Home Is Where the Smart Is: Development and Validation of the Cybersecurity Self-Efficacy in Smart Homes (CySESH) Scale
Authors
Title of the Paper
Home Is Where the Smart Is: Development and Validation of the Cybersecurity Self-Efficacy in Smart Homes (CySESH) Scale
Paper Information
- Research Area: Cybersecurity in smart homes, development and validation of self-efficacy scales
- Keywords: Self-efficacy, cybersecurity, smart homes, scale development, validation
Research Background and Problem Statement
-
Identified Problems or Challenges:
- The widespread adoption of smart home devices has raised concerns about security and privacy, yet users' security behaviors have not significantly improved, a phenomenon referred to as the "privacy paradox."
- There is a lack of standardized cybersecurity self-efficacy (CSE) scales specifically tailored to the smart home domain. Existing tools are often informally developed, lack validation, and may lead to misleading conclusions.
- The complexity of smart home systems, the involvement of multiple user roles, and the high data security demands of automated devices pose challenges for researchers and users.
-
Significance:
- Self-efficacy plays a critical role in how users choose and execute security behaviors, serving as a psychological indicator for predicting safer practices.
- Developing a self-efficacy scale specific to the smart home context can help understand and improve users' cybersecurity behaviors, supporting empirical research and policy implementation.
-
Research Motivation and Related Work: The authors, drawing on Social Cognitive Theory (SCT), hypothesize the importance of cybersecurity self-efficacy in influencing user security behaviors in smart homes. They call for standardized tools to reduce inconsistencies in research and speculative biases in interpreting results.
Proposed Solution
-
Proposed Solution:
- Development and validation of a 12-item scale named "Cybersecurity Self-Efficacy in Smart Homes (CySESH)" focusing on self-efficacy in the smart home cybersecurity domain.
- The scale was designed following SCT principles and psychometric standards, with rigorous steps from item generation to pilot testing and final validation.
-
Innovations:
- The first validated scale dedicated to cybersecurity in smart homes.
- Strict adherence to psychometric and scale development practices, addressing objectivity, reliability, and validity.
- Enhanced content and construct validity through multiple rounds of pilot studies and analyses, ensuring clear differentiation from other psychological constructs.
-
Implementation Steps and Key Techniques:
- Item Development:
- Conducted a systematic review of existing literature to identify relevant contexts.
- Organized expert workshops to determine core representative issues and generated an initial pool of 45 items.
- Scale Development:
- Optimized the initial scale through pilot testing, removing ambiguous or poorly performing items.
- Adjusted items to ensure coverage of five cybersecurity application stages: purchasing, setup, daily use, maintenance, and disposal.
- Scale Validation:
- Data collection and validation analysis (two independent studies, total sample size of 971 participants).
- Reliability testing (Cronbach’s α=0.90) and validity analysis (including convergent and discriminant validity).
- Item Development:
Research Findings
-
Specific Findings:
- Successfully developed the 12-item CySESH scale to measure users' cybersecurity self-efficacy in smart homes.
- The scale demonstrated excellent reliability, content validity, and construct validity:
- Reliability: Cronbach’s α of 0.90.
- Convergent Validity: High correlation with the Information Security Self-Efficacy Scale (r=0.64, p<.001).
- Discriminant Validity: Significantly lower correlations with self-esteem (r=0.17), optimism (r=0.18), and outcome expectancy (r=0.26).
-
Comparison with Existing Solutions:
- Compared to studies using unvalidated, informally developed scales, CySESH offers a standardized, efficient, and low-cost measurement tool.
- Greater focus on domain specificity, addressing the overgeneralization limitations of existing tools.
-
Experiment or Evaluation Results:
- Data analysis confirmed the scale's unidimensional design and strong performance (high CFA fit indices).
- Four validity analyses supported the scale's characteristics, though validity related to outcome expectancy was slightly lower than anticipated.
-
Limitations and Future Directions:
- Limitations:
- Samples were sourced from the Prolific platform, primarily English-speaking users, which may not represent other cultural groups.
- Limited testing of applicability across diverse user backgrounds (e.g., IT professionals).
- Gender imbalance in the dataset may affect the generalizability of certain analyses.
- Future Directions:
- Conduct broader cross-cultural validation and explore applicability beyond the smart home domain.
- Develop a shorter version of the scale for large-scale applications.
- Investigate the scale's predictive validity for long-term behaviors, particularly the relationship between self-efficacy and actual behavioral practices.
- Explore applications in specific populations (e.g., children, elderly users).
- Limitations:
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can smart home users' cybersecurity self-efficacy (CSE) be reliably measured?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- How can a CSE scale for smart homes be developed and validated based on social cognitive theory (SCT)?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- Can the CySESH scale effectively predict users' cybersecurity behavior?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
Practical Problems
1- Smart home users are unclear on how to improve their own cybersecurity behavior.Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- 100%
Informing the Design of Privacy-Empowering Tools for the Connected Home
CHI '20· Privacy by Design & User Control +1
- 100%
Investigating Tangible Privacy-Preserving Mechanisms for Future Smart Homes
CHI '23· Privacy by Design & User Control +1
- 75%
"It did not give me an option to decline": A Longitudinal Analysis of the User Experience of Security and Privacy in Smart Home Products
CHI '21· Privacy by Design & User Control +2
- 75%
Overlooking context: How do Defaults and Framing Reduce Deliberation in Smart Home Privacy Decision-Making?
CHI '21· Privacy by Design & User Control +1
- 75%
Towards Understanding Family Privacy and Security Literacy Conversations at Home: Design Implications for Privacy Literacy Interfaces
CHI '24· Privacy by Design & User Control +1
- 75%
PrivacyHub: A Functional Tangible and Digital Ecosystem for Interoperable Smart Home Privacy Awareness and Control
CHI '25· Privacy by Design & User Control +2
- 67%
Defending My Castle: A Co-Design Study of Privacy Mechanisms for Smart Homes
CHI '19· Privacy by Design & User Control +1
- 67%
"It would probably turn into a social faux-pas": Users' and Bystanders' Preferences of Privacy Awareness Mechanisms in Smart Homes
CHI '22· Privacy by Design & User Control +1
- 67%
Manual, Hybrid, and Automatic Privacy Covers for Smart Home Cameras
DIS '24· Privacy by Design & User Control +1
- 67%
Privacy-Enhancing Technology and Everyday Augmented Reality: Understanding Bystanders’ Varying Needs for Awareness and Consent
UbiComp '23· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)