Comportamientos humanos de riesgo en la ciberseguridad: Un análisis de contraseñas débiles, falta de actualización y clics en enlaces no verificados.

Autores/as

  • Alberto Jair Cruz Landa 📩 Universidad Veracruzana, México
  • Juan Manuel Gutiérrez Méndez Universidad Veracruzana, México
  • Juan Carlos Jiménez Márquez Universidad Veracruzana, México
  • Martha Elizabet Domínguez Bárcenas Universidad Veracruzana, México
  • Alicia Yazmín Rojas Luna Universidad Veracruzana, México

Palabras clave:

Ciberseguridad, comportamiento humano, contraseñas débiles, actualización de software, enlaces no verificados, vulnerabilidad.

Resumen

Los comportamientos humanos relacionados con el uso de contraseñas débiles, la falta de actualizaciones de software y la interacción con hipervínculos no verificados, conllevan riesgos en el ámbito de la ciberseguridad. Cabe destacar que independientemente de los avances en el ámbito tecnológico el factor humano es responsable en un alto número de incidencias de seguridad, debido a errores, omisiones o decisiones humanas. La literatura en ciberseguridad aún presenta una desconexión entre la identificación de los comportamientos humanos de riesgo, las consecuencias que estos generan y los factores que los originan. Esta falta de articulación limita la comprensión integral del problema y provoca que muchas soluciones propuestas resulten excesivamente técnicas o poco accesibles para el usuario final, dificultando la mitigación efectiva de estas conductas dentro de los sistemas de información. El presente estudio tiene como objetivo analizar las consecuencias asociadas y factores que influyen en los comportamientos humanos de riesgo en ciberseguridad, a través de una revisión sistemática de literatura, con el fin de recuperar estrategias de prevención.

Biografía del autor/a

Juan Manuel Gutiérrez Méndez, Universidad Veracruzana, México

Juan Manuel Gutiérrez Méndez: es Profesor de Tiempo Completo de la Facultad de Estadística e Informática de la Universidad Veracruzana y participa en la Licenciatura en Ciberseguridad e Infraestructura de Cómputo. Su trayectoria profesional y académica se ha desarrollado en los ámbitos de tecnologías de la información, infraestructura tecnológica, desarrollo de software y ciberseguridad. Sus áreas de interés se centran en las tecnologías de la información y la ciberseguridad, particularmente en protección de datos, seguridad de infraestructura, ciberseguridad usable y aplicación de marcos de referencia con una perspectiva tecnológica, organizacional y humana. 

Juan Carlos Jiménez Márquez, Universidad Veracruzana, México

Juan Carlos Jiménez Márquez : es Profesor de Tiempo Completo de la Facultad de Estadística e Informática de la Universidad Veracruzana. Es Licenciado en Informática, Maestro en Comunicación y Tecnologías Educativas y Doctor en Educación. Su trayectoria académica y profesional se ha desarrollado en las áreas de tecnologías de la información, redes, servicios de cómputo, infraestructura tecnológica y ciberseguridad. Sus áreas de interés se centran en ciberseguridad, seguridad de redes e infraestructura, Internet de las Cosas y aplicación de tecnologías emergentes en contextos educativos. 

Martha Elizabet Domínguez Bárcenas, Universidad Veracruzana, México

Martha Elizabet Domínguez Bárcenas. Es Profesora de Tiempo Completo en la Facultad de Estadística e Informática de la Universidad Veracruzana, con adscripción a la Lic. en Ingeniería de Ciberseguridad e Infraestructura de Cómputo. Es Licenciada en Informática y Maestra en Redes y Telecomunicaciones. Su trayectoria académica se ha desarrollado en las áreas de redes e infraestructura tecnológica. En el ámbito de la ciberseguridad, sus áreas de interés se orientan a la seguridad de infraestructura y a la ciberseguridad social. 

Alicia Yazmín Rojas Luna, Universidad Veracruzana, México

Alicia Yazmín Rojas Luna: es Técnico Académico de la Facultad de Estadística e Informática de la Universidad Veracruzana. Es Licenciada en Informática, Maestra en Sistemas Interactivos Centrados en el Usuario y Maestra en Ciberseguridad. Su experiencia académica y profesional se desarrolla en las áreas de Interacción Humano-Computadora, Experiencia de Usuario y Ciberseguridad, con énfasis en diseño centrado en el usuario, evaluación de usabilidad y UX, accesibilidad y seguridad usable. Sus áreas de interés se enfocan en el estudio de la interacción entre las personas y los sistemas digitales, particularmente en privacidad, diseño de experiencias seguras, comportamiento del usuario ante riesgos de ciberseguridad y evaluación de tecnologías interactivas desde una perspectiva humana, tecnológica y de seguridad

Citas

Baki, S., Verma, R., Mukherjee, A., & Gnawali, O. (2017). Scaling and effectiveness of email masquerade attacks: Exploiting natural language generation. En Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (pp. 469–482). Association for Computing Machinery. https://doi.org/10.1145/3052973.3053037

Bilge, L., Han, Y., & Dell’Amico, M. (2017). RiskTeller: Predicting the risk of cyber incidents. En Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1299–1311). Association for Computing Machinery. https://doi.org/10.1145/3133956.3134022

Coker, J. (2025). 95% of data breaches tied to human error in 2024. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/data-breaches-human-error/

Desolda, G., Ferro, L. S., Marrella, A., Catarci, T., & Costabile, M. F. (2021). Human factors in phishing attacks: A systematic literature review. ACM Computing Surveys, 54(8), Article 173, 1–35. https://doi.org/10.1145/3469886

French, L. (2025, 11 de marzo). 95% of data breaches involve human error, report reveals. SC World. https://www.scworld.com/news/95-of-data-breaches-involve-human-error-report-reveals/

Gulenko, I. (2014). Improving passwords: Influence of emotions on security behaviour. Information Management & Computer Security, 22(2), 167–178. https://doi.org/10.1108/IMCS-09-2013-0068

Hossain, M. N., Hassan, M. M., Monir, R. J., Sayeed, M. S., Wajiha, S., & Ullah, S. W. (2023). Cyber security and people: Human nature, psychology, and training affect user awareness, social engineering, and security professional education and preparedness. En 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT). IEEE. https://doi.org/10.1109/ICCCNT56998.2023.10307467

Iannone, E., Sellitto, G., Iaccarino, E., Ferrucci, F., De Lucia, A., & Palomba, F. (2024). Early and realistic exploitability prediction of just-disclosed software vulnerabilities: How reliable can it be? ACM Transactions on Software Engineering and Methodology, 33(6), 1–41. https://doi.org/10.1145/3654443

Ivanov, N., Lou, J., Chen, T., Li, J., & Yan, Q. (2021). Targeting the weakest link: Social engineering attacks in Ethereum smart contracts. En Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security (pp. 787–801). Association for Computing Machinery. https://doi.org/10.1145/3433210.3453085

Jampen, D., Gür, G., Sutter, T., & Tellenbach, B. (2020). Don’t click: Towards an effective anti-phishing training. A comparative literature review. Human-centric Computing and Information Sciences, 10, Article 33. https://doi.org/10.1186/s13673-020-00237-7

Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2021). Falling for phishing: An empirical investigation into people’s email response behaviors. En Proceedings of the 42nd International Conference on Information Systems (ICIS 2021). https://doi.org/10.48550/arXiv.2108.04766

Jones, A. (2024). Human error cybersecurity statistics. I.S. Partners. https://www.ispartnersllc.com/blog/human-error-cybersecurity-statistics/

Juma’h, A. H., & Alnsour, Y. (2020). The effect of data breaches on company performance. International Journal of Accounting & Information Management, 28(2), 275–301. https://doi.org/10.1108/IJAIM-01-2019-0006

Khadka, K., Ullah, A. B., Ma, W., Marroquin, E. M., & Alem, Y. (2023). A survey on the principles of persuasion as a social engineering strategy in phishing. En 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) (pp. 1631–1638). IEEE. https://doi.org/10.1109/TrustCom60117.2023.00222

Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University & Durham University. https://ebse.webspace.durham.ac.uk/ebse-bibliography/guidelines-for-performing-systematic-literature-reviews-in-software-engineering/

Kovačević, A., Putnik, N., & Tošković, O. (2020). Factors related to cyber security behavior. IEEE Access, 8, 125140–125148. https://doi.org/10.1109/ACCESS.2020.3007867

Kumar, I. (2023). Emerging threats in cybersecurity: A review article. International Journal of Applied and Natural Sciences, 1(1), 1–8. https://bluemarkpublishers.com/index.php/IJANS/article/view/2

Kuraku, S., Kalla, D., Smith, N., & Samaah, F. (2023). Exploring how user behavior shapes cybersecurity awareness in the face of phishing attacks. International Journal of Computer Trends and Technology, 71(11), 74–79. https://doi.org/10.14445/22312803/IJCTT-V71I11P111

Makanto, P. K., & Eze, J. S. (2023). Mitigating human vulnerabilities in cybersecurity: Understanding human flaws and implementing effective countermeasures. Bournemouth University. https://www.researchgate.net/publication/376520059_Mitigating_Human_Vulnerabilities_in_Cybersecurity_Understanding_Human_Flaws_and_Implementing_Effective_Countermeasures

Montañez, R., Golob, E., & Xu, S. (2020). Human cognition through the lens of social engineering cyberattacks. Frontiers in Psychology, 11, 1755. https://doi.org/10.3389/fpsyg.2020.01755

Mugarza, I., Yarza, I., Agirre, I., Lussiana, F., & Botta, S. (2021). Safety and security concept for software updates on mixed-criticality systems. CORDIS, European Commission. https://cordis.europa.eu/project/id/871465/results

Pashchenko, I., Vu, D.-L., & Massacci, F. (2020). A qualitative study of dependency management and its security implications. En Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (pp. 1513–1531). Association for Computing Machinery. https://doi.org/10.1145/3372297.3417232

Petelka, J., Zou, Y., & Schaub, F. (2019). Put your warning where your link is: Improving and evaluating email phishing warnings. En Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems. Association for Computing Machinery. https://doi.org/10.1145/3290605.3300748

Popay, J., Roberts, H., Sowden, A., Petticrew, M., Arai, L., Rodgers, M., Britten, N., Roen, K., & Duffy, S. (2006). Guidance on the conduct of narrative synthesis in systematic reviews: A product from the ESRC Methods Programme. https://doi.org/10.13140/2.1.1018.4643

Sathe, A. K., Patil, D. D., Lalge, G. V., & Nawale, S. R. (2025). Social engineering attack: Understanding human vulnerability in cybersecurity. International Journal of Social Impact. https://ijsi.in/pdf-viewer/?id=2254

Triplett, W. J. (2022). Addressing human factors in cybersecurity leadership. Journal of Cybersecurity and Privacy, 2(3), 573–586. https://doi.org/10.3390/jcp2030029

Ur, B., Bees, J., Segreti, S. M., Bauer, L., Christin, N., & Cranor, L. F. (2016). Do users’ perceptions of password security match reality? En Proceedings of the 2016 CHI Conference on Human Factors in Computing Systems (pp. 3748–3760). Association for Computing Machinery. https://doi.org/10.1145/2858036.2858546

von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. En Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623–642). USENIX Association. https://www.usenix.org/conference/soups2024/presentation/von-preuschen

Wang, B., Li, X., de Aguiar, L. P., Menasché, D. S., & Shafiq, Z. (2017). Characterizing and modeling patching practices of industrial control systems. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 1(1), 1–23. https://doi.org/10.1145/3084455

Wash, R., & Rader, E. (2021). Prioritizing security over usability: Strategies for how people choose passwords. Journal of Cybersecurity, 7(1), tyab012. https://doi.org/10.1093/cybsec/tyab012

Wohlin, C. (2014). Guidelines for snowballing in systematic literature studies and a replication in software engineering. En Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering. Association for Computing Machinery. https://doi.org/10.1145/2601248.2601268

Yeng, P. K., Fauzi, M. A., & Yang, B. (2022). A comprehensive assessment of human factors in cyber security compliance toward enhancing the security practice of healthcare staff in paperless hospitals. Information, 13(7), 335. https://doi.org/10.3390/info13070335

Yeo, L. H., & Banfield, J. (2022). Human factors in electronic health records cybersecurity breach: An exploratory analysis. Perspectives in Health Information Management, 19(Spring), 1i. https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9123525/

Zhang, H., Babar, M. A., & Tell, P. (2011). Identifying relevant studies in software engineering. Information and Software Technology, 53(6), 625–637. https://doi.org/10.1016/j.infsof.2010.12.010

Zimmermann, V., Marky, K., & Renaud, K. (2020). How experts detect phishing scam emails. Proceedings of the ACM on Human-Computer Interaction, 4(CSCW2), 1–28. https://doi.org/10.1145/3415231

Zimmermann, V., Marky, K., & Renaud, K. (2023). Hybrid password meters for more secure passwords: A comprehensive study of password meters including nudges and password information. Behaviour & Information Technology, 42(6), 700–743. https://doi.org/10.1080/0144929X.2022.2042384

Descargas

Publicado

2026-09-15

Cómo citar

Cruz Landa, A. J., Gutiérrez Méndez, J. M. ., Jiménez Márquez, J. C. ., Domínguez Bárcenas, M. E., & Rojas Luna, A. Y. (2026). Comportamientos humanos de riesgo en la ciberseguridad: Un análisis de contraseñas débiles, falta de actualización y clics en enlaces no verificados. ReCIBE, Revista electrónica De Computación, Informática, Biomédica Y Electrónica, 15(3). Recuperado a partir de https://recibe.cucei.udg.mx/index.php/ReCIBE/article/view/comportamientos_humanos

Número

Sección

Computación e Informática