Human Vulnerability Assessment in Cybersecurity: A Systematic Literature Review of Methods, Models, and Instruments
This systematic literature review analyzes methods, models, and instruments for assessing human vulnerabilities in cybersecurity from 2017 to 2025, revealing that current approaches remain fragmented and static, thereby highlighting the critical need for dynamic, holistic frameworks that address both unintentional and intentional human factors.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine cybersecurity as a giant, high-tech castle. For years, the guards (the security experts) have been obsessed with checking the walls, the locks, and the moats. They make sure the digital gates are strong and the software is unbreakable. But this paper argues that the castle is still getting breached, not because the walls are weak, but because the people living inside are being tricked, tired out, or manipulated.
This research is a "systematic literature review," which is like a super-organized librarian who went through every book, article, and study published between 2017 and 2025 to answer one big question: "How are we currently measuring the weaknesses of the human mind in cybersecurity, and is it enough?"
Here is the breakdown of their findings, using simple analogies:
1. The Problem: We Only Check the "Doors," Not the "People"
The authors found that most current security checks focus on what people do (like clicking a bad link or using a weak password). They call this "Behavioral Factors."
- The Analogy: Imagine a doctor who only checks if a patient is coughing (the behavior) but never asks why they are coughing. Are they allergic? Are they stressed? Are they sick?
- The Reality: The paper says we are great at spotting the "cough" (the risky action), but we are terrible at understanding the "illness" (the tiredness, the stress, the personality traits, or the social pressure that caused the cough in the first place).
2. The New Map: A "Human Factor Taxonomy"
To fix this confusion, the authors created a new "map" (a taxonomy) to organize all the different ways humans can be vulnerable. They divided these weaknesses into four main neighborhoods:
- The Psychological Neighborhood (The "Who You Are"): This includes your personality, your emotions, and your ethics. Are you naturally trusting? Are you stressed? Do you have a "bad apple" personality that might want to steal things on purpose?
- The Cognitive Neighborhood (The "How You Think"): This is about your brain's processing. Do you get tired easily? Do you trust AI too much? Do you have mental shortcuts that make you fall for scams?
- The Behavioral Neighborhood (The "What You Do"): This is the actual action. Did you click the link? Did you share your password? This is what most current tools measure.
- The Performance State Neighborhood (The "How You Feel Right Now"): This is temporary. Are you rushing? Are you interrupted? Are you multitasking? A tired, rushed person is more vulnerable than a rested one, even if they are the same person.
The Twist: The map also includes "Weather Conditions" (Moderators). These are things like your age, your job, how much training you've had, or the culture of your office. These don't cause the weakness directly, but they change how strong or weak you are.
3. The Big Discovery: We Are Missing the "Whole Picture"
The researchers looked at 54 different studies and found some major gaps:
- We focus too much on the "Cough": Most studies only look at Behavior and Thinking. They rarely look deep into Personality or Temporary States (like fatigue).
- We treat "Accidents" and "Crimes" as different: Most tools check for accidental mistakes (like clicking a phishing email) OR intentional crimes (like an employee stealing data). Very few tools try to understand both at the same time. The paper argues that the same human traits (like stress or poor ethics) can lead to both accidents and crimes, but we are studying them separately.
- We are "Static" when we should be "Dynamic": Imagine taking a photo of a person and saying, "This is their security level forever." That's what most tools do. But humans change! If you are tired today, you are vulnerable. If you are well-rested tomorrow, you might be safe. The paper says we need video, not photos. We need tools that watch how vulnerability changes over time.
- We ignore the "AI Trap": The paper notes that almost no one is studying how humans get tricked by Artificial Intelligence yet. We are trusting AI too much, and our brains are getting lazy (a phenomenon called "cognitive offloading"), but our security tools haven't caught up to this new danger.
4. The Conclusion: We Need a "Smart, Living System"
The paper concludes that we are currently using a "fragmented" approach. It's like having a team of specialists where one checks your eyes, another checks your feet, and a third checks your ears, but no one is talking to each other to see how the whole body is doing.
The authors' final message:
To truly secure our digital world, we need to stop just looking at the "bad clicks" and start building a system that understands the whole human. We need tools that:
- Look at personality, thinking, actions, and temporary states all at once.
- Watch how vulnerability changes from day to day (dynamic).
- Understand how one person's weakness can spread to others (propagation).
- Account for the fact that humans can make mistakes or be malicious, and the root causes often overlap.
In short: We are building better locks for the castle, but we need to start understanding the people living inside it much better.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.