The variable that predicts secure behavior and almost no program measures

Una persona de traje de pie junto a un piano público abierto en el hall de una estación, con la banqueta corrida hacia afuera y el bolso todavía en la mano, mirando el teclado sin sentarse

The variable that predicts secure behavior and almost no program measures

The variable that predicts secure behavior and almost no program measures

Three thousand five hundred people across seven countries answered two different questions inside the same survey. One was a knowledge test on information security, with right and wrong answers. The other was how much they believed they knew.

They then reported how often they did concrete things, such as checking where a link points before opening it, or installing updates when they show up.

Both answers related to what they said they did, and not with the same weight. The team behind the 2017 study put a number on the difference: one extra point on the knowledge test moved reported behavior about four times less than one extra point on the confidence scale. The two scales do not share the same range and the authors flag it, so that exact figure is worth reading with caution. That confidence weighs more than knowledge is not.

Knowing the right answer was not enough. It also took believing you knew what to do with it.

And that is where a blind spot opens up in awareness programs. The dashboard records the first question, because a knowledge test leaves a score. The second is almost nowhere, and the name psychology gives it is self-efficacy.

What is self-efficacy and what does it have to do with security?

Self-efficacy is a person’s belief about their own capacity to carry out a specific action in a specific situation. It is distinct from self-esteem, from optimism and from actual competence. It is a judgment about what one can do, always phrased as “I can do this”.

The word doing the work there is “specific”. Self-efficacy is always defined by a domain and by a specific action. Someone can have high self-efficacy for noticing that an email looks off and low self-efficacy for deciding what to do about that email, and both belong to the same program.

In security the support does not come from a single paper. ENISA’s evidence review on behavioural science models applied to cybersecurity went through the protection motivation and planned behaviour literature and concluded that self-efficacy turned out to be a reliable, moderately strong predictor of security intention and behaviour. The same review draws a consequence for campaign design. Intervening on people’s capacity to respond is more likely to produce results than pressing harder on the threat.

In why phishing is not a knowledge problem I wrote that much of this decision-making happens without deliberation in between. Self-efficacy works one step earlier than that, on whether the person expects to be able to do something with whatever they conclude.

What weighs more, knowing or believing you can?

The seven-country study surveyed 500 people from each of them: China, France, Japan, Russia, South Korea, the United Arab Emirates and the United States. The model accounted for 38.5% of the variation in reported behavior, and inside it knowledge had a significant and small effect while confidence in that knowledge had a larger one.

That result carries two limits the team itself declares, and they change how it reads. The first is that the outcome variable is self-reported behavior intentions rather than observed behavior, so the study speaks about what people say they do. The second is that it uses nationality as an approximation of culture, which the authors acknowledge as a coarse measure. The claim about observed behavior is the one ENISA supports, having reviewed studies where self-efficacy predicts both.

Knowledge neither drops out of the picture nor governs it. It is one of the variables, with a real and small effect, and there is another one alongside it carrying more weight that no end-of-course questionnaire captures.

There was already a precedent for this on the blog. In what awareness validation questions really measure I worked through the distance between answering well and acting well. This finding adds something different. There is a second question almost nobody asks that anticipates more than the first one.

Is showing the risk enough?

Here the evidence undercuts the comfortable headline. Awareness circles tend to hold that appealing to fear backfires, and the largest available meta-analysis of fear appeals does not support that. Across 127 articles, 248 independent samples and 27,372 participants, the authors found no identified circumstance in which a fear appeal turned around and produced the opposite effect.

What they did find was a difference in size. When the message included efficacy statements, which alongside showing the risk say what to do and hold that the person can do it, the mean effect on attitudes, intentions and behavior was 0.43 across 92 samples, measured on the standard effect-size scale. Without them it was 0.21 across 154 samples. Both are modest effects, and the complete message doubles the one that only raises alarm. The 95% confidence intervals do not overlap.

The message that only shows the threat is therefore halfway there, and the missing half is the one that speaks about capacity. For behaviors that have to be repeated, which is almost everything a program asks for, the effect they measured is smaller still.

A shelf holding twelve glass measuring jugs with wooden rulers between them, each graduated on a different scale and none matches the one next to it

Why does this variable never show up on dashboards?

There is still no standard instrument for cybersecurity self-efficacy that a program can adopt and apply directly.

A 2024 systematic review analysed 174 studies on cybersecurity self-efficacy and found 173 different ways of measuring it, only five of which were used more than once. There is no consolidated measure the field has settled on.

Evidence on how to raise it is thin too. Only 13 of those 174 studies tested an intervention meant to move it, none of them was replicated, and the authors themselves conclude that their effectiveness remains speculative.

For an awareness program that puts the variable closer to design and internal evaluation than to comparison with other organizations. A scale of your own works for tracking your own population over time, and only if it is kept identical from one year to the next.

What the program gets to decide

The belief that one can do something is built along four routes, and they do not weigh the same. The 2024 review orders them following Albert Bandura’s original formulation, and that ordering translates fairly cleanly into program decisions.

  1. Your own accomplishment, made visible. The strongest route is having carried out the action and having seen the result. For a program that means producing occasions where a person executes a complete security action and gets a response about what happened, not only occasions where they recognize the right answer on a list.
  2. Watching someone similar do it. The second route is observing another person perform the behavior. The review notes that it is understudied compared with the others, so it goes in as a design hypothesis rather than a supported recommendation. It can be tried in a group and measured separately.
  3. Saying it is the weakest route. Verbal persuasion, of the “you can spot an email like that” kind, appears in the original formulation as a relatively weak source. A message that only asserts the capacity, without either of the two routes above, is the least powerful lever of the four.
  4. The fourth route explains the trouble with alarm campaigns. Emotional arousal also informs the belief. When arousal runs high, a person does not expect to cope and adjusts their judgment about what they can do downward. A campaign built on threat alone operates on the least reliable of the four routes, and in the wrong direction. It is the other side of what the fear meta-analysis showed from the data.

In how a security habit falls apart when the context changes I argued that the program’s variable is the cue and not motivation. This piece completes that argument. The cue fires the behavior, and the belief that one can execute it decides whether that behavior is available to be fired at all.

Which behavioral indicators to watch instead of the click rate is already covered in is your awareness program measuring what matters?. What this piece adds is the layer underneath, the variable those indicators leave implicit.

On measurement it pays to stay conservative. While there is no comparable instrument, what a program can observe today are the consequences of that belief, and the most visible one is somebody doing something about security without being assigned it.

The SMARTFENSE dashboard already carries indicators closer to that than the click rate. The reports hub includes the reporting rate and the proactivity rate alongside the completion rate in its executive view, plus an adoption report that looks at voluntary content consumption. Those numbers do not measure self-efficacy, and saying so matters. They record actions that a person who feels capable takes more often, a different thing from the belief itself.

For the first route, accomplishment with a visible result, the phishing report button is the platform’s clearest case: whoever reports a simulation gets instant feedback, plus experience points and gamification badges. The limit is on that same page. When the reported email is a real one, the information goes out to the response team and no feedback is promised to whoever reported it. That loop, seen from operations, is worked through in what happens to the reporting habit when nobody answers.

Knowledge can be verified with a question. The belief that one can use it only shows up when somebody acts without being asked.

Tatiana Stacul

Psicóloga cognitivo-conductual enfocada en comportamiento humano en entornos digitales: estudia cómo la atención, la carga cognitiva y la respuesta emocional al riesgo condicionan la toma de decisiones frente a la pantalla. Colabora con SMARTFENSE en el diseño de contenidos de concienciación en ciberseguridad y divulga sobre ciberpsicología y bienestar digital en Código Calma. Forma parte de Women4Cyber Sweden y Cibervoluntarios.

Leave a Reply