Modeling students’ email security behavior toward phishing threats using PMT for gamified cybersecurity awareness design

Purpose This study aims to examine the psychological factors associated with students’ email security behavior toward phishing threats and uses these findings to inform future gamified cybersecurity awareness (GCA) design decisions. It addresses the need for awareness interventions that are grounded in users’ behavioral characteristics rather than relying primarily on passive information delivery. Design/methodology/approach A quantitative survey design was used. Data were collected from 544 university students using a closed-ended questionnaire grounded in protection motivation theory (PMT). Covariance-based structural equation modeling was used to test the hypothesized relationships among perceived susceptibility, perceived severity, self-efficacy and email security behavior. Multi-group analysis examined whether these relationships differed between students with and without prior cybersecurity awareness or training exposure. Findings Perceived threat severity and self-efficacy significantly predicted email security behavior, while perceived susceptibility had no significant direct effect. Prior cybersecurity awareness or training exposure did not significantly moderate any of the hypothesized relationships. The model explained 40.7% of the variance in email security behavior. Research limitations/implications The study relied on self-reported data, convenience sampling and a predominantly undergraduate student sample, which may limit generalizability. The PMT model also used a focused specification comprising susceptibility, severity and self-efficacy, while prior awareness or training was operationalized only as a binary exposure measure. Future studies should use broader PMT specifications, more detailed measures of awareness and training characteristics, objective behavioral measures and experimental or longitudinal designs. Practical implications The findings suggest that future GCA interventions should prioritize making phishing consequences tangible and strengthening users’ confidence and capability to respond through mechanisms such as realistic scenarios, branching decision activities, guided practice, immediate feedback and progressive challenges. Approaches aimed at increasing personal relevance may also be explored, although the nonsignificant effect of perceived susceptibility warrants caution. Social implications Better designed awareness interventions may help users recognize phishing risks, understand their potential consequences and develop greater confidence in responding appropriately. Such approaches may support efforts to address human-related cybersecurity vulnerabilities in educational and organizational contexts. Originality/value This study demonstrates how behavioral modeling can be used to inform the design of future GCA interventions. By identifying which PMT-related psychological factors are more strongly associated with students’ email security behavior, the study provides an evidence base for prioritizing design goals and selecting gamification mechanisms aligned with users’ behavioral needs, rather than applying game elements in an ad hoc or one-size-fits-all manner.

Authors

Institutions

Publication Details

Journal
Information and Computer Security
Published
2026-09-15
DOI
https://doi.org/10.1108/ics-05-2026-0317
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Modeling students’ email security behavior toward phishing threats using PMT for gamified cybersecurity awareness design

SangGyu Nam, Anderson Kevin Gwenhure, Athicha Umnouyvittayakul, Napussanun Nakmangsang et al.
Information and Computer Security
Information and Cyber Security
article

Modeling students’ email security behavior toward phishing threats using PMT for gamified cybersecurity awareness design

SangGyu Nam, Anderson Kevin Gwenhure, Athicha Umnouyvittayakul, Napussanun Nakmangsang, Lily Lalinee Ord
article en

Abstract

Purpose This study aims to examine the psychological factors associated with students’ email security behavior toward phishing threats and uses these findings to inform future gamified cybersecurity awareness (GCA) design decisions. It addresses the need for awareness interventions that are grounded in users’ behavioral characteristics rather than relying primarily on passive information delivery. Design/methodology/approach A quantitative survey design was used. Data were collected from 544 university students using a closed-ended questionnaire grounded in protection motivation theory (PMT). Covariance-based structural equation modeling was used to test the hypothesized relationships among perceived susceptibility, perceived severity, self-efficacy and email security behavior. Multi-group analysis examined whether these relationships differed between students with and without prior cybersecurity awareness or training exposure. Findings Perceived threat severity and self-efficacy significantly predicted email security behavior, while perceived susceptibility had no significant direct effect. Prior cybersecurity awareness or training exposure did not significantly moderate any of the hypothesized relationships. The model explained 40.7% of the variance in email security behavior. Research limitations/implications The study relied on self-reported data, convenience sampling and a predominantly undergraduate student sample, which may limit generalizability. The PMT model also used a focused specification comprising susceptibility, severity and self-efficacy, while prior awareness or training was operationalized only as a binary exposure measure. Future studies should use broader PMT specifications, more detailed measures of awareness and training characteristics, objective behavioral measures and experimental or longitudinal designs. Practical implications The findings suggest that future GCA interventions should prioritize making phishing consequences tangible and strengthening users’ confidence and capability to respond through mechanisms such as realistic scenarios, branching decision activities, guided practice, immediate feedback and progressive challenges. Approaches aimed at increasing personal relevance may also be explored, although the nonsignificant effect of perceived susceptibility warrants caution. Social implications Better designed awareness interventions may help users recognize phishing risks, understand their potential consequences and develop greater confidence in responding appropriately. Such approaches may support efforts to address human-related cybersecurity vulnerabilities in educational and organizational contexts. Originality/value This study demonstrates how behavioral modeling can be used to inform the design of future GCA interventions. By identifying which PMT-related psychological factors are more strongly associated with students’ email security behavior, the study provides an evidence base for prioritizing design goals and selecting gamification mechanisms aligned with users’ behavioral needs, rather than applying game elements in an ad hoc or one-size-fits-all manner.

Information and Computer Security
Thammasat University (TH)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.