Article Review 2
Perceived Security Risks and Cybersecurity Compliance Attitude
Introduction
This article focuses on how personality traits impact cybersecurity behavior and whether people actually follow security policies.
Cybersecurity is more about people than technology. Who someone is as a person directly affects how they behave and whether they comply with security practices.
Connection to Social Science Principles
This article clearly connects to social science because it focuses on human behavior, psychology, and decision-making.
It uses:
- Psychology (personality traits)
- Behavioral science (how people act online)
- Theory-based frameworks (PMT and TPB)
- Cause-and-effect relationships
This reinforces a key idea from class: cybersecurity problems are not just technical issues. They are human behavior issues.
Research Question:
How do personality traits influence cybersecurity behavior and compliance, and how does perceived risk affect that relationship?
Hypothesis:
- Personality traits influence cybersecurity behavior
- Personality traits influence compliance attitude
- Cybersecurity behavior acts as a mediator
- Perceived security risk acts as a moderator
Independent Variable:
Big Five personality traits
Dependent Variable:
- Cybersecurity behavior
- Cybersecurity compliance attitude
Types of Research Methods used:
This study used a quantitative research method.
- Sample size: 259 employees
- Data collected through structured surveys
- Participants came from different organizational environments
The study focused on measurable data rather than opinions or interviews.
Types of Data Analysis used:
The researchers used Structural Equation Modeling (SEM) to analyze relationships between variables.
They also used:
- Confirmatory Factor Analysis (CFA)
- Correlation analysis
The results showed strong relationships between behavior and compliance, and the model explained a large portion of the outcomes.
Connections to other Course Concepts
This study directly connects to multiple concepts from class, especially the idea that cybersecurity must be understood through a social science lens, not just a technical one.
One major connection is the principle of empiricism. The course material explains that “we can’t, and shouldn’t, rely on opinions or hunches to frame our understanding of cybercrime and cybersecurity” . This study follows that exactly by using real data and statistical modeling instead of assumptions to understand behavior.
Another strong connection is determinism, which states that behavior is influenced by prior conditions. The course asks questions like “why do individuals choose to ignore training about cyber hygiene?” . That is exactly what this study is answering. It shows that personality traits and risk perception directly influence whether someone follows security practices.
The principle of relativism also applies here. The course explains that all systems are connected and that changes in technology affect social behavior . This study proves that by showing how psychological traits (social system) directly impact cybersecurity behavior (technological system).
This also connects to the idea that cybersecurity is about human behavior at scale, not just systems. As discussed in the course reading on social cybersecurity, the field focuses on understanding and predicting “cyber-mediated changes in human behavior, social, cultural, and political outcomes” . That is exactly what this study is doing by linking personality to behavior and compliance.
Finally, this ties into the concept of “securing the human”, which emphasizes that cybersecurity must include human factors, not just technical controls. Cybersecurity is described as involving “technology, people, information, and processes” . This study reinforces that idea by showing that people are the deciding factor in whether security actually works.
Connections to the Concerns or contributions of Marginalized Groups
The article does not directly focus on marginalized groups, but the findings still apply.
Not everyone has the same:
- access to cybersecurity training
- understanding of risk
- ability to respond to threats
If organizations treat all users the same, they risk leaving some groups behind. This shows the importance of tailoring cybersecurity approaches to different types of people.
Overall societal contributions of the study
This study shows that cybersecurity is not just a technical issue — it is a human issue.
Key contributions:
- Personality influences behavior
- Behavior influences compliance
- Risk perception strengthens or weakens both
The study suggests that organizations should move away from a one-size-fits-all approach and instead design cybersecurity training based on how people think and behave.
This improves real-world security and reduces risk.
Reference
Ghaleb, M. M. S., & Sattarov, A. (2025). Perceived Security Risks and Cybersecurity Compliance Attitude: Role of Personality Traits and Cybersecurity Behavior. International Journal of Cyber Criminology, 19(1), 27–53.
Beskow, D. M., & Carley, K. M. (2019). Social cybersecurity: An emerging national security requirement. Military Review.
Mountrouidou, X., Vosen, D., Kari, C., Azhar, M. Q., Bhatia, S., Gagne, G., Maguire, J., Tudor, L., & Yuen, T. T. (2019). Securing the human: A review of literature on broadening diversity in cybersecurity education. ACM.
Old Dominion University. (2026). CYSE201S Module 2: Principles of Social Sciences and Cybersecurity