Human Factors and Social Engineering in Cybersecurity: A Qualitative Case Study and ISO/Iec 27001-aligned Ethical Response Framework
This qualitative case study at William V. S. Tubman University analyzes human factors and social engineering vulnerabilities across different university roles to propose an ISO/IEC 27001-aligned ethical framework that shifts cybersecurity defense from static awareness campaigns to role-sensitive, privacy-respecting, and continuously improved human-risk governance.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Invisible Battle for Your Brain
Imagine the internet as a massive, bustling city. For years, the city planners (cybersecurity experts) have been building taller walls, stronger gates, and smarter locks to keep the bad guys out. They installed firewalls like moats and encryption like unbreakable vaults. But there's a problem: the city has a back door that no amount of steel can lock. That back door is you.
This is the world of social engineering. Instead of hacking a computer's code, attackers hack the human mind. They use tricks like pretending to be your boss, creating a fake sense of emergency, or pretending to be a helpful friend to trick you into handing over your keys (passwords) or opening a door they shouldn't. It works because it exploits how our brains naturally work: we trust people who sound important, we panic when we hear "urgent," and we get tired when we have too much to do.
For a long time, security experts thought the answer was just to tell people, "Don't click weird links!" But this paper suggests that's like telling a swimmer to "just don't drown" without teaching them how to swim. The real question isn't whether people are careless; it's how the pressure of school, work, and deadlines makes even smart people vulnerable. This study dives into that messy, human side of security to see how we can build better defenses that actually fit how we think and feel.
The Story of the University City
In this study, a team of researchers from William V. S. Tubman University in Liberia decided to stop guessing and start listening. They wanted to understand how different groups of people in a university setting—tech-savvy IT staff, engineering students, and beginners in a foundation program—react when someone tries to trick them online.
Think of the university as a giant ship. The IT support staff are the engineers in the engine room; they know how the ship works. The engineering students are the deckhands learning to navigate; they know the tools but are still busy with their own tasks. The foundation learners are the new passengers just getting on board; they don't know the rules of the ship yet.
The researchers gathered these three groups for a series of "chat circles" (focus groups). They didn't just ask, "Are you careful?" Instead, they played out scenarios: What if you get an urgent email from the Dean saying your account will be deleted in five minutes? What if a "help desk" calls asking for your password? They listened to what the participants said, how they felt, and what they would actually do.
What They Found: It's Not One-Size-Fits-All
The big discovery is that there is no single "human error." Different groups get tricked in different ways, and the usual "one-size-fits-all" security training is failing everyone.
1. The Engineers in the Engine Room (IT Staff)
The IT staff knew the most about security. They could spot a fake email a mile away. But here's the twist: they were the most exhausted by security training. Imagine being a firefighter who has to watch the same safety video every single week. Eventually, you stop listening. The study found that because these staff members are bombarded with security messages, they suffer from "training fatigue." They know the rules, but they are tired of hearing them, which makes them less alert.
2. The Busy Deckhands (Engineering Students)
The engineering students were actually very good at spotting the tricks. They knew to check the sender's address and look for weird links. However, they were the most likely to make a mistake when they were stressed or overloaded. When they were juggling homework, deadlines, and a flood of emails, their brains got tired. In that moment of "cognitive overload," even a smart student might click the wrong button just to get the task done quickly. They weren't careless; they were just too busy to be careful.
3. The New Passengers (Foundation Learners)
The beginners didn't have the same level of technical knowledge. They didn't know the fancy tricks to spot a fake email. But they also weren't "fatigued" because they hadn't been trained yet. The study suggests they need a different kind of help: simple, basic building blocks. They need to learn the very first rules of the road before they can handle complex traffic.
The "Human Weakness" Myth is Dead
The paper argues strongly against the idea that humans are just "the weakest link" in the chain. That's like blaming a car for having a flat tire when the road is full of nails. The researchers found that people aren't naturally careless; they are situated decision-makers.
If you are tired, stressed, or told that your boss is watching, your brain takes shortcuts. It trusts the person who sounds like an authority figure. It clicks the button to make the "urgent" problem go away. The study shows that these mistakes happen because the environment is set up to trick us, not because we are stupid.
The New Game Plan: A Customized Shield
So, what's the solution? The authors propose a new framework that aligns with international security standards (ISO/IEC 27001), but with a human heart. Instead of sending the same boring email to everyone, they suggest a tiered approach:
- For the Beginners: Give them simple, confidence-building lessons. Teach them the basics of "don't share your password" and "who do I call if I'm confused?"
- For the Busy Students: Don't just lecture them. Give them quick, realistic practice that fits into their busy lives. Teach them how to pause and verify when they are stressed.
- For the IT Experts: Stop the repetitive training. Give them advanced, interesting challenges that feel real and connect to actual problems they face. Keep them engaged so they don't tune out.
The framework also emphasizes ethical monitoring. This means if the university tracks who clicks on a fake test link, they shouldn't punish that person. Instead, they should use it as a learning moment. It's like a coach helping a player improve, not a referee throwing them off the field.
The Bottom Line
This study suggests that to win the battle against hackers who trick people, we need to stop treating humans like broken robots that need fixing. We need to treat them like people who get tired, stressed, and busy. By understanding that a stressed student, a tired IT worker, and a new learner all need different kinds of support, universities (and companies) can build a security system that actually works.
The researchers admit this is just the beginning. They studied one university with a small group of people, so their findings are a strong suggestion, not a final law of physics. But the message is clear: if we want to be safe online, we have to design our defenses to fit the messy, wonderful, and sometimes tired reality of being human.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.