Risky Human Behaviors in Cybersecurity: An Analysis of Weak Passwords, Failure to Update, and Clicking on Unverified Links.

Authors

  • Alberto Jair Cruz Landa 📩 Universidad Veracruzana, México
  • Juan Manuel Gutiérrez Méndez Universidad Veracruzana, México
  • Juan Carlos Jiménez Márquez Universidad Veracruzana, México
  • Martha Elizabet Domínguez Bárcenas Universidad Veracruzana, México
  • Alicia Yazmín Rojas Luna Universidad Veracruzana, México

Keywords:

Cybersecurity, human behavior, weak passwords, software updates, unverified links, vulnerability

Abstract

Human behaviors related to the use of weak passwords, the lack of software updates, and interaction with unverified hyperlinks pose significant risks in the field of cybersecurity. Despite technological advances, the human factor remains responsible for a high number of security incidents due to human errors, omissions, or decisions. Cybersecurity literature still shows a lack of connection between the identification of risky human behaviors, the consequences they generate, and the factors that cause them. This lack of articulation limits a comprehensive understanding of the problem and leads many proposed solutions to be technical or less accessible to end users, making it difficult to effectively mitigate these behaviors within information systems. This study aims to analyze the associated consequences and factors of risky human behaviors in cybersecurity through a systematic literature review, in order to identify prevention strategies.

Author Biographies

Juan Manuel Gutiérrez Méndez, Universidad Veracruzana, México

Juan Manuel Gutiérrez Méndez: is a full-time Professor at the Faculty of Statistics and Informatics of the Veracruzana University and is involved in the Bachelor’s Degree in Cybersecurity and Computing Infrastructure. His professional and academic career has developed in the fields of information technology, technological infrastructure, software development, and cybersecurity. His areas of interest focus on information technology and cybersecurity, particularly data protection, infrastructure security, usable cybersecurity, and the application of reference frameworks from technological, organizational, and human perspectives.

Juan Carlos Jiménez Márquez, Universidad Veracruzana, México

Juan Carlos Jiménez Márquez: is a full-time Professor at the Faculty of Statistics and Informatics of the Veracruzana University. He holds a Bachelor’s Degree in Computer Science, a Master’s Degree in Communication and Educational Technologies, and a Ph.D. in Education. His academic and professional career has developed in the areas of information technology, networks, computing services, technological infrastructure, and cybersecurity. His areas of interest focus on cybersecurity, network and infrastructure security, the Internet of Things, and the application of emerging technologies in educational contexts.    

Martha Elizabet Domínguez Bárcenas, Universidad Veracruzana, México

Martha Elizabet Domínguez Bárcenas: is a full-time Professor at the Faculty of Statistics and Informatics of the Veracruzana University, affiliated with the Bachelor’s Degree in Cybersecurity and Computing Infrastructure Engineering. She holds a Bachelor’s Degree in Computer Science and a Master’s Degree in Networks and Telecommunications. Her academic career has focused on the areas of networking and technological infrastructure. In the field of cybersecurity, her areas of interest focus on infrastructure security and social cybersecurity.

Alicia Yazmín Rojas Luna, Universidad Veracruzana, México

Alicia Yazmín Rojas Luna: is an Academic Technician at the Faculty of Statistics and Informatics of the Veracruzana University. She holds a Bachelor’s Degree in Computer Science, a Master’s Degree in User-Centered Interactive Systems, and a Master’s Degree in Cybersecurity. Her academic and professional experience focuses on Human–Computer Interaction, User Experience, and Cybersecurity, with an emphasis on user-centered design, usability and UX evaluation, accessibility, and usable security. Her areas of interest focus on the study of interaction between people and digital systems, particularly privacy, secure experience design, user behavior in response to cybersecurity risks, and the evaluation of interactive technologies from human, technological, and security perspectives.

References

Baki, S., Verma, R., Mukherjee, A., & Gnawali, O. (2017). Scaling and effectiveness of email masquerade attacks: Exploiting natural language generation. En Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (pp. 469–482). Association for Computing Machinery. https://doi.org/10.1145/3052973.3053037

Bilge, L., Han, Y., & Dell’Amico, M. (2017). RiskTeller: Predicting the risk of cyber incidents. En Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1299–1311). Association for Computing Machinery. https://doi.org/10.1145/3133956.3134022

Coker, J. (2025). 95% of data breaches tied to human error in 2024. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/data-breaches-human-error/

Desolda, G., Ferro, L. S., Marrella, A., Catarci, T., & Costabile, M. F. (2021). Human factors in phishing attacks: A systematic literature review. ACM Computing Surveys, 54(8), Article 173, 1–35. https://doi.org/10.1145/3469886

French, L. (2025, 11 de marzo). 95% of data breaches involve human error, report reveals. SC World. https://www.scworld.com/news/95-of-data-breaches-involve-human-error-report-reveals/

Gulenko, I. (2014). Improving passwords: Influence of emotions on security behaviour. Information Management & Computer Security, 22(2), 167–178. https://doi.org/10.1108/IMCS-09-2013-0068

Hossain, M. N., Hassan, M. M., Monir, R. J., Sayeed, M. S., Wajiha, S., & Ullah, S. W. (2023). Cyber security and people: Human nature, psychology, and training affect user awareness, social engineering, and security professional education and preparedness. En 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT). IEEE. https://doi.org/10.1109/ICCCNT56998.2023.10307467

Iannone, E., Sellitto, G., Iaccarino, E., Ferrucci, F., De Lucia, A., & Palomba, F. (2024). Early and realistic exploitability prediction of just-disclosed software vulnerabilities: How reliable can it be? ACM Transactions on Software Engineering and Methodology, 33(6), 1–41. https://doi.org/10.1145/3654443

Ivanov, N., Lou, J., Chen, T., Li, J., & Yan, Q. (2021). Targeting the weakest link: Social engineering attacks in Ethereum smart contracts. En Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security (pp. 787–801). Association for Computing Machinery. https://doi.org/10.1145/3433210.3453085

Jampen, D., Gür, G., Sutter, T., & Tellenbach, B. (2020). Don’t click: Towards an effective anti-phishing training. A comparative literature review. Human-centric Computing and Information Sciences, 10, Article 33. https://doi.org/10.1186/s13673-020-00237-7

Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2021). Falling for phishing: An empirical investigation into people’s email response behaviors. En Proceedings of the 42nd International Conference on Information Systems (ICIS 2021). https://doi.org/10.48550/arXiv.2108.04766

Jones, A. (2024). Human error cybersecurity statistics. I.S. Partners. https://www.ispartnersllc.com/blog/human-error-cybersecurity-statistics/

Juma’h, A. H., & Alnsour, Y. (2020). The effect of data breaches on company performance. International Journal of Accounting & Information Management, 28(2), 275–301. https://doi.org/10.1108/IJAIM-01-2019-0006

Khadka, K., Ullah, A. B., Ma, W., Marroquin, E. M., & Alem, Y. (2023). A survey on the principles of persuasion as a social engineering strategy in phishing. En 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) (pp. 1631–1638). IEEE. https://doi.org/10.1109/TrustCom60117.2023.00222

Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University & Durham University. https://ebse.webspace.durham.ac.uk/ebse-bibliography/guidelines-for-performing-systematic-literature-reviews-in-software-engineering/

Kovačević, A., Putnik, N., & Tošković, O. (2020). Factors related to cyber security behavior. IEEE Access, 8, 125140–125148. https://doi.org/10.1109/ACCESS.2020.3007867

Kumar, I. (2023). Emerging threats in cybersecurity: A review article. International Journal of Applied and Natural Sciences, 1(1), 1–8. https://bluemarkpublishers.com/index.php/IJANS/article/view/2

Kuraku, S., Kalla, D., Smith, N., & Samaah, F. (2023). Exploring how user behavior shapes cybersecurity awareness in the face of phishing attacks. International Journal of Computer Trends and Technology, 71(11), 74–79. https://doi.org/10.14445/22312803/IJCTT-V71I11P111

Makanto, P. K., & Eze, J. S. (2023). Mitigating human vulnerabilities in cybersecurity: Understanding human flaws and implementing effective countermeasures. Bournemouth University. https://www.researchgate.net/publication/376520059_Mitigating_Human_Vulnerabilities_in_Cybersecurity_Understanding_Human_Flaws_and_Implementing_Effective_Countermeasures

Montañez, R., Golob, E., & Xu, S. (2020). Human cognition through the lens of social engineering cyberattacks. Frontiers in Psychology, 11, 1755. https://doi.org/10.3389/fpsyg.2020.01755

Mugarza, I., Yarza, I., Agirre, I., Lussiana, F., & Botta, S. (2021). Safety and security concept for software updates on mixed-criticality systems. CORDIS, European Commission. https://cordis.europa.eu/project/id/871465/results

Pashchenko, I., Vu, D.-L., & Massacci, F. (2020). A qualitative study of dependency management and its security implications. En Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (pp. 1513–1531). Association for Computing Machinery. https://doi.org/10.1145/3372297.3417232

Petelka, J., Zou, Y., & Schaub, F. (2019). Put your warning where your link is: Improving and evaluating email phishing warnings. En Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems. Association for Computing Machinery. https://doi.org/10.1145/3290605.3300748

Popay, J., Roberts, H., Sowden, A., Petticrew, M., Arai, L., Rodgers, M., Britten, N., Roen, K., & Duffy, S. (2006). Guidance on the conduct of narrative synthesis in systematic reviews: A product from the ESRC Methods Programme. https://doi.org/10.13140/2.1.1018.4643

Sathe, A. K., Patil, D. D., Lalge, G. V., & Nawale, S. R. (2025). Social engineering attack: Understanding human vulnerability in cybersecurity. International Journal of Social Impact. https://ijsi.in/pdf-viewer/?id=2254

Triplett, W. J. (2022). Addressing human factors in cybersecurity leadership. Journal of Cybersecurity and Privacy, 2(3), 573–586. https://doi.org/10.3390/jcp2030029

Ur, B., Bees, J., Segreti, S. M., Bauer, L., Christin, N., & Cranor, L. F. (2016). Do users’ perceptions of password security match reality? En Proceedings of the 2016 CHI Conference on Human Factors in Computing Systems (pp. 3748–3760). Association for Computing Machinery. https://doi.org/10.1145/2858036.2858546

von Preuschen, A., Schuhmacher, M. C., & Zimmermann, V. (2024). Beyond fear and frustration: Towards a holistic understanding of emotions in cybersecurity. En Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) (pp. 623–642). USENIX Association. https://www.usenix.org/conference/soups2024/presentation/von-preuschen

Wang, B., Li, X., de Aguiar, L. P., Menasché, D. S., & Shafiq, Z. (2017). Characterizing and modeling patching practices of industrial control systems. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 1(1), 1–23. https://doi.org/10.1145/3084455

Wash, R., & Rader, E. (2021). Prioritizing security over usability: Strategies for how people choose passwords. Journal of Cybersecurity, 7(1), tyab012. https://doi.org/10.1093/cybsec/tyab012

Wohlin, C. (2014). Guidelines for snowballing in systematic literature studies and a replication in software engineering. En Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering. Association for Computing Machinery. https://doi.org/10.1145/2601248.2601268

Yeng, P. K., Fauzi, M. A., & Yang, B. (2022). A comprehensive assessment of human factors in cyber security compliance toward enhancing the security practice of healthcare staff in paperless hospitals. Information, 13(7), 335. https://doi.org/10.3390/info13070335

Yeo, L. H., & Banfield, J. (2022). Human factors in electronic health records cybersecurity breach: An exploratory analysis. Perspectives in Health Information Management, 19(Spring), 1i. https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9123525/

Zhang, H., Babar, M. A., & Tell, P. (2011). Identifying relevant studies in software engineering. Information and Software Technology, 53(6), 625–637. https://doi.org/10.1016/j.infsof.2010.12.010

Zimmermann, V., Marky, K., & Renaud, K. (2020). How experts detect phishing scam emails. Proceedings of the ACM on Human-Computer Interaction, 4(CSCW2), 1–28. https://doi.org/10.1145/3415231

Zimmermann, V., Marky, K., & Renaud, K. (2023). Hybrid password meters for more secure passwords: A comprehensive study of password meters including nudges and password information. Behaviour & Information Technology, 42(6), 700–743. https://doi.org/10.1080/0144929X.2022.2042384

Published

2026-09-15

How to Cite

Cruz Landa, A. J., Gutiérrez Méndez, J. M. ., Jiménez Márquez, J. C. ., Domínguez Bárcenas, M. E., & Rojas Luna, A. Y. (2026). Risky Human Behaviors in Cybersecurity: An Analysis of Weak Passwords, Failure to Update, and Clicking on Unverified Links. ReCIBE, Electronic Journal of Computing, Informatics, Biomedical and Electronics, 15(3). Retrieved from https://recibe.cucei.udg.mx/index.php/ReCIBE/article/view/comportamientos_humanos

Issue

Section

Computer Science & IT