Research constructs and items
| Latent variable | Items |
|---|---|
| Perceived threat severity (Zahedi et al., 2015) | |
| PS1 | Considering the severity of damage caused by a phishing attack, I perceive it to be (very low/very high) |
| PS2 | The potential damage from a phishing attack is (very low/very high) |
| PS3 | My possible loss due to a phishing attack is (very low/very high) |
| Perceived vulnerability (Zahedi et al., 2015) | |
| PV1 | In my opinion, the probability of encountering a phishing attack is (very low/very high) |
| PV2 | The likelihood that I will experience a phishing attack is (very low/very high) |
| PV3 | I believe the chances of encountering a phishing attack are (very low/very high) |
| Perceived risk (Anwar et al., 2017; Ng et al., 2009) | |
| PR1 | I am aware that my organization's data and resources may be compromised if I don't pay adequate attention to phishing attack tricks |
| PR2 | I am not convinced that an information security breach can occur at my workplace through clicking email links |
| PR3 | I check the links in my email or SMS to ensure they are not harmful before clicking |
| PR4 | I avoid opening email attachments from unknown senders |
| Perceived barriers (Anwar et al., 2017; Ng et al., 2009) | |
| PB1 | Checking the security of an email with an attachment is inconvenient for me |
| PB2 | I don't have enough time to check for phishing clues in an email |
| PB3 | I lack the knowledge to identify phishing clues in an email |
| PB4 | I haven't received adequate training to recognize phishing-related clues |
| Response efficacy (Boss et al., 2015) | |
| RE1 | I believe that adopting security software and practices effectively protects against phishing attacks |
| RE2 | Adopting security software and practices is effective in countering phishing attempts |
| RE3 | By adopting security software and practices, a computer is more likely to be protected from phishing attacks |
| Self-efficacy (Arachchilage and Love, 2014) | |
| SE1 | I am confident that I can successfully gain anti-phishing knowledge even if I have never learned it before |
| SE2 | I believe I can gain anti-phishing knowledge with the available resources for reference |
| SE3 | I am confident that I can successfully acquire anti-phishing knowledge independently |
| SE4 | I am confident that I can successfully gain anti-phishing knowledge with ample time |
| Conceptual knowledge (Arachchilage and Love, 2014) | |
| CK1 | I have the intention to obtain anti-phishing knowledge to protect against phishing attacks |
| CK2 | I predict that I will acquire anti-phishing knowledge to safeguard against phishing attacks |
| CK3 | I feel that I do not desire to acquire anti-phishing knowledge to avoid phishing attacks |
| Procedural knowledge (Arachchilage and Love, 2014) | |
| PK1 | I possess an overall awareness of potential security threats and their negative consequences |
| PK2 | I frequently update my anti-phishing knowledge to defend against suspected ‘phishing' URLs |
| PK3 | Updating anti-phishing knowledge is essential to counter phishing attacks |
| Information security awareness (Zhan et al., 2019; Bulgurcu et al., 2010) | |
| ISA1 | I possess an overall awareness of potential security threats and their negative consequences |
| ISA2 | I have sufficient knowledge about the effects of potential security problems |
| ISA3 | I understand the concerns regarding the risks posed by information security |
| Employees' intention (Anwar et al., 2017) | |
| IB1 | I maintain my computer's anti-virus software up to date |
| IB2 | I observe unusual computer behaviors/responses (e.g. pop-up windows in the computer, etc.) |
| IB3 | I don't open email attachments from unknown senders |
| Latent variable | Items |
|---|---|
| PS1 | Considering the severity of damage caused by a phishing attack, I perceive it to be (very low/very high) |
| PS2 | The potential damage from a phishing attack is (very low/very high) |
| PS3 | My possible loss due to a phishing attack is (very low/very high) |
| PV1 | In my opinion, the probability of encountering a phishing attack is (very low/very high) |
| PV2 | The likelihood that I will experience a phishing attack is (very low/very high) |
| PV3 | I believe the chances of encountering a phishing attack are (very low/very high) |
| PR1 | I am aware that my organization's data and resources may be compromised if I don't pay adequate attention to phishing attack tricks |
| PR2 | I am not convinced that an information security breach can occur at my workplace through clicking email links |
| PR3 | I check the links in my email or SMS to ensure they are not harmful before clicking |
| PR4 | I avoid opening email attachments from unknown senders |
| PB1 | Checking the security of an email with an attachment is inconvenient for me |
| PB2 | I don't have enough time to check for phishing clues in an email |
| PB3 | I lack the knowledge to identify phishing clues in an email |
| PB4 | I haven't received adequate training to recognize phishing-related clues |
| RE1 | I believe that adopting security software and practices effectively protects against phishing attacks |
| RE2 | Adopting security software and practices is effective in countering phishing attempts |
| RE3 | By adopting security software and practices, a computer is more likely to be protected from phishing attacks |
| SE1 | I am confident that I can successfully gain anti-phishing knowledge even if I have never learned it before |
| SE2 | I believe I can gain anti-phishing knowledge with the available resources for reference |
| SE3 | I am confident that I can successfully acquire anti-phishing knowledge independently |
| SE4 | I am confident that I can successfully gain anti-phishing knowledge with ample time |
| CK1 | I have the intention to obtain anti-phishing knowledge to protect against phishing attacks |
| CK2 | I predict that I will acquire anti-phishing knowledge to safeguard against phishing attacks |
| CK3 | I feel that I do not desire to acquire anti-phishing knowledge to avoid phishing attacks |
| PK1 | I possess an overall awareness of potential security threats and their negative consequences |
| PK2 | I frequently update my anti-phishing knowledge to defend against suspected ‘phishing' URLs |
| PK3 | Updating anti-phishing knowledge is essential to counter phishing attacks |
| ISA1 | I possess an overall awareness of potential security threats and their negative consequences |
| ISA2 | I have sufficient knowledge about the effects of potential security problems |
| ISA3 | I understand the concerns regarding the risks posed by information security |
| IB1 | I maintain my computer's anti-virus software up to date |
| IB2 | I observe unusual computer behaviors/responses (e.g. pop-up windows in the computer, etc.) |
| IB3 | I don't open email attachments from unknown senders |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.