Assessing the effect of cybersecurity training on End-users: A Meta-analysis

被引:0
|
作者
Prummer, Julia [1 ]
van Steen, Tommy [1 ]
van den Berg, Bibi [1 ]
机构
[1] Leiden Univ, Inst Secur & Global Affairs, Fac Governance & Global Affairs, Leiden, Netherlands
关键词
Meta-Analysis; Cybersecurity; Behaviour Change; Training; end-users; SECURITY AWARENESS; SERIOUS GAMES; EMPLOYEES; BEHAVIOR;
D O I
10.1016/j.cose.2024.104206
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity behaviour of end-users continues to be a growing topic of conversation, both in organisations and in academia, as end-users are often said to be the last line of defence against cyberattacks. Unfortunately, endusers are often not aware that they engage in risky cyber behaviours and can, in turn, make themselves and the organisations that they work for vulnerable. Attempting to change end-user behaviour through training programs has become common practice in many organisations, a trend that is reflected in the academic literature as well. While a variety of literature reviews on the topic are available, an assessment of the effectiveness of these training programs through a meta-analysis has so far not been conducted. We carried out a meta-analysis based on a systematic literature review on the topic and an updated literature search in order to assess the overall effectiveness of cybersecurity training programs. We identified 69 studies that were eligible for inclusion. Our analysis shows that training overall has a positive effect on end-users (d = 0.75, 95%CI [0.58, 0.92]), particularly when assessing predictors of behaviour such as attitudes or knowledge (d = 1.02, 95%CI [0.58, 1.46]). Interestingly, studies assessing changes in behaviour are not able to match these results (d = 0.36, 95%CI [-0.09, 0.80]), showcasing a clear inability of current training approaches to change behaviour. The effect sizes obtained in this meta-analysis can act as smallest effect sizes of interest (SESOIs) for future research on end-user cybersecurity training. Further findings with regards to the effectiveness of individual training methods and other moderators are discussed.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Assessing the provision of public-facing cybersecurity guidance for end-users
    Holton, Nirosha
    Furnell, Steven
    2020 IEEE 6TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2020), 2020, : 161 - 168
  • [2] TAILORING DATABASE TRAINING FOR END-USERS
    AHRENS, JD
    SANKAR, CS
    MIS QUARTERLY, 1993, 17 (04) : 419 - 439
  • [3] Enabling end-users: Information skills training
    Edwards, Sylvia Lauretta
    Bruce, Christine
    LIBRARY HI TECH, 2007, 25 (04) : 622 - 623
  • [4] Enabling end-users: Information skills training
    du Preez, M
    ELECTRONIC LIBRARY, 2005, 23 (06): : 714 - 715
  • [5] OST - A TRAINING PACKAGE FOR END-USERS OF ONLINE SYSTEMS
    ARMSTRONG, CJ
    LARGE, JA
    PROGRAM-AUTOMATED LIBRARY AND INFORMATION SYSTEMS, 1987, 21 (04): : 333 - 349
  • [6] Cybersecurity Risks in the Deployment and Use of Digital Business Cards: Implications for Organizations and End-Users
    Rutherford, Dale
    Wu, Ningning
    2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 765 - 770
  • [7] Strengthening Cyber Security Policy by Means of End-Users Dedicated Training
    Margarov, Gevorg
    CYBER SECURITY AND RESILIENCY POLICY FRAMEWORK, 2014, 38 : 49 - 56
  • [8] Training end-users - Using scientific Internet-subject directories
    Beekink, M
    ECONTENT, 2000, 23 (02) : 57 - 60
  • [9] Training your Intranet's end-users and content-providers
    Funkhouser, LF
    SOCIETY FOR TECHNICAL COMMUNICATION 44TH ANNUAL CONFERENCE, 1997 PROCEEDINGS, 1997, : 393 - 393
  • [10] EXPERIENCES AT EXXON IN TRAINING END-USERS TO SEARCH TECHNICAL DATABASES ONLINE
    WALTON, KR
    DEDERT, PL
    ONLINE, 1983, 7 (05): : 42 - 50