{"id":45981,"date":"2026-09-14T11:00:00","date_gmt":"2026-09-14T09:00:00","guid":{"rendered":"https:\/\/smartfense.com\/?p=45981"},"modified":"2026-09-14T15:07:07","modified_gmt":"2026-09-14T13:07:07","slug":"variable-that-predicts-secure-behavior","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/","title":{"rendered":"The variable that predicts secure behavior and almost no program measures"},"content":{"rendered":"<h1>The variable that predicts secure behavior and almost no program measures<\/h1>\n<p>Three thousand five hundred people across seven countries answered two different questions inside the same survey. One was a knowledge test on information security, with right and wrong answers. The other was how much they believed they knew.<\/p>\n<p>They then reported how often they did concrete things, such as checking where a link points before opening it, or installing updates when they show up.<\/p>\n<p>Both answers related to what they said they did, and not with the same weight. The team behind the <a href=\"https:\/\/mahmoods01.github.io\/files\/chi17-cross-cultural-study.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">2017 study<\/a> put a number on the difference: one extra point on the knowledge test moved reported behavior about four times less than one extra point on the confidence scale. The two scales do not share the same range and the authors flag it, so that exact figure is worth reading with caution. That confidence weighs more than knowledge is not.<\/p>\n<p>Knowing the right answer was not enough. It also took believing you knew what to do with it.<\/p>\n<p>And that is where a blind spot opens up in awareness programs. The dashboard records the first question, because a knowledge test leaves a score. The second is almost nowhere, and the name psychology gives it is self-efficacy.<\/p>\n<h2>What is self-efficacy and what does it have to do with security?<\/h2>\n<p>Self-efficacy is a person\u2019s belief about their own capacity to carry out a specific action in a specific situation. It is distinct from self-esteem, from optimism and from actual competence. It is a judgment about what one can do, always phrased as \u201cI can do this\u201d.<\/p>\n<p>The word doing the work there is \u201cspecific\u201d. Self-efficacy is always defined by a domain and by a specific action. Someone can have high self-efficacy for noticing that an email looks off and low self-efficacy for deciding what to do about that email, and both belong to the same program.<\/p>\n<p>In security the support does not come from a single paper. <a href=\"https:\/\/www.enisa.europa.eu\/sites\/default\/files\/publications\/WP2018%20O.3.3.2.%20Review%20of%20Behavioural%20Sciences%20Research%20in%20the%20Field%20of%20Cybersecurity.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">ENISA\u2019s evidence review<\/a> on behavioural science models applied to cybersecurity went through the protection motivation and planned behaviour literature and concluded that self-efficacy turned out to be a reliable, moderately strong predictor of security intention and behaviour. The same review draws a consequence for campaign design. Intervening on people\u2019s capacity to respond is more likely to produce results than pressing harder on the threat.<\/p>\n<p>In <a href=\"https:\/\/smartfense.com\/en\/blog\/phishing-no-es-problema-de-conocimiento\/\">why phishing is not a knowledge problem<\/a> I wrote that much of this decision-making happens without deliberation in between. Self-efficacy works one step earlier than that, on whether the person expects to be able to do something with whatever they conclude.<\/p>\n<h2>What weighs more, knowing or believing you can?<\/h2>\n<p>The seven-country study surveyed 500 people from each of them: China, France, Japan, Russia, South Korea, the United Arab Emirates and the United States. The model accounted for 38.5% of the variation in reported behavior, and inside it knowledge had a significant and small effect while confidence in that knowledge had a larger one.<\/p>\n<p>That result carries two limits the team itself declares, and they change how it reads. The first is that the outcome variable is self-reported behavior intentions rather than observed behavior, so the study speaks about what people say they do. The second is that it uses nationality as an approximation of culture, which the authors acknowledge as a coarse measure. The claim about observed behavior is the one ENISA supports, having reviewed studies where self-efficacy predicts both.<\/p>\n<p>Knowledge neither drops out of the picture nor governs it. It is one of the variables, with a real and small effect, and there is another one alongside it carrying more weight that no end-of-course questionnaire captures.<\/p>\n<p>There was already a precedent for this on the blog. In <a href=\"https:\/\/smartfense.com\/en\/blog\/awareness-validation-questions-what-they-measure\/\">what awareness validation questions really measure<\/a> I worked through the distance between answering well and acting well. This finding adds something different. There is a second question almost nobody asks that anticipates more than the first one.<\/p>\n<h2>Is showing the risk enough?<\/h2>\n<p>Here the evidence undercuts the comfortable headline. Awareness circles tend to hold that appealing to fear backfires, and the <a href=\"https:\/\/socialactionlab.org\/file\/2024\/01\/Tannenbaum_Appealing-to-Fear-A-Meta-Analysis-of-Fear-Appeal-Effectiveness-and-Theories_2015.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">largest available meta-analysis of fear appeals<\/a> does not support that. Across 127 articles, 248 independent samples and 27,372 participants, the authors found no identified circumstance in which a fear appeal turned around and produced the opposite effect.<\/p>\n<p>What they did find was a difference in size. When the message included efficacy statements, which alongside showing the risk say what to do and hold that the person can do it, the mean effect on attitudes, intentions and behavior was 0.43 across 92 samples, measured on the standard effect-size scale. Without them it was 0.21 across 154 samples. Both are modest effects, and the complete message doubles the one that only raises alarm. The 95% confidence intervals do not overlap.<\/p>\n<p>The message that only shows the threat is therefore halfway there, and the missing half is the one that speaks about capacity. For behaviors that have to be repeated, which is almost everything a program asks for, the effect they measured is smaller still.<\/p>\n<p><img decoding=\"async\" alt=\"A shelf holding twelve glass measuring jugs with wooden rulers between them, each graduated on a different scale and none matches the one next to it\" src=\"https:\/\/smartfense.com\/file\/2026\/09\/apoyo-01-autoeficacia-1789047017.jpg\" \/><\/p>\n<h2>Why does this variable never show up on dashboards?<\/h2>\n<p>There is still no standard instrument for cybersecurity self-efficacy that a program can adopt and apply directly.<\/p>\n<p>A <a href=\"https:\/\/hss-opus.ub.ruhr-uni-bochum.de\/opus4\/frontdoor\/deliver\/index\/docId\/14117\/file\/BorgertNeleTrans2.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">2024 systematic review<\/a> analysed 174 studies on cybersecurity self-efficacy and found 173 different ways of measuring it, only five of which were used more than once. There is no consolidated measure the field has settled on.<\/p>\n<p>Evidence on how to raise it is thin too. Only 13 of those 174 studies tested an intervention meant to move it, none of them was replicated, and the authors themselves conclude that their effectiveness remains speculative.<\/p>\n<p>For an awareness program that puts the variable closer to design and internal evaluation than to comparison with other organizations. A scale of your own works for tracking your own population over time, and only if it is kept identical from one year to the next.<\/p>\n<h2>What the program gets to decide<\/h2>\n<p>The belief that one can do something is built along four routes, and they do not weigh the same. The 2024 review orders them following Albert Bandura\u2019s original formulation, and that ordering translates fairly cleanly into program decisions.<\/p>\n<ol>\n<li><strong>Your own accomplishment, made visible.<\/strong> The strongest route is having carried out the action and having seen the result. For a program that means producing occasions where a person executes a complete security action and gets a response about what happened, not only occasions where they recognize the right answer on a list.<\/li>\n<li><strong>Watching someone similar do it.<\/strong> The second route is observing another person perform the behavior. The review notes that it is understudied compared with the others, so it goes in as a design hypothesis rather than a supported recommendation. It can be tried in a group and measured separately.<\/li>\n<li><strong>Saying it is the weakest route.<\/strong> Verbal persuasion, of the \u201cyou can spot an email like that\u201d kind, appears in the original formulation as a relatively weak source. A message that only asserts the capacity, without either of the two routes above, is the least powerful lever of the four.<\/li>\n<li><strong>The fourth route explains the trouble with alarm campaigns.<\/strong> Emotional arousal also informs the belief. When arousal runs high, a person does not expect to cope and adjusts their judgment about what they can do downward. A campaign built on threat alone operates on the least reliable of the four routes, and in the wrong direction. It is the other side of what the fear meta-analysis showed from the data.<\/li>\n<\/ol>\n<p>In <a href=\"https:\/\/smartfense.com\/en\/blog\/security-habits-depend-on-context\/\">how a security habit falls apart when the context changes<\/a> I argued that the program\u2019s variable is the cue and not motivation. This piece completes that argument. The cue fires the behavior, and the belief that one can execute it decides whether that behavior is available to be fired at all.<\/p>\n<p>Which behavioral indicators to watch instead of the click rate is already covered in <a href=\"https:\/\/smartfense.com\/en\/blog\/awareness-program-measuring-what-matters\/\">is your awareness program measuring what matters?<\/a>. What this piece adds is the layer underneath, the variable those indicators leave implicit.<\/p>\n<p>On measurement it pays to stay conservative. While there is no comparable instrument, what a program can observe today are the consequences of that belief, and the most visible one is somebody doing something about security without being assigned it.<\/p>\n<p>The SMARTFENSE dashboard already carries indicators closer to that than the click rate. The <a href=\"https:\/\/smartfense.com\/en\/platform\/reports-and-auditing\/\">reports hub<\/a> includes the reporting rate and the proactivity rate alongside the completion rate in its executive view, plus an adoption report that looks at voluntary content consumption. Those numbers do not measure self-efficacy, and saying so matters. They record actions that a person who feels capable takes more often, a different thing from the belief itself.<\/p>\n<p>For the first route, accomplishment with a visible result, the <a href=\"https:\/\/smartfense.com\/en\/productos\/plataforma\/phishing-report-button\/\">phishing report button<\/a> is the platform\u2019s clearest case: whoever reports a simulation gets instant feedback, plus experience points and gamification badges. The limit is on that same page. When the reported email is a real one, the information goes out to the response team and no feedback is promised to whoever reported it. That loop, seen from operations, is worked through in <a href=\"https:\/\/smartfense.com\/en\/blog\/phishing-reporting-habit-no-response\/\">what happens to the reporting habit when nobody answers<\/a>.<\/p>\n<p>Knowledge can be verified with a question. The belief that one can use it only shows up when somebody acts without being asked.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.<\/p>\n","protected":false},"author":32,"featured_media":45977,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[435,2124,2258,2068,2165,2063],"class_list":["post-45981","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-behavioral-change","tag-comportamiento-humano","tag-cyberpsychology","tag-metricas-de-seguridad","tag-psicologia-cognitiva","tag-riesgo-humano"],"acf":[],"yoast_head":" \n<title>What predicts secure behavior in cybersecurity<\/title>\n<meta name=\"description\" content=\"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What predicts secure behavior in cybersecurity\" \/>\n<meta property=\"og:description\" content=\"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T09:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-14T13:07:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tatiana Stacul\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tatiana Stacul\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/\"},\"author\":{\"name\":\"Tatiana Stacul\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f59bcb8bf8bf643f42cae8998bf12d61\"},\"headline\":\"The variable that predicts secure behavior and almost no program measures\",\"datePublished\":\"2026-09-14T09:00:00+00:00\",\"dateModified\":\"2026-09-14T13:07:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/\"},\"wordCount\":1560,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-9.jpg\",\"keywords\":[\"behavioral change\",\"comportamiento humano\",\"cyberpsychology\",\"m\u00e9tricas de seguridad\",\"psicolog\u00eda cognitiva\",\"riesgo humano\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/\",\"name\":\"What predicts secure behavior in cybersecurity\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-9.jpg\",\"datePublished\":\"2026-09-14T09:00:00+00:00\",\"dateModified\":\"2026-09-14T13:07:07+00:00\",\"description\":\"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-9.jpg\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-9.jpg\",\"width\":1376,\"height\":768,\"caption\":\"Una persona de traje de pie junto a un piano p\u00fablico abierto en el hall de una estaci\u00f3n, con la banqueta corrida hacia afuera y el bolso todav\u00eda en la mano, mirando el teclado sin sentarse\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/variable-that-predicts-secure-behavior\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The variable that predicts secure behavior and almost no program measures\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"description\":\"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.\",\"foundingDate\":\"2016\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/smartfense\\\/\"],\"knowsAbout\":[\"Concienciaci\u00f3n en ciberseguridad\",\"Security awareness training\",\"Simulaci\u00f3n de phishing\",\"Simulaci\u00f3n de ransomware\",\"Smishing\",\"Gesti\u00f3n del riesgo humano\",\"Cumplimiento normativo en seguridad de la informaci\u00f3n\"],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"Argentina\"},{\"@type\":\"Country\",\"name\":\"Chile\"},{\"@type\":\"Country\",\"name\":\"Colombia\"},{\"@type\":\"Country\",\"name\":\"M\u00e9xico\"},{\"@type\":\"Country\",\"name\":\"Per\u00fa\"},{\"@type\":\"Country\",\"name\":\"Uruguay\"},{\"@type\":\"Country\",\"name\":\"Paraguay\"},{\"@type\":\"Country\",\"name\":\"Ecuador\"},{\"@type\":\"Country\",\"name\":\"Panam\u00e1\"},{\"@type\":\"Country\",\"name\":\"Costa Rica\"},{\"@type\":\"Country\",\"name\":\"Rep\u00fablica Dominicana\"},{\"@type\":\"Country\",\"name\":\"Guatemala\"},{\"@type\":\"Country\",\"name\":\"Bolivia\"},{\"@type\":\"Country\",\"name\":\"Brasil\"},{\"@type\":\"Country\",\"name\":\"Espa\u00f1a\"},{\"@type\":\"Country\",\"name\":\"Portugal\"},{\"@type\":\"Country\",\"name\":\"Italia\"}],\"slogan\":\"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.\",\"founder\":{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},\"employee\":[{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},{\"@type\":\"Person\",\"name\":\"Mauro S\u00e1nchez\",\"jobTitle\":\"CTO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/maurolsanchez\\\/\"},{\"@type\":\"Person\",\"name\":\"Leonardo Bally\",\"jobTitle\":\"COO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/lbally\\\/\"},{\"@type\":\"Person\",\"name\":\"Nicol\u00e1s Bruna\",\"jobTitle\":\"Chief Product Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"},{\"@type\":\"Person\",\"name\":\"Carla Caggiano\",\"jobTitle\":\"Chief Content Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carla-v-caggiano\\\/\"},{\"@type\":\"Person\",\"name\":\"Salom\u00e9 Carpio\",\"jobTitle\":\"Global Head of Sales\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/salome-carpio\\\/\"},{\"@type\":\"Person\",\"name\":\"Andr\u00e9s Lista\",\"jobTitle\":\"Global Head of Alliances\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/andreslista\\\/\"},{\"@type\":\"Person\",\"name\":\"Ezequiel Azzarini\",\"jobTitle\":\"Sales Development Director\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/ezequielazzarini\\\/\"},{\"@type\":\"Person\",\"name\":\"Emilia Pal\u00e1\",\"jobTitle\":\"Head of People & Culture\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mariaemiliapala\\\/\"},{\"@type\":\"Person\",\"name\":\"Florencia Carmel\u00e9\",\"jobTitle\":\"Administration Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mar%C3%ADa-florencia-carmele\\\/\"},{\"@type\":\"Person\",\"name\":\"Carolina Barlatay\",\"jobTitle\":\"Finance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carolina-barlatay\\\/\"},{\"@type\":\"Person\",\"name\":\"Valeria Carena\",\"jobTitle\":\"Compliance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/valeriacarena\\\/\"}],\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"value\":63},\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"C\\\/ Santos Ovejero 1, Despacho P1-03\",\"addressLocality\":\"Le\u00f3n\",\"addressRegion\":\"Castilla y Le\u00f3n\",\"postalCode\":\"24008\",\"addressCountry\":\"ES\"},\"foundingLocation\":{\"@type\":\"Place\",\"address\":{\"@type\":\"PostalAddress\",\"addressRegion\":\"C\u00f3rdoba\",\"addressCountry\":\"AR\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f59bcb8bf8bf643f42cae8998bf12d61\",\"name\":\"Tatiana Stacul\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/tatiana-stacul-avatar-150x150.png\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/tatiana-stacul-avatar-150x150.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/tatiana-stacul-avatar-150x150.png\",\"caption\":\"Tatiana Stacul\"},\"description\":\"Psic\u00f3loga cognitivo-conductual enfocada en comportamiento humano en entornos digitales: estudia c\u00f3mo la atenci\u00f3n, la carga cognitiva y la respuesta emocional al riesgo condicionan la toma de decisiones frente a la pantalla. Colabora con SMARTFENSE en el dise\u00f1o de contenidos de concienciaci\u00f3n en ciberseguridad y divulga sobre ciberpsicolog\u00eda y bienestar digital en C\u00f3digo Calma. Forma parte de Women4Cyber Sweden y Cibervoluntarios.\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/tatiana-stacul\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"What predicts secure behavior in cybersecurity","description":"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/","og_locale":"en_US","og_type":"article","og_title":"What predicts secure behavior in cybersecurity","og_description":"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.","og_url":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/","og_site_name":"SMARTFENSE","article_published_time":"2026-09-14T09:00:00+00:00","article_modified_time":"2026-09-14T13:07:07+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg","type":"image\/jpeg"}],"author":"Tatiana Stacul","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Tatiana Stacul","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/"},"author":{"name":"Tatiana Stacul","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f59bcb8bf8bf643f42cae8998bf12d61"},"headline":"The variable that predicts secure behavior and almost no program measures","datePublished":"2026-09-14T09:00:00+00:00","dateModified":"2026-09-14T13:07:07+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/"},"wordCount":1560,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg","keywords":["behavioral change","comportamiento humano","cyberpsychology","m\u00e9tricas de seguridad","psicolog\u00eda cognitiva","riesgo humano"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/","url":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/","name":"What predicts secure behavior in cybersecurity","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg","datePublished":"2026-09-14T09:00:00+00:00","dateModified":"2026-09-14T13:07:07+00:00","description":"Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg","contentUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-9.jpg","width":1376,"height":768,"caption":"Una persona de traje de pie junto a un piano p\u00fablico abierto en el hall de una estaci\u00f3n, con la banqueta corrida hacia afuera y el bolso todav\u00eda en la mano, mirando el teclado sin sentarse"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/variable-that-predicts-secure-behavior\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"The variable that predicts secure behavior and almost no program measures"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"},"description":"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.","foundingDate":"2016","sameAs":["https:\/\/www.linkedin.com\/company\/smartfense\/"],"knowsAbout":["Concienciaci\u00f3n en ciberseguridad","Security awareness training","Simulaci\u00f3n de phishing","Simulaci\u00f3n de ransomware","Smishing","Gesti\u00f3n del riesgo humano","Cumplimiento normativo en seguridad de la informaci\u00f3n"],"areaServed":[{"@type":"Country","name":"Argentina"},{"@type":"Country","name":"Chile"},{"@type":"Country","name":"Colombia"},{"@type":"Country","name":"M\u00e9xico"},{"@type":"Country","name":"Per\u00fa"},{"@type":"Country","name":"Uruguay"},{"@type":"Country","name":"Paraguay"},{"@type":"Country","name":"Ecuador"},{"@type":"Country","name":"Panam\u00e1"},{"@type":"Country","name":"Costa Rica"},{"@type":"Country","name":"Rep\u00fablica Dominicana"},{"@type":"Country","name":"Guatemala"},{"@type":"Country","name":"Bolivia"},{"@type":"Country","name":"Brasil"},{"@type":"Country","name":"Espa\u00f1a"},{"@type":"Country","name":"Portugal"},{"@type":"Country","name":"Italia"}],"slogan":"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.","founder":{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},"employee":[{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},{"@type":"Person","name":"Mauro S\u00e1nchez","jobTitle":"CTO","sameAs":"https:\/\/www.linkedin.com\/in\/maurolsanchez\/"},{"@type":"Person","name":"Leonardo Bally","jobTitle":"COO","sameAs":"https:\/\/www.linkedin.com\/in\/lbally\/"},{"@type":"Person","name":"Nicol\u00e1s Bruna","jobTitle":"Chief Product Officer","sameAs":"https:\/\/www.linkedin.com\/in\/nicolasbruna\/"},{"@type":"Person","name":"Carla Caggiano","jobTitle":"Chief Content Officer","sameAs":"https:\/\/www.linkedin.com\/in\/carla-v-caggiano\/"},{"@type":"Person","name":"Salom\u00e9 Carpio","jobTitle":"Global Head of Sales","sameAs":"https:\/\/www.linkedin.com\/in\/salome-carpio\/"},{"@type":"Person","name":"Andr\u00e9s Lista","jobTitle":"Global Head of Alliances","sameAs":"https:\/\/www.linkedin.com\/in\/andreslista\/"},{"@type":"Person","name":"Ezequiel Azzarini","jobTitle":"Sales Development Director","sameAs":"https:\/\/www.linkedin.com\/in\/ezequielazzarini\/"},{"@type":"Person","name":"Emilia Pal\u00e1","jobTitle":"Head of People & Culture","sameAs":"https:\/\/www.linkedin.com\/in\/mariaemiliapala\/"},{"@type":"Person","name":"Florencia Carmel\u00e9","jobTitle":"Administration Manager","sameAs":"https:\/\/www.linkedin.com\/in\/mar%C3%ADa-florencia-carmele\/"},{"@type":"Person","name":"Carolina Barlatay","jobTitle":"Finance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/carolina-barlatay\/"},{"@type":"Person","name":"Valeria Carena","jobTitle":"Compliance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/valeriacarena\/"}],"numberOfEmployees":{"@type":"QuantitativeValue","value":63},"address":{"@type":"PostalAddress","streetAddress":"C\/ Santos Ovejero 1, Despacho P1-03","addressLocality":"Le\u00f3n","addressRegion":"Castilla y Le\u00f3n","postalCode":"24008","addressCountry":"ES"},"foundingLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressRegion":"C\u00f3rdoba","addressCountry":"AR"}}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f59bcb8bf8bf643f42cae8998bf12d61","name":"Tatiana Stacul","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/file\/2026\/05\/tatiana-stacul-avatar-150x150.png","url":"https:\/\/smartfense.com\/file\/2026\/05\/tatiana-stacul-avatar-150x150.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/05\/tatiana-stacul-avatar-150x150.png","caption":"Tatiana Stacul"},"description":"Psic\u00f3loga cognitivo-conductual enfocada en comportamiento humano en entornos digitales: estudia c\u00f3mo la atenci\u00f3n, la carga cognitiva y la respuesta emocional al riesgo condicionan la toma de decisiones frente a la pantalla. Colabora con SMARTFENSE en el dise\u00f1o de contenidos de concienciaci\u00f3n en ciberseguridad y divulga sobre ciberpsicolog\u00eda y bienestar digital en C\u00f3digo Calma. Forma parte de Women4Cyber Sweden y Cibervoluntarios.","url":"https:\/\/smartfense.com\/en\/author\/tatiana-stacul\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=45981"}],"version-history":[{"count":2,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45981\/revisions"}],"predecessor-version":[{"id":46039,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45981\/revisions\/46039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/45977"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=45981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=45981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=45981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}