Skip to article sections

Cybersecurity is increasingly recognised as a socio-technical problem in which security outcomes depend not only on technical controls but also on how people interact with technologies, interpret security situations and act within organisational environments. Nevertheless, human-centred cybersecurity research has often examined these elements separately. Users may be studied in terms of their security knowledge or attitudes; interventions may be evaluated in terms of changes in detection or decision-making; and organisational processes may be considered independently of the people who operate within them.

This separation matters because security behaviour does not occur in isolation. Human actions are shaped by the technologies through which people interact, the constraints under which they work, the information available to them and the organisational processes that follow their actions. Researchers have argued for moving from a “human-as-problem” towards a “human-as-solution” cybersecurity mindset, emphasising that security outcomes emerge through interactions between people, technologies and organisational structures (Zimmermann and Renaud, 2019). Earlier human-centred security research similarly demonstrated that security practices depend on stakeholder responsibilities, communication and interactions within organisational contexts (Flechais and Sasse, 2009; Werlinger et al., 2009).

The question, therefore, is not simply whether people are sufficiently “secure”. A more useful question is how human capability, system conditions and organisational practices interact to produce security outcomes.

The four papers (Farzand et al., 2026b; Schöni et al., 2026; Burda et al., 2026; Chitare et al., 2026) in this special section provide an opportunity to examine this question from complementary perspectives. These papers are extended versions of the papers selected from the 2024 European Symposium on Usable Security 2024, held in Karlstad, Sweden, on 30 September to October 2024. They do not constitute a single empirical test of an integrated model. Instead, they address different points in a connected process: how human-centred constructs are measured, how individual capability can be assessed and developed, how users translate judgements into security action, and how organisations communicate and respond to security activity.

The first challenge is measurement. Human-centred cybersecurity research increasingly depends on constructs such as privacy concerns, security attitudes, knowledge, proficiency and behavioural intentions (Farzand et al., 2025a). Conclusions about users consequently depend on whether these constructs are measured in a valid and meaningful way. Farzand et al. (2026b), extending previous work with a representative UK sample on granular privacy constructs, found that participants did not consistently associate scale statements with the constructs researchers intended those statements to represent, with substantial differences also emerging between the UK and earlier US samples. Their findings reinforce that prior evidence of reliability or psychometric validation does not by itself guarantee that respondents interpret scale items as capturing the conceptual distinctions assumed by researchers. Similar concerns about the careful development and validation of measures are evident in usable security and privacy research (Faklaris et al., 2019; Ayalon and Toch, 2019). Measurement is particularly important when it is subsequently used to determine how users should be treated. If users are categorised according to a construct, that categorisation becomes part of the intervention itself. Schöni et al. (2026) illustrated this issue through proficiency-based categorisation for personalised phishing training. Across two studies, they found that tailoring training according to phishing proficiency improved proficiency and reduced differences between participants, with improvements also transferring to phishing classification accuracy. These findings point to an important distinction. Measurement is not the intervention; it is part of the basis on which interventions are designed. Consequently, research needs to consider both whether a construct can be measured reliably and whether it is sufficiently meaningful for the decision that follows from its measurement.

The second challenge is adaptive intervention. Human-centred security research has demonstrated that users differ in knowledge, experience, goals, constraints and ways of making security decisions (Wash, 2020). Security behaviour is consequently more complex than a simple distinction between users who can and cannot identify a threat. Schöni et al. (2026) extend this perspective by showing how differences in capability can be used to tailor intervention. This raises a broader research question: rather than asking only whether a security intervention works, researchers should increasingly ask for whom, under what conditions and through which mechanisms it works.

The third challenge is security action. Recognising a threat is not necessarily the same as responding to it. In organisational settings, employees may need to report a suspicious message, seek assistance, warn colleagues or take another protective action. Burda et al. (2026) demonstrated this distinction through their investigation of phishing reporting. Their study identified motivations including protecting the organisation and colleagues, a sense of responsibility, awareness of consequences and feelings of insecurity. The likelihood of reporting was also related to characteristics of the phishing message, including its sophistication and credibility. This suggests that security interventions should distinguish between at least three stages: recognition, decision and action. Improving recognition does not guarantee that the desired action will follow. Conversely, organisational processes may enable useful action even when individual certainty is limited. A reporting mechanism, for example, can allow an employee to escalate uncertainty rather than requiring the employee to resolve that uncertainty independently.

The fourth challenge is organisational response. Human-centred security activity does not end when an employee acts. Reports, questions, warnings and other forms of employee-generated security activity enter organisational processes. What happens next can influence both immediate security outcomes and future behaviour. Chitare et al. (2026) demonstrated the complexity of this process in their study of transparent communication around sophisticated phishing attacks. Their interviews with cybersecurity practitioners identified situations in which threats intercepted before employee interaction were not communicated to employees. Privacy concerns, ongoing investigations and reputational considerations were among the factors affecting communication decisions. This finding is important because it challenges a simple assumption that more security information is necessarily better. Organisational communication involves decisions about what information should be shared, with whom, when and for what purpose. These decisions can shape employees’ understanding of threats and their preparedness to recognise and respond to similar attacks in the future.

The four papers in this special section address distinct questions concerning human-centred cybersecurity: whether researchers are measuring the constructs they intend to measure, whether training can be tailored to individual capability, why employees take security action and how organisations communicate about security threats.

Their contribution is therefore not that they collectively demonstrate a completed transition from individual security behaviour to organisational resilience. Rather, when considered together, they reveal several points at which human-centred cybersecurity research can be connected more explicitly.

The central opportunity is to understand the relationship between measurement, capability, intervention, security action and organisational response. Such a perspective retains the individual as an important focus of cybersecurity research while recognising that individuals operate within systems that shape what they can do, what they choose to do and what happens when they do it.

The resulting research agenda is consequently not about replacing the study of users with the study of organisations. It is about understanding how these levels interact. Human-centred cybersecurity becomes more meaningful when it can explain not only whether people behave securely, but how security environments enable that behaviour, how organisations respond to it, and how those interactions shape future security practice. The challenge for the field is therefore to move from isolated measurements and interventions towards connected empirical accounts of how people, technologies and organisational practices jointly produce cybersecurity outcomes.

That is where the next generation of human-centred cybersecurity research can make a substantive contribution.

Ayalon
,
O.
and
Toch
,
E.
(
2019
), “
Evaluating users’ perceptions about a system’s privacy: differentiating social and institutional aspects
”,
Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS),
pp.
41
-
59
.
Burda
,
P.
,
Allodi
,
L.
,
Serebrenik
,
A.
and
Zannone
,
N.
(
2026
), “
Phishing reporting in organizations: what motivates employees to take action?
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
562
-
589
, doi: .
Chitare
,
N.
,
Coventry
,
L.
and
Nicholson
,
J.
(
2026
), “
Exploring transparent communication for organisational cyber-resilience to sophisticated phishing attacks
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
546
-
561
, doi: .
Faklaris
,
C.
,
Dabbish
,
L.
and
Hong
,
J.I.
(
2019
), “
A Self-Report measure of End-User security attitudes (SA-6)
”,
Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS),
pp.
61
-
77
.
Farzand
,
H.
,
Farooq
,
A.
,
Salminen
,
J.
and
Jansen
,
B.J.
(
2025a
), “
When scales fail to measure up: how not to measure social media privacy–findings of a representative survey in 16 countries
”,
Proceedings of the Extended Abstracts of the CHI Conference on Human Factors in Computing Systems
, pp.
1
-
9
.
Farzand
,
H.
,
Abdelwahab Gaballah
,
S.
,
Macdonald
,
S.
,
Khamis
,
M.
and
Marky
,
K.
(
2026b
), “
Revisiting privacy scales: an investigation into the ability of privacy scales to capture and distinguish granular privacy constructs
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
521
-
545
, doi: .
Flechais
,
I.
and
Sasse
,
M.A.
(
2009
), “
Stakeholder involvement, motivation, responsibility, communication: how to design usable security in e-science
”,
International Journal of Human-Computer Studies
, Vol.
67
No.
4
, pp.
281
-
296
.
Schöni
,
L.
,
Roch
,
N.
,
Carles
,
V.
,
Sievers
,
H.
,
Strohmeier
,
M.
,
Mayer
,
P.
and
Zimmermann
,
V.
(
2026
), “
Phishing for proficiency: evaluating proficiency-based categorisation for personalised phishing training
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
590
-
609
, doi: .
Wash
,
R.
(
2020
), “
How experts detect phishing scam emails
”,
Proceedings of the ACM on Human-Computer Interaction
, Vol.
4
No.
CSCW2
, p.
160
.
Werlinger
,
R.
,
Hawkey
,
K.
,
Botta
,
D.
and
Beznosov
,
K.
(
2009
), “
Security practitioners in context: their activities and interactions with other stakeholders within organizations
”,
International Journal of Human-Computer Studies
, Vol.
67
No.
7
, pp.
584
-
606
.
Zimmermann
,
V.
and
Renaud
,
K.
(
2019
), “
Moving from a ‘human-as-problem’ to a ‘human-as-solution’ cybersecurity mindset
”,
International Journal of Human-Computer Studies
, Vol.
131
, pp.
169
-
187
.
Licensed re-use rights only

Data & Figures

Contents

Supplements

References

Ayalon
,
O.
and
Toch
,
E.
(
2019
), “
Evaluating users’ perceptions about a system’s privacy: differentiating social and institutional aspects
”,
Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS),
pp.
41
-
59
.
Burda
,
P.
,
Allodi
,
L.
,
Serebrenik
,
A.
and
Zannone
,
N.
(
2026
), “
Phishing reporting in organizations: what motivates employees to take action?
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
562
-
589
, doi: .
Chitare
,
N.
,
Coventry
,
L.
and
Nicholson
,
J.
(
2026
), “
Exploring transparent communication for organisational cyber-resilience to sophisticated phishing attacks
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
546
-
561
, doi: .
Faklaris
,
C.
,
Dabbish
,
L.
and
Hong
,
J.I.
(
2019
), “
A Self-Report measure of End-User security attitudes (SA-6)
”,
Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS),
pp.
61
-
77
.
Farzand
,
H.
,
Farooq
,
A.
,
Salminen
,
J.
and
Jansen
,
B.J.
(
2025a
), “
When scales fail to measure up: how not to measure social media privacy–findings of a representative survey in 16 countries
”,
Proceedings of the Extended Abstracts of the CHI Conference on Human Factors in Computing Systems
, pp.
1
-
9
.
Farzand
,
H.
,
Abdelwahab Gaballah
,
S.
,
Macdonald
,
S.
,
Khamis
,
M.
and
Marky
,
K.
(
2026b
), “
Revisiting privacy scales: an investigation into the ability of privacy scales to capture and distinguish granular privacy constructs
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
521
-
545
, doi: .
Flechais
,
I.
and
Sasse
,
M.A.
(
2009
), “
Stakeholder involvement, motivation, responsibility, communication: how to design usable security in e-science
”,
International Journal of Human-Computer Studies
, Vol.
67
No.
4
, pp.
281
-
296
.
Schöni
,
L.
,
Roch
,
N.
,
Carles
,
V.
,
Sievers
,
H.
,
Strohmeier
,
M.
,
Mayer
,
P.
and
Zimmermann
,
V.
(
2026
), “
Phishing for proficiency: evaluating proficiency-based categorisation for personalised phishing training
”,
Information and Computer Security
, Vol.
34
No.
4
, pp.
590
-
609
, doi: .
Wash
,
R.
(
2020
), “
How experts detect phishing scam emails
”,
Proceedings of the ACM on Human-Computer Interaction
, Vol.
4
No.
CSCW2
, p.
160
.
Werlinger
,
R.
,
Hawkey
,
K.
,
Botta
,
D.
and
Beznosov
,
K.
(
2009
), “
Security practitioners in context: their activities and interactions with other stakeholders within organizations
”,
International Journal of Human-Computer Studies
, Vol.
67
No.
7
, pp.
584
-
606
.
Zimmermann
,
V.
and
Renaud
,
K.
(
2019
), “
Moving from a ‘human-as-problem’ to a ‘human-as-solution’ cybersecurity mindset
”,
International Journal of Human-Computer Studies
, Vol.
131
, pp.
169
-
187
.

Languages

or Create an Account

Close subscription notice
Close access options