","volume":"8","author":"Azizollah","year":"2016","journal-title":"Glob. J. Health Sci."},{"key":"ref_141","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1145\/3631341.3631348","article-title":"A taxonomy of SETA methods and linkage to delivery preferences","volume":"54","author":"Nohlberg","year":"2023","journal-title":"ACM SIGMIS Database DATABASE Adv. Inf. Syst."},{"key":"ref_142","doi-asserted-by":"crossref","first-page":"615","DOI":"10.1111\/j.1540-5915.2012.00361.x","article-title":"Managing employee compliance with information security policies: The critical role of top management and organizational culture","volume":"43","author":"Hu","year":"2012","journal-title":"Decis. Sci."},{"key":"ref_143","unstructured":"Jaeger, L., Ament, C., and Eckhardt, A. (2017, January 10-13). The closer you get the more aware you become\u2013a case study about psychological distance to information security incidents. Proceedings of the ICIS 2017: Transforming Society with Digital Innovation, Seoul, Republic of Korea."},{"key":"ref_144","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1080\/19393555.2022.2077265","article-title":"Measuring organizational information security awareness in South Africa","volume":"32","author":"Kritzinger","year":"2023","journal-title":"Inf. Secur. J. A Glob. Perspect."},{"key":"ref_145","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1007\/BF02291575","article-title":"An index of factorial simplicity","volume":"39","author":"Kaiser","year":"1974","journal-title":"Psychometrika"},{"key":"ref_146","doi-asserted-by":"crossref","first-page":"3192","DOI":"10.1016\/j.jbusres.2015.12.008","article-title":"Common methods variance detection in business research","volume":"69","author":"Fuller","year":"2016","journal-title":"J. Bus. Res."},{"key":"ref_147","unstructured":"NIST (2024, August 02). Computer Security Resource Center, Available online: https:\/\/csrc.nist.gov\/glossary\/term\/cybersecurity."},{"key":"ref_148","doi-asserted-by":"crossref","first-page":"311","DOI":"10.1007\/978-3-319-16486-1_31","article-title":"Cyber resilience\u2014Fundamentals for a definition","volume":"353","author":"Henkel","year":"2015","journal-title":"Adv. Intell. Syst. Comput."},{"key":"ref_149","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","article-title":"From information security to cyber security","volume":"38","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_150","unstructured":"Laudon, K.C., and Laudon, J.P. (2012). Management Information Systems, Prentice-Hall. [12th ed.]."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/15\/8\/505\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:40:19Z","timestamp":1760110819000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/15\/8\/505"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,21]]},"references-count":150,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["info15080505"],"URL":"https:\/\/doi.org\/10.3390\/info15080505","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,21]]}}}