Self-Efficacy and Security Behavior: Results from a Systematic Review of Research Methods
Authors
Title of the Paper
Self-Efficacy and Security Behavior: Results from a Systematic Review of Research Methods
Paper Information
- Subject Area: Cybersecurity, Psychology, and User Behavior
- Keywords: Self-efficacy, Cybersecurity, Systematic review, Research methods, Security behavior, Psychometrics
Research Background and Issues
-
Issues or Challenges:
- The psychological foundation of cybersecurity behavior has yet to be standardized, particularly in the measurement and theoretical mechanisms of "self-efficacy."
- Inconsistent definitions and methods in existing literature lead to fragmented data and difficulties in reproducing research findings.
-
Importance of the Research:
- Data privacy and IT security have become key public concerns, and the formation of secure habits lies at the intersection of technology and psychology.
- Self-efficacy is considered the only psychological variable that significantly predicts cybersecurity behavior, making it crucial to study its role and operational potential.
-
Motivation and Related Work:
- Building on previous studies (e.g., He et al., 2014), this paper aims to comprehensively evaluate research methods and existing issues regarding self-efficacy in the cybersecurity domain.
Solution
-
Proposed Methods or Solutions:
- This paper systematically reviewed 174 studies conducted between 2010 and 2021, analyzing:
- The quality and methods of measuring cybersecurity self-efficacy.
- The role of self-efficacy in theoretical frameworks.
- Intervention designs targeting self-efficacy.
- Multi-database searches, dual coding, and strict exclusion criteria were employed to minimize selection bias.
- This paper systematically reviewed 174 studies conducted between 2010 and 2021, analyzing:
-
Innovative Contributions:
- Conducted a systematic evaluation of the fragmentation issue across interdisciplinary literature and proposed recommendations for data standardization.
- Provided an extensive variable analysis, categorizing variables as "causes," "outcomes," or "both."
-
Implementation Steps and Techniques:
- Data collection utilized 18 databases, covering both quantitative and qualitative studies.
- Variables coded included sample information, study types, measurement tools, psychometric properties, and intervention methods.
- Both quantitative and qualitative analysis methods were applied, including data aggregation, network analysis, and exploratory statistics.
Research Findings
-
Specific Findings:
- Identified 173 unique tools for measuring cybersecurity self-efficacy, most of which were used only once.
- Weak psychometric standards: While average reliability was high, validation analyses (e.g., validity testing) were generally lacking.
- Extracted and analyzed 55 outcome variables and 51 causal variables, highlighting the diverse yet non-standardized roles of self-efficacy.
- Only 13 studies designed interventions targeting self-efficacy, none of which were replicated.
-
Comparison with Existing Solutions:
- Compared to previous reviews (e.g., He et al., 2014), the issues remain unresolved, with measurement tools becoming even more diverse and fragmented.
- Emphasized the need for improved consistency in psychometric standards and integration of theoretical frameworks.
-
Experimental or Evaluation Results:
- The weighted average Cronbach α coefficient for newly introduced scales was approximately 0.87, indicating good reliability.
- Intervention methods primarily focused on training and activity design, suggesting "mastery experiences" as the main mechanism of action.
- Theoretical frameworks lacked consensus in variable definitions, with multiple pathways or dual causal relationships observed among variables.
-
Limitations and Future Directions:
- This paper only evaluated data up to 2021, requiring updates over time.
- Transparency and detailed reporting in studies were insufficient, particularly regarding scale development processes and intervention mechanisms.
- Future work should focus on scale construction, theoretical simplification, and replication of interventions.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can measurement methods for cybersecurity self-efficacy be improved?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- What role does self-efficacy play in cybersecurity theoretical frameworks?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- Which intervention designs most effectively improve self-efficacy related to cybersecurity behavior?Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
Practical Problems
1- Users lack standardized tools and methods to improve confidence and effectiveness of cybersecurity habits.Category: Privacy Experience, Control, and Workflow DesignSimilar questionsarrow_forward
- 100%
Small Talk, Big Impact: The Role of Everyday Conversations in Cybersecurity Practices
CHI '26· Privacy Perception & Decision-Making +1
- 75%
Collaborative Work in Malware Analysis: Understanding the Roles and Challenges of Malware Analysts
CHI '25· Privacy Perception & Decision-Making +1
- 67%
A World Full of Privacy and Security (Mis)conceptions? Findings of a Representative Survey in 12 Countries
CHI '23· Privacy by Design & User Control +2
- 67%
"Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTs
CHI '26· Cybersecurity Training & Awareness +2
- 67%
From Fear to Control: Developing a Three-Factor Scale for Cybersecurity Anxiety (CybAS)
CHI '26· Privacy Perception & Decision-Making +2
- 60%
Security Managers Are Not The Enemy Either
CHI '19· Privacy by Design & User Control +1
- 60%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 60%
Measuring Identity Confusion with Uniform Resource Locators
CHI '20· Privacy Perception & Decision-Making +1
- 60%
Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
CHI '23· Privacy Perception & Decision-Making +1
- 60%
Understanding and Improving User Adoption and Security Awareness in Password Checkup Services
CHI '25· Passwords & Authentication +1
Based on Jaccard similarity of research subtopics & professions (≥60%)