Table 2

Research constructs and items

Latent variableItems
Perceived threat severity (Zahedi et al., 2015)
PS1Considering the severity of damage caused by a phishing attack, I perceive it to be (very low/very high)
PS2The potential damage from a phishing attack is (very low/very high)
PS3My possible loss due to a phishing attack is (very low/very high)
Perceived vulnerability (Zahedi et al., 2015)
PV1In my opinion, the probability of encountering a phishing attack is (very low/very high)
PV2The likelihood that I will experience a phishing attack is (very low/very high)
PV3I believe the chances of encountering a phishing attack are (very low/very high)
Perceived risk (Anwar et al., 2017; Ng et al., 2009)
PR1I am aware that my organization's data and resources may be compromised if I don't pay adequate attention to phishing attack tricks
PR2I am not convinced that an information security breach can occur at my workplace through clicking email links
PR3I check the links in my email or SMS to ensure they are not harmful before clicking
PR4I avoid opening email attachments from unknown senders
Perceived barriers (Anwar et al., 2017; Ng et al., 2009)
PB1Checking the security of an email with an attachment is inconvenient for me
PB2I don't have enough time to check for phishing clues in an email
PB3I lack the knowledge to identify phishing clues in an email
PB4I haven't received adequate training to recognize phishing-related clues
Response efficacy (Boss et al., 2015)
RE1I believe that adopting security software and practices effectively protects against phishing attacks
RE2Adopting security software and practices is effective in countering phishing attempts
RE3By adopting security software and practices, a computer is more likely to be protected from phishing attacks
Self-efficacy (Arachchilage and Love, 2014)
SE1I am confident that I can successfully gain anti-phishing knowledge even if I have never learned it before
SE2I believe I can gain anti-phishing knowledge with the available resources for reference
SE3I am confident that I can successfully acquire anti-phishing knowledge independently
SE4I am confident that I can successfully gain anti-phishing knowledge with ample time
Conceptual knowledge (Arachchilage and Love, 2014)
CK1I have the intention to obtain anti-phishing knowledge to protect against phishing attacks
CK2I predict that I will acquire anti-phishing knowledge to safeguard against phishing attacks
CK3I feel that I do not desire to acquire anti-phishing knowledge to avoid phishing attacks
Procedural knowledge (Arachchilage and Love, 2014)
PK1I possess an overall awareness of potential security threats and their negative consequences
PK2I frequently update my anti-phishing knowledge to defend against suspected ‘phishing' URLs
PK3Updating anti-phishing knowledge is essential to counter phishing attacks
Information security awareness (Zhan et al., 2019; Bulgurcu et al., 2010)
ISA1I possess an overall awareness of potential security threats and their negative consequences
ISA2I have sufficient knowledge about the effects of potential security problems
ISA3I understand the concerns regarding the risks posed by information security
Employees' intention (Anwar et al., 2017)
IB1I maintain my computer's anti-virus software up to date
IB2I observe unusual computer behaviors/responses (e.g. pop-up windows in the computer, etc.)
IB3I don't open email attachments from unknown senders

or Create an Account

Close subscription notice
Close access options