Modeling students’ email security behavior toward phishing threats using PMT for gamified cybersecurity awareness design
Purpose This study aims to examine the psychological factors associated with students’ email security behavior toward phishing threats and uses these findings to inform future gamified cybersecurity awareness (GCA) design decisions. It addresses the need for awareness interventions that are grounded in users’ behavioral characteristics rather than relying primarily on passive information delivery. Design/methodology/approach A quantitative survey design was used. Data were collected from 544 university students using a closed-ended questionnaire grounded in protection motivation theory (PMT). Covariance-based structural equation modeling was used to test the hypothesized relationships among perceived susceptibility, perceived severity, self-efficacy and email security behavior. Multi-group analysis examined whether these relationships differed between students with and without prior cybersecurity awareness or training exposure. Findings Perceived threat severity and self-efficacy significantly predicted email security behavior, while perceived susceptibility had no significant direct effect. Prior cybersecurity awareness or training exposure did not significantly moderate any of the hypothesized relationships. The model explained 40.7% of the variance in email security behavior. Research limitations/implications The study relied on self-reported data, convenience sampling and a predominantly undergraduate student sample, which may limit generalizability. The PMT model also used a focused specification comprising susceptibility, severity and self-efficacy, while prior awareness or training was operationalized only as a binary exposure measure. Future studies should use broader PMT specifications, more detailed measures of awareness and training characteristics, objective behavioral measures and experimental or longitudinal designs. Practical implications The findings suggest that future GCA interventions should prioritize making phishing consequences tangible and strengthening users’ confidence and capability to respond through mechanisms such as realistic scenarios, branching decision activities, guided practice, immediate feedback and progressive challenges. Approaches aimed at increasing personal relevance may also be explored, although the nonsignificant effect of perceived susceptibility warrants caution. Social implications Better designed awareness interventions may help users recognize phishing risks, understand their potential consequences and develop greater confidence in responding appropriately. Such approaches may support efforts to address human-related cybersecurity vulnerabilities in educational and organizational contexts. Originality/value This study demonstrates how behavioral modeling can be used to inform the design of future GCA interventions. By identifying which PMT-related psychological factors are more strongly associated with students’ email security behavior, the study provides an evidence base for prioritizing design goals and selecting gamification mechanisms aligned with users’ behavioral needs, rather than applying game elements in an ad hoc or one-size-fits-all manner.
Authors
- SangGyu Nam (ORCID: https://orcid.org/0000-0002-7424-8469)
- Anderson Kevin Gwenhure (ORCID: https://orcid.org/0009-0005-7427-9635)
- Athicha Umnouyvittayakul (ORCID: https://orcid.org/0009-0002-2086-0676)
- Napussanun Nakmangsang (ORCID: https://orcid.org/0009-0004-0055-5556)
- Lily Lalinee Ord (ORCID: https://orcid.org/0009-0000-8792-7500)
Institutions
- Thammasat University (TH)
Publication Details
- Journal
- Information and Computer Security
- Published
- 2026-09-15
- DOI
- https://doi.org/10.1108/ics-05-2026-0317
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00