Identifying factors influencing the employee's intention with self-protective behaviors against phishing attacks
基于保护动机理论,研究了200名高校员工面对网络钓鱼攻击时,影响其自我保护行为意向的因素,发现感知脆弱性、风险、障碍、反应效能和自我效能等关键作用。
Purpose Phishing is a form of social engineering attack that poses an increasingly significant risk in today's digital era. The challenges and implications associated with phishing affect both end users and organizations. However, organizations face particularly serious consequences, as a single employee's error can compromise the security and privacy of the entire organization. Design/methodology/approach This research examines the factors influencing employees' intentions to adopt self-protective behaviors against phishing attacks using protection motivation theory (PMT). The study sample comprised 200 employees working in higher education institutions (HEIs). Findings Perceived vulnerability, perceived risk, perceived barriers, response efficacy and self-efficacy influence behavioral intention. The findings also identify significant positive associations between conceptual knowledge and self-efficacy, procedural knowledge and self-efficacy and perceived vulnerability and information security awareness. Originality/value This study contributes to the state of the art by extending PMT by integrating conceptual and procedural knowledge to explain employees' self-protective behaviors against phishing attacks. It also provides empirical evidence from the higher education sector, a context that has received limited attention in prior phishing research.