Source-linked AI summary
Cyber Security Awareness Campaigns: Why do they fail to change behaviour?
Maria Bada, Angela M. Sasse, Jason R. C. Nurse
TL;DR
The paper examines why cyber security awareness campaigns often fail to change behaviour despite communicating security risks and recommended practices. Through a psychological literature review and analysis of campaigns in the UK and Africa, it identifies requirements for more effective behaviour change, including actionable guidance, motivation, feedback, cultural sensitivity, and better-designed systems.
Problem
Many individuals do not comply with expected security behaviours because they may not perceive risks or understand the correct behaviour, while knowledge alone does not ensure action.
Method
The paper reviews psychological models and persuasion techniques, analyses factors associated with successful and unsuccessful campaigns, and reflects on campaign examples from the UK and Africa.
Results
Effective awareness requires more than information: guidance should be targeted, actionable, doable, simple, consistent, and supported by motivation, training, feedback, and suitable system design.
Takeaways & Limitations
Campaigns should move from awareness toward tangible, habitual behaviours embedded in organisational security culture, while avoiding fear-based messaging and excessive complexity.
Takeaways & Limitations
Evaluating public information-security awareness remains difficult because large-scale behavioural metrics, such as phishing emails opened or unauthorised-page accesses, are hard to measure.
Abstract
from arXiv · showhide
The present paper focuses on Cyber Security Awareness Campaigns, and aims to identify key factors regarding security which may lead them to failing to appropriately change people's behaviour. Past and current efforts to improve information-security practices and promote a sustainable society have not had the desired impact. It is important therefore to critically reflect on the challenges involved in improving information-security behaviours for citizens, consumers and employees. In particular, our work considers these challenges from a Psychology perspective, as we believe that understanding how people perceive risks is critical to creating effective awareness campaigns. Changing behaviour requires more than providing information about risks and reactive behaviours - firstly, people must be able to understand and apply the advice, and secondly, they must be motivated and willing to do so - and the latter requires changes to attitudes and intentions. These antecedents of behaviour change are identified in several psychological models of behaviour. We review the suitability of persuasion techniques, including the widely used 'fear appeals'. From this range of literature, we extract essential components for an awareness campaign as well as factors which can lead to a campaign's success or failure. Finally, we present examples of existing awareness campaigns in different cultures (the UK and Africa) and reflect on these.
1 Introduction
Cyber security awareness campaigns seek to influence secure online behaviour, but policy compliance remains limited when people do not perceive risks or understand the expected behaviour. The paper reviews psychological theories to clarify why behaviour change is difficult and how campaigns might become more effective.
- Many individuals do not comply with security policies because they may not perceive risks or understand the correct behaviour.
- Secure behaviour requires people to accept advice as relevant, understand how to respond, and remain willing to act despite competing demands.
- The paper conducts a focused literature review applying psychological theories to cyber security awareness and behaviour.
- It examines campaign effectiveness, behavioural influences, persuasion techniques, success factors, failure factors, and examples from different cultures.
2 Cyber security awareness campaigns
Awareness programmes are intended to communicate security requirements and appropriate behaviour, yet information alone has not reliably produced real-world action. Difficult interfaces, poor system design, ambiguous warnings, and threatening messages can contribute to mistakes, avoidance, stress, or disengagement.
- Awareness and training programmes communicate security requirements and appropriate behaviour, but materials must be interesting, current, simple, and audience-relevant.
- Governments promote secure online transactions while major attacks continue, partly because security interfaces can be too difficult for lay users.
- People may know correct answers without applying them, while systems that are difficult to use can prompt mistakes or security avoidance.
- Ambiguous warnings and complicated advice can lead individuals to abandon protective efforts, while threatening messages may increase stress, repulsion, or denial.
3 Factors influencing change in online behaviour
Behaviour change depends on more than information: motivation, ability, beliefs, social and environmental influences, perceived control, usability, and cultural fit all shape whether people act securely. Campaigns therefore need evidence-based, context-sensitive approaches that reduce effort and align messages with recipients’ characteristics.
- Simply providing information often has modest or unintended effects, so behaviour-change efforts should draw on evidence about how people actually behave.
- Nine behavioural influences include messengers, incentives, norms, defaults, salience, priming, affect, commitments, and ego.
- Effective behaviour change requires identifying conscious and unconscious personal, environmental, and social sources of influence.
- Personal motivation and ability are powerful influences, and campaigns must address the gap between what people say and what they do.
- Security fatigue can arise when procedures obstruct primary tasks or demand sustained vigilance, creating risks for organisational health.
- Security, functionality, and usability are usually conflicting goals, so moving toward one can move systems away from the others.
- Perceived control concerns how much control people feel they have, and is most valuable when their own efforts can improve their condition.
- Messages are more persuasive when they match recipients’ cultural themes, psychological characteristics, motivational orientations, or self-guides.
4 Persuasion techniques
Persuasion can target conscious reasoning or automatic judgment, using techniques such as fear, humour, expertise, repetition, intensity, and scientific evidence. The review indicates that fear appeals alone are unreliable, whereas simple, culturally informed interventions that account for self-efficacy and attitudes are more promising.
- Persuasion seeks to change attitudes or behaviour without coercion or deception through rational-cognitive or context-focused approaches.
- Common persuasion techniques include fear, humour, expertise, repetition, intensity, and scientific evidence.
- People judge whether they can perform the required action and whether its effort is worthwhile, while persuaders seek attention, credibility, trust, and motivation.
- Fear appeals can persuade in some situations but become counterproductive in others, especially when campaigns rely on frightening hacker imagery.
- Protection Motivation Theory links responses to both cyber-threat appraisal and personal self-efficacy.
- 4.1 Influence strategies: Security advice should be simple and easy to adopt, with advantages of the desired behaviour made clear despite message overload and the threat-behaviour gap.
- 4.1 Influence strategies: Interventions grounded in behavioural theory and attentive to cultural beliefs and attitudes are more likely to succeed.
5 Factors leading to success or failure of a cyber security awareness campaign
Successful cyber security awareness campaigns must build practical ability, motivation, perceived control, and cultural fit while avoiding unrealistic assumptions and weak evaluation. Campaign failure can follow from poorly aligned advice, inadequate materials, fear appeals, and insufficient measurement.
- Success factors: Effective campaigns teach usable skills because apparent lack of motivation may reflect insufficient ability.Campaigns often demand substantial effort and skills without demonstrating whether behaviour changes.
- Failure factors: Campaigns fail when solutions are misaligned with risks, progress and value are unmeasured, assumptions about motivation are wrong, or expectations are unrealistic.These problems can accompany campaigns that place substantial effort and skill demands on the public.
- Failure factors: Fear appeals may be insufficient because threatening imagery can seem funny or make audiences feel disconnected from the advertisement.The paper specifically identifies fear invocation as an inadequate standalone route to behaviour change.
- Failure factors: Common pitfalls include confusing compliance awareness with desired behaviour, using unengaging materials, failing to assess programmes, and covering only one topic or threat.The paper also notes that awareness should be treated as a distinct discipline and supported by multiple training exercises.
- Success factors: Campaigns should use simple, consistent behavioural rules that strengthen people’s perceived control and acceptance of recommended practices.Perceived control affects both behavioural intentions and actual behaviour.
- Success factors: Cultural differences in risk perception should shape campaign planning, and learning new behaviours requires ongoing support.Willingness to change alone may not sustain the learning process.
- Evaluation: Large-scale evaluation is difficult because behaviours such as opening phishing emails or accessing unauthorised pages are hard to measure across the public.The paper therefore calls for defined large-scale metrics to evaluate awareness efforts.
- Scope: The paper reviews personal, social, and environmental influences on online behaviour and identifies factors associated with campaign success or failure.Its analysis frames campaign outcomes through multiple sources of behavioural influence.
6 Case studies
The case studies compare UK and African cyber security awareness campaigns across different cultural and resource contexts. UK campaigns emphasize individual responsibility and practical advice, whereas African examples use more collective messages and partnership-oriented goals.
- Case-study scope: The case-study comparison examines UK and African campaigns to explore cultural differences reflected in awareness efforts.The countries also differ in the investment devoted to influencing secure online behaviour.
- UK campaigns: GetSafeOnline is jointly funded by government and private-sector organisations, serves home and business users, and provides extensive threat information and protective advice.Its positive message assigns individuals responsibility for using and applying the repository’s guidance to their own context.
- UK campaigns: Cyber Streetwise targets home and business users with practical security tips, including strong passwords, antivirus software, privacy checks, and retailer-security checks.Its positive messaging presents users as part of the cyber security chain.
- African campaigns: ISC Africa is an industry- and community-wide effort that promotes safe, responsible computer and Internet use through a collective message about protecting everyone.Its stated aims include minimising inherent risks and increasing consumer trust.
- African campaigns: Parents’ Corner coordinates government, industry, and civil society to protect and empower children, educate them, and build stakeholder partnerships.Its tips frame online safety through social awareness, caution, and mutual protection.
- Case-study scope: The UK has many national campaigns, while the paper notes that Africa has relatively few existing awareness campaigns.The authors suggest that this difference could indicate differences in resources or current emphasis on cyber security.
- Cultural comparison: The UK examples mainly frame security as individual responsibility, whereas African campaign messages refer more to users in relation to others.The comparison reflects individualist and collectivist approaches in the campaigns reviewed.
- Shared limitations: Most official campaign sites in the UK and Africa do not provide helplines for reporting cybercrime or receiving assistance.The paper identifies this as a potentially useful feature for less-skilled users.
7 Conclusions
The review concludes that effective cyber security awareness requires behaviour-focused, psychologically informed campaigns rather than knowledge transfer alone. Campaign success depends on actionable education, sustained feedback, professional preparation, and sensitivity to cultural context, while further evaluation is needed.
- Knowledge and awareness are prerequisites for behaviour change but are insufficient without additional influencing strategies and positive behaviours embedded as habits within security culture.Poorly designed security systems and policies are also identified as a major reason users do not behave optimally.
- Behaviour change should be assessed through risk reduction rather than correct answers, because knowledge does not establish motivation to act securely.Simple, consistent behavioural rules can improve acceptance by strengthening people’s perception of control.
- Effective campaigns should be professionally organised, targeted, actionable, doable, feedback-oriented, and supported by training and continuous feedback after people are willing to change.The review also recommends adapting campaigns to different cultural contexts and characteristics.
- Fear is not an effective general tactic for awareness campaigns because it can scare people who are least able to afford taking risks.The authors distinguish fear-based messaging from broader campaign requirements such as actionable education and feedback.
- The paper’s conclusions remain provisional because the authors plan a more substantial evaluation of campaigns worldwide, particularly in North America and Asia.That future work is intended to examine implementation of the proposed factors and campaign success levels.