PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 12, 2025Digital Threats Research and Practice5 citationsOpen Access

Human Factors in Information Security: A Quantitative Study with Technical Solutions to Prevent Social Engineering Attacks

View Full Paper
DJDennis Tan Jia JunARAhmad Sahban RafsanjaniSASaad Aslam

Key Points

  • The study finds significant vulnerabilities due to human factors in social engineering attacks, emphasizing a comprehensive understanding is essential.
  • According to the Internet Crime Report 2023, impersonation and business email compromise have caused losses of 2.9 billion dollars and 1.3 billion dollars respectively.
  • Using a quantitative questionnaire, 208 responses were collected to evaluate public knowledge and behaviors regarding human factors in cybersecurity.
  • Results suggest a balanced approach integrating technical and human solutions is necessary, prompting the proposal of a new security framework.

Abstract

Human factors play a critical role in enabling social engineering attacks that exploit human behaviors, cognitive biases, and psychological vulnerabilities to manipulate individuals and breach security protocols. The lack of a comprehensive understanding and effective countermeasures addressing these human factors has allowed attackers to execute successful social engineering attacks worldwide, leading to severe security breaches. According to the Internet Crime Report 2023, impersonation and business email compromise are among the costliest attacks compared to other forms of cybercrimes, with both leading to the loss of 2.9 billion dollars and 1.3 billion dollars. This research paper investigates the role of human factors in social engineering attacks and examines their growing prevalence and impact through real-life case studies. Additionally, it reviews various security frameworks and techniques from existing literature to identify their strengths and limitations, providing a foundation for a new conceptual security framework. To deepen our understanding of these issues, a quantitative questionnaire was conducted, collecting 208 responses to assess public knowledge, behaviors, experiences, and opinions related to human factors in information security and social engineering. The result provided several key insights such as revealing a lack of understanding of human factors and social engineering among respondents and suggesting that both technical and human aspects contribute to social engineering vulnerabilities. The findings emphasize the need for a balanced approach, leading to the proposal of a new security framework that integrates technical and human solutions to mitigate these risks effectively. By thoroughly following the framework, organizations can implement the most appropriate and effective technical and human measures, tailored to the data they have collected.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Jun et al. (2025) studied this question.

synapsesocial.com/papers/68d44a1d31b076d99fa52fe3https://doi.org/10.1145/3767320
Ask AI
Helpful
Bookmark
Share
View Full Paper