Article navigation
Purpose

This study aims to examine the psychological factors associated with students’ email security behavior toward phishing threats and uses these findings to inform future gamified cybersecurity awareness (GCA) design decisions. It addresses the need for awareness interventions that are grounded in users’ behavioral characteristics rather than relying primarily on passive information delivery.

Design/methodology/approach

A quantitative survey design was used. Data were collected from 544 university students using a closed-ended questionnaire grounded in protection motivation theory (PMT). Covariance-based structural equation modeling was used to test the hypothesized relationships among perceived susceptibility, perceived severity, self-efficacy and email security behavior. Multi-group analysis examined whether these relationships differed between students with and without prior cybersecurity awareness or training exposure.

Findings

Perceived threat severity and self-efficacy significantly predicted email security behavior, while perceived susceptibility had no significant direct effect. Prior cybersecurity awareness or training exposure did not significantly moderate any of the hypothesized relationships. The model explained 40.7% of the variance in email security behavior.

Research limitations/implications

The study relied on self-reported data, convenience sampling and a predominantly undergraduate student sample, which may limit generalizability. The PMT model also used a focused specification comprising susceptibility, severity and self-efficacy, while prior awareness or training was operationalized only as a binary exposure measure. Future studies should use broader PMT specifications, more detailed measures of awareness and training characteristics, objective behavioral measures and experimental or longitudinal designs.

Practical implications

The findings suggest that future GCA interventions should prioritize making phishing consequences tangible and strengthening users’ confidence and capability to respond through mechanisms such as realistic scenarios, branching decision activities, guided practice, immediate feedback and progressive challenges. Approaches aimed at increasing personal relevance may also be explored, although the nonsignificant effect of perceived susceptibility warrants caution.

Social implications

Better designed awareness interventions may help users recognize phishing risks, understand their potential consequences and develop greater confidence in responding appropriately. Such approaches may support efforts to address human-related cybersecurity vulnerabilities in educational and organizational contexts.

Originality/value

This study demonstrates how behavioral modeling can be used to inform the design of future GCA interventions. By identifying which PMT-related psychological factors are more strongly associated with students’ email security behavior, the study provides an evidence base for prioritizing design goals and selecting gamification mechanisms aligned with users’ behavioral needs, rather than applying game elements in an ad hoc or one-size-fits-all manner.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close subscription notice
Close access options