The sudden and complete dominance of social media by a few select companies has often led users to feel at odds with the rapidly changing business strategies in digital environments. One practice, the secondary use of personal information, has received limited attention in privacy behavior research. While many people remain unaware of how much of their data is collected, the secondary use of personal information, using personal information for reasons beyond the original transaction, is an increasing concern among social media users. Grounded in privacy calculus theory, this study aimed to propose and empirically test a research model regarding user concerns about secondary data use and its impact on self-disclosure intentions on Facebook. Privacy calculus research seeks to explain the privacy paradox, which refers to the disconnect between individuals' privacy concerns and their actual behavior. We posit that users are not perfectly rational but rather operate under conditions of bounded rationality, shaped by both real-world and engineered constraints, particularly evident in secondary data use practices. The findings demonstrate that concerns about the secondary use of personal information significantly diminish users' perceived benefits and heighten their perceived risks. Despite this, users continue to perceive that the benefits of information disclosure outweigh the risks. Our findings suggest that the opaque, multilayered nature of secondary data use on social media platforms exemplifies the conditions of bounded rationality under which users operate. Faced with limited information, cognitive constraints, and complex data ecosystems, individuals engage in satisficing behaviors that inadvertently increase their vulnerability to exploitation. Building on this observation, we extend privacy calculus by modeling disclosure decisions under bounded rationality and by centering secondary data use as the key driver of privacy concerns.
Malicious insiders remain among the most persistent cybersecurity concerns, yet existing frameworks often overlook the psychological predispositions that drive unethical intent. This study examines how Machiavellianism, a dark personality trait characterized by manipulation, strategic self-interest, and moral disengagement, influences the elements of the well-established criminological framework of the Fraud Triangle to shape insider threat intention. Using a sample of 768 full-time U.S.-based employees and partial least squares structural equation modeling (PLS-SEM), the analysis investigates how Machiavellianism affects perceptions of pressure, opportunity, and rationalization. Results reveal that Machiavellianism significantly influences all three constructs, with rationalization emerging as the strongest and most significant pathway to the intention to commit malicious insider behavior. These findings highlight how individuals high in Machiavellianism cognitively justify unethical actions, positioning rationalization as a key psychological mechanism in threat formation. Theoretically, this study extends insider threat literature by demonstrating the relevance of personality traits, specifically Machiavellianism, in shaping key situational perceptions. It advances understanding of the Fraud Triangle by emphasizing justification not merely as a cognitive condition, but as a pivotal mechanism through which individuals justify malicious intent. By integrating a dark personality trait into a situational framework, this study refines our understanding of how insider threats emerge and supports more behaviorally informed approaches to cybersecurity risk modeling.
The rapid proliferation of cybersecurity automation is transforming Security Operations Centers (SOCs), introducing new complexities to operational dynamics and altering the traditional role of the security analyst. This rapid deployment, particularly with the rise of generative AI, increases analysts' susceptibility to an uncritical overreliance on technology, a phenomenon known as automation bias, which presents a significant human-factor vulnerability. To investigate this vulnerability, this study uses a multigroup approach to analyze how an analyst's fundamental preference for human versus automation-led activity moderates their perception and use of cybersecurity tools. We conducted a mixed-methods study, comprising a quantitative structural model with 661 participants (N = 440 human-centered and N = 221 automation-centered analysts) and qualitative interviews with 40 analysts. Participant preferences were reassessed 12 months later. Our findings reveal two distinct analyst profiles with opposing risks. Pro-automation analysts practice cognitive offloading, achieving efficiency but fostering a vulnerability to confirmation bias, evidenced by a counterintuitive positive link between systematic thinking and automation bias. Conversely, pro-human analysts experience cognitive tethering, in which inherent skepticism may be linked to disuse of automation and a vulnerability to cognitive overload. Further group differences were revealed in the optimal levels of automation selected, with participants in the pro-automation group doubling down on their willingness for security tools to possess complete autonomy, opting for levels 7-10 where human involvement is minimal. This study contributes a framework for understanding the human factor in cybersecurity by identifying preference as a key moderator of socio-technical risk, providing a basis for tailored training, intelligent task allocation, and balanced team composition.
The video game market is forecasted to be valued at $321.6 billion by 2027. Today, younger generations increasingly prefer spending their leisurely time playing online video games. Beyond providing a leisurely – and often competitive – activity to the bulk of its user base, online video games provide cybercriminals with an environment that is free from the reigns of legal enforcement. More specifically, with the growing popularity and uptake of the microtransaction business model, money launderers are provided with novel channels to move their illicitly gained funds. A continuously expanding body of evidence underscores that money laundering is occurring through online video games. Foremost, cybercriminals are attracted to the anonymity and global reach offered by online video games with few to no controls currently in place to disrupt laundering processes. Furthermore, regulations are struggling to keep pace with the latest money laundering strategies employed by cybercriminals. This paper explores and discusses money laundering in the context of online video games. Core vulnerabilities enabling money laundering to occur through online video games are identified. Security controls to reduce the scale of laundering are proposed.
Cybercrime is often assumed to be limited to more mature economic sectors. Yet, cybercrime is known to migrate to less tightly regulated domains—including online video gaming. Account compromise and virtual asset theft is a challenge that confronts the entire online video gaming industry. Increasingly, video game companies are required to promptly identify malicious online activity and take prompt remedial action. This paper conducts a social network analysis of 358,054 Roblox users that participated in the Roblox virtual asset marketplace over a 12-month period. Results from a multiple logistic regression analysis provide video game companies with actionable findings that can be leveraged during the implementation of organizational security controls, including policy, governance mechanism and system design decisions. Key findings reveal that the prosocial nature of online gamers’ friendship circles play a central role in determining the likelihood that accounts are banned for malicious account activity. Third-party trading website usage, posting trade advertisements as part of a social engineering exploit, and the age of user accounts constitute further risk factors that should be accounted for when managing customer risk. To complement the regression analysis, five classifiers were trained with social network-derived features. Cross-validated results show that network-derived features have strong discriminative power and should form part of a defense-in-depth approach to combatting cybercrime in online video gaming.
Virtual assets distributed in online video games are a novel medium of exchange that are exploited for fraud and money laundering because of the low-risk environment within which the assets are exchanged. Virtual asset marketplaces inadvertently facilitate money laundering operations by functioning as critical entry and exit points for illicit proceeds. While prevailing scholarly discussion emphasizes the suitability of online video games to small-scale laundering operations, this paper challenges that perspective. A three-part argument is formulated which demonstrates the occurrence of large-scale money laundering in the online video gaming ecosystem. Analyzing virtual asset sales on three marketplaces over a 12-month period reveals significant marketplace vulnerabilities which can (and are) exploited by cybercriminals. Employing Bayesian confirmation theory, this paper combines empirical analysis with further corroborating items of evidence to demonstrate the occurrence of large-scale virtual laundering. The results provide scholars, practitioners and regulatory bodies a foundation on which future interdisciplinary research and discussion can build to mitigate cybercrime-related harms inflicted on society.
Purpose Researchers looking for ways to change the insecure behaviour that results in phishing have considered multiple possible reasons for such behaviour. Therefore, the purpose of this paper is to understand the role of optimism bias (OB – defined as a cognitive bias), which characterises overly optimistic or unrealistic individuals, to ensure secure behaviour. Research that focused on issues such as personality traits, trust, attitude and Security, Education, Training and Awareness (SETA) was considered. Design/methodology/approach This study built on a recontextualized version of the theory of planned behaviour to evaluate the influence that optimism bias has on phishing susceptibility. To model the data, an analysis was performed on 226 survey responses from a South African financial services organisation using partial least squares (PLS) path modelling. Findings This study found that overly optimistic employees were inclined to behave insecurely, while factors such as attitude and trust significantly influenced the intention to behave securely. Practical implications Our contribution to practice seeks to enhance the effectiveness of SETA by identifying and addressing the optimism bias weakness to deliver a more successful training outcome. Originality/value Our study enriches the Information Systems literature by evaluating the effect of a cognitive bias on phishing susceptibility and offers a contextual explanation of the resultant behaviour.
The volume and complexity of alerts that security operation center (SOC) analysts must manage necessitate automation. Increased automation in SOCs amplifies the risk of automation bias and complacency whereby security analysts become over-reliant on automation, failing to seek confirmatory or contradictory information. To identify automation characteristics that assist in the mitigation of automation bias and complacency, we investigated the current and proposed application areas of automation in SOCs and discussed its implications for security analysts. A scoping review of 599 articles from four databases was conducted. The final 48 articles were reviewed by two researchers for quality control and were imported into NVivo14. Thematic analysis was performed, and the use of automation throughout the incident response lifecycle was recognized, predominantly in the detection and response phases. Artificial intelligence and machine learning solutions are increasingly prominent in SOCs, yet support for the human-in-the-loop component is evident. The research culminates by contributing the SOC Automation Implementation Guidelines (SAIG), comprising functional and non-functional requirements for SOC automation tools that, if implemented, permit a mutually beneficial relationship between security analysts and intelligent machines. This is of practical value to human automation researchers and SOCs striving to optimize processes. Theoretically, a continued understanding of automation bias and its components is achieved.
In spite of increasing attacks against crypto-currency platforms, involving staggeringly large amounts of money, there has been surprisingly little research into how the blockchain infrastructure at the core of these platforms could be enhanced to improve security. This study examines security weaknesses in public blockchains in an attempt to gain a clearer view of the vulnerabilities.
The dynamic nature in which sophisticated cyberattacks are being launched has resulted in novel threat actor techniques. This renders traditional security approaches less effective. Therefore, organizations must adapt their security controls, placing an increased emphasis on detective and corrective controls (i.e., response and recovery mechanisms). These efforts promote resilient systems capable of rapidly recovering from cyberattacks and adapting their behavior based on the organization's updated environmental conditions. This paper applies the uncertainty reduction theory, arguing that the cybersecurity community must embrace uncertainty as an opportunity for improvement. To date, research on incident response has predominantly focused on the resilience of recovery mechanisms, falling short of discussing how systems improve post-disruption. This work offers a novel investigation into systems that have been enhanced as a result of experiencing disruption within the context of cybersecurity, termed antifragile systems. Chaos engineering represents a prominent method for resilience engineering, also offering applicability to the achievement of antifragility. This is accomplished by exposing systems to short-term stressors and adversity in a controlled environment to establish long-term operational sustainability. This paper contributes to the cybersecurity incident response literature by developing The Resilient System Model, defining five system classifications: fragile, reliable, robust, recovery, and antifragile. This is necessary because these system classifications are sometimes incorrectly defined and are applied inconsistently. Organizational systems must strive to be as in line with the model as possible – where their strengths lie in anticipatory practices, gradual system improvement, and controlled experiments that foster learning initiatives.
The continuous integration of automated tools into security operation centers (SOCs) increases the volume of alerts for security analysts. This amplifies the risk of automation bias and complacency to the point that security analysts have reported missing, ignoring, and not acting upon critical alerts. Enhancing the SOC environment has predominantly been researched from a technical standpoint, failing to consider the socio-technical elements adequately. However, our research fills this gap and provides practical insights for optimizing processes in SOCs. The synergy between security analysts and automation can potentially augment threat detection and response capabilities, ensuring a more robust defense if effective human-automation collaboration is established. A scoping review of 599 articles from four databases led to a final selection of 49 articles. Thematic analysis resulted in 609 coding references generated across four main themes: SOC automation challenges, automation application areas, implications on analysts, and human factor sentiment. Our findings emphasize the extent to which automation can be implemented across the incident response lifecycle. The SOC Automation Matrix represents our primary contribution to achieving a mutually beneficial relationship between analyst and machine. This matrix describes the properties of four distinct human-automation combinations. This is of practical value to SOCs striving to optimize their processes, as our matrix mentions socio-technical system characteristics for automated tools.
Purpose This paper aims to investigate how best to classify money laundering through online video games (i.e. virtual laundering). Currently, there is no taxonomy available for scholars and practitioners to refer to when discussing money laundering through online video games. Without a well-defined taxonomy it becomes difficult to reason through, formulate and implement effective regulatory measures, policies and security controls. As such, efforts to prevent and reduce virtual laundering incidence rates are hampered. Design/methodology/approach This paper proposes three mutually exclusive virtual laundering categorizations. However, instead of fixating on the processes undergirding individual instances of virtual laundering, it is argued that focusing on the initial locale of the illicit proceeds provides the appropriate framing within which to classify instances of virtual laundering. Thus, the act of classification becomes an ontological endeavour, rather than an attempt at elucidating an inherently varied process (as is common of the placement, layering and integration model). Findings A taxonomy is proposed that details three core virtual laundering processes. It is demonstrated how different virtual laundering categories have varied levels of associated risk, and thus, demand unique interventions. Originality/value To the best of the authors’ knowledge, this is the first taxonomy available in the knowledge base that systematically classifies instances of virtual laundering. The taxonomy is available for scholars and practitioners to use and apply when discussing how to regulate and formulate legislation, policies and appropriate security controls.
Frequent and habitual engagement with social media can reinforce certain activities such as sharing, clicking hyperlinks, and liking, which may be performed with insufficient cognition. In this study, we aimed to examine the associations between personality traits, habits, and information processing to identify social media users who are susceptible to phishing attacks. Our experimental data consisted of 215 social media users. The results revealed two important findings. First, users who scored high on the personality traits of extraversion, agreeableness, and neuroticism were more likely to engage in habitual behaviors that increase their susceptibility to phishing attacks, whereas those who scored high on conscientiousness were less likely. Second, users who habitually react to social media posts were more likely to apply heuristic processing, making them more susceptible to phishing attacks than those who applied systematic processing.
Self-disclosure as influenced by perceived risks and benefits plays an important role within the context of social media use and the associated privacy risk. Some social media platforms, like Facebook (now part of Meta Platforms Inc.), provide users with elaborate means to control privacy risk. Conversely, Instagram (also part of Meta) provides users with fewer such mechanisms as a function of self-disclosure. Therefore, self-disclosure as a product of risk and benefit assessment may differ considerably as a function of the technological affordances that control such disclosure. This is particularly the case considering that such a benefit and risk assessment is further influenced by a user's trust in that provider, not to mention their proclivity for disclosing without any rational risk and benefit assessments, as is the case when disclosing as a function of fear of missing out (FoMO). Given the influence that provider trust and FoMO might have when assessing risks and benefits, this study evaluated the extent to which perceived risks and benefits mediate self-disclosure on Facebook and Instagram, in particular within the context of provider trust and FoMO. Based on an adapted version of privacy calculus, we evaluated our research model by analyzing 720 survey responses using partial least squares path modeling. Our results indicate that perceived benefits mediate the relationship between FoMO and intention to self-disclose when using Instagram, but not when using Facebook. Additionally, we found perceived benefits and perceived risks to mediate the relationship between trust in provider and intention to self-disclose for Facebook and Instagram. Surprisingly, we found no evidence to suggest that the relationship between FoMO and intention to self-disclose is mediated by perceived risks when using Facebook, with the converse being true when using Instagram. We conclude that the transitory (ephemeral) nature of some methods of self-disclosure on Instagram are used as a means to mitigate privacy risks. (c) 2022 Elsevier Ltd. All rights reserved.
Online users are responsible for protecting their online privacy themselves: the mantra is custodiat te (protect yourself). Even so, there is a great deal of evidence pointing to the fact that online users generally do not act to preserve the privacy of their personal information, consequently disclosing more than they ought to and unwisely divulging sensitive information. Such self-disclosure has many negative consequences, including the invasion of privacy and identity theft. This often points to a need for more knowledge and awareness but does not explain why even knowledgeable users fail to preserve their privacy. One explanation for this phenomenon may be attributed to online privacy fatigue. Given the importance of online privacy and the lack of integrative online privacy fatigue research, this scoping review aims to provide researchers with an understanding of online privacy fatigue, its antecedents and outcomes, as well as a critical analysis of the methodological approaches used. A scoping review based on the PRISMA-ScR checklist was conducted. Only empirical studies focusing on online privacy were included, with nontechnological studies being excluded. All studies had to be written in English. A search strategy encompassing six electronic databases resulted in eighteen eligible studies, and a backward search of the references resulted in an additional five publications. Of the 23 studies, the majority were quantitative (74%), with fewer than half being theory driven (48%). Privacy fatigue was mainly conceptualized as a loss of control (74% of studies). Five categories of privacy fatigue antecedents were identified: privacy risk, privacy control and management, knowledge and information, individual differences, and privacy policy characteristics. This study highlights the need for greater attention to be paid to the methodological design and theoretical underpinning of future research. Quantitative studies should carefully consider the use of CB-SEM or PLS-SEM, should aim to increase the sample size, and should improve on analytical rigor. In addition, to ensure that the field matures, future studies should be underpinned by established theoretical frameworks. This review reveals a notable absence of privacy fatigue research when modeling the influence of privacy threats and invasions and their relationship with privacy burnout, privacy resignation, and increased self-disclosure. In addition, this review provides insight into theoretical and practical research recommendations that future privacy fatigue researchers should consider going forward.
Purpose The average employee spends a total of 18.6 h every two months on password-related activities, including password retries and resets. The problem is caused by the user forgetting or mistyping the password (usually because of character switching). The source of this issue is that while a password containing combinations of lowercase characters, uppercase characters, digits and special characters (LUDS) offers a reasonable level of security, it is complex to type and/or memorise, which prolongs the user authentication process. This results in much time being spent for no benefit (as perceived by users), as the user authentication process is merely a prerequisite for whatever a user intends to accomplish. This study aims to address this issue, passphrases that exclude the LUDS guidelines are proposed. Design/methodology/approach To discover constructs that create security and to investigate usability concerns relating to the memory and typing issues concerning passphrases, this study was guided by three theories as follows: Shannon’s entropy theory was used to assess security, chunking theory to analyse memory issues and the keystroke level model to assess typing issues. These three constructs were then evaluated against passwords and passphrases to determine whether passphrases better address the security and usability issues related to text-based user authentication. A content analysis was performed to identify common password compositions currently used. A login assessment experiment was used to collect data on user authentication and user – system interaction with passwords and passphrases in line with the constructs that have an impact on user authentication issues related to security, memory and typing. User–system interaction data was collected from a purposeful sample size of 112 participants, logging in at least once a day for 10 days. An expert review, which comprised usability and security experts with specific years of industry and/or academic experience, was also used to validate results and conclusions. All the experts were given questions and content to ensure sufficient context was provided and relevant feedback was obtained. A pilot study involving 10 participants (experts in security and/or usability) was performed on the login assessment website and the content was given to the experts beforehand. Both the website and the expert review content was refined after feedback was received from the pilot study. Findings It was concluded that, overall, passphrases better support the user during the user authentication process in terms of security, memory issues and typing issues. Originality/value This research aims at promoting the use of a specific type of passphrase instead of complex passwords. Three core aspects need to be assessed in conjunction with each other (security, memorisation and typing) to determine whether user-friendly passphrases can support user authentication better than passwords.
Increased urbanization against the backdrop of limited resources complicates city planning and the management of functions, including public safety. The smart city concept can help, but most previous smart city systems have focused on utilizing automated sensors and analyzing quantitative data. In developing nations, limited resources make using the mobile phone to enable the crowdsourcing of qualitative public safety reports from the public a more viable option. However, there is no best practice for analyzing such citizen reports for a smart city in a developing nation. Given the rise of megacities in developing nations, many of which struggle to provide access to vital resources, this study developed and tested a model for guiding the analysis of unstructured natural language texts instead of traditional sensory data. In the study, citizens engaged with the project and 663 usable reports were received. Following a design science approach, the model was developed through an extensive review of related literature, and assessed and refined by observing the associated model prototype. This study emphasizes that a city-specific ontology needs to be developed and that natural language processing should be its focus, specifically within the larger context of our smart city qualitative data analysis (SCQDA) model. Together, these aspects enable this study to contribute practically, as we prove that cities in developing nations can improve the lives of their citizens using that which is already at their disposal instead of specialized (and often expensive) sensory networks.