Risky Human Behaviors in Cybersecurity: An Analysis of Weak Passwords, Failure to Update, and Clicking on Unverified Links.
Keywords:
Cybersecurity, human behavior, weak passwords, software updates, unverified links, vulnerabilityAbstract
Human behaviors related to the use of weak passwords, the lack of software updates, and interaction with unverified hyperlinks pose significant risks in the field of cybersecurity. Despite technological advances, the human factor remains responsible for a high number of security incidents due to human errors, omissions, or decisions. Cybersecurity literature still shows a lack of connection between the identification of risky human behaviors, the consequences they generate, and the factors that cause them. This lack of articulation limits a comprehensive understanding of the problem and leads many proposed solutions to be technical or less accessible to end users, making it difficult to effectively mitigate these behaviors within information systems. This study aims to analyze the associated consequences and factors of risky human behaviors in cybersecurity through a systematic literature review, in order to identify prevention strategies.References
Baki, S., Verma, R., Mukherjee, A., & Gnawali, O. (2017). Scaling and effectiveness of email masquerade attacks: Exploiting natural language generation. En Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (pp. 469–482). Association for Computing Machinery. https://doi.org/10.1145/3052973.3053037
Bilge, L., Han, Y., & Dell’Amico, M. (2017). RiskTeller: Predicting the risk of cyber incidents. En Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1299–1311). Association for Computing Machinery. https://doi.org/10.1145/3133956.3134022
Coker, J. (2025). 95% of data breaches tied to human error in 2024. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/data-breaches-human-error/
Desolda, G., Ferro, L. S., Marrella, A., Catarci, T., & Costabile, M. F. (2021). Human factors in phishing attacks: A systematic literature review. ACM Computing Surveys, 54(8), Article 173, 1–35. https://doi.org/10.1145/3469886
French, L. (2025, 11 de marzo). 95% of data breaches involve human error, report reveals. SC World. https://www.scworld.com/news/95-of-data-breaches-involve-human-error-report-reveals/
Gulenko, I. (2014). Improving passwords: Influence of emotions on security behaviour. Information Management & Computer Security, 22(2), 167–178. https://doi.org/10.1108/IMCS-09-2013-0068
Hossain, M. N., Hassan, M. M., Monir, R. J., Sayeed, M. S., Wajiha, S., & Ullah, S. W. (2023). Cyber security and people: Human nature, psychology, and training affect user awareness, social engineering, and security professional education and preparedness. En 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT). IEEE. https://doi.org/10.1109/ICCCNT56998.2023.10307467
Iannone, E., Sellitto, G., Iaccarino, E., Ferrucci, F., De Lucia, A., & Palomba, F. (2024). Early and realistic exploitability prediction of just-disclosed software vulnerabilities: How reliable can it be? ACM Transactions on Software Engineering and Methodology, 33(6), 1–41. https://doi.org/10.1145/3654443
Ivanov, N., Lou, J., Chen, T., Li, J., & Yan, Q. (2021). Targeting the weakest link: Social engineering attacks in Ethereum smart contracts. En Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security (pp. 787–801). Association for Computing Machinery. https://doi.org/10.1145/3433210.3453085
Jampen, D., Gür, G., Sutter, T., & Tellenbach, B. (2020). Don’t click: Towards an effective anti-phishing training. A comparative literature review. Human-centric Computing and Information Sciences, 10, Article 33. https://doi.org/10.1186/s13673-020-00237-7
Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2021). Falling for phishing: An empirical investigation into people’s email response behaviors. En Proceedings of the 42nd International Conference on Information Systems (ICIS 2021). https://doi.org/10.48550/arXiv.2108.04766
Jones, A. (2024). Human error cybersecurity statistics. I.S. Partners. https://www.ispartnersllc.com/blog/human-error-cybersecurity-statistics/
Juma’h, A. H., & Alnsour, Y. (2020). The effect of data breaches on company performance. International Journal of Accounting & Information Management, 28(2), 275–301. https://doi.org/10.1108/IJAIM-01-2019-0006
Khadka, K., Ullah, A. B., Ma, W., Marroquin, E. M., & Alem, Y. (2023). A survey on the principles of persuasion as a social engineering strategy in phishing. En 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) (pp. 1631–1638). IEEE. https://doi.org/10.1109/TrustCom60117.2023.00222
Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University & Durham University. https://ebse.webspace.durham.ac.uk/ebse-bibliography/guidelines-for-performing-systematic-literature-reviews-in-software-engineering/
Kovačević, A., Putnik, N., & Tošković, O. (2020). Factors related to cyber security behavior. IEEE Access, 8, 125140–125148. https://doi.org/10.1109/ACCESS.2020.3007867
Kumar, I. (2023). Emerging threats in cybersecurity: A review article. International Journal of Applied and Natural Sciences, 1(1), 1–8. https://bluemarkpublishers.com/index.php/IJANS/article/view/2
Kuraku, S., Kalla, D., Smith, N., & Samaah, F. (2023). Exploring how user behavior shapes cybersecurity awareness in the face of phishing attacks. International Journal of Computer Trends and Technology, 71(11), 74–79. https://doi.org/10.14445/22312803/IJCTT-V71I11P111
Makanto, P. K., & Eze, J. S. (2023). Mitigating human vulnerabilities in cybersecurity: Understanding human flaws and implementing effective countermeasures. Bournemouth University. https://www.researchgate.net/publication/376520059_Mitigating_Human_Vulnerabilities_in_Cybersecurity_Understanding_Human_Flaws_and_Implementing_Effective_Countermeasures
Montañez, R., Golob, E., & Xu, S. (2020). Human cognition through the lens of social engineering cyberattacks. Frontiers in Psychology, 11, 1755. https://doi.org/10.3389/fpsyg.2020.01755
Mugarza, I., Yarza, I., Agirre, I., Lussiana, F., & Botta, S. (2021). Safety and security concept for software updates on mixed-criticality systems. CORDIS, European Commission. https://cordis.europa.eu/project/id/871465/results
Pashchenko, I., Vu, D.-L., & Massacci, F. (2020). A qualitative study of dependency management and its security implications. En Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (pp. 1513–1531). Association for Computing Machinery. https://doi.org/10.1145/3372297.3417232
Petelka, J., Zou, Y., & Schaub, F. (2019). Put your warning where your link is: Improving and evaluating email phishing warnings. En Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems. Association for Computing Machinery. https://doi.org/10.1145/3290605.3300748
Popay, J., Roberts, H., Sowden, A., Petticrew, M., Arai, L., Rodgers, M., Britten, N., Roen, K., & Duffy, S. (2006). Guidance on the conduct of narrative synthesis in systematic reviews: A product from the ESRC Methods Programme. https://doi.org/10.13140/2.1.1018.4643
Sathe, A. K., Patil, D. D., Lalge, G. V., & Nawale, S. R. (2025). Social engineering attack: Understanding human vulnerability in cybersecurity. International Journal of Social Impact. https://ijsi.in/pdf-viewer/?id=2254
Triplett, W. J. (2022). Addressing human factors in cybersecurity leadership. Journal of Cybersecurity and Privacy, 2(3), 573–586. https://doi.org/10.3390/jcp2030029
Ur, B., Bees, J., Segreti, S. M., Bauer, L., Christin, N., & Cranor, L. F. (2016). Do users’ perceptions of password security match reality? En Proceedings of the 2016 CHI Conference on Human Factors in Computing Systems (pp. 3748–3760). Association for Computing Machinery. https://doi.org/10.1145/2858036.2858546
von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. En Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623–642). USENIX Association. https://www.usenix.org/conference/soups2024/presentation/von-preuschen
Wang, B., Li, X., de Aguiar, L. P., Menasché, D. S., & Shafiq, Z. (2017). Characterizing and modeling patching practices of industrial control systems. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 1(1), 1–23. https://doi.org/10.1145/3084455
Wash, R., & Rader, E. (2021). Prioritizing security over usability: Strategies for how people choose passwords. Journal of Cybersecurity, 7(1), tyab012. https://doi.org/10.1093/cybsec/tyab012
Wohlin, C. (2014). Guidelines for snowballing in systematic literature studies and a replication in software engineering. En Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering. Association for Computing Machinery. https://doi.org/10.1145/2601248.2601268
Yeng, P. K., Fauzi, M. A., & Yang, B. (2022). A comprehensive assessment of human factors in cyber security compliance toward enhancing the security practice of healthcare staff in paperless hospitals. Information, 13(7), 335. https://doi.org/10.3390/info13070335
Yeo, L. H., & Banfield, J. (2022). Human factors in electronic health records cybersecurity breach: An exploratory analysis. Perspectives in Health Information Management, 19(Spring), 1i. https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9123525/
Zhang, H., Babar, M. A., & Tell, P. (2011). Identifying relevant studies in software engineering. Information and Software Technology, 53(6), 625–637. https://doi.org/10.1016/j.infsof.2010.12.010
Zimmermann, V., Marky, K., & Renaud, K. (2020). How experts detect phishing scam emails. Proceedings of the ACM on Human-Computer Interaction, 4(CSCW2), 1–28. https://doi.org/10.1145/3415231
Zimmermann, V., Marky, K., & Renaud, K. (2023). Hybrid password meters for more secure passwords: A comprehensive study of password meters including nudges and password information. Behaviour & Information Technology, 42(6), 700–743. https://doi.org/10.1080/0144929X.2022.2042384
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 ReCIBE, electronic journal of Computing, Informatics, Biomedical and Electronics

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.