{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T15:35:37Z","timestamp":1781019337396,"version":"3.54.1"},"reference-count":63,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T00:00:00Z","timestamp":1756944000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>This study presents a novel and interpretable, deployment-ready framework for predicting cybersecurity incidents through item-level behavioral, cognitive, and dispositional indicators. Based on survey data from 453 professionals across countries and sectors, we developed 72 logistic regression models across twelve self-reported incident outcomes\u2014from account lockouts to full device compromise\u2014within six analytically stratified layers (Education, IT, Hungary, UK, USA, and full sample). Drawing on five theoretically grounded domains\u2014cybersecurity behavior, digital literacy, personality traits, risk rationalization, and work\u2013life boundary blurring\u2014our models preserve the full granularity of individual responses rather than relying on aggregated scores, offering rare transparency and interpretability for real-world applications. This approach reveals how stratified models, despite smaller sample sizes, often outperform general ones by capturing behavioral and contextual specificity. Moderately prevalent outcomes (e.g., suspicious logins, multiple mild incidents) yielded the most robust predictions, while rare-event models, though occasionally high in \u201cArea Under the Receiver Operating Characteristic Curve\u201d (AUC), suffered from overfitting under cross-validation. Beyond model construction, we introduce threshold calibration and fairness-aware integration of demographic variables, enabling ethically grounded deployment in diverse organizational contexts. By unifying theoretical depth, item-level precision, multilayer stratification, and operational guidance, this study establishes a scalable blueprint for human-centric cybersecurity. It bridges the gap between behavioral science and risk analytics, offering the tools and insights needed to detect, predict, and mitigate user-level threats in increasingly blurred digital environments.<\/jats:p>","DOI":"10.3390\/jcp5030067","type":"journal-article","created":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T07:46:17Z","timestamp":1757058377000},"page":"67","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Predicting Cybersecurity Incidents via Self-Reported Behavioral and Psychological Indicators: A Stratified Logistic Regression Approach"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4623-8404","authenticated-orcid":false,"given":"L\u00e1szl\u00f3","family":"Bogn\u00e1r","sequence":"first","affiliation":[{"name":"Department of Information Technology, University of Duna\u00fajv\u00e1ros, 2400 Duna\u00fajv\u00e1ros, Hungary"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,4]]},"reference":[{"key":"ref_1","first-page":"102212","article-title":"Bring Your Own Device (BYOD) as reversed IT adoption: Insights into managers\u2019 coping strategies","volume":"56","author":"Barlette","year":"2021","journal-title":"Int. J. Inf. Manag."},{"key":"ref_2","first-page":"234","article-title":"Working from home: Cybersecurity in the age of COVID-19","volume":"21","author":"Borkovich","year":"2020","journal-title":"Issues Inf. Syst."},{"key":"ref_3","first-page":"102726","article-title":"Evaluating the cyber security readiness of organizations and its influence on performance","volume":"58","author":"Hasan","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"371","DOI":"10.1007\/s10111-021-00683-y","article-title":"Leveraging human factors in cybersecurity: An integrated methodological approach","volume":"24","author":"Pollini","year":"2022","journal-title":"Cogn. Technol. Work."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10869-021-09732-9","article-title":"Organizational science and cybersecurity: Abundant opportunities for research at the interface","volume":"37","author":"Dalal","year":"2022","journal-title":"J. Bus. Psychol."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1016\/j.ijhcs.2019.05.005","article-title":"Moving from a \u2018human-as-problem\u201d to a \u2018human-as-solution\u201d cybersecurity mindset","volume":"131","author":"Zimmermann","year":"2019","journal-title":"Int. J. Human-Computer Stud."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"101747","DOI":"10.1016\/j.cose.2020.101747","article-title":"A comprehensive model of information security factors for decision-makers","volume":"92","author":"Diesch","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_8","unstructured":"Kantola, J., Barath, T., Nazir, S., and Andre, T. (2018). Human factors in information security culture: A literature review. Advances in Human Factors in Cybersecurity, Springer."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1037\/a0035076","article-title":"A diary study on work-related smartphone use, psychological detachment and exhaustion: Examining the role of the perceived segmentation norm","volume":"19","author":"Derks","year":"2014","journal-title":"J. Occup. Health Psychol."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"112","DOI":"10.1016\/j.jvb.2012.04.003","article-title":"Work\u2013nonwork boundary management profiles: A person-centered approach","volume":"81","author":"Kossek","year":"2012","journal-title":"J. Vocat. Behav."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"258","DOI":"10.1108\/XJM-10-2020-0186","article-title":"Work-life balance\u2014A systematic review","volume":"20","author":"Thilagavathy","year":"2023","journal-title":"Vilakshan-XIMB J. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1016\/j.chb.2016.11.065","article-title":"Individual differences and Information Security Awareness","volume":"69","author":"McCormac","year":"2017","journal-title":"Comput. Hum. Behav."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Siponen, M., Soliman, W., Topalli, V., and Vestman, T. (2024). Reconsidering neutralization techniques in behavioral cyber-security as cybersecurity hygiene discounting. SSRN.","DOI":"10.2139\/ssrn.4779061"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"103741","DOI":"10.1016\/j.cose.2024.103741","article-title":"A typology of cybersecurity behavior among knowledge workers","volume":"140","author":"Baltuttis","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Redmiles, E.M., Kross, S., and Mazurek, M.L. (2016, January 24\u201328). How I learned to be secure: A census-representative survey of security advice sources and behavior. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978307"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1186\/s42400-020-00050-w","article-title":"Review and insight on the behavioral aspects of cybersecurity","volume":"3","author":"Lahcen","year":"2020","journal-title":"Cybersecurity"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Guan, T., Chang, S., Deng, Y., Xue, F., Wang, C., and Jia, X. (2025). Oriented SAR Ship Detection Based on Edge Deformable Convolution and Point Set Representation. Remote Sens., 17.","DOI":"10.3390\/rs17091612"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"472","DOI":"10.2307\/259305","article-title":"All in a Day\u2019S Work: Boundaries and Micro Role Transitions","volume":"25","author":"Ashforth","year":"2000","journal-title":"Acad. Manag. Rev."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"153","DOI":"10.2307\/2654783","article-title":"Home and Work: Negotiating Boundaries through Everyday Life","volume":"27","author":"Voydanoff","year":"1996","journal-title":"Contemp. Sociol. A J. Rev."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1337","DOI":"10.1287\/orsc.1120.0806","article-title":"The Autonomy Paradox: The Implications of Mobile Email Devices for Knowledge Professionals","volume":"24","author":"Mazmanian","year":"2013","journal-title":"Organ. Sci."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1177\/1440783310365583","article-title":"Enacting virtual connections between work and home","volume":"46","author":"Wajcman","year":"2010","journal-title":"J. Sociol."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1177\/23197145221115530","article-title":"A Systematic Literature Review of Work-Life Balance Using ADO Model","volume":"12","author":"Singh","year":"2022","journal-title":"FIIB Bus. Rev."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1207\/s15327957pspr0303_3","article-title":"Moral Disengagement in the Perpetration of Inhumanities","volume":"3","author":"Bandura","year":"1999","journal-title":"Pers. Soc. Psychol. Rev."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"266","DOI":"10.1111\/isj.12129","article-title":"Examining employee computer abuse intentions: Insights from justice, deterrence and neutralization perspectives","volume":"28","author":"Willison","year":"2018","journal-title":"Inf. Syst. J."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"220","DOI":"10.1016\/j.chb.2014.05.043","article-title":"Understanding personal use of the Internet at work: An integrated model of neutralization techniques and general deterrence theory","volume":"38","author":"Cheng","year":"2014","journal-title":"Comput. Hum. Behav."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"486","DOI":"10.1016\/j.cose.2011.05.002","article-title":"Understanding the mindset of the abusive insider: An examination of insiders\u2019 causal reasoning following internal security changes","volume":"30","author":"Posey","year":"2011","journal-title":"Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"487","DOI":"10.2307\/25750688","article-title":"Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations","volume":"34","author":"Siponen","year":"2010","journal-title":"MIS Q."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1974","DOI":"10.1108\/JKM-09-2024-1049","article-title":"Testing a comprehensive model of employee IS misuse in a developing economy context","volume":"29","author":"Mohammed","year":"2025","journal-title":"J. Knowl. Manag."},{"key":"ref_29","first-page":"269","article-title":"Employees Attitude towards Cyber Security and Risky Online Behaviours: An Empirical Assessment in the United Kingdom","volume":"12","author":"Hadlington","year":"2018","journal-title":"Int. J. Cyber Criminol."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"489","DOI":"10.1515\/jhsem-2014-0035","article-title":"From Weakest Link to Security Hero: Transforming Staff Security Behavior","volume":"11","author":"Pfleeger","year":"2014","journal-title":"J. Homel. Secur. Emerg. Manag."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"190","DOI":"10.1016\/j.im.2012.04.002","article-title":"Motivating IS security compliance: Insights from Habit and Protection Motivation Theory","volume":"49","author":"Vance","year":"2012","journal-title":"Inf. Manag."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Bogn\u00e1r, L., and Botty\u00e1n, L. (2024). Evaluating Online Security Behavior: Development and Validation of a Personal Cybersecurity Awareness Scale for University Students. Educ. Sci., 14.","DOI":"10.3390\/educsci14060588"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"523","DOI":"10.2307\/25750690","article-title":"Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information Security Awareness","volume":"34","author":"Bulgurcu","year":"2010","journal-title":"MIS Q."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"815","DOI":"10.1016\/j.dss.2008.11.010","article-title":"Studying users\u2019 computer security behavior: A health belief perspective","volume":"46","author":"Ng","year":"2009","journal-title":"Decis. Support Syst."},{"key":"ref_35","first-page":"82","article-title":"Cyber Security Awareness, Knowledge and Behavior: A Comparative Study","volume":"62","author":"Zwilling","year":"2020","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"103402","DOI":"10.1016\/j.sysarc.2025.103402","article-title":"A systematic review of multi-factor authentication in digital payment systems: NIST standards alignment and industry implementation analysis","volume":"162","author":"Pham","year":"2025","journal-title":"J. Syst. Arch."},{"key":"ref_37","unstructured":"Radwan, R., and Zejnilovic, S. (2025, August 26). Password Reuse Is Rampant: Nearly Half of Observed User Logins Are Compromised. Cloudflare Blog. Available online: https:\/\/blog.cloudflare.com\/password-reuse-rampant-half-user-logins-compromised."},{"key":"ref_38","unstructured":"Blanton, S. (2025, August 26). 50+ Password Statistics & Trends to Know in JumpCloud. Available online: https:\/\/jumpcloud.com\/blog\/password-statistics-trends."},{"key":"ref_39","unstructured":"Gilster, P. (1997). Digital Literacy, Wiley Computer Pub."},{"key":"ref_40","unstructured":"DiMaggio, P., and Hargittai, E. (2001). From the \u2018Digital Divide\u2019 to \u2018Digital Inequality\u2019: Studying Internet Use as Penetration Increases, Princeton University Center."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"371","DOI":"10.1177\/0894439305275911","article-title":"Survey Measures of Web-Oriented Digital Literacy","volume":"23","author":"Hargittai","year":"2005","journal-title":"Soc. Sci. Comput. Rev."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1177\/0093650211418338","article-title":"Digital Literacy and Privacy Behavior Online","volume":"40","author":"Park","year":"2011","journal-title":"Commun. Res."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1177\/1461444813487959","article-title":"The digital divide shifts to differences in usage","volume":"16","year":"2014","journal-title":"New Media Soc."},{"key":"ref_44","unstructured":"Ramadhany, A.F., Damayanti, N.E., Rahmania, L.A. (2024, January 15\u201316). Digital literacy as a cyber crime defense and prevention strategy. Proceedings of the 9th International Seminar of Research Month 2024, Surabaya, Indonesia."},{"key":"ref_45","unstructured":"Phan, B.T., Do, P.H., and Le, D.Q. (2024, January 1\u20132). The impact of digital literacy on personal information security: Evidence from Vietnam. Proceedings of the International Conference on Emerging Challenges: Sustainable Strategies in the Data-driven Economy (ICECH 2024), Thanh Hoa, Vietnam."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"77","DOI":"10.62271\/pjc.171.77.96","article-title":"The impact of digital literacy on cybercrime awareness, victimization, and prevention measures: A study of cyberbullying in Saudi Arabia","volume":"17","author":"Ismaeel","year":"2025","journal-title":"Pak. J. Criminol."},{"key":"ref_47","unstructured":"Pervin, L.A., and John, O.P. (1999). A five-factor theory of personality. Handbook of Personality: Theory and Research, Guilford Press. [2nd ed.]."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1016\/j.cose.2017.11.015","article-title":"Correlating human traits and cyber security behavior intentions","volume":"73","author":"Gratian","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"e00346","DOI":"10.1016\/j.heliyon.2017.e00346","article-title":"Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours","volume":"3","author":"Hadlington","year":"2017","journal-title":"Heliyon"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1057\/ejis.2008.29","article-title":"Personality traits and concern for privacy: An empirical study in the context of location-based services","volume":"17","author":"Junglas","year":"2008","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"434","DOI":"10.1016\/j.dss.2011.01.017","article-title":"The role of affect and cognition on online consumers\u2019 decision to disclose personal information to unfamiliar online vendors","volume":"51","author":"Li","year":"2011","journal-title":"Decis. Support Syst."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1037\/ppm0000247","article-title":"Personality as a predictor of cybersecurity behavior","volume":"9","author":"Shappie","year":"2020","journal-title":"Psychol. Popul. Media"},{"key":"ref_53","unstructured":"Halevi, T., Lewis, J., and Memon, N. (2013). A closer look at the self-reported behaviors of users on social networks. arXiv, Available online: https:\/\/arxiv.org\/abs\/1301.7643."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"107770","DOI":"10.1016\/j.chb.2023.107770","article-title":"The digital harms of smart home devices: A systematic literature review","volume":"145","author":"Kemp","year":"2023","journal-title":"Comput. Hum. Behav."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Wash, R., and Cooper, M.M. (2018, January 31). Who provides phishing training? Facts, stories, and people like me. Proceedings of the 2018 ACM CHI Conference on Human Factors in Computing Systems (CHI \u201918), Montreal, QC, Canada.","DOI":"10.1145\/3173574.3174066"},{"key":"ref_56","unstructured":"Conard, C.F. (2024). Quantifying the Severity of a Cybersecurity Incident for Incident Reporting. [Master\u2019s Thesis, Massachusetts Institute of Technology]."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1080\/10580530.2015.1117842","article-title":"Impact of Users\u2019 Security Awareness on Desktop Security Behavior: A Protection Motivation Theory Perspective","volume":"33","author":"Hanus","year":"2016","journal-title":"Inf. Syst. Manag."},{"key":"ref_58","unstructured":"de Bruin, M. (2022). Individual and Contextual Variables of Cyber Security Behaviour. [Master\u2019s Thesis, University of London]. Available online: https:\/\/arxiv.org\/abs\/2405.16215."},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Khaliq, S., Tariq, Z.U.A., and Masood, A. (2020, January 12\u201313). Role of user and entity behavior analytics in detecting insider attacks. Proceedings of the 2020 International Conference on Cyber Warfare and Security (ICCWS), Norfolk, VA, USA.","DOI":"10.1109\/ICCWS48432.2020.9292394"},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Danish, M. (2024). Enhancing cyber security through predictive analytics: Real-time threat detection and response. arXiv.","DOI":"10.14569\/IJACSA.2025.0160804"},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"22","DOI":"10.1016\/j.jbef.2017.12.004","article-title":"Prolific.ac\u2014A subject pool for online experiments","volume":"17","author":"Palan","year":"2018","journal-title":"J. Behav. Exp. Finance"},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1175\/1520-0493(1950)078<0001:VOFEIT>2.0.CO;2","article-title":"Verification of forecasts expressed in terms of probability","volume":"78","author":"Brier","year":"1950","journal-title":"Mon. Weather. Rev."},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Rasool, A., Aslam, S., Hussain, N., Imtiaz, S., and Riaz, W. (2025). nBERT: Harnessing NLP for Emotion Recognition in Psychotherapy to Transform Mental Health Care. Information, 16.","DOI":"10.3390\/info16040301"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/67\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:39:31Z","timestamp":1760035171000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/67"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,4]]},"references-count":63,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030067"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030067","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,4]]}}}