Routing Cybersecurity Awareness Training by FFM Personality Trait: A Quasi-Experimental Evaluation Glory Okwataa , Mohammad A. Razzaquea,∗
arXiv:2605.24551v1 [cs.CR] 23 May 2026
a School of Computing, Engineering and Digital Technologies, Teesside University, UK
ARTICLE INFO
ABSTRACT
Keywords: cybersecurity awareness training social engineering Five-Factor Model BFI-10 personality-conditional content delivery mobile learning quasi-experimental evaluation adaptive security education
Cybersecurity awareness training has historically adopted a one-size-fits-all approach, despite established individual differences in how users process and retain security information. Personality has been proposed as one axis along which training content might be tailored; yet no prior study had implemented and empirically evaluated a complete personality-conditional system end-to-end. This paper reports the design, implementation, and quasi-experimental evaluation of TailoredSec, a mobile cybersecurity awareness application that routes training content based on a user’s dominant FiveFactor Model (FFM) personality trait, as measured by the ten-item Big Five Inventory (BFI-10). Seventy-four UK-based adults were allocated to a traditional video-training condition (𝑛 = 40) or a personality-conditional condition (𝑛 = 34). Both groups completed a four-item scenario-based pre-assessment (scored 0–40), a single training session, and an equivalent post-assessment. The personality-conditional group additionally completed the BFI-10 (Big Five Inventory-10) and was routed to one of four training modules covering five FFM traits (Conscientiousness and Neuroticism share a module). Pre-assessment scores did not differ between groups (𝑡(69.1) = 0.43, 𝑝 = .67), confirming baseline equivalence. The personality-conditional group scored significantly higher on the post-assessment (𝑀 = 35.88, 𝑆𝐷 = 5.00 vs 𝑀 = 30.75, 𝑆𝐷 = 10.23; Welch’s 𝑡(58.5) = −2.81, 𝑝 = .003; Cohen’s 𝑑 = 0.62; 95%,CI [1.47, 8.79] marks), with a pass-rate of 100% versus 77.5% (Fisher’s exact 𝑝 < .01). A variance ratio of 4.19 indicates a ceiling effect that likely understates the true advantage. Usability was rated 4 or 5 out of 5 by 85.3% of 68 respondents. These results offer preliminary support for personality-conditional content routing as a feasible design principle for cybersecurity awareness training. Key limitations include non-randomised allocation, an authordeveloped unvalidated outcome instrument with non-parallel pre/post items, and a single-session design with no retention follow-up. Future work should employ a pre-registered randomised design with a validated cybersecurity awareness scale.
1. Introduction Social engineering attacks, which manipulate human psychology rather than exploit technical vulnerabilities, have become the dominant entry vector for data breaches [1, 2]. The 2025 Verizon Data Breach Investigations Report documented that 60% of all breaches involved the human element [3], with social engineering and pretexting incidents increasing by 50% year on year. The proliferation of generative AI tools further amplifies this threat by enabling attackers to craft personalised, linguistically polished lures at scale [4, 5]. Yet the predominant organisational response— mandatory annual awareness training delivered identically to all employees—has changed little in its basic structure [6]. The training is still uniform, but the attacks are not. Uniform training fails for a well-documented reason: standardised content cannot accommodate the variation in prior knowledge, cognitive style, risk perception, and motivation that employees bring to a training session [7]. People differ, and they differ in how they encode threat information, in their susceptibility to specific social engineering tactics [8, 9], and in the pedagogical formats that best support knowledge retention [10, 11]. A growing body of ∗ Corresponding author: [email protected]
Mohammad
A.
Razzaque,
evidence links personality traits, particularly those captured by the Five-Factor Model (FFM) [12], to cybersecurity behaviour [13–15]. Conscientious individuals exhibit stronger security compliance [16, 17], while extraversion and high agreeableness are associated with greater susceptibility to phishing and pretexting [18–20]. FFM trait profiles could therefore serve as a routing variable for training content; yet no prior study has built a complete mobile application around this idea, deployed it with a real user population, and compared it against a control condition. Three prior lines of work come closest. Uebelacker and Quiel [21] proposed a conceptual mapping between FFM traits and Cialdini’s persuasion principles [22], suggesting trait-specific coping mechanisms for security training, but they did not implement or evaluate a training system. Gianotti et al. [23] proposed incorporating FFM traits into an educational recommender system architecture for general learning, without a cybersecurity focus or empirical evaluation. Thorp et al. [24] demonstrated that FFM traits moderated the effectiveness of virtual-reality-based cybersecurity training, but the training content itself was not varied by trait. The present study addresses this gap by implementing a full system in which BFI-10 scores determine which of four training modules a participant receives and by evaluating the resulting system against a traditional-training control.
[email protected] (G. Okwata); [email protected] (M.A. Razzaque) ORCID (s): 0000-0002-5572-057X (M.A. Razzaque)
Okwata and Razzaque: Preprint submitted to Elsevier
Page 1 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
This paper makes three contributions. First, we present the design and implementation of TailoredSec, a cybersecurity awareness mobile application that operationalises FFM trait scores as a content-routing variable, with the routing rule, content mapping (five traits to four modules), tie-breaking, and BFI-10 scoring algorithm fully specified to a replication standard. Second, we report a quasi-experimental comparison (𝑛 = 74; non-randomised; baseline-equivalent on pre-assessment, 𝑡(69.1) = 0.43, 𝑝 = .67) showing a moderate, statistically significant postassessment advantage of personality-conditional training over traditional video training (Welch’s 𝑡(58.5) = −2.81, 𝑝 = .003, Cohen’s 𝑑 = 0.62, 95 % CI for mean difference [1.47, 8.79]), with 100% versus 77.5% pass-rates (Fisher’s exact 𝑝 < .01). Third, we make the design choices, psychometric constraints, and analytic limitations of the study explicit—including the ceiling effect visible in the post-test variance (𝐹ratio = 4.19), the individual-routing limitations of the BFI-10, and the non-parallel pre/post instrument— and we use these to formulate a pre-registered replication design that the research community can build upon. The remainder of the paper is structured as follows. Section 2 reviews the literature on social engineering susceptibility, FFM-based training differentiation, and mobile platforms for security education. Section 3 describes the study design, participants, ethics, instruments, and analysis plan. Section 4 details the system architecture and implementation of TailoredSec. Section 5 presents the empirical results. Section 6 interprets the findings, addresses limitations, and proposes future directions. Section 8 concludes.
2. Background and Related Work 2.1. Social Engineering as the Primary Human-Layer Threat Social engineering exploits the psychological and social vulnerabilities of individuals rather than technical weaknesses in information systems, making it particularly difficult to defend against through purely technical means [25, 26]. Attacks range from phishing and spear-phishing to pretexting, baiting, tailgating, and vishing, and typically exploit Cialdini’s principles of influence—reciprocity, commitment, social proof, authority, liking, and scarcity [9, 22]. Across reported incidents, between 70% and 95% involve a human element, at a cost to organisations ranging from thousands to millions of pounds in direct financial loss, regulatory penalty, and reputational damage [1, 27, 28]. Security awareness training is the most widely deployed form of human-layer protection and is at least as important as technical perimeter controls [6].
2.2. Limitations of Uniform Security Awareness Training Conventional security awareness training programmes share a common architecture: a standardised curriculum delivered via presentation slides, e-learning modules, or
Okwata and Razzaque: Preprint submitted to Elsevier
mandatory video content, typically on an annual or biannual schedule. Evaluation of these programmes reveals a consistent pattern: short-term knowledge gains that dissipate rapidly, low engagement, negligible impact on long-term behaviour, and high recidivism on phishing simulations [7, 10]. Lawson et al. [20] demonstrated that within an organisation subjected to repeated simulated phishing campaigns, a stable minority of employees continued to click malicious links despite training, suggesting that a single, uniform intervention cannot address the heterogeneity of individual risk profiles. Parsons et al. [29], in developing the Human Aspects of Information Security Questionnaire (HAIS-Q), similarly found that security behaviours vary substantially across individuals and domains, reinforcing the case for differentiated rather than uniform training approaches. At its core, the onesize-fits-all model assumes all learners respond equivalently to the same content and framing, a claim contradicted by decades of educational psychology research [30–32].
2.3. Personality and Cybersecurity Behaviour The FFM, also known as the OCEAN model, covers five broad dimensions of human personality—Openness to experience, Conscientiousness, Extraversion, Agreeableness, and Neuroticism—and is the dominant framework for personality assessment in academic and applied settings [12]. Multiple independent studies now link FFM traits to information security behaviour. Gratian et al. [14] found that Openness and Conscientiousness were among the strongest individual-level predictors of security intention in a sample of 500 participants. Shappie et al. [13] reported that Conscientiousness and Agreeableness positively predicted self-reported cybersecurity compliance, while Neuroticism was negatively associated with secure password practices. Kennison and Chan-Tin [16] and Kalhoro et al. [17] identified low Conscientiousness and high Extraversion as consistent risk factors for security-compromising behaviour in workplace samples. Albladi and Weir [18] demonstrated that personality traits mediated the relationship between online behaviour and victimisation, with trust and impulsivity as key intervening variables. Across these studies, the FFM— security behaviour link is consistent, with typical effect sizes (𝑟) in the 0.1–0.3 range at the trait level [33]. Two caveats deserve mention. First, the trait–susceptibility relationships observed in the literature are primarily correlational and mediated by variables such as online exposure and risk perception; personality is not destiny with respect to security behaviour. Second, the BFI-10 used in the present study was designed and validated for group-level research. Rammstedt and John [34] explicitly caution that its twoitem per-trait structure yields retest reliabilities of 𝑟 = .49 (Neuroticism, German sample) to 𝑟 = .79 (Extraversion, US sample), which is insufficient for individual clinical diagnosis. This psychometric limitation of using BFI-10 scores for individual content-routing decisions is discussed further in Section 6.
Page 2 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
2.4. FFM Traits, Susceptibility, and Coping Mechanisms Uebelacker and Quiel’s [21] theoretical framework provides the most direct basis for linking individual FFM traits to training content design. Their analysis of the personality– persuasion correspondence identified the following traitspecific patterns and coping recommendations, subsequently extended by Papatsaroucha et al. [35]: Openness: Individuals high in Openness are characterised by intellectual curiosity and a propensity for novel experiences, which increases susceptibility to baiting attacks [36]. Training formats that provide interactive, exploratory, and intellectually stimulating content—such as gamification and problem-based scenarios—are most effective for this group [21, 24]. Conscientiousness: Conscientious individuals tend to follow rules and respect authority, which paradoxically increases their susceptibility to authority-based manipulation [37]. General security awareness training covering policy and procedural norms is recommended, as this format aligns with their normative disposition [19, 21]. Extraversion: Extraverted individuals are socially motivated and enjoy interactive media; they are more vulnerable to social engineering via social media and communication platforms [18]. Personalised, rewarding, and socially framed content is most effective [21]. Agreeableness: High Agreeableness is associated with trust, compliance, and prosocial motivation, increasing vulnerability to authority, reciprocity, and liking appeals [35]. Narrative and storytelling-based training, presenting social engineering through concrete case studies, has been recommended to recalibrate overgeneralised trust [21]. Neuroticism: Neurotic individuals tend to exhibit anxiety and risk-aversion, which can paradoxically limit susceptibility by heightening vigilance toward suspicious communications [38]. General security awareness training, similar to that for Conscientiousness, is recommended given the limited incremental vulnerability of this trait [21]. These recommendations had not, however, been implemented and tested in a deployed training system before the present study. Table 1 summarises the trait characteristics and corresponding module formats. Figure 1 illustrates the resulting content routing structure, showing the 5-to-4 module collapse.
BFI-10 Dominant Trait
Training Module
Openness
Swipeable Cards (Baiting/Phishing)
Extraversion
Audio Podcast (Reward-based)
Agreeableness
Storytelling Video (Case-study narrative)
Conscientiousness shared
General Video (Security awareness)
Neuroticism
Okwata and Razzaque: Preprint submitted to Elsevier
Table 1: Summary of FFM personality traits, cybersecurity susceptibility, and training recommendations. Susceptibility levels adapted from Uebelacker and Quiel [21] and Papatsaroucha et al. [35]. Trait
Susceptibility vector
Recommended format
Openness
Baiting, curiosity exploitation Authority, commitment appeals Phishing, socialmedia manipulation Reciprocity, liking, social proof Lower susceptibility via vigilance
Interactive / gamified content General awareness video Reward-based / personalised content Storytelling / narrative video General awareness video
Conscientiousness Extraversion Agreeableness Neuroticism
Figure 1: Content routing structure. BFI-10 dominant trait scores map five FFM traits onto four training modules. Conscientiousness and Neuroticism share a general security awareness video module.
2.5. Adaptive and Personalised Learning in Security Training Personalised e-learning systems modify content based on learner characteristics to improve engagement and outcomes [11]. In general education, personality-informed personalisation has clear empirical backing: Komarraju et al. [31] found FFM traits explained 14% of GPA variance, and Lai et al. [39] showed that personality profiles inferred from online learning behaviour could reliably guide content selection. In the cybersecurity domain, however, such systems remain rare. Giannakas et al. [40] developed a game-based mobile application for cybersecurity education aimed at younger learners, but did not personalise content by personality trait. Sudha et al. [41] demonstrated that smartphone-based interactive modules improved cybersecurity knowledge at the high-school level, again without trait-based personalisation. No prior cybersecurity study had deployed and evaluated a complete trait-routing system. The present study fills that gap by deploying a mobile application that routes cybersecurity awareness content by FFM trait and comparing it against a control condition. One terminological point: the system implements personalityconditional content routing—a one-shot assignment based on a personality profile—not adaptive learning in the technical sense, which requires continuous updating of a learner model from real-time performance data (as in intelligent tutoring systems or knowledge-tracing models) [11]. This distinction is maintained throughout.
3. Methodology 3.1. Study Design This study employed a quasi-experimental betweensubjects design with pre- and post-assessment measurement. Participants were allocated to one of two conditions: a traditional training condition (Sample 1, 𝑛 = 40) and a Page 3 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait Assessed for eligibility 𝑛 = 112
Did not complete (𝑛 = 38): APK sideload barriers or no response
Enrolled and allocated (𝑛 = 74)
Sample 1 — Traditional Allocated: 𝑛 = 40
Sample 2 — Personality-conditional Allocated: 𝑛 = 34
Completed training (𝑛 = 40)
Completed training (𝑛 = 34); 33 received personality-routed content; 1 passed pre-assessment
Analysed (𝑛 = 40) Analysed (𝑛 = 34) Figure 2: CONSORT-style participant flow diagram. Of 112 individuals approached, 74 completed the study. Non-completers (𝑛 = 38) did not install the application, most likely due to reluctance to enable sideloading of an unsigned APK. One participant in Sample 2 passed the pre-assessment and proceeded directly to post-assessment without receiving personality-routed training content.
personality-conditional training condition (Sample 2, 𝑛 = 34). The unit of analysis was the individual participant. The study was not randomised; participants who contacted the researcher first were allocated to Sample 1 until the target for that group was reached, after which subsequent participants were allocated to Sample 2. This allocation mechanism produced groups that did not differ on preassessment performance (see Section 5.2), but it limits causal inference. The study is therefore described throughout as quasi-experimental.
3.2. Participants and Recruitment A convenience sample of 112 UK-based adults was approached via direct researcher contact and participant referral networks between October and December 2023. Inclusion criteria were: (i) UK residence, (ii) ownership of an Android smartphone capable of sideloading an unsigned APK, and (iii) availability for a single self-directed session of approximately 15–30 minutes. No exclusion criteria related to prior cybersecurity knowledge were applied. Seventy-four participants completed the study, yielding a completion rate of 66.1%. The 38 non-completers (33.9%) did not engage with the application; the most plausible reason is reluctance to enable the installation of an unsigned APK, which requires non-default device settings. This attrition mechanism introduces a selection bias towards participants who are more technically literate or security-confident, which is discussed in Section 7. The CONSORT-style (Consolidated Standards of Reporting Trials) participant flow diagram is presented in Figure 2.
Okwata and Razzaque: Preprint submitted to Elsevier
3.3. Ethics The study was conducted under the ethical framework of Teesside University’s School of Computing, Engineering, and Digital Technologies. No personally identifying information (PII) was collected at any stage. Participants were informed of the study’s purpose, voluntary nature, data handling procedures, and their right to withdraw at any point without consequence via a consent notification displayed on the application’s onboarding screen. All data were stored on Google Firebase Firestore under enforced security rules, accessible only to the research team. Quiz responses were recorded anonymously using a session identifier that could not be linked to any individual outside the session.
3.4. Instruments 3.4.1. Personality Assessment: BFI-10 Personality was assessed using the Big Five Inventory10 (BFI-10) [34], a validated 10-item instrument measuring each of the five FFM dimensions with two items per trait on a five-point Likert scale (1 = Disagree strongly, 5 = Agree strongly). The BFI-10 was selected over the full BFI-44 [42] or the NEO-PI-R (60 items) on the grounds of brevity and acceptability within a mobile application context. It captures approximately 70% of the variance of the BFI-44 and has demonstrated acceptable construct validity [34, 43]. Items 1, 3, 4, 5, and 7 are reverse-scored prior to summing (see Section 4.4).
Page 4 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
3.4.2. Social Engineering Awareness: Scenario-Based MCQ We measured social engineering awareness by developing a four-item , scenario-based multiple-choice questionnaire administered at both pre- and post-assessment. Each item presented a realistic social engineering scenario drawn from five threat categories (phishing, vishing, tailgating, pretexting, and baiting), with four response options scored 0 (no credit) or 10 (full credit), yielding a total score of 0– 40 per assessment. A passing score was defined a priori as ≥ 30, equivalent to correctly answering at least three of the four scenarios.
Algorithm 1 BFI-10 Personality-Conditional Content Routing Require: BFI-10 responses 𝑟1 , … , 𝑟10 ∈ {1, 2, 3, 4, 5} Ensure: Training module 𝑀 ∈ {Cards, Video, Podcast, Story} 1: Reverse-score items 1,3,4,5,7: 𝑟𝑖 ← 6 − 𝑟𝑖 2: Compute trait scores: 3: 𝐸 ← 𝑟1 + 𝑟6 ⊳ Extraversion 4: 𝐴 ← 𝑟2 + 𝑟7 ⊳ Agreeableness 5: 𝐶 ← 𝑟3 + 𝑟8 ⊳ Conscientiousness 6: 𝑁 ← 𝑟4 + 𝑟9 ⊳ Neuroticism 7: 𝑂 ← 𝑟5 + 𝑟10 ⊳ Openness 8: dominant ← arg max𝜏∈{𝑂,𝐶,𝐸,𝐴,𝑁} 𝜏 (ties: priority 𝑂>𝐴>𝐸>𝐶>𝑁) 9: if dominant = 𝑂 then return 𝑀 ← Swipeable Cards 10: end if 11: if dominant ∈ {𝐶, 𝑁} then return 𝑀 ← General Awareness Video 12: end if 13: if dominant = 𝐸 then return 𝑀 ← Audio Podcast 14: end if 15: if dominant = 𝐴 then return 𝑀 ← Storytelling Video 16: end if
3.4.3. Usability Feedback: Five-Item Likert Survey Post-training usability was assessed via an anonymous five-point Likert survey administered through Google Forms, covering four dimensions: overall usability, perceived quality of adaptive content matching, helpfulness of app features for understanding social engineering, and ease of use.
3.5. Construct Operationalisation Table 2 provides a complete operationalisation of all constructs measured in the study. Table 2: Construct operationalisation table. Construct
Instrument
Items / range
Source
Personality trait
BFI-10
Rammstedt John [34]
SE awareness
Scenario MCQ
Usability
Likert survey
App performance
Apptim
10 items; 5pt Likert; 2 items/trait; reverse-scored 4 items; 0–40 pts; non-parallel pre/post 4 dimensions; 5pt scale CPU, memory, energy, threads
Authordeveloped Authordeveloped Apptim [44]
3.6. Adaptation Decision Rule The formal specification of the personality-conditional content routing logic is given in Algorithm 1. After scoring the BFI-10, the dominant trait is determined as the argmax over the five trait scores. In the case of a tie between two or more traits, the system applies a predefined priority order (Openness > Agreeableness > Extraversion > Conscientiousness > Neuroticism) that allocates ties to the trait with the most differentiated training module. Conscientiousness and Neuroticism share the general awareness video module, so the 5-trait input space maps onto 4 training modules (see Figure 1). Participants who scored ≥ 30 on the preassessment (passing) were shown a pass screen and could optionally proceed to the training and post-assessment; those who failed (< 30) proceeded directly to the BFI-10 and the routed training module.
Okwata and Razzaque: Preprint submitted to Elsevier
3.7. Procedure &
Participants received an invitation message containing installation instructions for the TailoredSec Android APK and a participation information sheet. The session was selfdirected and asynchronous; participants completed all elements (pre-assessment, training, post-assessment, and optional feedback survey) in a single continuous session, estimated to take 15–30 minutes. The onboarding screen displayed the consent statement. Participants allocated to Sample 1 received a general cybersecurity awareness video followed by the post-assessment, without completing the BFI10. Participants allocated to Sample 2 who failed the preassessment (< 30 marks) completed the BFI-10, received the routed training module, and then completed the postassessment.
3.8. Analysis Plan The primary outcome variable was the post-assessment score (0–40). The primary hypothesis was that the personalityconditional group would score higher on the post-assessment than the traditional group (directional hypothesis; onetailed test). Pre-assessment scores were analysed using Welch’s independent-samples 𝑡-test to assess baseline equivalence. The primary outcome comparison used Welch’s independent-samples 𝑡-test (chosen over Student’s 𝑡-test to account for unequal sample variances). Effect size was reported as Cohen’s 𝑑, computed from pooled standard deviation, with 95% confidence intervals on the mean difference derived from Welch’s standard error. The passrate contingency (Fisher’s exact test was used, rather than Pearson’s 𝜒 2 , because one cell had an expected count of zero) was computed for the ≥ 30-mark threshold. Variance Page 5 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
UI (Figma/Flutterflow)
Logic (Maths & Algorithms)
Storage (Cache/firestore)
API/AI
Users/Participants Local/App state Backend Queries/Storage Options
Figure 3: Overview of TailoredSec system architecture. The Android client manages application state in-memory (FlutterFlow AppState cache); scores and session data are persisted to Firebase Firestore on completion of each quiz segment.
homogeneity was examined via the variance ratio 𝑠2Trad ∕𝑠2PC ; a ratio substantially greater than 1 was interpreted as evidence of a ceiling effect in the personality-conditional group.
4. System Design and Implementation 4.1. Technology Stack and Architecture The TailoredSec application was implemented as a native Android application using FlutterFlow [45], a visual nocode/low-code development environment built on the Flutter framework, which enables cross-platform deployment from a single codebase. Firebase Firestore [46] was used as the serverless NoSQL backend for real-time data persistence, providing schema-flexible storage for pre- and postassessment scores and session metadata. The user interface was prototyped in Figma [47] prior to implementation. No user authentication was implemented, consistent with the ethical requirement for anonymous participation; a sessionlevel identifier was generated at runtime and discarded upon session completion. The high-level system architecture, illustrating the data flow between the client (Android device), app state cache, and Firebase Firestore backend, is shown in Figure 3.
4.2. Application Workflow The application implements a conditional branching workflow based on the pre-assessment outcome and BFI-10 score. The logical flow is illustrated in Figure 4.
4.3. Onboarding and Pre-Assessment The onboarding screen presents (Figure 5) the consent statement and allows participants to select a light or dark colour theme; no personally identifying information is requested or collected. Upon confirming consent, participants proceed to the four-item scenario-based (social engineering scenarios) pre-assessment. Each scenario is presented as a text vignette with four radio-button response options. The scoring logic is implemented as a conditional expression in the mobile app state: a correct response increments the running score variable by 10 points; an incorrect response increments it by 0. Upon completion of the fourth item, the application evaluates whether the accumulated score meets the pass threshold (≥ 30). If so, the user is directed to a pass confirmation screen; if not, they are directed to a failure
Okwata and Razzaque: Preprint submitted to Elsevier
Figure 4: Application logical flow. Participants who pass the pre-assessment (≥ 30) may exit or proceed directly to postassessment. Participants who fail are routed through the BFI-10 (personality-conditional group) or directly to standard training (traditional group), and then to post-assessment.
screen with routing instructions. Representative screenshots of the pre-assessment interface are shown in Figure 6.
4.4. BFI-10 Scoring The BFI-10 was presented as ten Likert-scale items. The scoring algorithm follows Rammstedt and John [34]: items 1, 3, 4, 5, and 7 are reverse-scored (score ← 6− response), and each trait is calculated as the sum of its two items (see Table 3). Reverse scoring was implemented by storing the complement value in the TailoredSec App’s integer variable at the point of user selection. For example, a response of “Strongly disagree” (scale value 1) to item 1 stores the value Page 6 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
Figure 5: User interface for the scenario-based pre-assessment quiz. Radio buttons present four response options per scenario; scoring logic is embedded in the navigation action of the “Next” button.
Figure 6: User interface for the scenario-based pre-assessment quiz. Radio buttons present four response options per scenario; scoring logic is embedded in the navigation action of the “Next” button.
5 in the persTestOpt1 state variable, yielding the correct reverse-scored contribution to the Extraversion subscale. The dominant trait was determined by comparing the five computed trait scores, and in the event of a tie, the priority order 𝑂 > 𝐴 > 𝐸 > 𝐶 > 𝑁 was applied. All five trait scores and the resulting dominant trait label were persisted to the database (i.e., Firebase Firestore) for the personalityconditional group. Okwata and Razzaque: Preprint submitted to Elsevier
Figure 7: The Big 5 Personality Test using BFI-10 model.
Table 3: BFI-10 scoring algorithm showing item assignment and reverse-scoring (R = reversed). Adapted from Rammstedt and John [34]. Trait
Item/Score 1
Item/Score 2
Total Score
Extraversion Agreeableness Conscientiousness Neuroticism Openness
1 (R) 2 3 (R) 4 (R) 5 (R)
6 7 (R) 8 9 10
𝑆𝑐𝑜𝑟𝑒1 + 𝑆𝑐𝑜𝑟𝑒2 𝑆𝑐𝑜𝑟𝑒1 + 𝑆𝑐𝑜𝑟𝑒2 𝑆𝑐𝑜𝑟𝑒1 + 𝑆𝑐𝑜𝑟𝑒2 𝑆𝑐𝑜𝑟𝑒1 + 𝑆𝑐𝑜𝑟𝑒2 𝑆𝑐𝑜𝑟𝑒1 + 𝑆𝑐𝑜𝑟𝑒2
Page 7 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
(a) Swipeable Flashcards.
(b) General Training.
(c) Reward-based Training.
(d) Story Telling.
Figure 8: Trait-based Personalised Training Modules.
4.5. Training Modules Four personality-specific training modules were implemented, informed by the coping mechanism recommendations of Uebelacker and Quiel [21]. The specific implementations represent pragmatic approximations to the ideal formats given the scope and resources of the project. Table 4 provides a comparison of the recommended and implemented formats. Table 4: Recommended training formats per FFM trait compared with the implementation in TailoredSec. Personality Openness
Recommended format
Interactive edutainment / gamification Conscientiousness General security awareness Extraversion Reward-based learning Agreeableness Narrative / storytelling Neuroticism General security awareness
Implemented format Swipeable flashcards cards) Awareness video
(4
Audio podcast + simulated loyalty-points reward Security incident storytelling video Awareness video (shared with Conscientiousness)
Openness module: Four swipeable flashcards (Figure 8 (a)) cover phishing, pretexting, tailgating, and impersonation tactics, along with detection tips. A “Continue to assessment” button appeared only after all four cards had been swiped, enforced by a conditional visibility rule on the app swipecard counter variable. Conscientiousness/Neuroticism module: A single general cybersecurity awareness video (Figure 8 (b)) covered Okwata and Razzaque: Preprint submitted to Elsevier
foundational social engineering concepts, policy norms, and protective behaviours relevant to authority-based and general manipulation. Extraversion module: Two audio podcasts introduced social engineering fundamentals and presented a live vishing scenario. A simulated Tesco loyalty-point reward (Figure 8 (c)) was displayed upon completion. Note: the differential reward mechanism in this module constitutes a potential confound, as it provides an extrinsic incentive not present in other modules; this is acknowledged as a limitation in Section 7. Agreeableness module: A storytelling video (Figure 8 (d)) presented social engineering attacks as narrative case studies of real-world incidents to develop empathic threat recognition and recalibrate the trust assumptions that underlie high-agreeableness vulnerability.
4.6. Post-Assessment and Database Design The post-assessment used four scenario-based MCQ items covering the same social engineering categories as the pre-assessment but with distinct scenarios to reduce item familiarity effects. Scoring logic was identical to the pre-assessment: correct responses contributed 10 points to the PostAssScore AppState variable. Upon completion, all session data—including pre-score, post-score, and (for the personality-conditional group) the five BFI-10 subscale scores and dominant trait label—were recorded in a secure database (Firebase). The Firebase database was protected by server-side security rules that restricted write access to the active session and read access to authenticated research team credentials only. Page 8 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
The compiled Android APK was benchmarked using Apptim [44], an industry-standard mobile application profiling tool, to verify that the application performed adequately on representative consumer hardware. The standard Apptim threshold configuration (example_thresholds.yml) was applied, with a heavy-usage threshold set at 600% (4200 MB) for all resource dimensions (App memory, App CPU, Energy score, Device CPU, Device memory, and Thread count). The application passed the benchmark on the first run with zero crashes. Peak memory usage reached approximately 3800 MB at application launch (approximately 15 seconds into the test) before declining to light-usage levels. Device memory stabilised at slightly above the medium-usage mark. All metrics remained below the heavy-usage threshold throughout the test session, confirming that the application performs acceptably on typical consumer Android hardware. The APK was also compiled and debugged in Android Studio with no errors. Table 5: Pre-assessment score frequency distribution by group. Pass mark = 30/40. Score
0 10 20 30 40
Sample 1 (Traditional, 𝑛 = 40)
Sample 2 (PC, 𝑛 = 33)
𝑓
%
𝑓
%
6 11 17 5 1
15.0 27.5 42.5 12.5 2.5
4 8 16 4 1
12.1 24.2 48.5 12.1 3.0
Mean (SD)
16.00 (9.82)
Table 6: Post-assessment score frequency distribution by group. Sample 1 (Traditional, 𝑛 = 40)
Score
0 10 20 30 40
Sample 2 (PC, 𝑛 = 34)
𝑓
%
𝑓
%
0 5 4 14 17
0.0 12.5 10.0 35.0 42.5
0 0 0 13 20
0.0 0.0 0.0 39.4 60.6
Mean (SD)
30.75 (10.23)
35.88 (5.00)
Post-assessment score distribution by group Traditional (𝑛=40) Personality-conditional (𝑛=34)
20 Frequency (𝑛)
4.7. Technical Performance Testing
10
0 0
10 20 30 Post-assessment score
40
Figure 9: Post-assessment score distributions. The personalityconditional group showed a highly concentrated distribution at the upper end (30–40), indicative of a ceiling effect in the four-item post-assessment instrument.
16.97 (9.51)
5. Results 5.1. Participant Flow and Attrition Of 112 individuals approached, 74 completed the study (66.1% completion rate). Sample 1 (traditional training) comprised 𝑛 = 40 participants, and Sample 2 (personalityconditional training) comprised 𝑛 = 34 participants. The participant flow is shown in Figure 2. All 74 completers provided complete pre- and post-assessment data. The preassessment frequency table for Sample 2 contains 33 entries (Table 5 rather than 34, as one participant passed the preassessment (≥ 30 marks) and proceeded directly to the postassessment without requiring the BFI-10 routing step.) The 𝑡-test analysis used 𝑛 = 34 for Sample 2 in alignment with the post-assessment records, which represent the complete analytical dataset.
5.2. Baseline Equivalence Pre-assessment score distributions for both groups are summarised in Table 5. The distributions are visually similar: the modal response in both groups was a score of 20 (Sample 1: 42.5%, Sample 2: 48.5%), and fewer than 15% of participants in either group achieved a passing score (≥ 30) at baseline. Group means were 𝑀Trad = 16.00 (𝑆𝐷 = 9.82, 𝑛 = 40) and 𝑀PC = 16.97 (𝑆𝐷 = 9.51, 𝑛 = 33). Welch’s independent-samples 𝑡-test confirmed no significant Okwata and Razzaque: Preprint submitted to Elsevier
difference between groups at baseline (𝑡(69.1) = 0.43, 𝑝 = .67, Cohen’s 𝑑 = 0.10), supporting the assumption of baseline equivalence and providing a valid basis for between group comparison on the post-assessment.
5.3. Primary Outcome: Post-Assessment Performance Post-assessment score distributions are presented in Table 6. A pronounced difference in distributional shape was observed between groups: Sample 1 exhibited a broad distribution across all score levels, whereas Sample 2 showed a highly concentrated distribution at the upper end of the scale (30 or 40), with no participant scoring below 30. This distributional asymmetry is illustrated in Figure 9. Welch’s independent-samples 𝑡-test indicated that the personality-conditional group scored significantly higher than the traditional group on the post-assessment (𝑡(58.5) = −2.81, 𝑝 = .003 one-tailed, 𝑝 = .007 two-tailed). The mean difference was 5.13 (35.88−30.75) marks (personalityconditional minus traditional), with a 95% confidence interval of [1.47, 8.79] marks. The effect size was in the medium range (Cohen’s 𝑑 = 0.62; pooled 𝑆𝐷 = 8.25). These results are presented in Table 7.
Page 9 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
Table 8: User feedback summary (𝑛 = 68). Ratings on a 5-point Likert scale (5 = Highest, 1 = Lowest). ≥4 = proportion rating 4 or 5.
Pass-rate comparison at ≥30-mark threshold 100
Proportion (%)
100
Traditional (𝑛=40) Personality-conditional (𝑛=33)
77.5
50 22.5
Dimension
5
4
3
2
1
≥4 %
Usability Adaptive content SE understanding Ease of use
41 20 18 47
17 23 25 17
7 18 19 4
2 4 4 0
1 3 2 0
85.3 63.2 63.2 94.1
0
0 Pass
Fail Post-assessment outcome
Figure 10: Pass-rate comparison at the 30-mark threshold. All 33 personality-conditional participants who received traitrouted training passed the post-assessment (100%), compared with 31/40 (77.5%) in the traditional group (Fisher’s exact 𝑝 < .01, one-tailed).
Table 7: Welch’s two-sample 𝑡-test on post-assessment scores (two-sample assuming unequal variances). PC = personality-conditional. Statistic
Sample 1 (Traditional)
Sample 2 (PC)
𝑛 Mean 𝑆𝐷 Variance
40 30.75 10.23 104.55
34 35.88 5.00 24.96
Welch’s 𝑡(58.5) = −2.81 𝑝 (one-tailed) = .003 𝑝 (two-tailed) = .007 Mean difference = 5.13 (95 % CI: [1.47, 8.79]) Cohen’s 𝑑 = 0.62 (medium effect) Variance ratio = 4.19 (ceiling effect indicator)
5.4. Pass-Rate Analysis The pass rate at the 30-mark threshold was 100% (33/33) for the personality-conditional group and 77.5% (31/40) for the traditional group, a difference of 22.5 percentage points. Because one cell of the 2 × 2 contingency table contained an expected count of zero, Fisher’s exact test was used in place of Pearson’s 𝜒 2 . The one-tailed Fisher’s exact test indicated a statistically significant difference in pass-rates between groups (𝑝 < .01). This result is visualised in Figure 10.
5.5. User Feedback A total of 68 participants completed the optional posttraining usability survey. Table 8 summarises ratings across the four survey dimensions. Usability and ease of use received the highest ratings: 85.3% of respondents rated usability at 4 or 5 (“High” or “Highest”), and 94.1% rated ease of use at 4 or 5. Ratings for the quality of adaptive content matching and the app’s contribution to social engineering understanding were lower but still positive: 63.2% rated adaptive content quality at 4 or 5, and 63.2% rated social engineering understanding at 4 or 5. Usability satisfaction was high; the ratings for adaptive content depth are the clearest signal for what to improve next. Okwata and Razzaque: Preprint submitted to Elsevier
6. Discussion 6.1. Interpretation of Findings Routing training content by dominant BFI-10 trait produced a statistically significant post-assessment advantage over uniform video training (𝑑 = 0.62, 95 % CI [1.47, 8.79] marks; Fisher’s exact 𝑝 < .01 on pass-rate). Because the two groups did not differ at baseline (𝑡(69.1) = 0.43, 𝑝 = .67), this difference cannot plausibly be attributed to pre-existing knowledge differences. The result aligns with prior work showing that personality-differentiated instruction improves learning outcomes [31, 48] and with the trait–content mapping proposed by Uebelacker and Quiel [21]. A 𝑑 of 0.62 sits above the typical range (𝑑 = 0.3–0.5) reported for security awareness interventions [7], which suggests that the trait-routing mechanism contributes something beyond what generic training can achieve. The usability ratings (85.3% rating usability 4 or 5 out of 5; 94.1% on ease of use) confirm that mobile delivery was acceptable to participants and did not suppress learning itself.
6.2. The Ceiling Effect and Its Implications The variance ratio of 4.19 (𝑠2Trad = 104.55 vs 𝑠2PC = 24.96) is the most technically significant feature of the results. It reflects a ceiling effect in the personality-conditional group: every participant scored either 30 or 40, so the four-item instrument had no discriminating power at all within that group above the 30-mark threshold. The true size of the post-assessment advantage is therefore understated. A harder instrument would spread the personalityconditional scores and would likely yield a larger effect estimate. Equally, the ceiling prevents any distinction between participants who gained shallow familiarity and those who achieved robust understanding. This is a strong case for using a validated, multi-item instrument (such as the HAIS-Q [29]) in any replication. The same ceiling partly explains the large pass-rate increase in Sample 1 (15% to 77.5% across a single general video session). That jump could reflect genuine learning from the video. It could equally reflect a testing effect, where completing the pre-assessment primed participants for the post-assessment scenarios. Because the two sets of items were deliberately non-parallel, the current data cannot separate the two.
Page 10 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
6.3. Psychometric Limitations of BFI-10 for Individual Routing Using BFI-10 scores to route individual participants raises a well-known psychometric problem. Rammstedt and John [34] explicitly validated the instrument for grouplevel research and warned against individual-level decisions because the two-item per-trait structure yields retest reliabilities of only 𝑟 = .49 (Neuroticism) to 𝑟 = .79 (Extraversion). Taking the argmax of five subscale scores, each derived from two items, will route a non-trivial fraction of participants to the wrong module [43]. The present study cannot estimate how large that fraction is; doing so would require test–retest data or a concurrent BFI-44 comparison. Future studies should either supplement BFI-10 routing with a longer instrument in a subsample, or replace it with a more reliable measure such as the BFI-44 or NEO-PI-3 from the outset.
6.4. Comparison with Prior Work Related studies have touched on parts of this problem without assembling the whole. Thorp et al. [24] found that Openness moderated how participants experienced VR-based cybersecurity training, but held content constant across trait groups. Halevi et al. [33] showed that personality predicted spear-phishing susceptibility without testing a trait-tailored intervention. The present study is the first to implement and empirically evaluate a complete personalityrouting training system in a mobile cybersecurity application. The 𝑑 = 0.62 effect and 100% pass-rate in the personality-conditional group are encouraging, though the methodological limitations catalogued here mean that any strong causal claim would be premature.
6.5. Practical Implications for Organisations For practitioners, the results are promising but warrant caution. A simple personality screening step—ten questionnaire items before training begins—was sufficient to produce a measurable knowledge gain over a generic video. The BFI10’s individual-level reliability means that routing departments or teams collectively (rather than person by person) may be the more defensible near-term approach; group-level personality profiles are more stable than individual scores from a two-item subscale. The mobile format itself added no apparent friction: 94.1% of respondents rated it easy to use, and the anonymous, no-authentication design removes common staff privacy concerns that can suppress training uptake [49].
7. Limitations and Future Work Eight limitations constrain the conclusions of this study. Assignment mechanism: Participants were not randomly assigned to conditions. Although baseline equivalence was confirmed on pre-assessment scores, non-random allocation means that unobserved confounders (e.g., motivation, IT literacy, prior cybersecurity exposure, or risk tolerance) could differ between groups. Future studies should Okwata and Razzaque: Preprint submitted to Elsevier
employ stratified random assignment, ideally with preregistration. Sample size and power: The achieved sample of 𝑛 = 74 was below the pre-specified target of 100. A power analysis for a one-tailed 𝑡-test at 𝛼 = .05 and 𝑑 = 0.62 suggests approximately 90% power at 𝑛 = 76 total, so the study is adequately powered for the observed effect, but replication with larger samples is needed to obtain stable effect size estimates. Outcome instrument: The four-item author-developed MCQ is not validated, contains non-parallel pre/post items, and exhibits a ceiling effect after effective training. Future studies should use a validated multi-item cybersecurity awareness scale such as the HAIS-Q [29] or the Security Behaviour Intentions Scale (SeBIS), which would provide better measurement fidelity and enable meaningful subgroup comparisons. Ceiling effect: The concentration of personality-conditional post-scores at 30 and 40 marks indicates that the postassessment was too easy for participants who received effective training, making it impossible to detect fine-grained differences in knowledge acquisition. A more sensitive instrument with items at multiple difficulty levels is essential for future evaluations. BFI-10 psychometric limitations: Individual-level routing based on BFI-10 argmax scores is psychometrically problematic given the instrument’s two-item-per-trait structure and moderate retest reliability [34, 43]. Future research should compare BFI-10 and BFI-44 routing decisions in the same sample to quantify the misassignment rate or use the NEO-PI-3 for higher measurement reliability. Differential incentive in the Extraversion module: The simulated loyalty-point reward offered to participants in the Extraversion training module introduces a differential extrinsic incentive that may have inflated engagement and post-assessment performance for participants routed to this module, confounding trait-specific effects. Future studies should equate incentive structures across modules. Selection bias from sideloading attrition: The 33.9% attrition is almost entirely attributable to the requirement to sideload an unsigned APK, which preferentially selects technically confident participants. The completer sample is therefore not representative of the general population, limiting generalisability. Deployment through an official app store or a web-based platform would address this bias. Single session and no retention follow-up: The study used a single training session with an immediate postassessment, providing no information about knowledge retention over time. A follow-up assessment at four weeks or three months is essential to evaluate whether personalityconditional training produces durable knowledge gains. Missing ANCOVA: A more rigorous analysis would use ANCOVA with the pre-assessment score as a covariate, which provides better control for baseline individual differences than a post-score-only comparison, even when groups are baseline-equivalent. This analysis was precluded here by the non-parallel nature of the pre/post instruments (different Page 11 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
scenarios) but should be implemented in future studies using parallel forms. Specific future work priorities, in order of impact, are: (1) a pre-registered randomised replication with stratified allocation by personality profile and 𝑛 ≥ 150; (2) adoption of the HAIS-Q as the primary outcome measure; (3) addition of BFI-44 for reliability comparison with BFI-10 routing decisions; (4) a four-week knowledge retention follow-up; (5) equalisation of incentive structures across training modules; (6) deployment through an official app store to eliminate sideloading selection bias; (7) screen-level engagement logging from Firebase Analytics to enable fidelity cheques; and (8) trait × condition interaction analysis to test whether specific trait–module pairings drive the overall effect.
Data Availability Statement The anonymised aggregate data supporting the results reported in this paper (pre- and post-assessment score distributions, BFI-10 subscale scores by routing group) are available from the corresponding author on reasonable request. Individual-level data are not publicly available to protect participant anonymity.
Acknowledgements The authors thank the 74 participants who voluntarily contributed their time to this study, and acknowledge the support of the School of Computing, Engineering and Digital Technologies at Teesside University in facilitating ethical oversight of the research.
8. Conclusions This paper presents the design, implementation, and quasi-experimental evaluation of TailoredSec, a mobile cybersecurity awareness application that routes training content based on users’ dominant Five-Factor Model personality trait as measured by the BFI-10. Across a sample of 74 UK-based adults allocated to a personality-conditional (𝑛 = 34) or traditional (𝑛 = 40) training condition, the personality-conditional group achieved a significantly higher post-assessment score (Welch’s 𝑡(58.5) = −2.81, 𝑝 = .003, Cohen’s 𝑑 = 0.62, 95 % CI [1.47, 8.79] marks) and a higher pass-rate (100% vs 77.5%; Fisher’s exact 𝑝 < .01), despite no significant pre-assessment difference between groups (𝑡(69.1) = 0.43, 𝑝 = .67). The application was rated highly usable by 85.3% of 68 feedback respondents. These results support the idea that routing training content by personality traits is feasible and worth pursuing more rigorously. The study contributes both a fully specified proof-of-concept system—routing algorithm, content mapping, and BFI-10 scoring all documented to replication standards—and an empirical baseline for comparison. The ceiling effect, BFI-10 routing reliability, and sideloading attrition documented here translate directly into a concrete list of what any follow-on study must fix. Deploying personality-based training is becoming cheaper as smartphones become standard corporate equipment. This study shows that even the simplest version—ten extra questionnaire items before a single training session—produced a measurable advantage over a generic video. Whether that advantage holds at scale, over time, and with a validated outcome measure is the question the field now needs to answer.
Declaration of Competing Interest The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.
Okwata and Razzaque: Preprint submitted to Elsevier
References [1] Verizon, 2023 Data Breach Investigations Report, 2023. URL: https: //www.verizon.com/business/resources/reports/dbir/, [Online; accessed 2024-01-10]. [2] N. Mashtalyar, U. Rupasinghe, S. Bhullar, Social engineering attacks: Recent advances and challenges, in: HCI for Cybersecurity, Privacy and Trust: Third International Conference, HCI-CPT 2021, Springer, 2021. doi:10.1007/978-3-030-77392-2_27. [3] K. Babcock, Human error causes 60% of data breaches: How to protect your organization | bitwarden, 2026. URL: https://bitwarden.com/blog/ how-to-protect-your-organization-from-human-error-and-data-breaches/,
[Online; accessed 2026-05-12]. [4] M. Gupta, C. Akiri, K. Aryal, E. Parker, L. Praharaj, From ChatGPT to ThreatGPT: Impact of generative AI in cybersecurity and privacy, IEEE Access 11 (2023) 80218–80245. [5] M. Aslam, Ai and cybersecurity: an ever-evolving landscape, International Journal of Advanced Engineering Technologies and Innovations 1 (2024) 52–71. [6] K. Khando, S. Gao, S. M. Islam, A. Salman, Enhancing employees information security awareness in private and public organisations: A systematic literature review, Computers & Security 106 (2021) 102267. [7] H. Aldawood, G. Skinner, Reviewing cyber security social engineering training and awareness programs—pitfalls and ongoing issues, Future Internet 11 (2019) 73. [8] M. Workman, Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security, Journal of the American Society for Information Science and Technology 59 (2008) 662–674. [9] J. Bullée, L. Montoya, W. Pieters, M. Junger, P. Hartel, On the anatomy of social engineering attacks: A literature-based dissection of successful attacks, Journal of Investigative Psychology and Offender Profiling 15 (2018) 20–45. [10] P. Kim, J. Homan, R. Metzer, How long do employees remember information security training programs? a study of knowledge acquisition and retention, Issues in Information Systems 17 (2016). [11] H. El-Sabagh, Adaptive e-learning environment based on learning styles and its impact on development students’ engagement, International Journal of Educational Technology in Higher Education 18 (2021) 1–24. [12] R. R. McCrae, O. P. John, An introduction to the five-factor model and its applications, Journal of Personality 60 (1992) 175–215. [13] A. T. Shappie, C. A. Dawson, S. M. Debb, Personality as a predictor of cybersecurity behavior, Psychology of Popular Media Culture 9 (2019) 475–480.
Page 12 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait [14] M. Gratian, S. Bandi, M. Cukier, J. Dykstra, A. Ginther, Correlating human traits and cyber security behaviour intentions, Computers & Security 73 (2018) 345–358. [15] D. Baltuttis, T. Teubner, M. T. Adam, A typology of cybersecurity behavior among knowledge workers, Computers & Security 140 (2024) 103741. [16] S. M. Kennison, E. Chan-Tin, Taking risks with cybersecurity: Using knowledge and personal characteristics to predict self-reported cybersecurity behaviors, Frontiers in Psychology 11 (2020) 546546. [17] S. Kalhoro, R. K. Ayyasamy, A. Jebna, A. Kalhoro, K. Krishnan, S. Nodeson, How personality traits impact on cyber security behaviors of SME employees, in: 2022 International Conference on Innovation and Intelligence for Informatics, Computing, and Technologies (3ICT), IEEE, 2022, pp. 635–641. [18] S. M. Albladi, G. R. Weir, Personality traits and cyber-attack victimisation: Multiple mediation analysis, in: 2017 Internet of Things Business Models, Users, and Networks, IEEE, 2017, pp. 1–6. doi:10.1109/CTTE.2017.8260932. [19] T. Halevi, J. Lewis, N. Memon, Cultural and psychological factors in cyber-security, in: Proceedings of the 18th International Conference on Information Integration and Web-based Applications and Services, ACM, 2016, pp. 318–324. [20] S. T. Lawson, M. Yeo, H. Hansen, E. Pearson, Phishing for long tails: Examining organizational repeat-clickers and non-clickers following a phishing simulation campaign, Computers & Security 99 (2020) 102064. [21] S. Uebelacker, S. Quiel, The social engineering personality framework, in: 2014 Workshop on Socio-Technical Aspects in Security and Trust, IEEE, 2014, pp. 24–30. doi:10.1109/STAST.2014.12. [22] R. Cialdini, Influence: The Psychology of Persuasion, HarperCollins, New York, 2009. [23] R. Gianotti, S. Cazella, P. Behar, A model for integrating personality traits into an educational recommender system, in: 2019 IEEE 19th International Conference on Advanced Learning Technologies (ICALT), 2019. doi:10.1109/ICALT.2019.00119. [24] S. Thorp, L. Rimol, S. Grassini, Association of the Big Five personality traits with training effectiveness, sense of presence, and cybersickness in virtual reality, Multimodal Technologies and Interaction 7 (2023). [25] F. Mouton, M. M. Malan, L. Leenen, H. Venter, Social engineering attack framework, in: 2014 Information Security for South Africa, 2014, pp. 1–9. doi:10.1109/ISSA.2014.6950510. [26] C. Hadnagy, Social engineering: The art of human hacking (2011). [27] M. Zwilling, G. Klien, D. Lesjak, Ł. Wiechetek, F. Cetin, H. N. Basim, Cyber security awareness, knowledge and behavior: A comparative study, Journal of Computer Information Systems 62 (2022) 82–97. [28] L. A. Tawalbeh, F. Muheidat, Factors that motivate defense against social engineering attacks across organizations, Procedia Computer Science 224 (2023) 75–82. [29] K. Parsons, D. Calic, M. Pattinson, M. Butavicius, A. McCormac, T. Zwaans, The development of the Human Aspects of Information Security Questionnaire (HAIS-Q): Testing reliability and validity, Computers & Security 69 (2017) 506–517. [30] A. Furnham, Personality and learning style: A study of three instruments, Personality and Individual Differences 13 (1992) 429–438. [31] M. Komarraju, S. J. Karau, R. R. Schmeck, A. Avdic, The Big Five personality traits, learning styles, and academic achievement, Personality and Individual Differences 51 (2011) 472–477. [32] J. Du, et al., An analysis of influence factors for academic performance about personality traits and thinking styles of students, in: 2017 12th International Conference on Computer Science and Education (ICCSE), 2017. doi:10.1109/ICCSE.2017.8085483. [33] T. Halevi, J. Lewis, N. Memon, Spear-phishing in the wild: A realworld study of personality, phishing self-efficacy and vulnerability to spear-phishing attacks, Social Science Research Network (2013). [34] B. Rammstedt, O. P. John, Measuring personality in one minute or less: A 10-item short version of the Big Five Inventory in English and German, Journal of Research in Personality 41 (2007) 203–212.
Okwata and Razzaque: Preprint submitted to Elsevier
[35] D. Papatsaroucha, Y. Nikoloudakis, I. Kefaloukos, E. Pallis, E. K. Markakis, A survey on human and personality vulnerability assessment in cyber-security: Challenges, approaches, and open issues, 2021. arXiv:2106.11625. [36] I. Alseadoon, M. Othman, S. Tang, Who is more susceptible to phishing emails? a Saudi Arabian study, Jurnal Teknologi 64 (2013). [37] B. Roberts, C. Lejuez, R. Krueger, J. Richards, P. Hill, What is conscientiousness and how can it be assessed?, Developmental Psychology 50 (2012) 1315–1330. [38] G. Bansal, F. Zahedi, D. Gefen, The impact of personal dispositions on information sensitivity, privacy concern and trust in disclosing health information online, Decision Support Systems 49 (2010) 138– 150. [39] S. Lai, et al., Automatic personality identification using students’ online learning behavior, IEEE Transactions on Learning Technologies 13 (2020) 26–37. [40] F. Giannakas, G. Kambourakis, S. Gritzalis, CyberAware: A mobile game-based app for cybersecurity education and awareness, in: 2015 International Conference on Interactive Mobile Communication Technologies and Learning (IMCL), 2015. doi:10.1109/IMCTL.2015. 7359553. [41] S. Sudha, et al., Impact of smartphone-based interactive learning modules on cybersecurity learning at the high-school level, in: 2023 IEEE Global Engineering Education Conference (EDUCON), 2023. doi:10.1109/EDUCON54358.2023.10125124. [42] O. P. John, E. M. Donahue, R. Kentle, Big Five Inventory (BFI), 1991. doi:10.1037/t07550-000. [43] B. Rammstedt, C. Beierlein, Can’t we make it any shorter? the limits of personality assessment and ways to overcome them, Journal of Individual Differences 35 (2014) 212–220. [44] M. Ahmad, Analysis of cross-platform mobile application development frameworks, International Journal of Innovative Technology and Exploring Engineering (2023). [45] FlutterFlow, FlutterFlow: Build high quality, customised apps quickly, 2024. URL: https://www.flutterflow.io/, [Online; accessed 202506-17]. [46] Google, Firestore | firebase, 2025. URL: https://firebase.google. com/docs/firestore, [Online; accessed 2025-06-17]. [47] P. Hidayanti, R. Handayani, B. Rifai, UI/UX design of online tickets for situ pasir maung tourism using the Figma application, SinkrOn 8 (2023) 1051–1063. [48] I. Blau, O. Weiser, Y. Eshet-Alkalai, Face-to-face versus one-way and two-way videoconferencing: How medium naturalness and personality traits influence achievement and perceived learning, in: 2016 11th Iberian Conference on Information Systems and Technologies (CISTI), 2016. doi:10.1109/CISTI.2016.7521581. [49] J. Isoaho, P. Nikander, Cybersecurity education: Bridging the gap between theory and practice, IEEE Security & Privacy 19 (2021) 70–76.
A. Consent Notification Text The following text was displayed on the application’s onboarding screen prior to commencement of the preassessment: Dear Participant, Thank you for considering participating in this survey. By completing and submitting the quiz and survey, you consent to participate voluntarily. Your responses will be kept confidential; contact details are provided in the information sheet if you have any concern. Thank you for your participation.
Page 13 of 14
Routing Cybersecurity Awareness Training by FFM Personality Trait
B. BFI-10 Questionnaire Items Participants rated their agreement with the following ten items on a five-point Likert scale (1 = Disagree strongly, 5 = Agree strongly). Items marked (R) were reverse-scored. Items and scoring algorithm from Rammstedt and John [34]. I see myself as someone who. . . 1. . . . is reserved. (Extraversion, R) 2. . . . is generally trusting. (Agreeableness) 3. . . . tends to be lazy. (Conscientiousness, R) 4. . . . is relaxed, handles stress well. (Neuroticism, R) 5. . . . has few artistic interests. (Openness, R) 6. . . . is outgoing, sociable. (Extraversion) 7. . . . tends to find fault with others. (Agreeableness, R) 8. . . . does a thorough job. (Conscientiousness) 9. . . . gets nervous easily. (Neuroticism) 10. . . . has an active imagination. (Openness)
C. Assessment Quiz Questions Pre-Assessment Scenarios (four items) Q1. You find a USB drive in your mailbox with a note stating it contains sensitive business data your company needs. What should you do? a. Immediately plug the USB drive into your computer to access the data b. Inform your company’s IT department about the found USB drive [correct] c. Copy the contents to your personal computer to investigate d. Connect the USB drive to an isolated computer to check its contents Q2. You receive a call from your bank asking you to verify account details to prevent unauthorised access. The caller knows some of your personal information. What is the best course of action? a. Provide the requested information to ensure your account’s security b. Politely hang up and call your bank using the official number from their website [correct] c. Ask the caller for their name and credentials before proceeding d. Request that the caller send you an official email for verification Q3. You receive an email from what appears to be a colleague urgently requesting a confidential client database. The email contains your colleague’s name, title, and company signature. What should you do? a. Share the database immediately to meet the urgent request b. Verify the request by calling your colleague on their known phone number [correct] c. Request approval from your supervisor before taking any action Okwata and Razzaque: Preprint submitted to Elsevier
d. Reply to the email asking for additional verification Q4. A stranger in the office car park identifies themselves as a new employee who forgot their access card and asks you to swipe them in. What should you do? a. Swipe them in as the property is heavily guarded b. Request to see their company ID access card before swiping them in c. Politely decline and direct them to obtain access through the proper channel [correct] d. Swipe them in to be helpful since they are a new employee
Post-Assessment Scenarios (four items) Q1. A colleague asks you to hold the door open for them to enter a secure area without using their access card. What should you do? a. Hold the door open to be courteous b. Politely refuse and ask them to use their access card [correct] c. Allow them entry without questioning d. Report the incident to security Q2. You receive an email informing you that you have won a prize and need to click a link to claim it. What action should you take? a. Click the link to claim your prize b. Forward the email to colleagues for confirmation c. Delete the email without clicking the link [correct] d. Click the link but do not provide any personal information Q3. You find a USB drive labelled “Employee Bonus Details” in the office car park. What should be your immediate action? a. Plug it into your computer to check the contents b. Report it to the IT department [correct] c. Take it home and examine its contents later d. Give it to a colleague to check Q4. During a work conference, a person you do not know well asks about your job role, current projects, and requests some internal company information. What is the most appropriate response? a. Politely decline to share internal information and report the interaction to your security team [correct] b. Share the information since you are at a professional conference c. Share a limited amount of information to appear cooperative d. Ask the person for their business card before responding
Page 14 of 14