← Latest papers
📄 social_science

Development and Validation of the Organizational Cybersecurity Perception Scale: A Protection Motivation Theory Instrument Contextualized by NIST CSF 2.0

This study develops and psychometrically validates the Organizational Cybersecurity Perception Scale (PMT-OCPS), a 27-item, six-factor instrument grounded in Protection Motivation Theory and contextualized by NIST CSF 2.0, which effectively measures employees' cognitive appraisals of organizational cybersecurity threats and capacities through robust statistical and known-groups analyses.

Original authors: Soner Çankaya, Fatih Samet Atasoy, Muhammet Kusan, Mustafa Tolga Bayraktar, Hakan Can Altunay, Erkan Faruk Şirin

Published 2026-07-28
📖 7 min read🧠 Deep dive

Original authors: Soner Çankaya, Fatih Samet Atasoy, Muhammet Kusan, Mustafa Tolga Bayraktar, Hakan Can Altunay, Erkan Faruk Şirin

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the digital world as a massive, bustling city where every building is a company, every road is a data cable, and every citizen is an employee. In this city, invisible monsters called "cyber threats" are constantly trying to break in, steal treasures, or cause chaos. For a long time, city planners (the tech experts) thought the only way to keep the city safe was to build stronger walls, install better locks, and hire more guards. But they realized something important: even the strongest castle falls if the people living inside don't believe the walls are real, or if they think the guards are useless, or if they feel the rules are just too annoying to follow.

This is where a famous idea called Protection Motivation Theory comes in. Think of it as a mental checklist our brains run when we face a danger. First, we ask, "How bad would it be if this happened?" (Threat Appraisal). Then, we ask, "Can I stop it? Is there a plan? Is it too much work?" (Coping Appraisal). If the answer to the second part is "Yes, I can handle it," we feel motivated to act. However, most studies have only looked at how individuals feel about their own passwords or clicking links. They haven't really asked: "How does an employee feel about the whole company's ability to fight these monsters?"

Enter the NIST Cybersecurity Framework, which is like a giant, official blueprint for how a city should manage its safety. It doesn't tell you what to feel, but it lists the six jobs a city needs to do: Govern (make rules), Identify (find the weak spots), Protect (build walls), Detect (spot the intruders), Respond (fight back), and Recover (fix the mess). The big question this research team wanted to answer was: Can we create a tool to measure exactly how employees perceive their city's safety, using the mental checklist of Protection Motivation Theory but filling it with the specific jobs from the NIST blueprint?


The Big Idea: A New "Safety Radar" for Companies

A team of researchers from Turkey decided to build a new tool, which they call the Organizational Cybersecurity Perception Scale (PMT-OCPS). You can think of this scale as a "Safety Radar" that companies can use to scan their employees' minds. Instead of asking, "Do you know how to change your password?" (which is a technical test), this radar asks, "Do you believe your company's security team is actually good at stopping hackers?" and "Do you feel like the security rules are too annoying to follow?"

The researchers started with a huge pile of 46 questions. They asked a panel of experts—psychologists, cybersecurity pros, and language wizards—to review them. The experts said, "These are good, but let's make them clearer and cut out the fluff." After some polishing and a small test run with 47 people, they whittled the list down to 29 questions, and then finally to a tight, 27-question "Safety Radar."

What They Found: The Six Pillars of Feeling Safe

When they tested this new radar on two large groups of people (519 people for the first test, and 400 different people to confirm the results), they discovered that employees don't just have one big feeling about security. Instead, their minds break the feeling down into six distinct pillars. It's like having six different sensors on a spaceship, each checking a different system:

  1. Perceived Severity: "How scary is the monster?" This measures how bad employees think a cyber-attack would be for the company (e.g., losing money, getting sued, or ruining their reputation).
  2. Perceived Vulnerability: "How likely is the monster to get us?" This is about how exposed employees feel their company's digital systems are to attacks.
  3. Preventive Efficacy: "Do the shields work?" This measures if employees believe the company's preventive measures (like software updates, training, and locks) are actually effective at stopping attacks before they start.
  4. Intervention Capability: "Can we fight back?" This is a brand-new discovery! The researchers found that employees distinguish between "preventing" an attack and "fighting" one. This pillar measures if employees trust the company's ability to detect an attack, respond to it quickly, and recover after the damage is done.
  5. Self-Efficacy: "Can I help?" This isn't about the company; it's about the employee. Do they feel capable of spotting a phishing email or reporting a problem?
  6. Response Cost: "Is it too much trouble?" This measures how annoying or burdensome employees find the security rules. If the rules feel like a heavy backpack, this score goes up, and people are less likely to follow them.

The "Aha!" Moment: Prevention vs. Intervention

The most exciting part of this study is what happened with the "Response Efficacy" part of the original theory. In the old days, scientists thought "Response Efficacy" was just one big bucket: "Do the safety measures work?" But this study showed that in a company, that bucket actually splits into two separate buckets: Prevention (stopping the bad guys at the gate) and Intervention (handling the mess if they get in).

The researchers suggest that employees are smart enough to know that having a great lock on the door (Prevention) is different from having a great emergency team ready to fix the fire if it starts (Intervention). This split is crucial because a company might be great at one but terrible at the other, and this new radar can tell the difference.

How Good is the Radar?

The researchers were very careful. They didn't just guess; they ran the numbers.

  • Reliability: The radar is consistent. If you take the test today and again in three weeks, you get almost the same score (a stability score of .882).
  • Accuracy: The six pillars they found are real and distinct. The data showed that "Prevention" and "Intervention" are indeed different feelings, not just the same thing repeated.
  • Real-World Check: They tested the radar on two different groups: sports institution employees and university staff. They found that people who had taken cybersecurity training felt more confident (higher Self-Efficacy) and thought the rules were less annoying (lower Response Cost). People who knew about a specific "Cybersecurity Unit" in their company felt the company was better at fighting back (higher Intervention Capability). This proves the radar actually picks up on real differences in how people feel.

What This Means (and What It Doesn't)

This new scale is a powerful tool for organizations. It doesn't tell you if a computer is infected with a virus; it tells you if the people feel safe and capable. If a company uses this radar and finds that their "Intervention Capability" score is low, they know they need to show their employees how well their emergency response team works. If the "Response Cost" score is high, they know their security rules are too complicated and need to be simplified.

However, the researchers are honest about the limits. This study was done in Turkey, mostly with public sector workers, so we don't know for sure if the radar works exactly the same way in a bank in New York or a factory in Tokyo. Also, this study only asked people what they felt; it didn't watch them to see if they actually followed the rules. But, it suggests strongly that how employees think about their company's security is a huge piece of the puzzle that we've been missing.

In short, this paper built a new, six-part compass to help companies navigate the human side of cybersecurity. It shows that to keep the digital city safe, you need to build strong walls, but you also need to make sure the citizens believe the walls work, trust the emergency team, and don't feel like the safety rules are too heavy to carry.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →