"A five-year-old could understand it" versus "This is way too confusing": Exploring Non-expert Understandings and Perceptions of Cybersecurity Definitions

Privacy by Design & User ControlCybersecurity Training & Awareness

Research Background and Issues

  • Identified Problems or Challenges:
    The authors found that existing cybersecurity definitions designed for non-experts are often difficult for the general public to fully understand. This communication gap may lead to misunderstandings, hinder participation, and alienate certain groups from digital security practices, ultimately resulting in a lack of collective responsibility for cybersecurity.

  • Significance:
    Cybersecurity is not solely the responsibility of experts; it requires active public participation to foster a shared sense of digital security. Without effective communication bridges, some groups may fail to adopt appropriate cybersecurity measures, increasing the risk of digital exclusion.

  • Research Motivation and Related Work:
    Existing cybersecurity definitions are typically tailored to technical, legal, or academic audiences. The authors argue for examining whether these definitions are suitable for the general public's understanding.
    Additionally, prior literature highlights the complexity and lack of standardization in cybersecurity definitions, which may lead to public misconceptions and inconsistent behaviors.

Proposed Solution

  • Proposed Methods or Solutions:
    The authors employed a semi-structured interview approach, studying 30 non-expert participants from diverse age and educational backgrounds. These participants were asked to evaluate various aspects of cybersecurity definitions, including terminology, structure, and comprehensiveness.

  • Innovative Contributions:

    • This is the first systematic exploration of public perceptions and understanding of cybersecurity definitions, uncovering not only varying interpretations but also misconceptions or incomplete understandings.
    • The study examines definitions as boundary objects, demonstrating how they can either facilitate or hinder comprehension.
    • Specific recommendations are provided to improve cybersecurity definitions and related communication formats, such as training materials and public cybersecurity education.
  • Implementation Steps:

    1. Definition Selection: From 134 online definitions, 8 representative ones were chosen based on complexity, source credibility, and content coverage.
    2. Study Design:
      • Two definitions (long and complex) were analyzed in detail, sentence by sentence.
      • Six definitions were used in a ranking task, where participants categorized them based on comprehensibility, practicality, and other characteristics.
    3. Data Collection and Analysis:
      • Interview transcripts were analyzed using thematic analysis, combining inductive and deductive coding.

Research Findings

  • Specific Findings:

    • Non-experts generally understand cybersecurity only at a basic protective level, with limited comprehension of its broader and deeper implications.
    • Participants preferred concise, easy-to-understand, and comprehensive definitions, while complex terminology and lengthy definitions posed barriers to understanding.
    • Overall, cybersecurity definitions can either enhance public safety awareness ("bridges") or impede understanding ("barriers").
  • Advantages Compared to Existing Solutions:

    • Provides detailed experimental results on public perceptions, helping identify specific terms or structures in definitions that lead to misunderstandings.
    • Expands the discussion on the applicability of cybersecurity definitions, addressing the needs of diverse groups (education levels, age demographics).
  • Experimental or Evaluation Results:

    • In the ranking task, definition option SA (concise yet comprehensive) was most favored by participants.
    • Participants with lower educational levels preferred simpler definitions, while those with higher education favored definitions with more technical terms and details.
  • Limitations and Future Directions:

    • The small sample size limits the generalizability of findings to other populations.
    • Non-random selection of definitions may introduce researcher bias.
    • Future research could explore cross-cultural perceptions of cybersecurity definitions and validate the influence of factors such as education and age in larger samples.
    • The study suggests extending the research to non-definition texts (e.g., warning messages, tutorials) and assessing comprehension of more complex cybersecurity terminology.

In conclusion, this study provides an in-depth analysis of the effectiveness of cybersecurity definitions from the perspective of non-experts. It offers practical recommendations for enhancing public cybersecurity awareness and opens up significant opportunities for future research.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/188621/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713820
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Privacy by Design & User Control, Cybersecurity Training & Awareness
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
1 related papers