← Latest papers
📄 other

Evaluating the human factor in cybersecurity threats (a Systematic Literature Review)

This systematic literature review synthesizes research from 2010 to 2026 to demonstrate that cybersecurity incidents stem from the complex interplay of cognitive, social, and organizational factors rather than isolated user errors, ultimately proposing an integrative human-centered framework to address these vulnerabilities.

Original authors: Alaa Abuiteiwi, Santiago Escobar

Published 2026-07-27
📖 4 min read☕ Coffee break read

Original authors: Alaa Abuiteiwi, Santiago Escobar

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the digital world as a massive, bustling city. In this city, we have towering skyscrapers made of code, highways of data, and invisible forcefields called firewalls designed to keep the bad guys out. For a long time, the architects of this city believed that if they just built stronger walls and smarter locks, they would be safe. But there's a catch: the city is inhabited by people. And people, unlike robots, get tired, distracted, curious, or tricked. This paper lives in the corner of science called cybersecurity, specifically focusing on the "human factor." Think of the human factor as the unpredictable variable in a math equation; it's the part where a person might forget a password, click a weird link because they were in a hurry, or accidentally leave a door open. The paper asks a simple but huge question: If we can't stop people from being human, how do we design our digital city so that our human mistakes don't bring the whole place down?

This isn't just about blaming people for being careless. The authors, Alaa Abuiteiwi and Santiago Escobar, went on a massive detective hunt. They didn't just look at one or two studies; they gathered and analyzed 125 different scientific papers published between 2010 and early 2026. They wanted to see if there was a pattern behind why security fails. Imagine trying to solve a mystery by reading 125 different police reports from different cities. That's what they did. They found that the old idea of "human error" is too simple. It's not just one person making one mistake. Instead, it's like a Rube Goldberg machine where a tired brain, a confusing computer screen, a boss who is in a rush, and a clever hacker all line up perfectly to cause a disaster.

The paper's main discovery is that security breaches rarely happen because a single person was stupid. They happen because of a chain reaction. The authors found five main areas where things go wrong: how our brains work (like being too optimistic or trusting), how hackers trick us (like sending fake emails that look real), the dangers of people inside the company (who might be angry or just careless), how the company culture treats security (does the boss care?), and how annoying or confusing the security tools are. If a security tool is too hard to use, people will find a way around it, just like you might sneak a snack into a movie theater if the line for the concession stand is too long.

The authors argue that we need to stop treating people like the "weak link" that needs to be fixed with more lectures. Instead, they suggest we need to build a system that understands people. They propose a new "framework," which is basically a blueprint for fixing these problems. This blueprint suggests that we need to look at the whole picture: the stress the employee is feeling, the design of the software they are using, and the culture of the office. They also point out that current ways of measuring security are messy. Some reports say 74% of breaches are human-related, while others say 95%. The paper explains that these numbers are different because everyone is counting different things, like counting "all accidents" versus "only the ones that caused a fire."

Ultimately, the paper suggests that we can't just train people to be perfect robots. We have to design our digital world to be forgiving of human nature. If the system is easier to use, less stressful, and supported by a culture that doesn't blame people for mistakes, then the "human firewall" becomes much stronger. The authors don't claim to have solved the problem forever—cybercriminals are always changing their tricks—but they have provided a much clearer map of where the real trouble spots are, moving us away from simple blame and toward smarter, more human-friendly solutions.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →