ConceptioArchivearXiv CS
arXiv CSopen access

Human Vulnerability Assessment in Cybersecurity: A Systematic Literature Review of Methods, Models, and Instruments

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

1

Human Vulnerability Assessment in Cybersecurity: A Systematic Literature Review of Methods, Models, and Instruments

arXiv:2605.22119v1 [cs.CR] 21 May 2026

Dimitra Papatsaroucha, Stavroula Psaroudaki, Eleftheria Vassilaki, Konstantina Pityanou, Evangelos K. Markakis

Abstract—In cybersecurity, vulnerability assessment has typically focused on identifying and measuring vulnerabilities within digital assets and technical infrastructures. However, there is growing recognition that this approach alone is inadequate without a structured examination of the human factor, which is becoming more frequently targeted and manipulated by cyber adversaries. Human vulnerabilities extend beyond individual susceptibility to cyber threats, encompassing a wide array of psychological, cognitive, behavioral, social, and contextual factors that can, whether unintentionally or intentionally, jeopardize the security and integrity of systems and data. Despite this recognition, human vulnerability assessment remains fragmented, often addressed from a static rather than a dynamic perspective, and with limited focus on the ways it propagates across individuals and systems; a growing body of literature has explored specific facets of the issue, including one-time assessments of security behavior, user awareness, and, to a degree, intentional insider threats and their detection. This research offers a systematic literature review (SLR) of Human Vulnerability Assessment (HVA) in cybersecurity, including methods, models, and instruments proposed for the conceptual or practical assessment of human vulnerabilities across various dimensions. Following the PRISMA framework, this review gathers relevant studies published from 2017 to 2025, aiming to investigate whether any assessment methods, models, or instruments exist that address the entire spectrum of human vulnerabilities dynamically. The findings highlight gaps and limitations in current proposed solutions and identify areas for further investigation regarding holistic assessment that simultaneously and dynamically considers the entire spectrum of both the unintentional and intentional dimensions of human vulnerability. Index Terms—Human Vulnerability Assessment, HumanCentered Cybersecurity, Human Factors, Insider Threats, Systematic Literature Review.

I. I NTRODUCTION

W

ITH the increasing use of Information and Communication Technologies (ICT) in government, industrial, and organizational contexts as well as in personal environments, cybersecurity has become an essential requirement for modern digital societies. The rapid growth of connected systems, cloud services, smart technologies, and digitally mediated workflows has dramatically expanded the surface of cyber threats. Organizations are increasingly exposed to risks stemming not only from technical vulnerabilities of digital assets and systems but also from the vulnerabilities of their respective human operators, indicating that cybersecurity Dimitra Papatsaroucha, Stavroula Psaroudaki, Eleftheria Vassilaki, Konstantina Pityanou, and Evangelos K. Markakis are with the Department of Electrical and Computer Engineering, Hellenic Mediterranean University, 71410 Heraklion, Greece

measures should not be isolated from human behavior, organizational culture, workplace conditions, and broader sociotechnical aspects1 2 . Meanwhile, the Cybersecurity Framework (CSF) 2.0, by the National Institute of Standards and Technology (NIST), highlights people, organizational context, continuous monitoring, and adaptive risk management as key elements of contemporary cybersecurity governance3 . Human error and susceptibility have long been acknowledged as significant factors in cybersecurity risk [1]–[3], cotributing to unintentional threats, where users may inadvertently participate in cyber incidents. According to the European Union Agency for Cybersecurity (ENISA), organizations remain vulnerable to cyber threats and data breaches even when technical safeguards and security infrastructures are in place, due to poor cybersecurity awareness, unsafe user practices, and lack of proper security behaviour4 . Meanwhile, cyber attacks are evolving, integrating behavioraly adaptive mechanisms to target human cognition, decision-making, and interaction patterns5 . Furthermore, the literature has started to place particular focus on intentional threats [4]–[6], where users may deliberately engage in malicious activities within the system they operate, aiming to exploit it for personal, financial, or idelogical purposes. According to the ENISA Threat Landscape 2025 report, insider threats and AI-assisted malicious activities continue to shape the evolving cyber threat landscape alongside social engineering, such as phishing, that ranks the highest6 . Human vulnerability in cybersecurity encompasses a wide spectrum of psychological, cognitive, behavioral, organizational, and contextual human factors [7]. Simultaneously, human vulnerability can be conceptualized in different ways, from static assessment methods that view vulnerability as a relatively fixed individual condition, often evaluated through profiling or psychometric evaluation [8]–[10], to dynamic and continuous approaches that consider vulnerability as an evolving state affected by behavioral adaptation, contextual conditions, environmental changes, and continuous interaction with digital systems [11]–[13]. In parallel, vulnerability may transcend individual isolated conditions and emerge as a broader socio-technical phenomenon involving relational dy1 https://www.enisa.europa.eu/publications/cybersecurity-culture-guidelinesbehavioural-aspects-of-cybersecurity 2 https://www.enisa.europa.eu/publications/cyber-security-culture-inorganisations 3 https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf 4 https://www.enisa.europa.eu/publications/raising-awareness-ofcybersecurity 5 https://www.enisa.europa.eu/news/cybersecurity-threats-fast-forward-2030 6 https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025

2

namics, influence mechanisms, and propagation effects within and between organizational environments [14]. In this context, Human Vulnerability Assessment (HVA) approaches aim to identify, assess, and model the human conditions that can lead to increased susceptibility to cyber threats. This study presents a Systematic Literature Review (SLR) of HVA approaches in cybersecurity, using the PRISMA framework [15]. The objective of the review is to systematically investigate whether existing methods, models, and assessment instruments address the broader spectrum of factors affecting human vulnerability while also considering dynamic and continuous assessment perspectives and vulnerability propagation mechanisms. To support this investigation, the study synthesizes the factors and additional variables affecting human vulnerability, as identified across the literature, and proposes a structured taxonomy that is used across the SLR as a classification framework to support deeper analysis of the studies considered eligible for inclusion. The remainder of this paper is structured as follows: Section II presents prior SLRs, surveys, and reviews across the literature that have discussed narrower dimensions of the research objective of this study; Section III discusses the human vulnerability-related factors identified across the literature and presents a structured taxonomy by grouping them into vulnerability domains and moderator groups; Section IV describes in detail the methodology followed in the SLR of this study, in adherence with the PRISMA framework; Section V presents the studies eligible for inclusion, by grouping them into methods, models, and instruments and providing the characteristics of each approach; Section VI analyses and synthesises the results of this SLR by classifying the eligible studies according to the proposed taxonomy of Section III while it also highlights trends, gaps, and limitations of the current landscape; and Section VII provides the concluding remarks of this study alongside limitations and future research dimensions.

attack vectors such as cognitive vulnerabilities to phishing [19] and social engineering-related susceptibility patterns, including emotional manipulation, overtrust in authority, and low security awareness [20], as well as amplification factors such as emotional manipulation and overtrust in AI [21]. Other reviews adopt behavioral or theoretical perspectives, examining demographic, psychological, and technical factors influencing security behavior and compliance [22]–[24], or focus on specific constructs such as self-efficacy [25]. Several studies further provide interdisciplinary, domain-specific, or context-specific reviews with regard to the involvement or influence of human factors in the security of digital spaces, including insider threats [26], [27], threats imposed by individuals operating within remote work environments [28] or in various sectors such as healthcare and agriculture [29], [30], technical detection approaches [31], [32], and mitigationoriented perspectives such as awareness training and security culture [33]–[35]. Despite the existence of these reviews, the literature still lacks a systematic and comprehensive synthesis of the methods, models, and instruments proposed to assess human vulnerabilities in cybersecurity across their full spectrum. Existing reviews remain inherently scoped to specific dimensions, such as particular behavioral constructs, single vulnerability domains, specific attack vectors, or broader human-factor discussions that do not center on assessment approaches themselves. In contrast, the present study adopts a holistic perspective by systematically identifying and analyzing all methods, models, and instruments proposed in the literature between 2017 and 2025 that aim to assess at least one dimension of human vulnerability in the cybersecurity domain. By consolidating these approaches across psychological, cognitive, behavioral, social, and contextual dimensions, this work provides a holistic overview of the current assessment landscape, enabling a more integrated understanding of how human vulnerabilities are conceptualized and measured.

II. R ELATED W ORK Prior SLRs, surveys, and reviews across literature have addressed narrower dimensions of the research objective of the present study. Most notably, even though some reviews focus on how cybersecurity-related behavior is assessed, emphasizing the assessment process and its components, they do not synthesize the methods, models, or instruments proposed across the scientific community to assess the full range of human vulnerabilities in cybersecurity contexts [16]. Other studies review assessment instruments developed for a single construct, such as information security awareness scales, examining their dimensions, rigor, and validity but remaining limited to that specific aspect of human vulnerability [17]. At a broader level, some reviews synthesize the human factor in cybersecurity by identifying major vulnerability themes and proposing integrative frameworks, yet without systematically centering the analysis on the methods, models, and instruments used to assess those vulnerabilities [18]. Beyond these studies, additional reviews across the literature explore human factors in cybersecurity by focusing in specific slices of the problem, including particular

III. H UMAN FACTORS Across the literature there are partial classifications provided with regard to human factors in cybersecurity. However, to the best of our knowledge, there lacks a unified taxonomy specifically designed for human vulnerability assessment. Some studies propose ontology-based representations of human factors within cybersecurity contexts [36], while others propose socio-technical assessment approaches integrating human, organizational, and technological aspects that influence vulnerability within the cyber space [1]. Additional studies provide conceptual categorizations of human cybersecurity factors and identify recurring categories such as psychological traits, cognitive mechanisms, behavioral practices, and contextual influences [1], [17], [36]–[38]. In addition, the synthesis and categorization of factors proposed in [5] has emphasized that malicious cyber behavior emerges from various interconnected aspects at multiple levels, including individual characteristics, interpersonal dynamics, group affiliations, and broader socio-cultural contexts. Nevertheless, none of these studies presents a comprehensive and holistic taxonomy specifically structured for eval-

3

uating human vulnerability mechanisms across the full human cybersecurity lifecycle considering both unintentional and intentional threats. Instead, existing classifications often mix intrinsic vulnerabilities with contextual variables, treat behavioral outcomes and underlying psychological mechanisms interchangeably, or focus on specific domains such as intentional insider threats, socio-technical risk analysis, or security awareness. To address this gap, the present study draws insight from current literature providing such partial classifications as elaborated above, identifies recurring concepts, and merges them in order to develop a Cybersecurity Human Factor Taxonomy designed specifically to support the SLR of HVA methods, models, and instruments. The taxonomy was created by incorporating evidence from two sources following an iterative process to synthesize the concept. The first source was the factor structure presented in [7], which identified many human susceptibility factors linked to both unintentional and intentional cyber threats. These encompassed demographics, personality traits, cognitive processes, emotions, cybersecurity awareness, training, behavioral patterns, cultural influences, and factors associated with maliciousness [5], [39]– [45]. The second source consisted of the analysis of the candidate taxonomy-related studies that were identified during the preparatory stage of this review [1], [34], [36]–[38]. These studies were examined specifically to determine whether an existing taxonomy could be adopted or extended instead of constructing a new classification. Recurring human factor categories and structural patterns relevant to cybersecurity vulnerability analysis were identified and evidence and insights extracted from these studies have been further enhanced, extended, and combined to construct the taxonomy utilised in the current study. A. Taxonomy Design & Development The developed taxonomy has been structured around two overarching classes, namely: i) vulnerability domains as conceptual categories, each of them grouping various human factors that function as vulnerability mechanisms, and the associated sub-factors that portray vectors, dimensions, or manifestations of the corresponding human factor, ii) contextual variables that function as moderators of human vulnerabilities. Taxonomy-related literature often merges these two classes, treating variables such as demographics, training, or cultural environment as vulnerabilities themselves. However, these variables mostly influence how vulnerabilities emerge or manifest rather than constituting vulnerabilities per se. This was particularly evident in relevant literature that has been investigating how such variables influence cognitive- or behavior-related vulnerability levels [46]–[53]. The design process adopted commonly utilised taxonomy design principles, identified across the literature [54], namely: mutual exclusivity, which helps ensure that each identified human factor belongs to only one vulnerability domain and duplication is avoided; collective exhaustiveness, according to which the pool of human factors needs to capture the entire conceptual space of human vulnerability, hence taxonomy

related studies as well as studies measuring, assessing, or aiming to identify links between susceptibility and specific human factors were investigated to construct the human factor pool; and conceptual coherence, which dictates that each domain of human factors groups concepts that have a similar functional role in shaping human vulnerability within cybersecurity contexts. These design principles formed the basis upon which four methodological steps were applied to construct the taxonomy. First, all candidate human factors extracted from the literature were consolidated into a single concept pool. This pool included both unintentional threat concepts, such as risk-taking behavior, lack of awareness, information disclosure practices, and security compliance tendencies, as well as intentional threat concepts, such as malicious personality traits, norms, values, and aggressive interpersonal behavior. Second, all factors of the pool were separated into the two major conceptual classes, by distinguishing between intrinsic vulnerability mechanisms and contextual variables, identifying vulnerability human factors and moderator indicators, respectively. Third, factors and indicators, resepctively, that were similar in concept were combined and restructured to avoid repetition while enhancing clarity. For example, trust-related constructs identified in several studies were combined to form the trust perception human factor, and technology acceptance variables like perceived usefulness, perceived ease of use, and behavioral intention to use systems were combined into technology perception. Fourth, the final list of factors and indicators were grouped into higher-order conceptual vulnerability domains and moderator groups, respectively, based on their functional role in human cyber vulnerability mechanisms. B. Cybersecurity Human Factor Taxonomy The developed Cybersecurity Human Factor Taxonomy follows a causal interaction model [55], commonly discussed in behavioral research, suggesting that psychological factors influence cognitive processes that in turn shape or affect behavioural patterns, while temporal conditions and environmental context may further affect behavior. The taxonomy is structured around i) four main vulnerability domains, reflecting the primary layers through which relevant human factors may be triggered and vulnerabilities may manifest in cybersecurity contexts and ii) four moderator groups, representing contextual conditions that may amplify, mitigate, or shape the effects of the human factors grouped under the four vulnerability domains. Both intentional and unintentional threats are considered in this structure, as human vulnerability extends beyond accidental user error to include factors associated with deliberate misuse of systems and data as well as with the exploitation of vulnerabilities of other users (e.g., through social engineering or insider manipulation) within the same cyber-physical system. This structure highlights, as already recognized across the literature [4], [5], [36], [43], [56], that human vulnerabilities and malicious cyber behaviors emerge from the interaction of factors operating at multiple levels. Vulnerability domains include Psychological Factors, Cognitive Factors, Behavioral Factors, and Human Performance

4

State Factors Regarding Psychological Factors, these include relatively stable individual characteristics that influence how individuals perceive and respond to cyber threats, such as personality traits, emotions, ethics, attitudes, mental stability, and self-perception. Under this domain, traits such as moral disengagement, low empathy, or malicious personality tendencies may be indicative of potential insider misuse [5]. Cognitive factors refer to mechanisms employed for information processing, including cognitive processes, biases, awareness, expertise, trust perception, technology perception, and risk appraisal. Within this domain, a key highlight in the taxonomy is the incorporation of emerging cybersecurity challenges associated with human-AI interaction, which is currently lacking from other classifications across the literature, potentially due to the very recent widespread use of Large Language Models (LLMs) in both professional and personal everyday life. Modern cyber environments increasingly involve the use of AI-driven tools, which introduce new forms of cognitive vulnerability such as automation bias, overreliance on AI-generated outputs, and reduced verification of machinegenerated information [57]–[59]. These vulnerabilities were incorporated into the taxonomy under the Human-AI Cognitive Interaction factor, as they represent specific manifestations of trust evaluation and cognitive bias in AI-assisted decisionmaking environments. On the other hand, behavioral factors describe the action patterns that expose individuals to cyber threats, including security behavior like risk-taking or policy non-compliance, and online behavior, such as information disclosure or browsing habits. In addition, behavioral factors may also capture observable manifestations of intentional threats, such as deliberate policy violations, misuse of access privileges, or malicious online actions. The distinction between cognitive and behavioral factors lies in the fact that cognitive factors capture knowledge, awareness, and perception of safe behavior, whereas behavioral factors reflect the actual actions and practices performed by users in digital environments. Furthermore, human performance state factors represent temporary performance conditions, such as alertness, time pressure, multitasking, and interruptions, which have a situational and dynamic nature. Contrary to stable characteristics, these factors may vary from one day to the next and their influence may change depending on the temporal and operational context of cybersecurity decisions. The Moderator class includes groups of variables such as demographics, cybersecurity training, prior experience with cyber incidents, and socio-cultural & environmental context. These further influence how vulnerabilities emerge, i.e., how human factors are triggered or how strongly they manifest, while they also shape the relationship among various human factors. Research indicates that demographics such as age, education, and occupation may have an effect on cybersecurity awareness and risk perception [47], [49], [60]–[62]. Furthermore, cybersecurity training may enhance awareness and improve security behavior by enhancing threat detection and response skills [63]–[65]. Meanwhile, prior experience with cyber incidents may influence how individuals perceive and respond to cybersecurity risks, by either making them

overconfident on their defense competency or very reluctant to proceed to risky behaviors [53], [66], [67]. This includes dimensions such as prior victimization, success or failure of incident detection, exposure only by observation, and previously adopted defense actions. Socio-cultural and environmental indicators, including norms, values, governance conditions, economic pressure, legal frameworks, and intergroup dynamics, strongly relate to intentional threats, as they may affect the perception of insider threat behavior as unacceptable, tolerated, or justified within a digital environment. Overall, socio-cultural and environmental factors highlight that malicious insiders cannot be fully understood solely through individual characteristics. Instead, intentional malicious cyber behavior often emerges from the interaction between individual traits and the broader social, cultural, and institutional contexts in which digital activities occur [5]. In Table I, below, the four Vulnerabilities Domains of the developed taxonomy are provided alongside the human factors they are composed of and several sub-factors that were identified across the literature as investigated dimensions. For each human factor, Table I indicates the Threat Relevance as well, that is the potential threat that may emerge from the manifestation of the human factor, i.e., Unintentional Threat (U), Intentional Threat, or both (U/I), as it was identified through the literature. In addition, Table II, further below, provides the four Moderator Groups, accompanied by the indicators that comprise them, the human factors that may be affected by their manifestation, as identified through the literature, and the Threat Relevance in a similar manner as in Table I. Each Vulnerability Domain and Moderator Group and their respective human factors and indicators are followed by a unique ID, in order to streamline the analysis of the studies included in the SLR and categorize the methods, models, and instruments accordingly in the sections that follow. Overall, the proposed taxonomy should be understood as a literature-grounded analytical framework developed specifically to support the systematic analysis of HVA-related studies reviewed in the current SLR. It does not attempt to define a psychological measurement instrument itself. Instead, it functions as a structured classification scheme used to map the coverage of existing HVA methods, models, and instruments across the space of human cyber vulnerabilities. Therefore, the purpose of this section is not to provide an exhaustive theoretical treatment of each factor, but to define the classification logic used to map the included studies. By systematically recording which vulnerability domains, human factors, moderators and indicators are addressed by each approach identified in the SLR, the taxonomy enables the review to identify conceptual gaps and determine whether current research adequately addresses the multidimensional nature of human cyber vulnerability, which is the primary objective of this study. Nonetheless, the development of the proposed Cybersecurity Human Factor Taxonomy may be interpreted as a secondary methodological contribution of this study.

5

TABLE I V ULNERABILITY D OMAINS AND H UMAN FACTORS Vulnerability Domain

Psychological Factors (PsyF)

Cognitive Factors (CogF)

Behavioral Factors (BehF)

Performance State Factors (PerF)

Human Factor

Subfactors / manifestations

Threat relevance

References

Personality traits (PsyF-1)

openness, agreeableness, conscientiousness, neuroticism, extraversion, sensation-seeking, impulsivity; Machiavellianism, psychopathy, narcissism

U/I

[4], [5], [10], [34], [36]–[40], [60], [68]–[70]

Emotions & feelings (PsyF-2)

mood, stress, anxiety, fear, anger, curiosity, guilt, regret, tension, happiness, sadness, disgust

U/I

[1], [36], [37], [39], [50], [60], [71]

Dispositional characteristics (PsyF-3)

conformity, credulity, friendliness, kindness, humility, courtesy, apathy, indifference, envy, self-control; sympathy, helpfulness, self-love, greed, lust, gluttony

U

[38], [60]

Ethics / moral reasoning (PsyF-4)

moral disengagement, moral intensity, personal responsibility

U/I

[1], [37], [60], [72], [73]

Mental stability (PsyF-5)

stability, instability

I

[4], [5], [36], [39], [40]

Self-perception (PsyF-6)

pessimistic, optimistic

I

[4], [5], [36], [39], [40]

Attitudes toward cyber behaviour (PsyF-7)

positive or negative attitudes toward cybersecurity practices

U/I

[4], [5], [34], [36], [37], [39], [40], [60], [74]

Cognitive processes (CogF-1)

information processing, decision-making / judgment, thinking set

U

[36], [37], [46], [60], [75]

Cognitive biases (CogF-2)

reasoning shortcuts, cultural biases

I

[4], [5], [36]–[40]

Cybersecurity awareness (CogF-3)

awareness of cyber threats and security practices

U

[1], [34], [37], [50], [66], [76]

Computer expertise (CogF-4)

digital literacy, technical competence

U

[34], [43], [77], [78]

Trust perception (CogF-5)

trust in people, automated systems, platforms, and information sharing

U

[34], [37]

Technology perception (CogF-6)

perceived usefulness, perceived ease of use, behavioral intention to use systems

U

[34]

Risk & protection appraisal (CogF-7)

perceived vulnerability, perceived severity, response efficacy, self-efficacy

U

[37], [38], [79]–[84]

Security / privacy perception (CogF-8)

perceived security, privacy concern, perceived control of information sharing

U

[34]

Human-AI Cognitive Interaction (CogF-9)

automation bias, AI over-trust, cognitive offloading, prompt-injection susceptibility

U

[37]

Security risk behavior (BehF-1)

active risk-taking, passive risk-taking, policy non-compliance, carelessness, inattentiveness, failure to verify information

U/I

[1], [34], [37], [41], [80], [85]–[90]

Interpersonal behavior (BehF-2)

hostile aggression, instrumental aggression, relational aggression, indirect aggression

I

[4], [5], [36], [39], [40]

Online self-disclosure (BehF-3)

disclosure of sensitive and non-sensitive information

U

[37], [50], [91]

Internet addiction (BehF-4)

normal level, moderate level, severe dependence

U

[34], [74]

Online / browsing habits (BehF-5)

social media engagement, browsing patterns

U

[34], [45], [92]

Alertness (PerF-1)

cognitive overload, fatigue, tiredness, vigilance level

U/I

[1], [36], [37], [39], [50], [60], [71], [90]

Time pressure (PerF-2)

urgency-driven decision making

U/I

[1], [37]

Multitasking (PerF-3)

simultaneous task handling

U/I

[1]

Interruptions (PerF-4)

attention switching, task disruption

U/I

[1]

6

TABLE II M ODERATORS TABLE Moderator Groups

Indicators / Attributes

Factors potentially affected

Threat Relevance

awareness, expertise, risk perception, security behavior

Primarily U

References

Age (Dem-1) Demographics (Dem)

Gender (Dem-2)

[47], [49], [60], [61], [93] [34], [38], [43], [94]

Education level (Dem-3) Occupation (Dem-4)

[60], [64], [65]

Awareness training (CTr-1) Cybersecurity training (CTr)

Experience with cyber incidents (Cexp)

Formal training (CTr-2)

awareness, computer expertise, security behavior

U

Certification (CTr-3)

[1], [37]

Frequency (CTr-4)

[34], [38]

Prior victimization (Cexp-1)

[53]

Prior detection success/failure (Cexp-2) Observational exposure (Cexp-3)

awareness, computer expertise, security behavior

U

[79] [67]

Defense action adoption (Cexp-4)

Socio-cultural & environmental context (SCE)

[61], [63]

[38]

Culture (SCE-1)

[95]

Societal conditions (SCE-2)

[51], [60], [96]

Norms (SCE-3)

[60]

Values (SCE-4)

[42], [97]

Economic stability (SCE-5)

psychological factors, risk perception, disclosure behavior, security behavior

Primarily I

Governance environment (SCE-6)

[4], [5], [39]

Media portrayal (SCE-7)

[1], [36], [40]

Legal status (SCE-8)

[37], [90]

Intergroup behavior (SCE-9)

[38]

Beyond the taxonomy’s role in supporting the SLR, it may also serve as a reference framework for future research aiming to design more comprehensive human vulnerability assessment methodologies. However, it should be highlighted that this taxonomy should be considered preliminary and additional research and experimentation is required to evaluate its validity before it could be formally considered as a scientifically valid taxonomy. IV. PRISMA M ETHODOLOGY This paper systematically analyzes a complete set of publications from 2017 to 2025 that were retrieved from various scientific libraries and publication search engines. The core objective of the SLR in this work is to investigate recent and relevant literature to evaluate if existing HVA methods, models, or instruments, either implemented or proposed on a conceptual basis, holistically and dynamically assess human vulnerabilities that may impose unintentional or intentional threats in digital environments. The SLR is guided by the following three primary Research Questions (RQs): • RQ1: What methods have been suggested for assessing human vulnerability in cybersecurity? • RQ2: What models have been currently proposed or implemented for identifying and evaluating or measuring human vulnerability in cybersecurity?

RQ3: What human vulnerability assessment instruments, such as questionnaires and scales, have been developed or designed within the realm of cybersecurity? Therefore, the contributions of this SLR include: i) performing a thorough literature review and identifying proposed approaches towards human vulnerability assessment within a cybersecurity context; ii) synthesizing and presenting the results of the literature review on current methods, models, and instruments for human vulnerability assessment; iii) conducting an analysis of the proposed approaches for human vulnerability assessment, and categorizing these according to the Cybersecurity Human Factor Taxonomy outlined in Section III; iv) documenting any gaps or limitations observed through the review, analysis, and synthesis of the studies eligible for inclusion. This section describes the roadmap employed for conducting the SLR. The method is founded on the principles and guidelines of the PRISMA framework [15]. •

A. Protocol and Eligibility Criteria Publications were deemed eligible for inclusion in this SLR if they were published between 2017 and 2025, through a peer-review procedure, and had the full-text version of the publication available online. Various fields of study, such as sociology, psychology, computer science, and criminology,

7

have shown a keen interest in human vulnerabilities pertaining to deception and fraudulent tactics, commonly employed in cyber attacks. Consequently, for this study, suitable studies were those that concentrated on the formulation of HVA frameworks within the domain of cybersecurity. Additionally, emerging directions, such as adaptive user modeling, AI-driven profiling, personalized cybersecurity education, and LLMbased behavioral modeling, were acknowledged as adjacent spaces to HVA but beyond the practical scope of this review that focused on studies that explicitly operationalize fundamental concepts of HVA. B. Information Sources & Search String A search query was designed and employed to perform a cross-search across four scientific digital libraries, namely: IEEE Xplore Digital Library7 , ACM Digital Library8 , ScienceDirect Digital Library9 , and SpringerLink Digital Library10 . In addition, the search process was complemented by applying the search query to Scopus11 and Google Scholar12 scientific search engines in order to identify any relevant publications that were not included in the aforementioned digital libraries. The query underwent minor adjustments, before applying to each digital library and search engine, to ensure that it would be inline with their query syntax guidelines and yield all relevant publications. (”cybersecurity” OR ”information security”) AND (”human vulnerabilities” OR ”human factor vulnerabilities” OR ”human risk factor” OR ”user awareness”) AND (”assessment” OR ”framework” OR ”model” OR ”tool” OR ”scale” OR ”technique” OR ”strategy” OR ”approach” OR ”method” OR ”UEBA” OR ”user behavior analytics”) NOT (“training” OR “case study”) C. Inclusion and Exclusion Criteria Inclusion and exclusion criteria were established for the screening process to ascertain that the selected articles are pertinent to the RQs and the main objective of the SLR. Publications were considered eligible for inclusion if they met the study’s protocol and eligibility criteria and addressed at least one of the specified RQs. Consequently, research studies were rejected based on the following exclusion criteria: i) Studies failing to meet the eligibility criteria of the SLR, specifically those published outside the 2017-2025 timeframe, lacking full-text online availability, not peer-reviewed, or not directly pertinent to the cybersecurity domain; ii) studies irrelevant to the RQs of the SLR; iii) studies not authored in the English language; iv) duplicate and repetitive studies; v) studies not directly addressing human vulnerabilities or focusing exclusively on technological vulnerabilities, or theorizing the concept of human vulnerability assessment in cybersecurity without proposing a specific method, model, or instrument for evaluating the human factor within the cybersecurity context. 7 ieeexplore.ieee.org/Xplore/home.jsp 8 dl.acm.org/ 9 sciencedirect.com/ 10 link.springer.com/ 11 scopus.com/ 12 scholar.google.com/

D. Article Selection & Search Results The search yielded 4,036 studies, which were reviewed by three independent researchers to eliminate bias, in accordance with the procedure depicted in Figure 1. At the pre-screening stage, 1,535 records were excluded according to the exclusion criteria of duplicate records, publication period, peer-review status, and manuscript language. The studies stemming from the pre-screening stage underwent two screening cycles, during which they were categorized into three groups according to the inclusion and exclusion criteria: included, excluded, and maybe. The papers categorized as ”maybe” underwent additional scrutiny and assessment by the researchers to decide upon their inclusion or exclusion.

Fig. 1. Identification of Studies following the PRISMA framework

During the 1st screening cycle, 2,501 articles were evaluated, and 2,125 were excluded based on title and abstract according to the established inclusion and exclusion criteria, leading to 376 studies sought for retrieval. Out of these, 46 could not be accessed owing to lack of online availability, such as [98]–[100], which were considered as potentially relevant works in the field of human vulnerability assessment in cybersecurity based on their abstracts, but could not be accessed due to subscription limitations. During the 2nd screening cycle, 330 retrieved studies were evaluated based on the established protocol and eligibility criteria, leading to the exclusion of 278 studies that focused on

8

theorizing human vulnerabilities instead of proposing a specific, either implemented or conceptualized, method, model, or instrument for assessing human vulnerabilities in a cybersecurity context. At the end of the entire screening process, 52 articles were selected for inclusion in this SLR, complemented by 2 additional studies, published in 2015 [9] and 2014 [8], which were identified through a backward snowballing process and acknowledged as ”honorable mentions” due to their esteemed recognition within the scientific community and their substantial citation records. The classification of the selected studies according to the RQs to which they relate to is illustrated in Figure 2. The research process revealed that most studies, 26 in particular, focus on designing and implementing computational models to measure dimensions of human vulnerability in cybersecurity. This is followed by 17 studies that propose and apply a method or framework. Finally, 11 studies present instruments, such as quastionnaires and scales, to assess specific human vulnerability factors.

in the SLR as “honorable mentions”, were excluded from this diagram as they do not reflect the full publication activity of those years. Focusing on the main study period, the research activity begins with a moderate number of 2 studies in 2017, followed by a sharp rise in 2018 with 9 studies, which also represents the year with the most published studies. From 2019 and onwards, the number of studies is somewhat stabilized at a moderate level, where 5 studies were published in 2019, and 7 studies were published in both 2020 and 2021. A small and temporal decline is observed in 2022, with 4 studies were published in that year, followed again by an increase in both 2023 and 2024 where 7 studies were published. The most recent year, 2025, shows a decrease similar to 2022, with 4 studies in that year. Overall, the figure suggests that the topic of human vulnerability assessment research has gained significant attention after 2018 and remains consistent, despite minor fluctuations.

Fig. 4. Studies Published per Year

Fig. 2. Study classification according to RQs

Figure 3 provides information about the publication venues of the selected studies. As illustrated, the majority of studies, 40 in prticular, originated from well-established conferences, while the rest 13 of them, originated from high-impact and peer-reviewed journals.

Fig. 3. Classification of Studies according to Publication Venues

Regarding the publication period of the included studies, the distribution of studies generally increases over time as depicted in Figure 4. As the SLR focused on the period 2017-2025, the studies of 2014 [8] and 2015 [9], acknowledged and included

V. H OW H UMAN V ULNERABILITY IS A SSESSED IN C YBERSECURITY A. Methods 1) Conceptual and Theoretical Methods: Conceptual and theoretical methods have mostly focused on defining how human vulnerability may be understood before proposing practical assessment mechanisms, providing important explanatory foundations and identifying important vulnerability variables. For unintentional threats, emphasis is placed on awareness degradation, cognitive overload, and policy noncompliance. As proposed by [101], linking security communication fatigue to information security policy noncompliance through the Protection Motivation Theory can provide insights on risk perception and self-efficacy under cognitive exhaustion. Furthermore, the BYOD-SAM framework proposed by [102] relies on technical controls and IT monitoring to assess and improve compliance of enterprise mobile-device users. For intentional threats, focus has been primarily on insider-threat dynamics, social influence, and psychological predispositions. Building on the Motivation, Opportunity, Capability (MOC) model, [103] proposed the MOCR theory, incorporating rationalization and influence / societal conditions from fraud theory to explain how an insider’s risk profile may evolve into malicious behavior. In addition, cognitive psychology dimensions have been utilized by [104] to classify cybercognitive attacks through factors such

9

as cognitive bias, mental stability, and personality traits, to explain how human vulnerabilities may be exploited to bypass technical defenses. Such approaches emphasize the psychological, cognitive, and organizational conditions influencing vulnerable or malicious cyber behavior; however, most remain pre-empirical and lack standardized assessment metrics, practical validation, and mechanisms for continuous or adaptive assessment. 2) Behavioral Observation and Analytical Methods: Behavioral observation and analytical methods conceptualize vulnerability primarily through observable actions, behavioral traces, and measurable indicators. Instead of relying on perceived attitudes or self-reported awareness, these approaches have attempted to assess vulnerability objectively through monitoring systems, scoring mechanisms, and quantitative analysis. For instance, the Pattern Based Intrusion Detection (PIDE) method continuously monitors user activity and compares it against expert-defined authorized and unauthorized behavioral signatures in order to identify suspicious insider actions [13]. From the analytical perspective, the inclusive Social Cyber Vulnerability (iSCV) metric was used by [105] to evaluate the susceptibility of underrepresented populations to social cyberattacks by analyzing demographics, computer literacy, and previous attack exposure. Regarding combining methods, the Digital-PASS simulation and the SocialScore tool were combined by [106] to quantify risky social media exposure and careless online self-disclosure through gamified privacy education mechanisms. Such approaches provide scalable and objective assessment mechanisms that are often compatible with continuous monitoring environments; however, the fact that they often rely on fixed behavioral signatures may render them difficult to adapt to previously unseen patterns. At the same time, analytical scoring systems may lack the psychological depth necessary to explain why users exhibit certain vulnerabilities. 3) Self-Reported and Qualitative Methods: Instead of relying on behavioral monitoring, self reported and qualitative approaches attempt to capture vulnerability through direct user input or contextual expert analysis. Self-reported methods conceptualize vulnerability primarily through perceived experiences, attitudes, and beliefs while qualitative and expertbased methods are mainly used to explore complex organizational and psychological dimensions of vulnerability, which can be particularly useful for capturing psychological states, perceptions, and contextual experiences. With regard to unintentional threats, self-reported methods have been used to assess knowledge, attitude, and behavior (KAB) dimensions of the cybersecurity maturity of users in [107] while questionnaires and self-diagnosis tools have been combined to identify high-risk behaviors before administering targeted awareness interventions in [108]. A four-component model of cyber fatigue was proposed and evaluated through qualitative case studies and interviews, assessing and categorizing fatigue into advice / action-related and attitudinal / cognitive dimensions [109]. In addition, graph-based scenario modeling and cognitive maps have been utilized by [110] to forecast organizational susceptibility to Business Email Compromise by cross-referencing personality traits against

emotional vulnerabilities across departments. Such methods remain limited by subjectivity, self-report bias, and their reliance on perceived rather than actual security behavior under realistic operational conditions. 4) Experimental and Simulation-Based Methods: Experimental and simulation-based methods conceptualize vulnerability primarily through user reactions under simulated operational conditions rather than through self-perception or theoretical profiling. They target vulnerability assesmment mostly through exposing users to controlled cyberattack scenarios and capturing realistic behavioral responses. For instance, a Bayesian Multi-armed Bandit testing strategy was proposed in [11], according to which system administrators distribute simulated malicious messages and binary user responses, such as clicking or ignoring the content, are recorded to dynamically identify users who are most susceptible to social engineering attacks. While such methods exhibit the ability to observe realistic user behavior in controlled attack environments, they often simplify vulnerability into limited behavioral outcomes and may overlook broader psychological, organizational, or contextual factors influencing user decisions. 5) Hybrid Methods: Hybrid methods have attempted to overcome the limitations of single-source assessment by combining multiple data collection and evaluation techniques. These approaches conceptualize vulnerability as a multidimensional phenomenon that cannot be captured adequately through isolated psychometric, behavioral, or technical measurements. For unintentional threats, hybrid approaches frequently have combined psychometric profiling with behavioral experimentation or continuous monitoring, such as integrating MBTI personality assessments with simulated phishing experiments, to demonstrate how different personality types respond differently to social engineering tactics [10]. Similarly, questionnaires have been combined with AI-driven image and text analysis to construct a ”Digital Human” ontology capable of generating personalized vulnerability scores from inferred human traits [56]. Vulnerability has also been assessed through continuous monitoring of user activity combined with demographic characteristics, IT expertise, and personality-related information [12]. For intentional threats, hybrid methods have integrated behavioral monitoring with advanced analytics to infer psychological characteristics from user activity. Natural Language Processing (NLP) has been applied to employeegenerated text in order to infer Big Five personality traits, which are subsequently used by machine learning algorithms to classify insider-threat profiles such as disgruntled employees or inadvertent insiders [111]. The trade-off for these approaches lies in complexity, dependence on continuous data collection, and integration of AI-driven analytics, which introduce important challenges regarding scalability, privacy, explainability, and practical deployment. B. Models 1) Machine learning-based Models: Machine-learning techniques have been employed across studies to detect intentional threats by identifying anomalies in user’s behavior,

10

typically assessing individuals indirectly by analyzing their browsing habits and system interactions. In most cases, a baseline of normal behavior is established and then mistakes and deviations are detected. An LSTM-CNN framework utilizing the Long Short-Term Memory (LSTM) and Convolutional Neural Networks (CNN) is used to extract features and patterns from system usage in [112], while another framework modeled an LSTM-based autoencoder capturing session activities in [113]. For improving detection outcomes in unbalanced datasets, a multi-modal user behavioral analytics (UBA) model is suggested in [114], incorporating four different detection algorithms. An alternative approach adopts a more networkcentric perspective, applying Deep Neural Networks to network traffic parameters and creating behavioral profiles based on browsing activity and device usage [115]. In addition, traditional machine learning techniques have been used, including data-layered systems combining statistical methods and classifiers for abnormal behavior detection [116], as well as decision trees and random forests for identifying malicious activities through system-level behavior analysis [117]. Such models have been reported as effective, but still showcase several important limitations, such as limited practical applicability due to dependence on synthetic datasets and a focus on detection accuracy at the expense of exploring psychological, behavioral, and social factors affecting the user’s vulnerability in cybersecurity contexts. As a result, such solutions seem to provide fragmented information about the root causes of insecure behavior, while their evaluation is often limited and underreported, with minimal to no insight into metrics and dataset characteristics, thus restricting precision and comparative analysis. 2) Analytical / Quantitative Models: Unlike machine learning approaches that have focused primarily on anomaly detection, analytical and quantitative models have targeted to explain and predict susceptibility through formal modeling, mathematical analysis, and statistical techniques. Several approaches have focused on phishing susceptibility and cognitive weaknesses associated with unintentional threats. Phishing success probability is estimated through the analysis of behavioral and emotional characteristics in [118] by focusing particularly on the ”hooking factor”, while a multi-layered statistical regression model, proposed in [119], combines psychological state, digital literacy, and cognitive biases to generate cumulative vulnerability ratings related to phishing susceptibility. Other approaches have translated risky user behavior into quantitative risk scores through telemetry data and weighted behavioral indicators [120]. More psychometricoriented models, like the Implicit Association Test-based model proposed in [121], measures unconscious cognitive associations related to phishing vulnerability through reactiontime scoring and urgency or persuasion cues, whereas fuzzyset Qualitative Comparative Analysis has been used in [122] to identify combinations of factors such as security education and awareness associated with vulnerability in e-commerce settings. Although these approaches provide more human-centric and measurable representations of vulnerability, many rely on small controlled samples, assume relatively static relationships

between factors, and remain limited in their ability to capture the dynamic and context-dependent nature of human behavior in operational cybersecurity environments. 3) Behavioral Observation / Monitoring Models: In contrast to both machine learning-based and analytical models, some studies have focused on the direct observation and monitoring of user behavior to detect anomalies. By tracking user activities and system interactions over time, such models evaluate human vulnerability in real-world environments. These approaches collect and analyze behavioral data to identify deviations connected to security threats, instead of directly assessing susceptibility or relying purely on anomaly detection. With regard to intentional threats, the use of UBA in [6] and User and Entity Behavior Analytics (UEBA) in [123] operate by establishing baselines for normal user behavior and flagging deviations by tracking user activities in organizational networks. User actions, such as access patterns and logins, form behavioral profiles that are displayed in dashboards and help identify insider threats focused on intentional risks like malicious or rule-breaking behaviors, assisting security analysts to evaluate responses and increase the effectiveness of the systems in operational settings [123]. In other approaches, the aggregation of user activity over a defined time frame has been utilized in order to minimize the false positives in anomaly identification [124]. Systems incorporating behavioral biometrics (BB), device-level tracking, and open-source intelligence (OSINT) have enabled behavior analysis to assess vulnerabilities of malicious intents [125]. Significantly, other models have focused on personal and organizational dimensions of vulnerability, promoting compliance by prioritizing policy awareness, training, and security proficiency [126]. The behavioral monitoring models that have been proposed across the literature showcase practicality and real-time capabilities but they also have key limitations. Many rely on case studies or small experiments with unclear metrics, lacking rigorous quantitative evaluation, while they depend on strict guidelines making them difficult to adjust to evolving threats and behaviors. While implementation remains limited to particular situations, it is worth noting that there is a focus on log-derived behaviors, which provides vague insights on the user’s psychological and cognitive motivations. 4) Experimental / Simulation-based Models: A different set of approaches uses supervised experimental and simulationbased models to assess human vulnerability under specific circumstances. These models have targeted to directly evaluate the relationships between security outcomes and human factors by actively exposing and monitoring users to simulated scenarios such as phishing or social engineering attacks. A key strategy in those approaches is the simulation of social engineering attacks imitating actual danger scenarios. More precisely, the Social Driven Vulnerability Assessment (SDVA) framework, proposed within the DOGANA project13 , follows an organized methodology that includes data collection, attack planning, simulated attack execution, and post-attack analysis. This approach enables a comprehensive assessment of user vulnerability to social engineering attacks by implementing 13 https://cordis.europa.eu/project/id/653618

11

persona modeling, communication tactics, and contextual delivery factors. Instead of focusing on intentional maliciousness, it exposes responses to situational cues, manipulation, and persuasion, recognizing cognitive and behavioral vulnerabilities [127]. Similarly, the Spear Phishing Exposure Level (SPEL) framework determines a Threat Exposure Level, assessing user awareness and experience by exposing users to simulated phishing scenarios. Using Protection Motivation Theory, these methods assess self-efficacy and perceived threats through users’ failure to recognize or respond to scams [66]. A more recent approach presented an RPA-powered phishing campaign simulation platform, capturing measurable behavioral outcomes to phishing attempts [128]. Nonetheless, most of the models under this category rely on simulated environments and may not capture the complexity of real-world attacks. Additionally, some of these models rely on self-reported or survey-based metrics, misleading real user activity. Some frameworks remain under development or lack quantitative assessment of their efficacy, while validation is partially restricted to certain industries. 5) Expert-based / Qualitative Models: A different viewpoint is offered by the studies that are using expert judgment and domain expertise to develop structured models for the assessment of human vulnerabilities. These approaches rely heavily on the use of expert’s knowledge to identify and evaluate human-related risk factors. In this context, a model combining the Human Factor Analysis and Classification System and Fuzzy Fault Tree Analysis [129] quantifies human error probability in smart grid substations. For human error calculation, the model defines and weighs the contributing factors in the faults tree structure based on expert opinion, calculating the probability of human error based on the expert-based evaluations of cognitive processes, organizational settings, and operational factors. Even though this category includes a single study across the literature, it emphasizes how critical it is to include expert knowledge in structured vulnerability assessment models. 6) Self-reported (survey-based) Models: Similarly to the assessment instruments, self-reported models measure human vulnerability by combining user’s opinions, attitudes, and self-assessed cybersecurity skills. From this perspective, the Human-Factored Cyber Security Capability Evaluation approach aims to identify the weak-link users by measuring workforce cybersecurity knowledge and abilities [130]. The framework consists of five levels: defining skills and baselines, collecting data via questionnaires, computing capabilities scores, visualizing results and identifying the weakest link. Individual cybersecurity skills are measured by analyzing responses and taking into account factors such as awareness, abilities, behavior, training and demographics. Although this method is effective for drawing attention to perceived weaknesses, it is limited in its ability to be generalized due to its reliance on self-reported data, assumptions for the correlation of knowledge, and actual capabilities and validation on a small industrial sample. 7) Hybrid Models: In an effort to provide a more comprehensive understanding and evaluation of human vulnerability, hybrid models have incorporated various approaches, bridging

the gap between behavioral monitoring and subjective selfreports as well as between experimental / simulation-based models and real-world data. For instance, the PoinTER framework used GDPR-compliant human pentesting in SMEs to assess vulnerability to phishing deception and cyber hygiene through simulated attacks combined with expert feedback from interviews [131]. Although scalability and consistency remain a limitation, this approach enhances interpretability by enabling both behavioral observation and contextual understanding via the interviews. Combining behavioral tracking, survey responses, and contextual elements including location, time, and past browsing activity, [132] synthesized a context-based Information Security Awareness (ISA) model that dynamically evaluates user risk in cybersecurity contexts. Even though integration complexity and data alignment create significant obstacles, this model reduces self-report bias by maintaining scalability through the combination of behavioral data with self-reported awareness metrics for comparing perceived activity. Moving one step further, the smartphone based ISA framework in [133] combines questionnaires, network traffic monitoring, and simulated cybersecurity challenges to identify vulnerable users and evaluate their responses to attack scenarios. Although a complex experimental design and data collection are needed, this approach combines various assessment dimensions for deepening human assessment. In addition, the HoS-ML framework, modeling human vulnerabilities in sociotechnical systems, incorporates behavioral data, psychological / relational factors, and machine learning to simulate risk propagation across organizational roles [134], [135]. This approach, which reflects a shift toward more intelligent and adaptive models, merges behavioral analysis with machine learning aiming to identify vulnerability patterns. C. Instruments 1) Self-reported survey-based instruments: Most identified instruments rely on self-reported survey data and aim to measure cybersecurity awareness, compliance with cybersecurity policies, susceptibility to persuasion, and both intentional and unintentional behaviors that may lead to cybersecurity compromise, such as [136], [137]. The common theme across all is their structured questionnaires, usually with Likert-scale items, that aim to measure human vulnerability from the reported knowledge, attitudes, intentions, traits, or practices. Some instruments address broad organizational cybersecurity behavior in multiple domains, such as the HAIS-Q questionnaire [8], which measures knowledge, attitude, and behavior in internet use, email use, password management, incident reporting, information handling, and mobile computing. Other approaches are more specific, such as SeBIS [9], which focuses on password generation, updating, device security, and proactive awareness. Additional instruments adopt more focused vulnerability measurements, such as susceptibility to persuasion included in StP-II [138], motivation to comply with security policies through competence, autonomy and relatedness, and cybersecurity failures through disclosure and intrusion vulnerability included in CSEC [139], or privacy exposure in the physical device context included in ODPS [140].

12

Those instruments measure psychometrics and rely on item generation, expert review, and statistical validation through exploratory or confirmatory factor analysis. Their main advantage is scalability since they are easy to be deployed across large samples and enable a standardized comparison between different user groups and settings. However, because they depend on self-report, they assess reported vulnerability rather than actual vulnerability. Responders are frequently asked to indicate what they believe they do, what they intend to do, or what they believe secure behavior is. This inevitably creates the limitation that the responses may indicate perceived norms, desirable behavior, or idealized self-presentation rather than the actual behavior of the user in real vulnerability conditions. Therefore, these instruments can be useful to measure perceived awareness, compliance perspective, and personality traits, but may be less successful at capturing cybersecurity decisions made under pressure, distraction, uncertainty, or deception. 2) Gamified / Interactive instruments: To address the limitations of self-reported instruments, gamified and interactive instruments have utilized scenario-based settings in which users are asked to respond to simulated scenarios rather than hypothetical questions. These approaches aim to evaluate more realistic behavior by integrating cybersecurity decisions within interactive environments. Following the research regarding human behavior toward cybersecurity policies instrument [136], the authors transformed the defined questionnaire into a gamified approach with intelligent, scenario-driven systems, allowing the users to engage with simulated cybersecurity contexts developed through web technologies [141]. Their methodology contains additional contextual factors that may be difficult to be measured by surveys, such as workload, interruptions, prior experience, and defense action adoption. While this approach reduces the response bias and can better simulate actual user behavior, it is still limited by predefined scenarios and needs validation against real-life environments. 3) Hybrid Instruments: To bridge the gap between selfreported responses and actual behavior, hybrid instruments integrate psychometric data with behavioral evaluation. The BCISQ instrument [142] combines self-assessment with simulated risky behavior to capture both cognitive and behavioral metrics. Furthermore, an additional approach proposed in [143] combines surveys with simulated attack scenarios, including phishing and ethical hacking experiments to indicate that psychological drivers like curiosity and impulsivity can lead users to exhibit risky cyber behavior. These studies highlight the commonly seen disparities between reported awareness and actual behavior, using factors such as awareness and trust perception, which can significantly influence user actions in realistic conditions, providing validity through psychological and cognitive measurements. Hybrid instruments have also combined surveys with interviews to enhance quantitative results with qualitative insights. Such an approach is the instrument to measure the cybersecurity awareness and cyber behaviors of college students proposed in [144], which utilizes a custom-built survey and interviews to evaluate cognitive and behavioral vulnerabilities, such as password reuse, lack of data backup, and the tendency

to prioritize convenience over security. As a result, it offers a more descriptive view of vulnerability, and more specifically around phishing susceptibility, identity theft, and password misuse. VI. A NALYSIS AND D ISCUSSION OF SLR R ESULTS A. Overall Results To evaluate the extent to which existing HVA approaches address the multidimensional nature of human cyber vulnerabilities, each identified method, model, or instrument was analyzed and mapped against the vulnerability domains and moderator groups of the Cybersecurity Human Factor Taxonomy designed in this study, to determine which human factors and indicators it explicitly assesses or operationalizes. Table III below presents the complete list of studies identified through the PRISMA methodology as eligible for inclusion in this SLR, ordered by year of publication (ascending), along with their mapping to the proposed taxonomy. For each study, the table reports whether it has been classified as a Method (Me), Model (Mo), or Instrument (I). The specific human factors and indicators addressed by each study have been recorded in the corresponding vulnerability and moderator columns. All studies included in the SLR addressed at least one vulnerability domain, while 45 out of the 53 included HVA approaches (85%) considered moderator groups as well, as can be seen in Figure 5. It is worth noting that, due to high variability across the studies regarding the terminology used to describe the human factors or indicators addressed, a conceptual analysis was performed in parallel in order to identify the underlying factors and indicators considered and ensure consistent mapping across studies. For instance, there were studies reporting they addressed ”digital literacy”, which in some cases referred to Cybersecurity awareness while in others it referred to Computer expertise.

Fig. 5. Moderator Availability in Studies

In addition to taxonomy mapping, further analytical dimensions were introduced in order to further characterize how the studies included in the SLR conceptualize and operationalize human cyber vulnerability, namely: i) threat relevance, ii) assessment or measurement approach, iii) vulnerability propagation, iv) vulnerability modelling approach. The threat relevance dimension classifies studies based on whether HVA is performed in light of Unintentional threats (U), Intentional threats (I), or both (U/I), allowing the review to evaluate

13

the extent to which existing HVA approaches consider malicious insider behavior alongside accidental human vulnerabilities. The assessment or measurement approach dimension investigates how human vulnerabilities are practically assessed or measured accross the reviewed studies, such as through self-reported instruments (i.e., surveys), experimental or simulation-based approaches, observation or monitoring procedures for capturing human behavior, machine-learning based models for identifyinf patterns and vulnerabilities, analytical or quantitative models to produce statistical results, expert-based or qualitative approaches, conceptual or theortical methodologies, gamified or interactive methods through which vulnerabilities may surface, and hybrid approaches combining methods. Furthermore, the vulnerability propagation dimension identifies whether and how a study conceptualizes the interaction or spread of vulnerability across different levels as follows: i) intra-individual refers to cascading interactions between vulnerability-related factors within the same individual, where one condition may influence or amplify another; ii) interindividual refers to the transmission or amplification of vulnerability between individuals through social interaction, trust relationships, communication patterns, or shared digital behavior, iii) systemic refers to the spread and reinforcement of vulnerabilities through broader socio-technical structures, organizational processes, operational dependencies, governance conditions, or collective behavioral dynamics. The vulnerability modelling dimension captures the extent to which vulnerability is conceptualized as fixed, contextdependent, or continuously evolving over time, as follows: i) static conceptualizes vulnerability as a relatively fixed or snapshot-based condition assessed at a specific point in time, typically through one-time measurements or stable profiles; ii) semi-dynamic incorporates contextual or fluctuating conditions, such as stress, fatigue, or situational influences, while still relying primarily on static or cross-sectional assessment approaches; iii) dynamic vulnerability modelling conceptualizes vulnerability as an evolving condition that changes over time according to user behavior, contextual influences, environmental conditions, or system interactions, often incorporating continuous monitoring, adaptive profiling, temporal analysis, or predictive assessment mechanisms. B. Detailed Results A thorough quantitative analysis was performed on the included studies, using as a basis their mapping to the proposed taxonomy, as depicted in Table III, aiming to unravel the aspects of human vulnerability that remain underrepresented among proposed approaches. The following sections provide the detailed results of this analysis, aiming to shed light upon the most commonly considered human factors and moderator indicators as well as the most frequently adopted combinations, assessment or measurement approaches, and the ways vulnerability is modelled and approached. 1) Vulnerability Domains & Human Factors: a) Human Factors considered across Studies: Figure 6 illustrates the overall distribution of all human factors assessed

in the reviewed studies, highlighting the frequency in which each factor is considered. The most noticeable studied factor is the Security Risk Behavior behavioral factor, with a high count of 50, indicating a primary focus in the literature among all factors considered. This is followed by the Cybersecurity Awareness and the Risk & Protection Appraisal cognitive factors, and the Online/browsing Habits behavioral factor, all of which are examined in a considerable number of studies. Less commonly evaluated factors include among others the Cognitive Biases cognitive factor, the Self-perception psychological factor, as well as the Alertness and Time-pressure performance state factors, with 10 occurences each. Among the least represented factors are Ethics / Morals Reasoning and Mental Stability psychological factors alongside Interruptions and Multitasking performance state factors, appearing only in a limited number of studies. Notably, Internet Addiction and Human-AI Cognitive Interaction behavioral factors, occurring only once, are the most underrepresented factors. In general, the figure shows that current studies put more emphasis on behavioral and cognitive factors than on psychological and performance state factors. This pattern suggests that current HVA approaches tend to operationalize vulnerability primarily through observable or measurable constructs rather than through more intrinsic or situational aspects. Delving further into the distribution of factors within each vulnerability domain, it is revealed that the dominance of behavioral and cognitive factors is driven by a limited subset of factors assessed within each domain rather than by a balanced consideration of all relevant human vulnerability mechanisms. More complex cognitive mechanisms, such as biases and human-AI interaction, remain underrepresented despite their relevance in modern cyber environments while there lacks a diverse set of behavioral factors capturing different forms of user interaction and exposure to cyber threats. In addition, the contribution of the psychological domain is concentrated around perception- and attitude-related aspects, while deeper mechanisms related to ethical judgment and psychological stability remain largely unexplored in current assessment approaches, indicating also limited consideration of factors that may be indicative of potential insider threats. Furthermore, situationl aspects such as the Multitasking and Interruptions factors are marginally considered, suggesting a narrow operationalization of performance state factors in current research even though such factors can render an individual more or less vulnerable from one day to the next. b) Most appeared combinations of Vulnerability Domains & Human Factors: Figure 7 presents the classification of studies based on combinations of vulnerability domains and how frequently these appear. Studies were identifying as addressing a particular domain if they assessed at least one human factory of the domain. As can be seen, the most common combination, with 22 studies, includes factors of the psychological, cognitive, and behavioral domains, indicating a general recognition in the literature that human vulnerability emerges from multi-layered interactions rather than from isolated factors and representing a tendency towards adopting a comprehensive approach.

14

TABLE III M APPING OF I NCLUDED S TUDIES TO THE C YBERSECURITY H UMAN FACTOR TAXONOMY Vulnerability Domains CogF BehF PerF Dem Security risk Personality behavior, Online I traits, Cybersecurity Age, self-disclosure, [8] (RQ3) Attitudes toward awareness Gender Online / browsing cyber behaviour habits Cybersecurity Age, Security risk I Attitudes toward awareness, Gender, behavior, Online / [9] (RQ3) cyber behaviour Security Education browsing habits / privacy perception level Security risk Cognitive biases, behavior, Personality Technology Time Interpersonal Mo traits, perception, pressure, behavior, Online [127] (RQ2) Dispositional Security Multitasking self-disclosure, characteristics / privacy Interruptions Online / browsing perception habits Ref. Categ.

[6]

Mo (RQ2)

PsyF

-

I Attitudes toward [141] (RQ3) cyber behaviour

-

-

Security risk behavior Security risk behavior, Interpersonal behavior, Online self-disclosure Security risk behavior, Online / browsing habits Security risk behavior, Interpersonal behavior, Online / browsing habits

Moderator Groups CTr Cexp

SCE

Threat Ass/Meas. Rel. Approach

Vuln. Prop

Vuln. Pub. Mod Year

Awareness raising, Formal training

-

Culture, Norms

U

SelfReported

Intra individual

Static 2014

Awareness raising

-

Economic stability

U

SelfReported

None

Static 2015

-

-

Culture, Societal conditions

U

Experimental/ SimulationBased

None

Semi2017 dynamic

Behavioral Observation / Systemic Dynamic 2017 Monitoring

-

Occupation

-

-

-

I

-

-

-

-

-

U

Self Reported

-

-

-

-

-

I

Machine LearningBased

Time pressure

-

Awareness raising, Formal training

-

Governance environment

U

Hybrid (Experiment, Interviews)

None

Static 2018

[112]

Mo (RQ2)

-

-

[131]

Mo (RQ2)

-

Cybersecurity awareness

[10]

Me (RQ1)

Personality traits

Cognitive processes, Risk & protection appraisal

Security risk behavior

-

-

Awareness raising

-

-

U

[11]

Me (RQ1)

-

Risk & protection appraisal

Security risk behavior

-

-

-

-

-

U

Personality traits, Cognitive I Dispositional processes, Risk & [138] (RQ3) characteristics protection appraisal

Security risk behavior, Interpersonal behavior

-

Age, Gender, Education level, Occupation

-

Prior detection (success/ failure), Observational exposure

Culture, Norms

U

Selfreported

IntraSemi2018 individual dynamic

Cognitive processes, Cybersecurity Self-perception, Mo awareness, Attitudes toward [130] (RQ2) Computer expertise, cyber behaviour Risk & protection appraisal, Security / privacy perception

Security risk behavior

Prior detection (success/ failure)

Culture, Norms, Governance environment

U

Selfreported

Systemic

-

-

I

Behavioral IntraObservation / Individual Dynamic 2018 Monitoring & Systemic

U

Hybrid (Behavioral IntraMonitoring / Individual Dynamic 2018 Analysis & & Systemic Survey)

-

I

Machine LearningBased

-

U

Experimental/ IntraSemiSimulation- Individual 2019 dynamic Based & Systemic

-

U

Behavioral IntraSemiObservation / Individual 2019 dynamic Monitoring & Systemic

[124]

Mo (RQ2)

-

-

Security risk behavior, Online / browsing habits

Cybersecurity Personality awareness, Security risk traits, Computer expertise, behavior, Online Me Dispositional Technology self-disclosure, [12] (RQ1) characteristics, perception, Risk & Online / browsing Attitudes toward protection appraisal, habits cyber behaviour Security / privacy perception Security risk Mo Personality behavior, Online / [114] (RQ2) traits browsing habits

Mo [66] (RQ2)

[126]

-

Mo Self-perception (RQ2)

Age, Awareness Gender, raising, Formal Alertness Education level, training, Occupation Certification

-

Occupation

-

Age, Gender

Awareness raising

-

Occupation

-

Cybersecurity Security risk awareness, Risk & behavior, Online protection appraisal self-disclosure

-

-

Cybersecurity awareness, Computer expertise

-

-

Security risk behavior

-

Prior Societal victimization, conditions, Prior Economic detection stability, (success/ Legal failure) status

-

Prior detection (success/ failure), Observational exposure Awareness Defence raising, Formal action training adoption

IntraDynamic 2018 individual

None

Static 2018

Hybrid IntraSemi(Survey, 2018 individual dynamic Experiment) Experimental/ SimulationNone Dynamic 2018 Based

Semi2018 dynamic

InterDynamic 2019 individual

15

Ref. Categ. [125]

Mo (RQ2)

I [142] (RQ3)

PsyF Emotions & Feelings

-

Vulnerability Domains CogF BehF -

Security risk behavior

Cybersecurity Security risk awareness, Risk & behavior, Online protection appraisal, self-disclosure, Security / privacy Online / browsing perception habits

Personality traits, Cybersecurity Emotions & awareness, Feelings, Me Computer expertise, Dispositional [111] (RQ1) Risk & protection characteristics, appraisal, Security / Ethics / moral privacy perception reasoning, Mental stability

Moderator Groups CTr Cexp

PerF

Dem

-

-

-

-

Age, Gender, Education level

-

Security risk behavior

Time pressure

Awareness raising, Occupation Formal training

SCE

Threat Rel.

-

-

U/I

-

Culture, Norms

U

Hybrid (Survey & Experiment)

Defense action adoption

Norms, Values, Legal status, Intergroup behavior

I

Hybrid (Behavioral Intra- & InterMonitoring / Individual & Dynamic 2020 Systemic Analysis & Survey)

[13]

Me (RQ1)

-

-

Security risk behavior

-

-

-

-

-

I

[113]

Mo (RQ2)

-

-

Security risk behavior, Online / browsing habits

-

Occupation

-

-

-

I

Cognitive processes, Cognitive biases, Prior Cybersecurity Security risk Age, detection awareness, behavior, Online Gender, Mo Attitudes toward Computer expertise, (success/ self-disclosure, Education [133] (RQ2) cyber behaviour failure), Trust perception, Online / browsing level, Observational Technology habits Occupation exposure perception, Risk & protection appraisal, Security / privacy perception Personality traits, Emotions & Cognitive Societal feelings, processes, conditions, Dispositional Cognitive biases, Security risk Norms, characteristics, Cybersecurity Mo behavior, Awareness Values, Ethics / moral awareness, [134] Alertness Occupation (RQ2) Interpersonal raising Governance reasoning, Mental Computer expertise, behavior environment, stability, SelfTrust perception, Intergroup perception, Risk & protection behavior Attitudes toward appraisal cyber behaviour Security risk Mo Risk & protection behavior, Online / [115] Occupation (RQ2) appraisal browsing habits Cognitive processes, Emotions & Security risk Cognitive biases, Societal Age, feelings, behavior, Cybersecurity conditions, Gender, Dispositional Interpersonal awareness, I Awareness Governance characteristics, Self- Computer expertise, behavior, Online Education [137] (RQ3) raising environment, perception, Technology self-disclosure, level, Intergroup Attitudes toward perception, Risk & Online / browsing Occupation behavior cyber behaviour protection appraisal, habits Security / privacy perception Cognitive processes, Cognitive biases, Security risk Personality traits, Cybersecurity behavior, Governance Dispositional awareness, Interpersonal Awareness Defense I Age, environment, characteristics, Computer expertise, behavior, Online raising, action [139] (RQ3) Occupation Legal Attitudes toward Technology self-disclosure, Frequency adoption status cyber behaviour perception, Risk & Online / browsing habits protection appraisal, Security / privacy perception Prior Cognitive victimization, processes, Security risk Prior Cybersecurity behavior, Alertness, detection awareness, Trust Interpersonal Time (success/ I perception, behavior, Online pressure, failure), [141] (RQ3) Risk & self-disclosure, Multitasking, Observational protection appraisal, Online / browsing Interruptions exposure, habits Security / privacy Defense perception action adoption

Ass/Meas. Approach Behavioral Observation / Monitoring

Behavioral Observation / Monitoring Machine LearningBased

Vuln. Prop

Vuln. Pub. Mod Year

None

Dynamic 2019

Intraindividual

Semi2019 dynamic

Intraindividual

Dynamic 2020

IntraIndividual Dynamic 2020 & Systemic

U

Hybrid (Survey & Behavioral Monitoring & Experiment)

U

Hybrid (Behavioral Intra- & InterAnalysis & Individual & Dynamic 2020 Machine Systemic LearningBased)

I

Machine LearningBased

None

Dynamic 2020

U

Self-Reported (Survey-Based)

Intraindividual

Static 2020

U

SelfReported

Intraindividual

Static 2021

U

Gamified / Interactive

Intraindividual

Semi2021 dynamic

Intraindividual

Dynamic 2020

16

Ref. Categ.

PsyF

[123]

Mo (RQ2)

-

[116]

Mo (RQ2)

-

Vulnerability Domains CogF BehF Security risk Cybersecurity behavior, Online / awareness browsing habits Security risk Risk & protection behavior, Online / appraisal browsing habits

Moderator Groups CTr Cexp

PerF

Dem

-

Occupation

-

-

-

-

SCE

Threat Rel.

-

-

I

-

-

I

Ass/Meas. Approach Behavioral Observation / Monitoring Machine LearningBased

Vuln. Prop

Vuln. Pub. Mod Year

Intraindividual

Dynamic 2021

None

Dynamic 2021

Emotions & feelings, Cognitive Dispositional processes, Security risk characteristics, Me Alertness, Observational Expert-Based / IntraSemiCognitive biases, behavior, Online / Ethics / moral [109] Values U 2021 (RQ1) Interruptions exposure Qualitative individual dynamic Trust perception, browsing habits reasoning, SelfTechnology perception, perception Attitudes toward cyber behaviour Personality traits, Cognitive Security risk Emotions & Culture, processes, behavior, feelings, Age, Societal Hybrid Cybersecurity Interpersonal Dispositional Gender, conditions, (Behavioral Me characteristics, awareness, behavior, Online Awareness IntraSemiEducation Norms, Monitoring / [56] U 2021 (RQ1) Ethics / moral Computer expertise, self-disclosure, raising individual dynamic level, Values, Analysis & reasoning, Self- Risk & protection Internet addiction, Occupation Economic Survey) appraisal, Security / Online / browsing perception, stability habits Attitudes toward privacy perception cyber behaviour Cognitive processes, Cognitive biases, Security risk Cybersecurity behavior, Awareness Self-perception, awareness, Trust Norms, Interpersonal Me SelfSemiraising, behavior, Online Gender None Attitudes toward Governance U perception, [108] 2021 (RQ1) Reported dynamic Formal cyber behaviour environment Technology self-disclosure, training perception, Risk & Online / browsing protection appraisal, habits Security / privacy perception Computer expertise, Security risk Age, Hybrid Prior Technology behavior, Gender, (Behavioral Mo Awareness detection perception, Risk & None Dynamic 2022 Interpersonal Education Monitoring / [132] U (RQ2) raising (success/ protection appraisal, behavior, Online / level, Analysis & failure) Security / privacy browsing habits Occupation Survey) perception Emotions & Cybersecurity Culture, [14] Alertness, Analytical / Intra- & Interfeelings, awareness, Mo Norms, Time Quantitative Individual & Dynamic 2022 Dispositional Computer expertise, U (RQ2) Governance [135] pressure Models Systemic characteristics, Risk & protection environment Mental stability appraisal Cognitive ExpertMe Security risk Systemic Dynamic 2022 processes, Risk & Based / [129] Alertness U (RQ1) behavior protection appraisal Qualitative Cybersecurity awareness, Trust Awareness Security risk Defense Hybrid I Attitudes toward perception, Risk & Age, raising, Societal behavior, Online / Time pressure action (Survey & None Static 2023 [144] U (RQ3) cyber behaviour protection appraisal, Gender Formal conditions browsing habits adoption Interviews) training Security / privacy perception Awareness Personality traits, Cybersecurity ExpertIntraMo Security risk raising, Emotions & awareness, Trust Values Based / Individual Dynamic 2023 [110] Occupation U (RQ2) behavior Formal feelings perception Qualitative & Systemic training Cognitive Intra- & InterMe Ethics / moral Security risk Societal Conceptual / processes, Individual & Dynamic 2023 [103] I (RQ1) reasoning behavior conditions Theoretical Computer expertise Systemic Personality traits, Emotions & Cognitive processes, Age, Analytical / Mo feelings, Cybersecurity Security risk Gender, IntraSemiQuantitative [118] Alertness U/I 2023 (RQ2) Dispositional awareness, Trust behavior Education individual dynamic Models characteristics, perception level Self-perception Cognitive processes, Prior Cybersecurity Awareness victimization, Me Attitudes toward awareness, Security risk raising, Governance Conceptual/ Occupation Defense None Dynamic 2023 [102] U (RQ1) cyber behaviour Computer expertise, behavior Formal environment Theoretical action Trust perception, training adoption Risk & protection appraisal

17

Vulnerability Domains Moderator Groups Threat Ass/Meas. Vuln. Vuln. Pub. Rel. Approach Prop Mod Year CogF BehF PerF CTr Cexp SCE Dem Cognitive Security risk processes, behavior, Online Cybersecurity Age, Defense Analytical/ Me Attitudes toward Awareness self-disclosure, awareness, Education action None Dynamic 2023 [106] U/I Quantitative (RQ1) cyber behaviour raising Online / browsing Technology level adoption Models habits perception, Security / privacy perception Cognitive Personality traits, Defense processes, Me Online / browsing Awareness Conceptual/ IntraSemiDispositional Occupation action Cybersecurity [104] I 2023 (RQ1) habits raising Theoretical individual dynamic characteristics awareness, Security adoption / privacy perception Security risk Machine Mo behavior, Online / LearningNone Dynamic 2024 [117] I (RQ2) browsing habits Based Cybersecurity Security risk Hybrid I Education Awareness Semi(Survey & Personality traits awareness, Trust behavior, Online / None [143] U 2024 (RQ3) level raising dynamic perception browsing habits Experiment) Cognitive Emotions & Awareness processes, Me feelings, raising, Observational Conceptual/ IntraSemiCybersecurity [101] Alertness U 2024 (RQ1) Attitudes toward Formal exposure Theoretical individual dynamic awareness, Risk & cyber behaviour training protection appraisal Cognitive processes, Personality traits, Cybersecurity Security risk Age, Culture, Analytical/ Emotions & awareness, Me Prior Semibehavior, Gender, Awareness Societal None Quantitative feelings, Conmputer expertise, [105] I 2024 (RQ1) raising victimization conditions, dynamic Interpersonal Education Models Attitudes toward Trust perception, behavior level Norms cyber behaviour Technology perception, Risk & protection appraisal Cognitive processes, Awareness Security risk Defense Analytical/ Cybersecurity Mo Attitudes toward raising, Intrabehavior, Online / action Quantitative Dynamic 2024 awareness, [120] U (RQ2) cyber behaviour Formal individual adoption Models Conmputer expertise, browsing habits training Security / privacy perception Emotions & Cognitive Age, feelings, I Security risk Awareness Prior SelfIntraGender, Static 2024 Self-perception, processes, Security [140] Culture U/I (RQ3) behavior raising victimization Reported individual Occupation Attitudes toward / privacy perception cyber behaviour Cognitive Age, processes, Awareness Alertness, Gender, Analytical/ Mo Attitudes toward Cognitive biases, Security risk raising, Prior IntraStatic 2024 Time Education Quantitative [121] I (RQ2) cyber behaviour Cybersecurity behavior Formal victimization individual pressure level, Models awareness, training Occupation Computer expertise Cybersecurity Age, awareness, Gender, Awareness Defense Analytical/ Mo Security risk SemiTechnology Education raising, action Quantitative None [122] I 2025 (RQ2) behavior dynamic perception, Risk & level, Certification adoption Models protection appraisal Occupation Cognitive processes, Cybersecurity Awareness Self-perception, awareness, Security risk Age, Me raising, SelfSemiAttitudes toward Technology behavior, Online Education None [107] U 2025 (RQ1) Formal Reported dynamic cyber behaviour perception, Risk & self-disclosure level training protection appraisal, Human-AI Cognitive Interaction Cognitive biases, Age, Analytical/ Mo Cybersecurity Security risk Gender, Economic IntraQuantitative Dynamic 2025 [119] Alertness U (RQ2) behavior stability individual awareness, Trust Education Models perception level Cognitive biases, Cybersecurity Security risk Emotions & Prior awareness, Trust behavior, Online Experimental/ feelings, detection Mo perception, Risk & self-disclosure, SimulationNone Dynamic 2025 [128] U (RQ2) Dispositional (success/ protection appraisal, Online / browsing Based characteristics failure) Security / privacy habits perception Ref. Categ.

PsyF

18

The next most frequent combination, although represented by significantly fewer studies, appears to be cognitive (CogF) and behavioral (BehF) factors, with 8 occurrences. The absence of inclusion of Psychological Factors (PsyF) in this combination further supports the observation that there is a number of studies that tends to prioritize measurable constructs, such as awareness and behavior, over deeper underlying mechanisms. The same number of studies was also identified for the combination including factors of all vulnerability domains, further highlighting the tendency towards multi-domain approaches. Despite the fact that this finding constitutes an important observation, the limited number of studies combining all vulnerability domains, compared to the studies including the PsyF-CoF-BehF combination, suggests that performance-related aspects are partially included alongside the three other domains. This observation further suggests the finding that situational and dynamic conditions are not systematically integrated into vulnerability assessment approaches. Moreover, even though single-domain approaches are less common, it is worth noting that when a single domain is considered this tends to correspond to behavioral factors, appearing in 6 studies.

to move towards holistic assessments, situational and dynamic aspects are treated as secondary additions rather than as core components of vulnerability assessment. These observations reinforce the pattern depicted in Figure 6, suggesting that current HVA approaches, even in multi-domain vulnerability contexts, often exhibit structural imbalance, with behavioral factors consistently receiving more emphasis.

Fig. 7. Classification of Studies based on the combinations of Vulnerability Domains assessed or considered

Fig. 6. Summary of assessed or considered Human Factors across studies

In addition, a deeper examination reveals that the domains included in multi-domain approaches are not equally represented in terms of the number of factors originating from each domain and included in the assessment. In particular, studies classified under the PsyF–CogF–BehF combination, include a higher number of behavioral factors, ranging between two and four per study, compared to a more limited inclusion of psychological factors, which are often restricted to one or two. Cognitive factors tend to occupy an intermediate position, with approximately two to three factors per study. A similar pattern is observed in studies incorporating all four domains where performance state factors are included but remain limited in number, typically appearing as one or two factors alongside a stronger representation of behavioral and cognitive factors. This adds to the observation that, even in approaches aiming

An additional analysis was performed to identify the most common combinations of the most frequently assessed human factors across the studies, illustrated in Figure 8. The most common combination is between Security Risk Behavior (BehF-1) and Cybersecurity Awareness (CogF-3), with 30 occurences, followed closely by Security Risk Behavior (BehF1) combined with the users’ Online/browsing Habits (BehF-5) and with Risk & Protection appraisal (CogF-7), with 27 and 25 occurences, respectively. Less frequent combinations include Security Risk Behavior (BehF-1) with Cognitive Processes (CogF-1) or Attitudes toward Cyber Behavior (PsyF-7), as well as Cybersecurity Awareness (CogF-3) with Risk & Protection Appraisal (CogF-7). Even though in this comparison these combinations appear less frequently than the most common ones, the number of studies including them remains considerable (20-21 studies), further higlighting the tendency towards combining behavioral and cognitive factors, in particular security risk behavior and risk protection appraisal. As observed, it is revealed that Security Risk Behavior (BehF-1) is consistently included as the common factor across high-frequency combinations. It is worth noting also that combinations that do not include Security Risk Behavior (BehF-1), such as the pairing of Cybersecurity Awareness (CogF-3) and Risk & Protection Appraisal (CogF-7), are rarely observed, suggesting that cognitive factors are not commonly assessed independently of behavioral outcomes. Furthermore, the limited inclusion of psychological factors in high-frequency combinations further highlights that psychological mechanisms are less frequently integrated into multifactor assessment approaches. The comparison between domain-level combination and factor-level dominance reveals that current HVA approaches

19

tend to be structurally multi-domain, having realized the multifacet nature of human vulnerability, but functionally behaviorcentric as the focus tends to be on factors related to observable user actions rather than on a balanced integration of psychological, cognitive, and behavioral mechanisms. In this sense, the strong emphasis on behavioral indicators suggests that many existing approaches primarily capture vulnerability at the point of manifestation, i.e., while users have already initiated an engagement in potentially risky or unsafe actions. Even though this provides valuable insights into observed behavior and human susceptibility hotspots in real-time and, potentially, real-world conditions, i.e., while humans operate within digital systems, it may limit the ability of such approaches to proactively identify underlying vulnerability conditions before they cascade into observable security-relevant actions.

cultural & Environmental Context group, and Certification and Frequency of the Cybersecurity Training group. This distribution reveals that while Awareness raising and Demographics have often been considered in HVA approaches, most Socio-cultural & Environmental Context indicators remain largely underexplored, despite their potential influence in vulnerabilities related to both unintentional and intentional threats. This distribution further highlights that current approaches tend to rely on observable or easily measurable attributes while more complex contextual conditions are less frequently considered, even though they may influence how vulnerabilities emerge and evolve and are also challenging to foresee. In addition, the dominance of Awareness raising as the most frequently considered indicator suggests that cybersecurity training is often treated as a factor indicative of potential susceptibility without though systematically distinguishing between different forms of training, their frequency, or their effectiveness, which is further supported by the limited presence of Certification and training Frequency indicators.

Fig. 8. Most Appeared Combinations of Most Assessed or Considered Human factors

2) Moderator Groups & Indicators: The sections below discuss the indicators considered by the studies (45) that included the assessment or measurement of Moderator Groups. It should be clarified that most of the reviewed studies did not consider Moderator Groups and indicators idependently from Vulnerability Domains and human factors; however, the analysis performed in this study presents the results separately to stay consistent with the proposed taxonomy. After the presentation of these results, this SLR follows an integrated approach to evaluate the coverage of both human factors and indicators of the reviewed studies, aiming to assess their holisticness towards HVA. a) Indicators considered across Studies: Figure 9 provides an overview of the frequency of all assessed or considered moderator indicators. As can be seen, Awareness raising, from the Cybersecurity Training moderator group, is the most dominant indicator with 27 occurrences, followed closely by Demographics indicators, such as Occupation (21 occurences), Age (20 occurences), and Gender (18 occurences). At the mid-level of frequency, indicators such as Education level from the Demographics group and Formal Training from the Cybersecurity Training group are observed, along with Norms from the Socio-cultural & Environmental Context group and Defense Action Adoption from the Experience with Cyberincidents group. The least represented include indicators such as Economic Stability and Legal Status from the Socio-

Fig. 9. Summary of assessed or considered Indicators across studies

b) Most Appeared Combinations of Moderator Groups & Indicators: Figure 10 illustrates the classification of reviewed studies based on the specific combinations of moderator groups they assess or consider. The analysis shows that the most common combination includes all four moderator groups (Dem-CTr-Cexp-SCE, 8 occurences). While this is an important observation, it is followed closely by studies focusing exclusively on a single moderator group, i.e., Demographics with 7 occurences. Notably, the Socio-cultural & Environmental Context group has been largely considered across the identified combinations, being combined with other groups in 20 studies and assessed as a stand-alone group in 3 studies, bringing the total representation of this group to 23 studies. This observation could be interpreted as contradictory to the findings stemming from Figure 9, but actually indicates that researchers increasingly acknowledge the broader environment as a variable affecting human vulnerability that should be considered in combination with other indicators.

20

A deeper examination of the internal composition of moderator group combinations was performed in a similar manner as for the vulnerability domains presented in the previous section. With regard to the latter observation about the inclusion of the Socio-cultural & Environmental Context group across 20 combinations, it is revealed that the inclusion of multiple moderator categories within a study does not necessarily correspond to a balanced representation of indicators from each group. Emphasis is often placed on easily measurable or commonly available indicators. For instance, studies incorporating all four moderator groups include a higher number of Demographic indicators, while indicators from the Sociocultural & Environmental Context group are more often than not limited to one or two aspects. Across other combinations, Cybersecurity Training indicators are most frequently represented by Awareness raising, which was anticipated based on Figure 9, while more specific indicators such as Certification (CTr-3) and training Frequency (CTr-4) are rarely included. The Experience with Cyber-incidents group is also selectively considered, most commonly through Defense Action adoption (Cexp-4) or prior Detection success/failure (Cexp-2), rather than through a broader representation of experiential dimensions. Overall, these patterns suggest that current approaches tend to be structurally inclusive but contextually shallow, in the sense that multiple moderator groups may be present, but their role in shaping vulnerability is not equally emphasized or systematically explored.

notable combinations include Gender and Awareness Raising (Dem-2-CTr-1), Awareness Raising and Formal Training (CTr1-CTr-2), and Gender and Education level (Dem-2-Dem-3). The frequent combination of Demographic indicators with Awareness Raising (CTr-1) and Formal Training (CTr-2) implies that training-related indicators are often evaluated in conjunction with user profiles, rather than as independent or context-sensitive elements. This observation highlights the tendency for moderator indicators to be employed for user categorization (e.g., age, gender, education), rather than to illustrate how contextual factors dynamically affect vulnerability within the broader operational environment of the user. These findings indicate that although moderator variables are widely recognized in the literature, their incorporation into HVA approaches remains mostly descriptive and user-focused, rather than contextually driven and system-oriented, which may hinder the capacity of existing approaches to effectively capture the influence of complex and evolving real-world conditions on vulnerability.

Fig. 11. Most appeared Combinations of Most Assessed or Considered Indicators

Fig. 10. Classification of Studies based on the combinations of Moderator Groups assessed or considered

This observation is further reinforced when delving deeper into the most appeared combinations of the most assessed or considered indicators presented in Figure 11, from which indicators of the SCE moderator group are completely absent as they are less frequently assessed, suggesting that comprehensive contextual modeling is not yet systematically adopted. The most common combination is Dem-1-Dem-2 (17 occurrences), representing a tendency to pair the Age and Gender indicators of the Demographics moderator group. This is followed by combinations of Age and Awareness Raising (Dem-1-CTr-1), and further demographic combinations. Other

3) Holisticness: An important finding of this SLR refers to the holisticness ratio of the proposed HVA solutions across the reviewed studies. Holisticness is interpreted as the breadth of vulnerability-related dimensions considered by a proposed HVA solution, including both human factors and moderator indicators, as depicted in Figure 12. Based on the proposed taxonomy, a holistic approach could include up to 46 variables in total, incorporating both the 25 identified human factors and the 21 identified moderator indicators. As revealed by the quantitative analysis evaluating human factor and indicator coverage, only a limited number of studies has considered a broad range of variables across multiple vulnerability domains and moderator groups. Particularly, the highest number of combined variables identified in a single study was 26 out of the 46 possible variables, resulting to a holisticness ratio of approximately 56.5%, indicating that even the study with the highest holisticness ratio still considers slightly more than half of the potential vulnerabilityrelated dimensions and contextual indicators considered in this review. In addition, it is revealed that the holisticness ratio does not correspond to balanced representations of factors and indicators. Holisticness has been considered mostly with regard to breadth rather than depth, which remains limited as

21

Fig. 12. Comparative Analysis of Considered Human Factors & Indicators across Studies

anticipated by the analysis provided above. Behavioral and cognitive factors are dominating assessment approaches with regard to human factors while contextual moderator variables and dynamic conditions, such as socio-cultural dimensions, remain underrepresented even among the studies with the highest holisticness ratios. Overall, the findings can be considered rather on the optimistic side, as they suggest that current HVA approaches acknowledge the multi-facet nature of human vulnerability and investigate assessment approaches that aim to account for more than one dimension. Nevertheless, this holisticness remains structurally imbalanced. 4) Threat Relevance: Another important finding of this SLR stems from the the classification of the included studies according to the Threat Type addressed by the methods, models, and instruments they propose, presented in Figure 13. As illustrated, the majority of the studies (62%) address solely vulnerabilities that may lead to Unintentional Threats, while fewer than half of them (30%) address vulnerabilities relevant to Intentional Threats. It is important to note that, despite the recognition of human factors and moderator indicators across the literature that are indicative of potential malicious behavior, only 8% of the proposed solutions address both Unintentional and Intentional Threats. This highlights an important gap in current methodologies and implementations and a significant limitation that needs to be considered for moving towards the development of holistic solutions that realise that humans may threaten systems and data both accidentally and deliberately.

Furthermore, Figures 14, 15, and 16 provide additional information regarding the human factors and indicators that dominate the assessment with regard to the threat type addressed. Because the number of studies differs across the three threat categories, the interpretation of these figures considers both absolute occurrences and relative prevalence within each category. Within this context, a clear pattern emerges as, across all three classifications, the Security Risk Behavior factor holds the highest rank with the most occurences in suggested approaches, independently of whether the assessed threats are intentional, unintentional, or both.

Fig. 14. Most considered Human Factors + Indicators for Studies addressing Unintentional Threats (U)

Fig. 13. Threat Type Classification of Studies

In studies addressing unintentional threats, cognitive factors are given particular focus with Cybersecurity Awareness, Risk & Protection Appraisal, and Security / Privacy Perception occuring often across assessments, alongside moderator indicators related to Awareness Raising, Formal Training, Age, and Gender. This suggests a strong tendency to conceptualize unintentional vulnerability primarily through insufficient aware-

22

ness, limited security understanding, or inadequate decisionmaking processes during interaction with digital systems. In contrast, studies addressing intentional threats demonstrate stronger emphasis on behavioral factors, in particular those associated with observable activity patterns, anomalyrelated behavior, and behavioral monitoring approaches. Even though psychological factors, such as Personality Traits, appear in fewer studies in absolute terms compared to the unintentional category, their relative prevalence remains notable. However, it is worth mentioning that across both threat types the consideration of Personality Traits is identified in around 1/3 of the reviewed studies. These observations suggest that intentional-threat-oriented approaches more frequently attempt to associate maliciousness tendency with deviant behavior and secondly with insiderrelated characteristics. At the same time, these studies showcase a focus on the Occupation indicator while incorporating comparatively fewer broader contextual or socio-cultural variables. This indicates that intentional maliciousness is often operationalized through behavioral deviation and user profiling rather than through deeper contextual, organizational, or environmental conditions that may dynamically influence intentional malicious cyber behavior.

indicator, a trend that is not present in studies focusing on a single threat category. However, because only four studies belong to this category, findings remain inconclusive. Overall, the comparison across threat categories indicates that the operationalization of vulnerability varies depending on the type of cyber threat addressed. However, despite these differences, the literature consistently prioritizes observable behavior while broader contextual, environmental, and sociocultural conditions as well as deeper psychological mechanisms remain underrepresented across all threat categories.

Fig. 16. Most considered Human Factors + Indicators for Studies addressing both Unintentional & Intentional Threats (U-I)

Fig. 15. Most considered Human Factors + Indicators for Studies addressing Intentional Threats (I)

Studies addressing both intentional and unintentional threats simultaneously, although limited in number, demonstrate broader factor coverage in relative terms than studies focusing on a single threat category. In addtion, it is observed that psychological factors, such as Emotion and Feelings and Self Perception, seem to have been considered more often in studies trying to address vulnerabilities of both threat types compared to studies aiming to address only a single threat category. Furthrmore, Age surfaces as the most considered moderator

5) Assessment or Measurement Approaches: Regarding assessment or measurement approaches adopted across the reviewed studies, Figure 17 illustrates the distribution of proposed or utilized techniques. As depicted, the most common approach is hybrid methods, included in 11 studies, which indicates the interest to combine multiple techniques for the assessment or measurement of different human vulnerability factors in cybersecurity. This is followed by the self-reported (survey-based) approaches, with 10 studies, which remain frequently used, possibly due to their easy deployment and ability to gather user perceptions and behaviours. Analytical / quantitative models are also important, employed in 7 studies, which indicate efforts to standardize vulnerability assessment though measurable metrics and move beyond purely descriptive or perception-based assessment. Following this, behavioral observation / monitoring and machine learning-based approaches, within 6 studies, highlight a focus in data-driven and automated analysis of user behavior. Some approaches include experiment / simulationbased methods and conceptual / theoretical approaches, with 4 studies each, while only one of the reviewed studies considers

23

a gamified / interactive approach, indicating this method may be still emerging within the scope of HVA in cybersecurity. Considering the high number of hybrid approaches adopted across studies, Figure 18 provides information about the most appeared combinations. As illustrated, the most common combination is behavioral monitoring / analysis with survey-based methods, which have been identified in 4 studies and represent a preference to combine objective behavioral data with selfreported user insights. The second most common combination is survey-based approaches with experimental methods, which is described in 2 studies and indicates the need to complement subjective responses with controlled evaluation settings. The rest of the combinations appear only once, which suggests that there are diverse combinations but not frequently reused or yet fully explored across the literature.

approaches are also included. This suggests the need for formalization and theoretical support. On the other hand, experimental / simulation-based and behavioral observation / monitoring approaches are less frequent, indicating a possible decrease in their use as standalone approaches. Furthermore, other approaches, such as the expert-based / qualitative and gamified / interactive methods, have not been widely used or mentioned throughout the years, which suggests that they are still understudied.

Fig. 18. Most Appeared Combinations of Hybrid Assessment or Measurement Approaches

Fig. 17. Assessment or Measurement Approaches Proposed or Utilized

Figure 19 compares the distribution of assessment and measurement approaches over time. It should be noted that the search was applied to the period 2017-2025, therefore the studies identified in 2014 and 2015, both of which are surveybased, were excluded from this diagram as they do not represent the entire research activity of those years. As depicted, early research (2017-2019) shows a consistent use of behavioral observation / monitoring, experimental / simulationbased, and self-reported (survey-based) approaches. Moreover, 2018 is a diverse year where many approaches have been considered, including the first use of hybrid and machine learning-based methods. From 2020 and onwards, hybrid approaches become more common, indicating the need to combine multiple methodologies. Additionally, machine learning-based approaches have increased, which reflects the need for adoption of data-driven methods and a gradual shift toward behavior-centric and continuously observable assessment techniques. Self-reported (survey-based) approaches have decreased in recent years, but they are nevertheless included, which demonstrates their continued consideration, possibly due to their ease of use. In recent years (2023-2025), research is centred on analytical / quantitative models, while conceptual / theoretical

Overall, the figure showcases a shift from traditional, single-method approaches, such as surveys and experiments, to combined and data-driven approaches, such as hybrid, machine learning, and analytical methods. This reflects the need towards more complex and extensive measurement approaches in human vulnerability research in cybersecurity while highlighting that the field is still evolving conceptually and methodologically. 6) Human Vulnerability Propagation & Modelling: Several patterns were revealed across the reviewed studies with regard to vulnerability propagation and modelling as well as regarding the relationship between them, which is depicted in Figure 20. Among the studies that operationalize propagation mechanisms, the most common appoach appears to be intra-individual propagation, identified in more than half of the studies, indicating that the literature recognizes that human vulnerability factors should not be assessed in isolation from one another, as the materialization of one may indicate the presense, increase, or decrease of another. However, inter-individual propagation remains exceptionally rare, while systemic propagation appears only in a limited subset of studies and is concentrated primarily within insider-threat, socio-technical, enterprise, or critical-infrastructure-oriented research. Despite that, many studies still fall within the “None” propagation category, indicating that a sunstantial number of proposed HVA solutions, almost 1/3, still focus on an individual assessment level without investigating how vulnerabilities interact among individuals or propagate across socio-technical structures. In terms of modelling, it is also woth noting that even though dynamic approaches seem to be substantially more common than expected, they are still

24

seldomly combined with vulnerability propagation. This highlights a disproportionate evolution in the field, as on one hand vulnerability assessment strongly moves towards approaches that acknowledge that it may evolve over time, but on the other hand it remains fragmented with regard to its social or relational propagation indicating that such effect mechanisms remain underrepresented.

Fig. 19. Assessment or Measurement Approach Distribution Per Year

A deeper analysis reveals clear methodological distinctions across modelling categories: static approaches are strongly associated with psychometric instruments and self-reported survey-based methods, whereas dynamic approaches correlate primarily with behavioral monitoring, simulation environments, UEBA systems, anomaly detection, and machinelearning-based techniques. At the same time, multidimensionality does not necessarily imply propagation modelling, as several studies exhibit broad factor coverage while still lacking propagation mechanisms. In contrast, studies implementing multi-level propagation mechanisms tend to demonstrate comparatively richer conceptual structures overall, including broader factor coverage, larger moderator integration, and stronger socio-technical framing.

Fig. 20. Distribution of HVA Studies by Vulnerability Propagation and Modeling Type

C. Discussion: Trends, Gaps and Limitations The results of this SLR reflect a broader conceptual and methodological evolution in proposed HVA solutions in nearly the past decade. Early studies mostly addressed vulnerabilities related to unintentional threats considering cybersecurity awareness and psychometric constructs, focusing on static profiling and behavioral patterns through self-reported approaches that fall short in capturing actual behaviour under realistic operational conditions. Over the years, the literature started shifting towards identifying insider threats through UEBA systems, anomaly detection, and behavioral analysis based on machine learning approaches; however, without investigating the underlying vulnerability mechanisms that may indicate or affect the emergence of intentional threats. In parallel, behavioral monitoring has also been employed to oversee user actions continuously and at scale, but they provide limited visibility into internal cognitive, emotional, or psychological mechanisms. More recent research has attempted to address this gap through adaptive monitoring, context-aware systems, and continuous assessment approaches. This shift has also led to the emergence of hybrid vulnerability assessment or measurement methods combining behavioral observation with a narrow set of psychometric and contextual information. However, these approaches are still relatively rare, potentially due to higher complexity, privacy concerns, integration challenges, and dependence on continuous data collection. Even though evolution in the field showcases a significant recognition of the multi-facet and continuously changing nature of human vulnerability, vulnerability itself is still largely understood through detection of observable user patterns, i.e., when risky behavior has already manifested, and remains far from a holistic consideration of the entire spectrum of human factors and moderator indicators. In addition, the more complex, underlying mechanisms, influencing risky actions, policy violations, browsing activity, or anomalous behavior patterns, remain underrepresented even in modern systems that adopt multi-factor assessment approaches. Moreover, in the ever-changing nature of AI-driven environments, there is little to no element of Human-AI interaction in the studies reviewed. Cognitive vulnerabilities related to automation bias, overtrust in AI systems, cognitive offloading, and AI-mediated manipulation are yet to be included in HVA approaches that need to be adapted to the evolving technological landscape. At the same time, the parallel consideration of both unintentional and intentional threats has been identified in a limited number of studies, while in most cases assessment is approached through different methodologies that do not intersect, indicating that accidental human errors and deliberate malicious actions continue to be treated as different phenomena instead of patters that could arise from common human, organisational, and contextual conditions. Behavioral dimensions and, in some cases, cognitive constructs have dominated the literature whereas psychological, contextual, and performance-related dimensions seem to lack similar attention in recent approaches, rendering proactive vulnerability identification an area still requiring investigation. Meanwhile, the conceptualization of vulnerability itself con-

25

tinues to be treated as a static trait without explicitly modelling long term susceptibility trajectories, changing psychological states, adaptive vulnerability states, peer influence, trust chain effects, collaborative susceptibility, and collective vulnerability. One-time questionnaires, fixed behavioral baselines, and pre-defined risk indicators that consider the assessment of individuals in isolation have constituted the most commonly adopted methods over the years. While influence between and among human factors within a single individual has been long recognized and more recent approaches tend to shift towards continuous and adaptive monitoring, there is still a lack of comprehensive considerations of vulnerability propagation across individuals and systems. Primarily, focus has been on tracking behavioral streams or anomaly patterns rather than modeling human vulnerability as an evolving and propagating socio-technical phenomenon, even though many cyber threats, such as social engineering and insider threats, inherently involve relational, organizational, and socially propagating dynamics. This observation is further supported by the fact that socio-cultural and environmental moderator indicators are largely underrepresented in current HVA approaches. Such variables may be indicative of how susceptibility manifests and vulnerability spreads among individuals and envrironments as well as of the ways intentional threats emerge across sociotechnical systems. In summary, the findings of this review indicate that human vulnerability in cybersecurity is still addressed in a fragmented way, with different studies focusing on isolated aspects of a very complex phenomenon. Future research thus would benefit from a shift away from isolated behavioral observations to continuously adaptive, psychologically grounded, context-aware, longitudinal and socially informed assessment ecosystems that are able to model vulnerability not only as an observable outcome, but also as an evolving human and socio-technical process. VII. C ONCLUSION The aim of this study was to systematically review Human Vulnerability Assessment approaches in cybersecurity to investigate whether a single solution exists that considers the entire spectrum of human factors and additional variables affecting human vulnerability, related to the emergence of both unintentional and intentional threats while also considering vulnerability propagation mechanisms and continuous and dynamic vulnerability modelling. The paper synthesised the findings of 54 studies, from 2017 to 2025, across methods, models and assessment instruments and performed a quantitative and qualitive analysis to provide a comprehensive picture of the current landscape. In parallel, this study also proposed a structured Cybersecurity Human Factor Taxonomy classifying human vulnerability into the domains of Psychological, Cognitive, Behavioral, and Human Performance State, supported by moderating variable groups related to demographics, cybersecurity training, previous cyber incident experience, and socio-cultural and environmental context. Common combinations, methodological trends, levels of holisticness, and differences in approaches were identified and

delineated, indicating that the majority of current proposed HVA solutions is behavior-centric, where vulnerability is operationalized through users observable behavior, awareness factors, and anomaly detection. More complex psychological, contextual, relational, and dynamic aspects of vulnerability remain largely underrepresented. Although multidimensional and adaptive perspectives are increasingly adopted in the literature, most studies still consider vulnerability as a separate and relatively static individual attribute, rather than as a dynamic socio-technical phenomenon influenced by contextual factors, changes over time, and vulnerability propagation within and between individuals and systems. Impostantly, Human-AI interaction remains to be considered as a new and growing dimension of human vulnerability in the modern cybersecurity environment. Despite the valuable insights gained, this review does not come without limitations. The proposed taxonomy is based on the literature reviewed, where the pool of human factors and moderator indicators has been synthesized based on the various studies that have investigated human vulnerability within cybersecurity contexts. It has been leveraged as a classification framework, supporting the analysis of the 54 identified studies of this SLR, and would benefit from further investigations about human vulnerability to deception and threat strategies in a broader manner, across other scientific domains such as criminology and social sciences. Following this investigation, additional sub-factors, manifestations, or emergent dimensions beyond those identified in the current study, within each vulnerability domain and moderator group, may be revealed and the resulting updated taxonomy would need to be formally validated or evaluated by experts in various domains. Additionally, future research should focus on identifying relationships both through current literature and empirical research: i) among human factors to unravel internal effects that they have on each other, and ii) between moderator indicators and human factors to better understand how human vulnerability can be assessed and quantified in a realistic way. Vulnerability propagation should be further investigated as well, to identify how it can be conceptualized and operationalized at intra-individual, inter-individual, and systemic levels, especially in socio-technical settings where vulnerabilities may propagate or amplify each other over time. Based on the insights gained through this SLR, the ultimate goal is to move towards the design and development of a holistic, dynamic, continuous, and propagation-aware HVA framework, incorporating psychometric models, behavioral monitoring, contextual reasoning, adaptive assessment mechanisms, and continuous monitoring tools. It is important to acknowledge also that this direction would require further investigation into the privacy, ethical, and governance issues of continuous human vulnerability assessment and monitoring to ensure that sensitive data are safeguarded and assessed individuals are not stigmatized. R EFERENCES [1] A. Pollini, T. C. Callari, A. Tedeschi, D. Ruscio, L. Save, F. Chiarugi, and D. Guerri, “Leveraging human factors in cybersecurity: an inte-

26

grated methodological approach,” Cognition, Technology and Work, vol. 24, pp. 371–390, 5 2022. [2] T. Rahman, R. Rohan, D. Pal, and P. Kanthamanon, “Human factors in cybersecurity: A scoping review,” in ACM International Conference Proceeding Series. Association for Computing Machinery, 6 2021. [3] K. Amoresano and B. Yankson, “Human error - a critical contributing factor to the rise in data breaches: A case study of higher education,” HOLISTICA – Journal of Business and Public Administration, vol. 14, pp. 110–132, 6 2023. [4] J. R. Nurse, O. Buckley, P. A. Legg, M. Goldsmith, S. Creese, G. R. Wright, and M. Whitty, “Understanding insider threat: A framework for characterising attacks,” in Proceedings - IEEE Symposium on Security and Privacy, vol. 2014-January. Institute of Electrical and Electronics Engineers Inc., 11 2014, pp. 214–228. [5] Z. M. King, D. S. Henshel, L. Flora, M. G. Cains, B. Hoffman, and C. Sample, “Characterizing and measuring maliciousness for cybersecurity risk assessment,” 2 2018. [6] B. Haim, E. Menahem, Y. Wolfsthal, and C. Meenan, “Visualizing insider threats: An effective interface for security analytics,” in International Conference on Intelligent User Interfaces, Proceedings IUI. Association for Computing Machinery, 3 2017, pp. 39–42. [7] D. Papatsaroucha, Y. Nikoloudakis, I. Kefaloukos, E. Pallis, and E. K. Markakis, “A survey on human and personality vulnerability assessment in cyber-security: Challenges, approaches, and open issues,” 2021. [Online]. Available: https://arxiv.org/abs/2106.09986 [8] K. Parsons, A. McCormac, M. Butavicius, M. Pattinson, and C. Jerram, “Determining employee awareness using the human aspects of information security questionnaire (hais-q),” Computers and Security, vol. 42, pp. 165–176, 2014. [9] S. Egelman and E. Peer, “Scaling the security wall : Developing a security behavior intentions scale (sebis),” in Conference on Human Factors in Computing Systems - Proceedings, vol. 2015-April. Association for Computing Machinery, 4 2015, pp. 2873–2882. [10] A. Cullen and L. Armitage, “A human vulnerability assessment methodology,” in Proceedings of the 2018 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA). IEEE, 2018. [11] E. Miehling, B. Xiao, R. Poovendran, and T. Başar, “A bayesian multi-armed bandit approach for identifying human vulnerabilities,” in Decision and Game Theory for Security, L. Bushnell, R. Poovendran, and T. Başar, Eds. Springer International Publishing, 2018, pp. 521– 539. [12] M. Alohali, N. Clarke, and S. Furnell, “The design and evaluation of a user-centric information security risk assessment and response framework,” International Journal of Advanced Computer Science and Applications (IJACSA), vol. 9, no. 10, 2018. [Online]. Available: www.ijacsa.thesai.org [13] Z. S. Malek, B. Trivedi, and A. Shah, “User behavior pattern -signature based intrusion detection,” in 2020 Fourth World Conference on Smart Trends in Systems, Security and Sustainability (WorldS4), 2020, pp. 549–552. [14] P. Perrotin, N. Belloir, S. Sadou, D. Hairion, and A. Beugnard, “Hos-ml: Socio-technical system adl dedicated to human vulnerability identification,” in Proceedings of the IEEE International Conference on Engineering of Complex Computer Systems, ICECCS, vol. 2022March. Institute of Electrical and Electronics Engineers Inc., 2022, pp. 11–16. [15] M. J. Page, J. E. McKenzie, P. M. Bossuyt, I. Boutron, T. C. Hoffmann, C. D. Mulrow, L. Shamseer, J. M. Tetzlaff, E. A. Akl, S. E. Brennan, R. Chou, J. Glanville, J. M. Grimshaw, A. Hróbjartsson, M. M. Lalu, T. Li, E. W. Loder, E. Mayo-Wilson, S. McDonald, L. A. McGuinness, L. A. Stewart, J. Thomas, A. C. Tricco, V. A. Welch, P. Whiting, and D. Moher, “The prisma 2020 statement: An updated guideline for reporting systematic reviews,” 3 2021. [16] K. Kannelønning and S. K. Katsikas, “A systematic literature review of how cybersecurity-related behavior has been assessed,” pp. 463–477, 10 2023. [17] R. Rohan, D. Pal, J. Hautamäki, S. Funilkul, W. Chutimaskul, and H. Thapliyal, “A systematic literature review of cybersecurity scales assessing information security awareness,” Heliyon, vol. 9, 3 2023. [18] A. Abuiteiwi and S. Escobar, “Evaluating the human factor in cybersecurity threats (a systematic literature review),” Polytechnic University of Valencia, Tech. Rep., 2025. [Online]. Available: https://ssrn.com/abstract=5465433 [19] D. Arévalo, D. Valarezo, W. Fuertes, M. F. Cazares, R. O. Andrade, and M. MacAs, “Human and cognitive factors involved in phishing detection. a literature review,” in Proceedings - 2023 Congress in

Computer Science, Computer Engineering, and Applied Computing, CSCE 2023. Institute of Electrical and Electronics Engineers Inc., 2023, pp. 608–614. [20] M. S. Tsauri, “Human vulnerabilities to social engineering attacks: A systematic literature review for building a human firewall,” Journal of Applied Informatics and Computing (JAIC), vol. 9, no. 4, 2025. [Online]. Available: http://jurnal.polibatam.ac.id/index.php/JAIC [21] R. Jabir, J. Le, and C. Nguyen, “Phishing attacks in the age of generative artificial intelligence: A systematic review of human factors,” 8 2025. [22] A. Almansoori, M. Al-Emran, and K. Shaalan, “Exploring the frontiers of cybersecurity behavior: A systematic review of studies and theories,” 5 2023. [23] R. A. Alsharida, B. A. S. Al-rimy, M. Al-Emran, and A. Zainal, “A systematic review of multi perspectives on human cybersecurity behavior,” Technology in Society, vol. 73, 5 2023. [24] P. Kuppusamy, G. N. Samy, N. Maarop, B. Shanmugam, and S. Perumal, “Information security policy compliance behavior models, theories, and influencing factors: A systematic literature review,” Journal of Theoretical and Applied Information Technology, vol. 15, p. 2022, 2022. [Online]. Available: www.jatit.org [25] N. Borgert, L. Jansen, I. Böse, J. Friedauer, M. A. Sasse, and M. Elson, “Self-eficacy and security behavior: Results from a systematic review of research methods,” in Conference on Human Factors in Computing Systems - Proceedings. Association for Computing Machinery, 5 2024. [26] W. Abdallah, “A systematic literature review : Human factor as insider threat in organizations,” Al Quds Open University, Palestine, Research Article/Report, 2023. [Online]. Available: https: //google.academia.edu/JournalofComputerScience [27] N. Pathirana, R. Roberts, H. Kalutarage, and C. D. McDermott, “Integrating human factors into insider threat detection – a systematic review,” ACM Computing Surveys, vol. 58, pp. 1–37, 7 2026. [Online]. Available: https://dl.acm.org/doi/10.1145/3798089 [28] M. Nizamuddin, “Investigating the cybersecurity risks of remote work: a systematic literature review of organizational vulnerabilities and mitigation strategies,” International Journal of Information Security, vol. 24, 8 2025. [29] S. Nifakos, K. Chandramouli, C. K. Nikolaou, P. Papachristou, S. Koch, E. Panaousis, and S. Bonacina, “Influence of human factors on cyber security within healthcare organisations: A systematic review,” 8 2021. [30] K. Bissadu, G. Hossain, L. P. Velagala, and S. Sonko, “Analyzing insider cyber threats and human factors within the framework of agriculture 5.0,” in 12th International Symposium on Digital Forensics and Security, ISDFS 2024. Institute of Electrical and Electronics Engineers Inc., 2024. [31] B. K. Sedraoui, A. Benmachiche, A. Makhlouf, and C. Chemam, “Intrusion detection with deep learning: A literature review,” in PAIS 2024 - Proceedings: 6th International Conference on Pattern Analysis and Intelligent Systems. Institute of Electrical and Electronics Engineers Inc., 2024. [32] P. Manoharan, J. Yin, H. Wang, Y. Zhang, and W. Ye, “Insider threat detection: A review,” in Proceedings - 2024 International Conference on Networking and Network Applications, NaNA 2024. Institute of Electrical and Electronics Engineers Inc., 2024, pp. 147–153. [33] A. Abzakh and A. Althunibat, “A review: Human factor and cybersecurity,” in 2023 International Conference on Information Technology: Cybersecurity Challenges for Sustainable Cities, ICIT 2023 - Proceeding. Institute of Electrical and Electronics Engineers Inc., 2023, pp. 589–592. [34] R. Rohan, S. Funilkul, D. Pal, and W. Chutimaskul, “Understanding of human factors in cybersecurity: A systematic literature review,” in 2021 International Conference on Computational Performance Evaluation, ComPE 2021. Institute of Electrical and Electronics Engineers Inc., 2021, pp. 133–140. [35] F. Masimba, F. Gumbo, and T. Zuva, “Deciphering the influence of human behavior on cybersecurity risks: An in-depth review of amplification and mitigation factors,” in 2025 5th International Multidisciplinary Information Technology and Engineering Conference (IMITEC). IEEE, 11 2025, pp. 1–6. [Online]. Available: https: //ieeexplore.ieee.org/document/11410469/ [36] A. Oltramari, D. Henshel, M. Cains, and B. Hoffman, “Towards a human factors ontology for cyber security,” in Proceedings of the International Workshop on Semantic Technology for Intelligence, Defense, and Security (STIDS), ser. CEUR Workshop Proceedings. CEUR-WS.org, 2015. [Online]. Available: https://ceur-ws.org/

27

[37] K. Khadka and A. B. Ullah, “Human factors in cybersecurity: an interdisciplinary review and framework proposal,” International Journal of Information Security, vol. 24, 6 2025. [38] J. Jeong, J. Mihelcic, G. Oliver, and C. Rudolph, “Towards an improved understanding of human factors in cybersecurity,” in Proceedings 2019 IEEE 5th International Conference on Collaboration and Internet Computing, CIC 2019. Institute of Electrical and Electronics Engineers Inc., 12 2019, pp. 338–345. [39] D. Henshel, M. G. Cains, B. Hoffman, and T. Kelley, “Trust as a human factor in holistic cyber security risk assessment,” in Procedia Manufacturing, vol. 3. Elsevier B.V., 2015, pp. 1117–1124. [40] D. Henshel, C. Sample, M. Cains, and B. Hoffman, “Integrating cultural factors into human factors framework and ontology for cyber attackers,” in Advances in Intelligent Systems and Computing, vol. 501. Springer Verlag, 2016, pp. 123–136. [41] I. Arend, A. Shabtai, T. Idan, R. Keinan, and Y. Bereby-Meyer, “Passive- and not active-risk tendencies predict cyber security behavior,” Computers and Security, vol. 96, 9 2020. [42] E. D. Frauenstein and S. Flowerday, “Susceptibility to phishing on social network sites: A personality information processing model,” Computers and Security, vol. 94, 7 2020. [43] M. Ovelgönne, T. Dumitras, B. A. Prakash, V. S. Subrahmanian, and B. Wang, “Understanding the relationship between human behavior and susceptibility to cyber attacks: A data-driven approach,” ACM Transactions on Intelligent Systems and Technology, vol. 8, 2 2017. [44] T. Whalen and C. Gates, “A psychological profile of defender personality traits,” in Proceedings of the 2007 New Security Paradigms Workshop (NSPW). ACM, 2007. [Online]. Available: https://dl.acm.org/doi/10.1145/1600110.1600125 [45] S. M. Albladi and G. R. Weir, “User characteristics that influence judgment of social engineering attacks in social networks,” Humancentric Computing and Information Sciences, vol. 8, 12 2018. [46] Z. Yan, T. Robertson, R. Yan, S. Y. Park, S. Bordoff, Q. Chen, and E. Sprissler, “Finding the weakest links in the weakest link: How well do undergraduate students make cybersecurity judgment?” Computers in Human Behavior, vol. 84, pp. 375–382, 7 2018. [47] M. Anwar, W. He, I. Ash, X. Yuan, L. Li, and L. Xu, “Gender difference and employees’ cybersecurity behaviors,” Computers in Human Behavior, vol. 69, pp. 437–443, 4 2017. [48] T. R. McEvoy and S. J. Kowalski, “Deriving cyber security risks from human and organizational factors – a socio-technical approach,” Complex Systems Informatics and Modeling Quarterly, vol. 2019, pp. 47–64, 2019. [49] R. Orji, A. M. Abdullahi, and K. Oyibo, “Personalizing persuasive technologies: Do gender and age affect susceptibility to persuasive strategies?” in UMAP 2018 - Adjunct Publication of the 26th Conference on User Modeling, Adaptation and Personalization. Association for Computing Machinery, Inc, 7 2018, pp. 329–334. [50] S. Mamonov and R. Benbunan-Fich, “The impact of information security threat awareness on privacy-protective behaviors,” Computers in Human Behavior, vol. 83, pp. 32–44, 6 2018. [51] A. Wiley, A. McCormac, and D. Calic, “More than the individual: Examining the relationship between culture and information security awareness,” Computers and Security, vol. 88, 1 2020. [52] N. C. Ebner, D. M. Ellis, T. Lin, H. A. Rocha, H. Yang, S. Dommaraju, A. Soliman, D. L. Woodard, G. R. Turner, R. N. Spreng, and D. S. Oliveira, “Uncovering susceptibility risk to online deception in aging,” Journals of Gerontology - Series B Psychological Sciences and Social Sciences, vol. 75, pp. 522–533, 2 2020. [53] R. Chen, J. Gaia, and H. R. Rao, “An examination of the effect of recent phishing encounters on phishing susceptibility,” Decision Support Systems, vol. 133, 6 2020. [54] R. C. Nickerson, U. Varshney, and J. Muntermann, “A method for taxonomy development and its application in information systems,” European Journal of Information Systems, vol. 22, pp. 336–359, 2013. [55] A. Bandura, “Social cognitive theory of personality,” The coherence of personality: Social-cognitive bases of consistency, variability, and organization, pp. 185–241, 1999. [56] A. Jurevičienė, A. Brilingaitė, and L. Bukauskas, “Digital human in cybersecurity risk assessment,” in Augmented Cognition, D. D. Schmorrow and C. M. Fidopiastis, Eds. Springer International Publishing, 2021, pp. 418–432. [57] G. Romeo and D. Conti, “Exploring automation bias in human–ai collaboration: a review and implications for explainable ai,” AI and Society, 1 2025.

[58] J. Tilbury, S. Flowerday, G. Bott, Y. T. Chua, E. Olson, and B. Foltz, “Human-factor vulnerabilities of automation in socs: A mixed-methods multigroup analysis,” Computers and Security, vol. 166, 7 2026. [59] S. A. Teo, “Artificial intelligence, human vulnerability and multilevel resilience,” Computer Law & Security Review, vol. 57, p. 106134, 2025. [Online]. Available: https://www.sciencedirect.com/ science/article/pii/S2212473X25000070 [60] Z. Wang, H. Zhu, and L. Sun, “Social engineering in cybersecurity: Effect mechanisms, human vulnerabilities and attack methods,” IEEE Access, vol. 9, pp. 11 895–11 910, 2021. [61] K. Parsons, M. Butavicius, P. Delfabbro, and M. Lillie, “Predicting susceptibility to social influence in phishing emails,” International Journal of Human Computer Studies, vol. 128, pp. 17–26, 8 2019. [62] R. Taib, K. Yu, S. Berkovsky, M. Wiggins, and P. Bayl-Smith, “Social engineering and organisational dependencies in phishing attacks,” in Human-Computer Interaction – INTERACT 2019, D. Lamas, F. Loizides, L. Nacke, H. Petrie, M. Winckler, and P. Zaphiris, Eds. Springer International Publishing, 2019, pp. 564–584. [63] A. Sumner, X. Yuan, M. Anwar, and M. McBride, “Examining factors impacting the effectiveness of anti-phishing trainings,” Journal of Computer Information Systems, vol. 62, pp. 975–997, 2022. [64] T. Cuchta, B. Blackwood, T. R. Devine, R. J. Niichel, K. M. Daniels, C. H. Lutjens, S. Maibach, and R. J. Stephenson, “Human risk factors in cybersecurity,” in SIGITE 2019 - Proceedings of the 20th Annual Conference on Information Technology Education. Association for Computing Machinery, Inc, 9 2019, pp. 87–92. [65] V. Linkov, P. Zámecnı́k, D. Havlı́cková, and C. W. Pai, “Human factors in the cybersecurity of autonomous vehicles: Trends in current research,” 2019. [66] V. Shakela and H. Jazri, “Assessment of spear phishing user experience and awareness: An evaluation framework model of spear phishing exposure level (spel) in the namibian financial industry,” in 2019 International Conference on Advances in Big Data, Computing and Data Communication Systems (icABCD), 2019, pp. 1–5. [67] L. Jaeger and A. Eckhardt, “Eyes wide open: The role of situational information security awareness for security-related behaviour,” Information Systems Journal, vol. 31, pp. 429–472, 5 2021. [68] S. Uebelacker and S. Quiel, “The social engineering personality framework,” in Proceedings - 4th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2014 - Co-located with 27th IEEE Computer Security Foundations Symposium, CSF 2014 in the Vienna Summer of Logic 2014. Institute of Electrical and Electronics Engineers Inc., 12 2014, pp. 24–30. [69] S. R. Curtis, P. Rajivan, D. N. Jones, and C. Gonzalez, “Phishing attempts among the dark triad: Patterns of attack and vulnerability,” Computers in Human Behavior, vol. 87, pp. 174–182, 10 2018. [70] J. H. Cho, H. Cam, and A. Oltramari, “Effect of personality traits on trust and risk to phishing vulnerability: Modeling and analysis,” in 2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support, CogSIMA 2016. Institute of Electrical and Electronics Engineers Inc., 6 2016, pp. 7–13. [71] N. H. Chowdhury, M. T. Adam, and T. Teubner, “Time pressure in human cybersecurity behavior: Theoretical framework and countermeasures,” Computers and Security, vol. 97, 10 2020. [72] M. N. AL-Nuaimi, “Human and contextual factors influencing cybersecurity in organizations, and implications for higher education institutions: a systematic review,” pp. 1–23, 1 2024. [73] A. R. Gillam and W. T. Foster, “Factors affecting risky cybersecurity behaviors by u.s. workers: An exploratory study,” Computers in Human Behavior, vol. 108, 7 2020. [74] L. Hadlington, “Human factors in cybersecurity; examining the link between internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours,” Heliyon, vol. 3, no. 7, p. e00346, 2017. [75] M. Corbett, “From law to folklore: Work stress and the yerkes-dodson law,” Journal of Managerial Psychology, vol. 30, pp. 741–752, 8 2015. [76] M. Alsharif, S. Mishra, and M. AlShehri, “Impact of human vulnerabilities on cybersecurity,” Computer Systems Science and Engineering, vol. 40, pp. 1153–1166, 9 2021. [77] B. Hanus, Y. A. Wu, and J. Parrish, “Phish me, phish me not,” Journal of Computer Information Systems, vol. 62, pp. 516–526, 2022. [78] T. Sharma and M. Bashir, “An analysis of phishing emails and how the human vulnerabilities are exploited,” in Advances in Human Factors in Cybersecurity, I. Corradini, E. Nardelli, and T. Ahram, Eds. Springer International Publishing, 2020, pp. 49–55. [79] A. H. Asfoor, F. A. Rahim, and S. Yussof, “Identifying factors that influence security behaviors relating to phishing attacks susceptibility:

28

A systematic literature review,” Journal of Theoretical and Applied [100] S. Omotoye and W. Chen, “Development of a comprehensive framework for detecting insider threats,” in ICT for Intelligent Systems, Information Technology, vol. 15, p. 15, 2020. [Online]. Available: www.jatit.org J. Choudrie, E. Tuba, T. Perumal, and A. Joshi, Eds. Springer Nature [80] F. Mwagwabi, T. McGill, and M. Dixon, “Short-term and long-term Singapore, 2026, pp. 379–389. effects of fear appeals in improving compliance with password guide[101] M. Li and A. Nehme, “Navigating information security communication lines,” Communications of the Association for Information Systems, fatigue: Understanding its impact on employee policy noncompliance,” vol. 42, pp. 147–182, 2 2018. in Proceedings of the 30th Americas Conference on Information [81] H. Liang and Y. Xue, “Understanding security behaviors in personal Systems (AMCIS 2024). Association for Information Systems (AIS), computer usage: A threat avoidance perspective,” Journal of the Asso2024. [Online]. Available: https://aisel.aisnet.org/amcis2024 ciation for Information Systems, vol. 11, pp. 394–413, 2010. [102] E. Shihepo, F. Bhunu-Shava, and M. Chitauro, “Designing a real[82] S. R. Boss, D. F. Galletta, P. B. Lowry, G. D. Moody, and time bring your own device security awareness model for mobile P. Polak, “What do systems users have to fear? using fear appeals to device users within namibian enterprises,” in 2023 6th International engender threats and fear that motivate protective security behaviors1,” Conference on Information Systems and Computer Networks, ISCON Management Information Systems Quarterly, vol. 39, pp. 837–864, 12 2023. Institute of Electrical and Electronics Engineers Inc., 2023. 2015. [Online]. Available: https://doi.org/10.25300/MISQ/2015/39.4.5 [103] S. Chaipa, E. K. Ngassam, and S. Singh, “Towards a new insider threat [83] A. Alturki, N. Alshwihi, and A. Algarni, “Factors influencing players’ mitigation framework,” in 2023 IST-Africa Conference (IST-Africa), susceptibility to social engineering in social gaming networks,” IEEE 2023, pp. 1–11. Access, vol. 8, pp. 97 383–97 391, 2020. [104] K.-B. Kim, E. Lim, and H.-Y. Kwon, “Processing model and classifica[84] L. D. Kimpe, M. Walrave, P. Verdegem, and K. Ponnet, “What we tion of cybercognitive attacks: Based on cognitive psychology,” IEEE think we know about cybersecurity: an investigation of the relationship Access, vol. 11, pp. 141 517–141 528, 2023. between perceived knowledge, internet trust, and protection motivation [105] S. Mitra, Q. Zhang, C. W. Chang, H. Salemi, H. Purohit, F. Zhang, in a cybercrime context,” Behaviour and Information Technology, M. Hong, C. T. Lu, and J. H. Cho, “Towards inclusive cybersecurity: vol. 41, pp. 1796–1808, 2022. Protecting the vulnerable with social cyber vulnerability metrics,” [85] E. U. Weber, A. R. Blais, and N. E. Betz, “A domain-specific riskin Proceedings - 2024 IEEE 6th International Conference on Trust, attitude scale: Measuring risk perceptions and risk behaviors,” Journal Privacy and Security in Intelligent Systems, and Applications, TPS-ISA of Behavioral Decision Making, vol. 15, pp. 263–290, 2002. 2024. Institute of Electrical and Electronics Engineers Inc., 2024, pp. [86] S. M. Kennison and E. Chan-Tin, “Taking risks with cybersecurity: 442–445. Using knowledge and personal characteristics to predict self-reported [106] J. McHatton and K. Ghazinour, “Mitigating social media privacy cybersecurity behaviors,” Frontiers in Psychology, vol. 11, 11 2020. concerns-a comprehensive study,” in IWSPA 2023 - Proceedings of the [87] M. Gratian, S. Bandi, M. Cukier, J. Dykstra, and A. Ginther, “Corre9th ACM International Workshop on Security and Privacy Analytics. lating human traits and cyber security behavior intentions,” Computers Association for Computing Machinery, Inc, 4 2023, pp. 27–32. and Security, vol. 73, pp. 345–358, 3 2018. [107] J. Barath, M. Harakal, M. Bencik, M. Dulik, and M. Revay, “Measuring [88] Y. Gangire, A. D. Veiga, and M. Herselman, A conceptual model of inan individual’s level of personal cyber security,” in 2025 Communicaformation security compliant behaviour based on the self-determination tion and Information Technologies Conference Proceedings, KIT 2025 theory. IEEE, 2019. - 13th International Scientific Conference. Institute of Electrical and [89] B. A. Gyunka and A. O. Christiana, “Analysis of human Electronics Engineers Inc., 2025. factors in cyber security: A case study of anonymous [108] M. Antunes, C. Silva, and F. Marques, “An integrated cybernetic attack on hbgary,” International Journal of Cyber-Security awareness strategy to assess cybersecurity attitudes and behaviours in and Digital Forensics (IJCSDF), vol. 6, no. 4, pp. 364– school context,” Applied Sciences (Switzerland), vol. 11, 12 2021. 373, 2017. [Online]. Available: https://sdiwc.net/digital-library/ [109] A. Reeves, P. Delfabbro, and D. Calic, “Encouraging employee engageanalysis-human-factors-cyber-security-case-study-anonymous-attack-hbgary ment with cybersecurity: How to tackle cyber fatigue,” SAGE Open, [90] E. Kadena and M. Gupi, “Human factors in cybersecurity: Risks and vol. 11, 2021. impacts,” Security science journal, vol. 2, pp. 51–64, 12 2021. [110] V. Feyzov, “Scenario approach to countering mail phishing attacks [91] L. N. Zlatolas, T. Welzer, M. Hölbl, M. Heričko, and A. Kamišalić, in the business sphere,” in Proceedings of 2023 16th International “A model of perception of privacy, trust, and self- disclosure on online Conference Management of Large-Scale System Development, MLSD social networks,” Entropy, vol. 21, 2019. 2023. Institute of Electrical and Electronics Engineers Inc., 2023. [92] H. J. Parker and S. V. Flowerday, “Contributing factors to increased [111] S. Eftimie, R. Moinescu, and C. Rǎcuciu, “Insider threat detection susceptibility to social media phishing attacks,” South African Journal using natural language processing and personality profiles,” in 2020 of Information Management, vol. 22, no. 1, pp. 1–11, 2020. [Online]. 13th International Conference on Communications (COMM), 2020, pp. Available: http://www.sajim.co.za 325–330. [93] T. McGill and N. Thompson, “Gender differences in information [112] F. Yuan, Y. Cao, Y. Shang, Y. Liu, J. Tan, and B. Fang, “Insider security perceptions and behaviour,” Information & Computer Security, threat detection with deep neural network,” in Computational Science vol. 26, no. 2, pp. 237–249, 2018. – ICCS 2018, Y. Shi, H. Fu, Y. Tian, V. V. Krzhizhanovskaya, M. H. [94] H. Abroshan, J. Devos, G. Poels, and E. Laermans, “Covid-19 and Lees, J. Dongarra, and P. M. A. Sloot, Eds. Springer International phishing: Effects of human emotions, behavior, and demographics on Publishing, 2018, pp. 43–54. the success of phishing attempts during the pandemic,” IEEE Access, [113] B. Sharma, P. Pokharel, and B. Joshi, “User behavior analytics for vol. 9, pp. 121 916–121 929, 2021. anomaly detection using lstm autoencoder-insider threat detection,” in [95] D. Ariu, E. Frumento, and G. Fumera, “Social engineering 2.0: A ACM International Conference Proceeding Series. Association for foundational work,” in ACM International Conference on Computing Computing Machinery, 7 2020. Frontiers 2017, CF 2017. Association for Computing Machinery, Inc, [114] J. Kim, M. Park, H. Kim, S. Cho, and P. Kang, “Insider threat detection 5 2017, pp. 319–325. based on user behavior modeling and anomaly detection algorithms,” [96] F. R. Abubaker and P. S. Boluk, “An intelligent model for vulnerability Applied Sciences (Switzerland), vol. 9, 10 2019. analysis of social media user,” in Proceedings - 2016 4th International [115] Y. Pan, “Network security and user abnormal behavior detection by Conference on Future Internet of Things and Cloud Workshops, Wusing deep neural network,” Internet Technology Letters, vol. 4, 5 2021. FiCloud 2016. Institute of Electrical and Electronics Engineers Inc., [116] H. Zhu and R. Gan, “Implementation system of network user abnormal 10 2016, pp. 258–263. behavior detection algorithm based on data layering,” in Proceedings [97] N. Akdemir and S. Yenal, “How phishers exploit the coronavirus of the 5th International Conference on I-SMAC (IoT in Social, Mobile, pandemic: A content analysis of covid-19 themed phishing emails,” Analytics and Cloud), I-SMAC 2021. Institute of Electrical and SAGE Open, vol. 11, 2021. Electronics Engineers Inc., 2021, pp. 1400–1403. [98] Y. Luo, A. Yazdanmehr, and N. Kumar, “An integrative model of [117] N. Dixit, R. Gupta, and P. Yadav, “User behavior analysis to detect inphishing susceptibility,” Computers & Security, vol. 149, p. 104164, sider threat by using machine learning algorithms,” in 4th International 2025. [Online]. Available: https://doi.org/10.1016/j.cose.2024.104164 Conference on Innovative Practices in Technology and Management [99] A. Girma and M. Tamirat, ““the impact of personality on cyberthreat 2024, ICIPTM 2024. Institute of Electrical and Electronics Engineers perception and mitigation”: An integrating behavioral insights by Inc., 2024. promoting a more comprehensive, human-oriented approach to threat identification and management,” in Intelligent Systems Conference. [118] S. A. Duman, R. Hayran, and I. Sogukpinar, “Impact analysis and Springer, 2025, pp. 695–707. performance model of social engineering techniques,” in ISDFS 2023

29

- 11th International Symposium on Digital Forensics and Security. Institute of Electrical and Electronics Engineers Inc., 2023. [119] S. A. Duman, A. Duman, R. Hayran, and I. Sogukpinar, “A multi-layer model of psychological factors and parametric approaches for humancentric phishing prevention,” in ISDFS 2025 - 13th International Symposium on Digital Forensics and Security. Institute of Electrical and Electronics Engineers Inc., 2025. [120] W. M. Wijesinghe, Y. P. Abeysinghe, M. A. Rukshana, A. M. Adhikari, K. Y. Abeywardhana, and D. Siriwardhana, “Polymorphic security enhancements for corporate environments utilizing behavior analytics,” in 2024 International Conference on Computer and Applications, ICCA 2024. Institute of Electrical and Electronics Engineers Inc., 2024. [121] G. E. Mocerino, C. Velotti, D. Gentile, L. Gallo, A. Botta, and G. Ventre, “Work in progress: Implicit association tests for understanding human factor in phishing beyond awareness,” in Proceedings - 9th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2024. Institute of Electrical and Electronics Engineers Inc., 2024, pp. 519–526. [122] N. Adnan, W. F. W. Fauzi, S. N. H. S. Abdullah, and S. Liu, “Human e-commerce protection module using fuzzy-set qualitative comparative analysis (fsQCA),” in Proceedings of the 2025 3rd International Conference on Cyber Resilience (ICCR). Institute of Electrical and Electronics Engineers (IEEE), 7 2025, pp. 1–7. [123] R. R and S. Babu, “Anomaly detection using user entity behavior analytics and data visualization,” in 2021 8th International Conference on Computing for Sustainable Global Development (INDIACom), 2021, pp. 842–847. [124] W. Jiang, Y. Tian, W. Liu, and W. Liu, “An insider threat detection method based on user behavior analysis,” in Intelligent Information Processing IX, Z. Shi, E. Mercier-Laurent, and J. Li, Eds. Springer International Publishing, 2018, pp. 421–429. [125] L. Astakhova and N. Muravyov, “A data collection and analysis system for managing the vulnerabilities of users of an information system in a small business,” in 2019 Ural Symposium on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT), 2019, pp. 193–196. [126] K. E. H. A. Alhosani, S. K. A. Khalid, N. A. Samsudin, S. Jamel, and K. M. b. Mohamad, “A policy driven, human oriented information security model: a case study in uae banking sector,” in 2019 IEEE Conference on Application, Information and Network Security (AINS), 2019, pp. 12–17. [127] B. Pacheco and N. Escravana, “Dogana: Research on human element advanced vulnerability assessment,” in Proceedings of the 2017 IEEE International Conference on Cyber-Security and Quality Assurance (CSQA). IEEE, 2017, pp. 47–51. [Online]. Available: https://ieeexplore.ieee.org/document/8334468 [128] D. Papatsaroucha, D. Kapouranis, N. Papachatzakis, and E. K. Markakis, “An rpa-powered simulated phishing campaign solution for assessing human susceptibility,” in EEITE 2025 - 6th International Conference in Electronic Engineering and Information Technology. Institute of Electrical and Electronics Engineers Inc., 2025. [129] C. Lin and Q. Xu, “Risk assessment of substation integrated antimisoperation system considering human reliability,” IEEE Transactions on Power Delivery, vol. 38, pp. 2022–2033, 6 2023. [130] U. D. Ani, H. He, and A. Tiwari, “Human factor security: evaluating the cybersecurity capacity of the industrial workforce,” Journal of Systems and Information Technology, vol. 21, pp. 2–35, 3 2019. [131] J. Archibald and K. Renaud, “Pointer: A gdpr-compliant framework for human pentesting (for smes),” in Proceedings of the 13th International Conference on Cyber Warfare and Security (ICCWS 2018). Academic Conferences and Publishing International Limited, 2018, pp. 9–17. [Online]. Available: https://www.academic-conferences.org/ [132] A. Solomon, M. Michaelshvili, R. Bitton, B. Shapira, L. Rokach, R. Puzis, and A. Shabtai, “Contextual security awareness: A contextbased approach for assessing the security awareness of users,” Knowledge-Based Systems, vol. 246, 6 2022. [133] R. Bitton, K. Boymgold, R. Puzis, and A. Shabtai, “Evaluating the information security awareness of smartphone users,” in Conference on Human Factors in Computing Systems - Proceedings. Association for Computing Machinery, 4 2020. [134] P. Perrotin, S. Sadou, D. Hairion, and A. Beugnard, “Detecting human vulnerably in socio-technical systems: A naval case study,” in Proceedings - 23rd ACM/IEEE International Conference on Model Driven Engineering Languages and Systems, MODELS-C 2020 - Companion Proceedings. Association for Computing Machinery, Inc, 10 2020, pp. 372–379.

[135] P. Perrotin, N. Belloir, S. Sadou, D. Hairion, and A. Beugnard, “Using the architecture of socio-technical system to analyse its vulnerability,” in 2022 17th Annual System of Systems Engineering Conference, SOSE 2022. Institute of Electrical and Electronics Engineers Inc., 2022, pp. 361–366. [136] K. A. Alissa, H. A. Alshehri, S. A. Dahdouh, B. M. Alsubaie, A. M. Alghamdi, A. Alharby, and N. A. Almubairik, “An instrument to measure human behavior toward cyber security policies,” in 2018 21st Saudi Computer Society National Computer Conference (NCC), 2018, pp. 1–6. [137] Y. Gangire, A. D. Veiga, and M. Herselman, “Assessing information security behaviour: a self-determination theory perspective,” Information and Computer Security, vol. 29, pp. 625–646, 10 2021. [138] D. Modic, R. Anderson, and J. Palomäki, “We will make you like our research: The development of a susceptibility-to-persuasion scale,” PLoS ONE, vol. 13, 3 2018. [139] J. R. Schoenherr and R. Thomson, “The cybersecurity (csec) questionnaire: Individual differences in unintentional insider threat behaviours,” in 2021 International Conference on Cyber Situational Awareness, Data Analytics and Assessment, CyberSA 2021. Institute of Electrical and Electronics Engineers Inc., 6 2021. [140] H. Farzand, K. Marky, and M. Khamis, “Out-of-device privacy unveiled: Designing and validating the out-of-device privacy scale (odps),” in Conference on Human Factors in Computing Systems Proceedings. Association for Computing Machinery, 5 2024. [141] K. A. Alissa, B. A. Aldeeb, H. A. Alshehri, S. A. Dahdouh, B. M. Alsubaie, A. M. Alghamdi, and M. K. Alsmadi, “Developing a simulated intelligent instrument to measure user behavior toward cybersecurity policies,” International Journal of Communication Networks and Information Security (IJCNIS), vol. 13, no. 1, pp. 138–144, 2021. [142] T. Velki and K. Šolić, “Development and validation of a new measurement instrument: The behavioral-cognitive internet security questionnaire (BCISQ),” Interdisciplinary Description of Complex Systems (INDECS), vol. 17, no. 1B, pp. 164–175, 2019. [Online]. Available: http://indecs.eu/2019/indecs2019-pp164-175.pdf [143] F. Hussain, R. Rahman, Z. S. Attarbashi, W. H. N. Fadaq, and M. Mustafa, “Understanding human behavior in phishing attacks across diverse user groups: An ethical hacking analysis,” in 2024 IEEE 1st Karachi Section Humanitarian Technology Conference, Khi-HTC 2024. Institute of Electrical and Electronics Engineers Inc., 2024. [144] H. S. Berry, “Survey of the challenges and solutions in cybersecurity awareness among college students,” in ISDFS 2023 - 11th International Symposium on Digital Forensics and Security. Institute of Electrical and Electronics Engineers Inc., 2023.

Dimitra Papatsaroucha is a Cybersecurity Associate Researcher in the Department of Electrical and Computer Engineering at the Hellenic Mediterranean University and Senior Research Project Manager and Lab Team Leader at the Pasiphae R&D Laboratory of HMU. She is currently pursuing a Ph.D. focused on Human Vulnerability Assessment and human-centered cybersecurity. Her research interests include cybersecurity, human factors in cybersecurity, privacy-enhancing technologies, secure data exchange, AI-enhanced threat detection, and secure digital infrastructures. She has contributed to more than 7 European research and innovation projects under Horizon 2020, Horizon Europe, and MSCA programmes, undertaking roles including Deputy Technical Coordinator and key scientific contributor in activities related to cybersecurity architectures, trusted digital ecosystems, privacy-preserving systems, and cyber resilience. She has co-authored more than 20 scientific publications and is actively involved in European proposal development, interdisciplinary research coordination, and stakeholder engagement within international R&D initiatives. She has presented the findings of her work at international conferences and scientific events and she has contributed to the scientific community as a programme committee member and peer reviewer for international venues. Her work combines applied cybersecurity research, secure system design, and human-centered approaches for next-generation cybersecurity and resilient digital infrastructures.

30

Stavroula Psaroudaki holds a Bachelor’s degree in Computer Science from the Democritus University of Thrace (DUTH) and is currently pursuing a Master of Science in Bioinformatics at the University of Crete. She is an Associate Researcher and Software Developer at the PASIPHAE Laboratory of the Hellenic Mediterranean University (HMU), actively contributing to European research and innovation projects under Horizon Europe and DIGITAL Europe. Her interests lie in the broader areas of computer science and include computational approaches to human vulnerability assessment, data analysis, methodological approaches for societal challenges, and bioinformatics.

Eleftheria Vassilaki holds a Bsc in Business Administration from the Hellenic Mediterranean University and is currently pursuing her Msc in Tourism and Hospitality Management. She is a Research Associate in Pasiphae Lab, where she is a member of the Human Vulnerability Assessment research team, and participates in several European research projects. Her interests lie in expanding her knowledge of management practices, market research, and combining her backround in business administration with her presence in academia.

Konstantina Pityanou received her B.Sc. degree in Informatics Engineering - Software Engineering from the Technological Educational Institute of Crete, in 2019. In 2022 she received her M.Sc. degree in Informatics Engineering from the Hellenic Mediterranean University (HMU) of Crete. She works as an Associate Researcher, Project Manager, and Software Developer at Pasiphae R&D Laboratory of HMU, actively contributing to European research and innovation projects under Horizon Europe. Her interests include cybersecurity best practices, browser technologies, server-side technologies, database management, API development, and User Experience and User Interface design. She has co-authored more than 10 scientific publications and has presented the findings of her work at international conferences and scientific events. Her skills encompass both front-end and back-end development, reflecting her commitment to supporting innovative research efforts.

Evangelos K. Markakis is an Assistant Professor at the Department of Electrical and Computer Engineering of the Hellenic Mediterranean University and Principal Investigator of the Pasiphae R&D Laboratory. His research focuses on cybersecurity, secure communications, post-quantum cryptography, quantum-resilient systems, secure software engineering, cyber-physical systems, and critical infrastructure protection. He has authored over 150 scientific publications and has participated in more than 60 European research and innovation projects, including FP5, FP6, FP7, H2020, and Horizon Europe actions. In several of these projects, he has served as Coordinator, Technical Coordinator, or key scientific contributor, leading activities in cybersecurity architecture, secure communications, trusted infrastructures, cyber resilience, and quantum-safe security. He has also contributed significantly to European proposal development, having helped raise over C100 million in competitive Horizon funding through proposals he has written or co-developed. His work combines academic research, applied cybersecurity engineering, and European project leadership, with strong emphasis on practical, interoperable, and standards-aware security solutions for public safety, healthcare, telecom, defence, and critical infrastructure domains.

Record · ID 216721 · SHA-256 5ab8e3f69c4c09d9
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.