INTRODUCTION Continued and persistent cyber attacks
Background and Rationale of Study
Continued and persistent cyber attacks below the threshold of armed conflict and
the possibility of a cyber attack of significant consequence call for significant
policymaking efforts to manage national cyber threats and bring the nation to an
acceptable level of risk (Cyberspace Solarium Commission, 2020; Office of the Director
of National Intelligence, 2021). Cyber attacks from Russia, China, Iran, and North Korea
on
American businesses have taken place without the cost of retaliation (The White House,
2018). Cyber-enabled economic espionage from China has resulted in trillions of dollars
of intellectual property theft (The White House, 2018). The need to address national
cybersecurity and economic losses from cyber attacks are major motivating factors for
formulating strategic cyber policy in America.
Growing threats in cyberspace present in various forms, including cyber
espionage, state-sanctioned criminal activity, information operations, and the possibility
of disrupting critical infrastructure employing a cyber offensive operation (Office of the
Director of National Intelligence, 2021). In addition to state threats, there has been a
seven-fold yearly increase in ransomware reports, with threat actors leveraging
misinformation to manipulate COVID-19 fears and the growth of IoT (devices with
internet connection capabilities) (BitDefender, 2020). To address these problems,
policymaking in cyberspace requires a complicated formulation that balances addressing
risk and increasing security with maintaining the efficiency and ease of use of the internet
for a system that is connected on a global scale (Hurwitz & Schaub, 2018).
In 2021, the United States experienced unprecedented cyber attacks from
nationstates and various criminal organizations with direct and indirect ties to China and
Russia (Sanger et al., 2021a). Recent attacks include the Microsoft Exchange hack that
resulted in a collaborative North Atlantic Treaty Organization (NATO) response addressed
to
China by Western allies (Kanno-Youngs & Sanger, 2021). In a cyber attack attributed to
Russia, the Solar Winds hack was characterized by free access to confidential United
States information systems, including the Department of Energy’s confidential nuclear
information (Sanger et al., 2021b). In an attack on critical infrastructure, the Colonial
pipeline ransomware attack had regional repercussions for the United States from a
criminal organization based out of Russia (Parfomak & Jaikaran, 2021). While these
cyber operations all operated below the threshold of armed conflict, they substantially
affect the operations and security of the United States. Countless operations have not
gained public attention, and counting cyber attacks is almost impossible (SEC, 2022).
While cyberspace is a relatively new development in human history (Leiner et al.,
2009), the utilization of cyber weapons, trends of cyber attacks, and debates about a
possible cyberwar have become an important national concern with interdisciplinary
policy implications (Gartzke, 2013). Of highest priority are the interconnected critical
infrastructure systems that utilize operational technology connected to the internet with
agencies like the Department of Homeland Security’s (DHS) Cybersecurity and
Infrastructure Security Agency (CISA) created specifically to thwart cyber threats to
critical infrastructure (McCaul, 2018). Protecting personal information and intellectual
property from cyber attacks is another concern in the form of large data breaches that
compromise the integrity of information systems (Hickey et al., 2020). Other than cyber
2
operations, using cyberspace to conduct information operations is characterized by
causing social disruption or confusion with disinformation (Rid, 2021). These threat
vectors in cyberspace are difficult to manage utilizing traditional policymaking.
To address the growing national cybersecurity problem, cyber policy issues that
motivate this dissertation are the Cyberspace Solarium Commission’s (2020) stated
strategic end state for national cybersecurity: a state of sufficient cyber resilience that can
deny (through heightened security measures) and deter (through imposing cost) cyber
operations through a whole-of-nation approach. To assist in the achievement of a
wholeof-nation effort this study offers models that explain why individuals are motivated
to engage in greater cybersecurity efforts at individuals and organizational levels in
response to societal threats.
This study addresses several gaps in the literature on national cybersecurity
policy. The first gap I address is the need to make clear the contextual effects of types of
cyber operations given the wide variation of cyber operation types experienced by
various states. I analyze this first gap through a lens of cyber threat and international
relations (IR) literature. The second gap that I address is the need for a holistic risk
perception framework that addresses the cognitive and emotional appraisals essential to
understanding a public response. I analyze this second gap through a psychological lens
of risk perception. Finally, a third gap I address is the implementation of cybersecurity at
the organizational level, including how societal risk perceptions and perceptions of
organizational cybersecurity effectiveness come together to influence attitudes and
compliance with organizational cybersecurity policy. I analyze this third gap through a
lens of expected utility modeling and frameworks established for information security.
These chapters incrementally build towards addressing a larger gap in literature,
3
collectively these chapters model individual and organizational cybersecurity responses
that represent a whole-of-nation implementation of national cybersecurity strategy.
To address these gaps, experimental surveys are utilized to support hypotheses that
explain the influence of cyber operations, psychological risk perception, and
organizational influence on cyber policy attitude and compliance. Motivated by the above
national cyber policy issues, I ask several research questions to move the academia of
policy and cybersecurity forward. Research questions of this dissertation include:
1. Do different types of cyber operations affect risk perception or cybersecurity
responses in university students across the United States? (Chapter 2)
2. Why do risk perception variables (anticipated negative emotional response,
perception of magnitude of effect of cyber disaster, and perception of likelihood of
cyber disaster) contribute willingness to engage in cybersecurity behaviors at the
individual level? (Chapter 3)
3. Do threat appraisals (psychological risk perception variables) and coping
appraisals (perception of organizational cybersecurity effectiveness) offer their
own paths in the explanation of intention to comply with organizational
cybersecurity policy? (Chapter 4)
Three Models
This dissertation offers three models that iteratively build towards explaining why
individuals respond to societal cyber threats, how their cybersecurity responses may then
be affected by cyber threats through risk perception, and how the combination of risk
perception and perceived efficacy contribute to organizational compliance. Research in
the area of cyber threats and cybersecurity is fairly nascent, as such this dissertation is
oriented to first addressing the foundational issues of the effects of cyber threats, then
4
building on how this effect may effect both individual and organizational variables. My
approach to building a body of knowledge that iteratively builds presents as repetitive
however this approach is necessary as the main message of this dissertation is that better
models and frameworks need to be utilized in the study of cybersecurity.
This dissertation operates with several assumptions: firstly, predicting cyber policy
support depends on the perception of risk from a disaster (Slovic, 2016) and the policy
alternatives provided as a substitute for the status quo (Anderson, 2015). Secondly, there
are enumerable accounts of cyber incidents below the threshold of armed conflict
(Cyberspace Solarium Commission, 2020), with only a handful of incidents resulting in
the possibility of a widespread disaster (for a recent example, note the Colonial Pipeline
ransomware attack (Parfomak & Jaikaran, 2021)). Some of these cyber operations are
published in national, state, and local news sources, leading to changes in the perception
of risk for the public. Thirdly, risk perception and cybersecurity responses to cyber
incidents result from various contextual cues that depend on the type of cyber operation.
In other words, while the unifying threat of cyber operations is using cyber as a means,
assessing the risk of cyber disaster is directly related to the cyber threat type. Fourthly,
experts perceive risk differently from lay people, with experts adopting an empirical
approach while lay people consume partisan media and respond emotionally (Slovic,
2000). Finally, cyber operations target specific organizations or IT networks, but the news
of cyber operations on specific organizations has a larger societal effect. As cyber
operations target organizations, organizations develop cyber policies to address
cybersecurity issues and lead in the implementation of cybersecurity technology. In
conclusion, diverse scenarios of different types of cyber operations and organizational
policy responses represent the evolutionary phenomenon of cyber policy.
5
Model 1
This quantitative dissertation offers three models to help explain the
implementation of national cyber policy. Chapter 2 presents the first study, offering
oneway ANOVA models and planned contrast that test for differences between cyber
operation types and control based on risk perception and cybersecurity response (see
Figure 1.1).
Figure 1.1
Cyber Threat Model
This first study utilizes an experimental approach that reviews differences in risk
perception and cybersecurity response elicited from fictitious news article headlines that
vary according to three cyber threat types: cyber degradation, cyber espionage, and cyber
disruption. This first chapter attempts to isolate the effects of different types of cyber
operations and examine why cyber operations differ depending on risk perception. This
study asks questions such as: Are specific cyber operations driven by emotional reactions?
Are they driven by a cognitive assessment, such as an assessment of the magnitude of
effect of the disaster or the likelihood of the disaster? Is there a noticeable effect on
cybersecurity response or reports of cyber risk when the various conditions of cyber
threats are presented?
6
Model 2
Chapter three presents a second study that builds on the first chapter and controls
for cyber operation types. Chapter 3 iteratively builds a model that takes a holistic
approach that includes cognitive and emotional aspects of psychological risk perception
to explain the relationship of cyber threat types and an individual cybersecurity response.
This second study explains the individual cybersecurity risk responses of willingness to
utilize privacy technology through risk perception factors (See Figure 1.2).
Figure 1.2
Risk Perception Model
First, I model cybersecurity responses with a conventional approach to measuring
risk perception using scales that measure the anticipated outcomes of a disaster and the
subjective probabilities of a cyber disaster’s occurrence. Next, I add a psychological
component that includes an anticipated negative emotional response scale that measures
dread to a model of conventional risk perception. Finally, the model adds a measure of
perceived cybersecurity knowledge to control for individual differences with a
cybersecurity awareness scale. Model improvements are tested to identify if the factors
significantly contribute to the betterment of the model. Finally, there is a review of the
mediation of cyber operations through risk perception to the cybersecurity response of
willingness to utilize privacy technology. This study asks: Why are individuals motivated
to address cybersecurity problems of societal cyber threats? What risk perception factors
7
contribute to a holistic cybersecurity model? Does risk perception mediate cyber
operation conditions toward a cybersecurity risk response?
Model 3
Chapter four builds on chapters one and two, testing the significance of the fit of a
path model that includes risk perception and organizational cybersecurity effectiveness to
explain attitudes towards organizational cybersecurity policy and intentions to comply
with it (See Figure 1.3).
Figure 1.3
Fusion
Model
This path model includes a hypothesized interaction of cyber threat type and
organizational cybersecurity initiatives. In addition to cyber threat conditions, o9bn
2rganizational cybersecurity policies using multifactor authentication (MFA) and a
cybersecurity response team are compared against a control. This chapter makes logical
assumptions about the interaction between threat and cybersecurity initiatives, such as the
use of MFA to help address possible espionage threats or the use of a cybersecurity team
being preferable if there are attacks on an organization’s system. This study aims to
8
explain a model of attitude towards organizational cybersecurity policy and intention to
comply with cybersecurity policy. This study asks: Is there an interaction between policy
type and the context of the type of threat? Can a path that includes cyber threat and policy
type be fitted on a model that includes a measure of organizational effectiveness and risk
perception towards organizational policy attitudes and intentions?
The collective theme of these papers is to better understand responses to cyber
threats that motivate cybersecurity implementation at individual and organizational
levels. The implications of these models will help to plan for the future of possible cyber
threats to America, help to model future risk perception as it relates to cybersecurity
responses, and help to explain the implementation of cybersecurity at the organizational
level. These research objectives can guide the assessment and evaluation of cyber threats
that inform national cybersecurity strategy.
Overview of the National Security Cyberspace Dilemma
Cyberspace presents a conundrum to traditional national security approaches for
several reasons thus requiring a whole-of-nation approach as outlined by the CSC.
Firstly, cyberspace problems occur in what can be described as a man-made domain or
the “fifth domain,” as opposed to land, sea, air, or space, and do not adhere to common
physical laws (Clarke & Knake, 2019). Problems occurring in a man-made domain
require specialized knowledge that is atypical of the other four domains typical in
military warfare and conflict response, with programmers of cyberspace able to code
their own rules of how interactions occur (Clarke & Knake, 2019). Because of the
necessity of specialized knowledge, lay people are not intuitively knowledgeable about
the risk and policy options to manage cyberspace.
9
To address fundamental issues of cyberspace as a man-made domain, several
considerations must be made. The private sector influences cyberspace, and to address
policy in the area of design, fostering public-private partnerships is key to influencing
cyberspace systems' design (Farwell, 2018). As a result, the overall cyber resilience of the
nation is more accurately reflected in the cumulative implementation of cyber policy by
private enterprises. Another consideration is that cyberspace is a globally interconnected
system of systems that requires collaboration with other states and global national
corporations to work towards creating a more resilient cyber ecology and establishing
standards and norms (Demchak, 2020).
Secondly, cyberspace problems have spatial concerns, lacking the need for
proximity and the ability to attack a target globally by relatively cheap means (Raymond,
2018). Physical state borders do little to play a role in the jurisdiction of cyberspace
interactions (Demchak & Dombrowski, 2018). Lack of jurisdiction results in difficulty
enforcing costs on attackers, with state actors exploiting gray space and hiding behind the
cover of their country while acting as if they are working independently from state
organizations (Libicki, 2018).
Thirdly, the difficulty of clearly declaring the origin of an attack presents problems
with imposing costs on attackers (Rid & Buchanan, 2015). Cyber attacks, by nature, are
inherently covert operations (Gartzke & Lindsay, 2015). The problem of attribution or the
difficulty of forensically linking an offender to an offensive cyber operation creates
problems that include uncertainty of response and the need for the defender to make a
clear case explaining who is responsible for the attack in order to justify to the
international community a retaliatory response.
10
To address these issues, several policy directions may take place, one direction is
the attempt to influence international standards and the agreement of an international
body that places higher costs on the offender (Cyberspace Solarium Commission, 2020).
While this does not solve the attribution problem, it deters the attack by increasing the
cost. Another policy solution is simply to increase defensive efforts and cyber resilience,
where systems can deny most attacks and if attacked return to a functioning baseline
quickly (Clarke & Knake, 2019). Increasing defensive efforts would largely nullify many
cyberspace problems. To achieve this, defensive responses to cyberspace require a societal
buy-in and a long-term strategy including developing a whole-of-nation approach
(Cyberspace Solarium Commission, 2020).
Fourthly, the cyberspace domain being relatively new offers evolving issues with
signaling, bargaining, and coercion (Valeriano et al., 2018). With many cyber attacks
occurring beneath the threshold of armed conflict, there is international ambiguity about
what types of repercussions are acceptable internationally (Gartzke & Lindsay, 2015).
Signaling of consequences for cyber operations presents a conundrum as the state that is
attacked is unsure of what is the coercive objective because attribution is uncertain
(Valeriano et al., 2018). To this end, America has not been able to clearly signal what
actions will be taken if cyberspace operations result in espionage or societal confusion,
alternatively, it is commonly agreed that cyber attacks resulting in destruction should be
met with kinetic response (Lin, 2018). To address cyberspace policy in signaling and
escalation it is recommended by the Cyberspace Solarium Commission (2020) that an
updated and public cyberspace directive endorsed by the American government will
delineate and make clear all actions that occur following a cyber attack.
Fifthly, a majority of the cyberspace incidents occur in the private sector (Farwell,
11
2018). This calls into question the responsibility of the government and private
corporations in the management of national security and defense. Some
corporations that utilize cyberspace have greater effects on society than others, as
is the case with the private corporations that manage critical infrastructure which
is considered essential to the daily functioning of American society (Corallo et al.,
2020). Attacks on critical infrastructure, by virtue of operational technology,
present a larger effect of direct disaster with the possibility of resulting in actual
physical consequences (Izycki & Vianna, 2021). For these reasons equity
problems arise because few private corporations are better able to address
cybersecurity issues than others with many global national corporations logically
opting to decline information sharing and collaborating with other smaller
corporations (CISA, 2019).
Finally, cyberspace problems do not have clear protocol, norms, or standards that
guide national security (Cyberspace Solarium Commission, 2020). Furthermore,
cyberspace incidents are confidential with lessons learned being few and far between
(Smeets, 2018). A consideration that needs to be addressed is the possibility of cyber
disclosures, specifically as they occur in a predominantly private sector. On the one hand,
state organizations and private businesses are hesitant to disclose because they have
liability and reputational problems, on the other hand, the only way to increase cyber
defensive efforts is to make known cyber attacks so that firewalls can be organized and
the means of offensive capabilities can be nullified (Clarke & Knake, 2019).
Due to the nascent nature of cybersecurity problems and the interdisciplinary
complexity of research there is a dearth of literature that highlights the multiple facets of
cybersecurity implementation including differences of types of cyber threats, different
12
mechanisms of psychological risk perception, use of cybersecurity tools for personal use,
perceptions of organizational cybersecurity effectiveness, and organizational and
individual cybersecurity responses. The dynamic nature of distributed confidential
problems in the private enterprise sector limits cybersecurity inquiry. Unveiling the
window of dynamics of cybersecurity policy of private businesses and individual use of
cybersecurity tools requires an alternate route. Using a survey approach that addresses
risk perception and acceptance at an individual and organizational level will be necessary
for implementing a national cyber strategy that includes a whole-of-nation approach.
Cyber Operations & The Cyber Threat Landscape
To better understand the threat of cyberspace and how it affects national security it
is important to understand the context of cyberspace operations in the current climate.
The 2021 Annual Threat Assessment of the US Intelligence Community (ATA) (Office of
the Director of National Intelligence, 2021) contextualizes the threats of 2021 as being
framed by global disruption, specifically with the competitive global environment
cultivated by Russia and China. The 2021 ATA specifically highlights China first and
Russia second among the identified threats listed in their threat assessment specifically
for their roles as global, influential competitors. Interestingly, while larger global threats
are framed by their document in the context of Great Power Competition, interactions
between these states to date are characterized by moments of frequent tensions and public
disagreement but have also been without declared conflict. As a result, much of the threat
and adversarial interactions occurs in gray spaces below the level of armed conflict thus
implying the need for a retooling of intelligence approaches (Watling, 2021). The use of
gray space occurring below the threshold of armed conflict is also true for cyberspace
incidents with China and Russia leading cyber offensives against the United States
13
(Valeriano & Maness, 2018) and with cyberspace being primarily conducted in gray
spaces below armed conflict (Libicki, 2018).
Along with the threats of Russia and China, the ATA (2021) also highlights the
presence of emerging technology as a framework for new threats to be considered as
force multipliers. Specifically, technology that optimizes the use of information as well as
new threat domains of space and cyber are identified as a force multiplier for addressing
the risk of a national threat (Office of the Director of National Intelligence, 2021).
Emerging threats offer an added layer of complexity because they include the use of
technology that has implications for both economic and defense uses thus heightening the
tensions of competition for security and economics at the same time (Moulton et al.,
2020). Technology such as artificial intelligence or machine learning can be used to both
influence economic and trade interactions with intelligence favoring a technologically
advanced state these same technologies also have the capability to be used for defense
interactions assisting in making tactical decisions at a precision and quick speed
(Moulton et al., 2020). Emerging technology in new domains therefore plays a role in
national security as it contributes both to competitive state economics and competitive
military uses.
Valeriano et al. (2022) presents the only peer-reviewed source of cyber conflict
incident data. According to Valeriano et al.’s (2018) review of cyber conflict data, not all
cyber operations are alike; rather they can be largely categorized into three different
buckets all of which are used by states to strategically gain specific competitive
advantages from their rivals. Firstly, cyber disruption is characterized as "[a] low cost,
low payoff form of cyber strategy designed to shape bargaining behavior (11)." Cyber
disruptions are ways to signal and test adversary responses. Cyber disruptions include
14
website defacement and DDoS incidents with a shared goal to undermine the public
confidence and challenge existing policy choices of an adversary. Secondly, states use
cyber espionage as an attempt to exploit information asymmetry and achieve long term
competitive gains through use of information. Cyber espionage is a covert operation and
unlike cyber disruption the goal is not to signal to the adversary rather the goal is to
leverage information towards a competitive or diplomatic position of advantage that can
be leveraged for state bargaining. Thirdly, cyber degradation is "coercive operations
designed to sabotage the enemy target[ing] networks, operations, or systems (12)." Cyber
degradation is costlier than cyber disruption or espionage but it results in higher coercive
payoffs. Cyber degradation includes attacks on critical infrastructure that can result in
death and widespread injury.
Valeriano et al. (2018) presents the conclusion that "the utility of cyber strategy is
as a form of political warfare optimized for the 21st century that relies on tacit bargaining
and ambiguous signaling to help rival states achieve a position of relative advantage in
long-term competition (13)." Cyber conflict presents a uniquely, new dynamic to
signaling among adversarial states that is at times ambiguous when attribution is
uncertain and bargaining is only made explicit when coupled with additive forms of
diplomatic communications.
While Valeriano et al. (2018) highlights the different motivations for China, the
United States, and Russia and they note that each of the three nation-states engage in
cyber conflict differently. In accordance with Valeriano et al.’s (2018) dataset the United
States is the leader of degradation cyber interactions suggesting that the United States
uses their cyber capabilities sparingly to maintain a superior advantage; China frequently
uses cyber espionage to bridge the gap of economic, military, and technological
15
competition; and Russia frequently uses cyber disruption and disinformation as a cheap
alternative to meet their political aspirations on the world stage. This finding highlights
the need for varied understanding and modeling of these different types of operations as
they are dependent on the state carrying out the attack.
This dissertation reviews responses elicited from a variety of offensive cyber
operation types. I hypothesize that different types of cyber operations have varied
cognitive and emotive appraisals resulting in different reasons why cyber operations are
perceived as deleterious. A differentiation of cyber operation is important to prevent
scholars attempting to describe cyber conflict without context of how cyber operations
may differ. This dissertation assumes that state use of cyber operations will continue to
evolve and that government responses will, spurred by evolving cyber operations, also
be pushed into evolving responsive policy to the extent that the United States may
experience new cyber operation types in the near future and must be ready to address the
policy ramifications of a new cyber landscape. Whole-Of-Nation Cyberspace Strategy
The Cyberspace Solarium Commission’s Final Report (2020) was the first-ever
attempt to provide strategic guidance for the United States to address evolving threats and
emerging technological vulnerabilities at a national scale. The 2019 National Defense
Authorization Act (Thornberry, 2018) chartered the U.S. Cyberspace Solarium
Commission (CSC). The President and Congress tasked the Commission to answer two
fundamental questions: What strategic approach will defend the United States against
cyberattacks with significant consequences? And what policies and legislation are
required to implement that strategy?
After conducting interviews with over 300 subject matter experts in the field of
cyberspace, the CSC endorsed a new strategy that is referred to as Layered Cyber
16
Deterrence (LCD). The goal of this strategy is to reduce the probability and impact of
cyberattacks of significant consequence. To achieve the goal of LCD, the CSC describes
three layers. The first layer, shape behavior, is a strategy of shaping cyberspace by
working with allies and partners to promote global norms and standards. The second
layer, deny benefits, is a strategy of increasing the cost of cyberattacks by addressing the
entire cyberspace ecosystem including the general public and private sectors to promote a
resilient and secure national network of cyberspace. The third layer, impose cost, is a
strategy of maintaining abilities to retaliate against actors to be used firstly, as a deterrent
that will reduce the likelihood of attack for fear of repercussion and secondly, as a
response should an actual attack occur.
Within the layers described above, the 2020 CSC report makes several
recommendations based on six pillars. The first, foundational pillar recommends
structural changes to the U.S. government's structure and organization for
cyberspace by addressing the necessity of establishing a National cyberspace
strategy, National Cyber Director, increasing Cybersecurity and Infrastructure
Security Agency's funding and reach, and creating a Congressional oversight
committee for cyberspace. The second pillar, under the layer of shaping behavior,
describes strengthening norms and nonmilitary tools to include diplomatic and
strategic use of cyber standards and norms by building a coalition of cyberspace
nations. The third, fourth, and fifth pillars fall under the layer of denying benefits
and make up the bulk of the LCD strategy. The third pillar recommends
promoting national resilience by creating a national infrastructure capable of
withstanding cyberattacks. The fourth pillar recommends reshaping the cyber
ecosystem by changing the baseline of cybersecurity for the entirety of the
17
internet. And the fifth pillar recommends operationalizing cybersecurity
collaboration with the private sector by directing private sector objectives towards
government supported cybersecurity national strategies. Lastly, the sixth pillar
recommends preserving and employing the military instrument of national power
to deter cyber offensives including a strategy of cyber persistence. Each pillar
within each layer has itemized policy recommendations.
To address the third, fourth, and fifth layers of denying benefits, the bulk of the
LCD strategy, I offer modeling in the preceding chapters that describes the
implementation of whole-of-nation strategies. I present models that can help promote
national resilience by ensuring compliance of organizational policy and individual use of
cybersecurity tools by examining the various cyber threat strategies conditions that have
been used in interstate conflict. I model the use of individual privacy tools as a response
to cybersecurity events in society to help explain how a new baseline of cybersecurity can
be possible through a variety of cyber threat context and through greater risk assessment
of cyber disasters. Finally, I present models that review both cyber threat and cyber policy
conditions that will help with greater collaboration by the public sectors to address
societal problems related to cyber threats.
18
CHAPTER TWO
CYBER THREATS: AN EXAMINATION OF CYBER DEGRADATION, ESPIONAGE,
AND DISRUPTION IN AMERICA
Abstract
In the information age, the new threats of cyber attacks on information systems are both
unremarkable and dreadful at the same time. This chapter examines the various cyber
threat conditions, proposed by Valeriano et al. (2018) that have been used to examine and
characterize interstate cyber conflict, to test cyber threat differences on lay people. Using
a national sample of university students, I offer a survey experiment that test the effects
of cyber degradation, cyber espionage, and cyber disruption on risk perception and
cybersecurity response variables. I find that cyber degradation has the greatest effect on
the risk perception variables of negative anticipated emotional response and perceived
magnitude of effect. Cyber threat types do not reveal a direct effect on any of the
measured cybersecurity response variables. Furthermore, a planned contrast of conditions
reveals that cyber espionage and cyber disruption can be distinguished in effect from a
from cyber degradation and in the case of anticipated negative emotional response cyber
espionage is found to elicit a significantly greater response than cyber disruption.
Introduction
In 2010, the Stuxnet worm targeted Iranian nuclear enrichment systems with such
precision that when the news of the cyber attack became public, it seemed that the
international conflict landscape might be revolutionized by cyber operational capabilities
(Lindsay, 2013). In 2012, the Defense Secretary of the United States likened the
possibility of a cyber attack on critical infrastructure to a possible “cyber-pearl harbor”
suggesting that a cyber attack can be used as a preemptive method for war (Bumiller &
19
Shanker, 2012). While a cyber-pearl harbor is still in the realm of possibility, over a
decade's worth of cyber interactions has shown that the Stuxnet worm was an outlier in
the realm of cyber probabilities (Valeriano et al., 2018). The possibilities of a cyber Pearl
Harbor and the evidence of such a weapon as Stuxnet have created a narrative of cyber
attack that skews to what is possible rather than having foundations in what is probable
(Gartzke, 2013). Today, growing threats in cyberspace include cyber espionage,
statesanctioned criminal activity, information operations, and the possibility of disruption
to critical infrastructure (Office of the Director of National Intelligence, 2021). Cyber
operations can take many forms, and addressing how different cyber operation types
activate different risk responses will inform critical strategic initiatives for an American
cyber strategy.
Valeriano et al.’s (2018) peer reviewed dataset outlines the realities of cyber
operations and asserts that cyber operations fall into three categories: cyber degradation,
cyber espionage, and cyber disruption. Valeriano et al.’s (2018) three types of cyber
operations are used strategically by different states to affect a variety of coercive ends.
Cyber operations have varied effects. Cyber disruption is described as temporary in
effect, cyber espionage as having possible downstream effects that may not be
immediately detectable, and cyber degradation having the possibility of a destructive
effect. In addition to varied effects, there are also varied probabilities to cyber operations,
with degradation operations being the least likely and only executed by relatively
technologically advanced states. Cyber disruption and espionage are more probable
depending on the attacking and defending states. As such, it is crucial to assess whether
risk measurements such as the perception of effect and perception of likelihood are
20
aligned with the different types of cyber operations rather than simply assuming all cyber
incidents are alike.
Researchers of cyber conflict utilize experimental survey methods to understand
public perceptions and to explain why people endorse a strong threat response to cyber
operations, especially when cyber threats are infrequently destructive and when their
actual behavior is incongruent with their reported risk assessment (Gomez & Villar, 2018;
Gomez & Whyte, 2021; Kostyuk & Wayne, 2021). Given the exaggerated distress of
cyber incidents, “Cyber doom” is an area of interest as there is a belief among lay people
that a sudden societal upheaval will be the product of cyber conflict (Lawson, 2013).
According to a 2022 survey by the Pew Research Center, Americans have consistently
reported cyber attacks from other counties as their highest international threat concern
(with the exception of the spread of infectious disease in 2020) – this is compared with
such topics as Russia’s / China’s power and influence, the condition of the global
economy, global climate change, etc (Silver, 2022).
Conditions of data breach (Kostyuk & Wayne, 2021), conditions of news content
on cyber attacks (Gomez & Villar, 2018), conditions of lethal and nonlethal terrorist
attacks (Shandler et al., 2021), and conditions of real-world exposure to a cyber attack
(Shandler & Gomez, 2023) are examples of recent cyber operations survey experiments.
This study addresses a gap in the literature by taking a holistic approach and examining
different types of cyber threat operations rather than a single type of cyber operation.
Given the nascent characteristics of a cyber disaster and the difficulties of
understanding information technology processes, it can be argued that the public is still
determining different aspects of risk perception and cybersecurity response. With the
different types of cyber operations and the limited knowledge of public risk perception,
21
this study aims to measure the public’s baseline perception of cyber threats and test for
significant differences depending on cyber operation type to make inferences of public
perception related to cyberconflict. In sum, this study offers various conditions of cyber
threat methods in the form of news headlines and assesses the various risk perceptions
and responses elicited by the headlines to identify perceived differences among cyber
threats.
Cyber Operation Types
State offensive cyber operations have historically been handled with secrecy;
however, this trend appears to be shifting as more countries choose to go public about
cyber offensives (Baram, 2022). In 2021, the United States experienced an unprecedented
number of cyber attacks from nation-states and various criminal organizations with direct
and indirect ties to China and Russia (Sanger et al., 2021a). One publicly attributed attack
is the Microsoft Exchange hack that resulted in a collaborative North Atlantic Treaty
Organization (NATO) response addressed to China by Western allies (Kanno-Youngs &
Sanger, 2021). The Solar Winds hack attributed to Russia resulted from a built-in
backdoor at the supply chain level that led to access to confidential United States
information systems, including the Department of Energy’s confidential nuclear
information (Sanger et al., 2021b). In an attack on critical infrastructure, the Colonial
Pipeline ransomware attack had regional repercussions for the United States and
originated from a criminal organization based out of Russia (Parfomak & Jaikaran, 2021).
These cyber operations all operated below the threshold of armed conflict. The sheer
number of cyber attacks is likened to a death by a thousand cuts, which substantially
affects the operations and security of the US. According to the SEC (2022), countless
cyber operations have not gained public attention, and cyber-attacks are occurring at such
22
a rate that attacks no longer gain national attention. Persistent state-motivated cyber
operations are quickly becoming normalized in the American psyche.
Cyber attacks on American businesses from Russia, China, Iran, and North Korea
have taken place without the cost of retaliation (The White House, 2018). Growing
threats include a variety of types, including espionage through cyber means,
statesanctioned criminal activity through the means of malware such as ransomware,
information operations in the form of disinformation campaigns, and the possibility of
disruption to critical infrastructure (Office of the Director of National Intelligence, 2021).
The losses to American businesses and the wide variety of threat vectors are a
considerable motivation for developing a strategic approach to address the growing cyber
problem (The White House, 2018).
Understanding how to categorize different cyber types is essential in
understanding how different threat vectors elicit different risk perceptions and responses.
Valeriano et al. (2018) categorizes cyber operations into three strategic types: disruption,
espionage, and degradation. According to Valeriano et al. (2018), cyber disruption is a
"low cost, low payoff form of cyber strategy designed to shape bargaining behavior (pg.
11)." Cyber disruptions are ways to signal and test adversary responses. Cyber disruptions
include website defacement and Distributed Denial of Service (DDoS) incidents with a
shared goal to undermine public confidence and challenge existing policy choices of an
adversary. Cyber disruption is a low-cost, low-reward cyber attack with the least potential
to cause disaster and is limited in effect, causing a temporary disruption to a system.
Secondly, states use cyber espionage to exploit the information asymmetry and
achieve long-term competitive gains through various levels of secret information
regarding state diplomatic and economic strategy and national security. Cyber espionage
23
is a covert operation where the goal is not to signal to the adversary; instead, the goal is to
leverage information toward a competitive or diplomatic advantage that can be used for
state bargaining. Data breaches are mired with state-sponsored activity. As an example,
China has been attributed to a variety of more well-known breaches, including the Office
of Personnel and Management (OPM) hack (Chaffetz, 2016), the Equifax hack (Robbins
& Sechooler, 2018), and the Marriott hack (Gressin, 2018). These data breaches have
compromised millions of individuals, requiring credit monitoring to ensure against
possible future intrusions. In the case of the 2015 OPM hack, 21.5 million Americans
were affected (Chaffetz, 2016). The OPM hack resulted in an Oversight Committee
Report with findings indicating that the hack could have been prevented if a more
significant budget had been placed on cybersecurity and an improved culture of cyber
hygiene had been implemented (Pham, 2016). In one of the most far-reaching data
breaches, the Equifax data breach resulted in an estimated 143 million Americans having
their personal information stolen (Robbins & Sechooler, 2018).
Finally, cyber degradation is "coercive operations designed to sabotage the enemy
target networks, operations, or systems (Valeriano et al., 2018, p. 12)." Cyber degradation
is more costlier than cyber disruption or espionage and produces higher coercive payoffs.
Cyber degradation includes attacks on critical infrastructure that can result in death and
widespread injury. Cyber operations such as Stuxnet describe cyber degradation where
the operation aims to affect coercion through a high-cost, high-payoff operation. Cyber
degradation can also describe an attack that will result in the failure of operational
technology, the technology utilized to affect real-world operations such as controls for
energy systems, chemical treatment, or pipelines. Notably, a cyber disruption such as a
DDoS attack can initially present as a disruption; however, a persistent activity such as
24
the case of the Estonia attack can be considered a form of cyber degradation (Jensen et
al., 2019).
Valeriano et al. (2018) concludes that "the utility of cyber strategy is as a form of
political warfare optimized for the 21st century that relies on tacit bargaining and
ambiguous signaling to help rival states achieve a position of relative advantage in
longterm competition (pg. 13)." Cyber conflict presents an ambiguous dynamic when
signaling the reason for a cyber attack especially when attribution is uncertain. In other
words, understanding the attacker's reason for the attack is highly limited if the attacked
state does not know who the attacking state is. While Valeriano et al. (2018) highlight the
different motivations for China, the United States, and Russia, they also note that each
nation-state engages in cyber conflict differently. Per Valeriano et al.’s (2018) dataset, the
United States is the leader in degradation operations, also suggesting that the U.S.
leverages its cyber capabilities sparingly to maintain a superior advantage; China
frequently uses espionage operations to bridge the gap of economic, military, and
technological competition; and Russia frequently uses cyber disruption and
disinformation operations as a cheap alternative to meet their political aspirations on the
world stage. These findings highlight the need for additional understanding and modeling
of these different types of operations as they depend on the nation carrying out the attack.
Other types of cyber operations categories proposed are limited and include Rid’s
(2013) description of cyber types that mirror Valeriano et al.s (2018). Rid (2013) states
that cyber types include sabotage, espionage, and subversion. Sabotage is much like
cyber degradation in that digital information is manipulated to sabotage an information
system. Espionage follows the description of cyber espionage. Rid (2013) includes
subversion to address information operations such as disinformation campaigns
25
facilitated through cyber means. Valeriano et al. (2018) argues that the scope of
information operations differs from that of cyber attacks. These categories of cyber
operations describe how various international states use cyber to achieve their goals;
however, Valeriano et al.’s (2018) approach is grounded in the only peer-reviewed cyber
operation dataset.
Policy Framework
While most policy processes are characterized by long periods of stasis and
incrementalism, the policy process occasionally makes sudden and punctuated changes.
This phenomenon of punctuations and long periods of stasis is well known through a lens
developed by Baumgartner and Jones (2009) called the Punctuated Equilibrium Theory
or PET. Under PET (Baumgartner & Jones, 2009), significant policy actions occur as
attention and venue access for a public problem grows. Punctuations occur as the policy
image of a particular policy domain experiences increased salience caused by new
information in the form of a new report about a societal condition or a sudden exogenous
event such as a disaster. A well-studied example of this is the increased salience in news
and change of tone by Congress in the area of nuclear energy. This punctuation occurred
following the publicized nuclear power plant disaster on the Three-mile island.
Previously, Congress discussed nuclear energy in a positive tone. Following increased
news of the condition of nuclear energy and expert analysis, the tone became negative,
leading to increased regulation of nuclear energy. With the recent adoption of various
Cyberspace Solarium Commission recommendations, there has been a sudden
punctuation of cyber policy adoption (Cyberspace Solarium Commission, 2021), and
understanding policy implementation would be the next appropriate step.
26
Kingdon’s (2011) Multiple Streams Framework (MSF) is another agenda-setting
framework that considers policy windows caused by a focusing event that is in
congruence with policy, political, and public streams. According to Kingdon (2011),
agenda-setting occurs independently in each stream. When all three streams bring an
issue to the top of their agenda, then the policy may be more likely to move forward. An
example of each stream includes the public stream as evidenced in news reports, the
policy stream as evidenced by legislative efforts, and the political stream as evidenced by
public political discussions such as Congressional hearings. Also, according to Kingdon
(2011), policy entrepreneurs are constantly refining the policy of a domain such that
policy evolves until it is fully developed and ripe for the moment when all three streams
align. Through the lens of Kingdon (2011), the Cyberspace Solarium Commission’s effort
is an attempt to accelerate this process with various cyberspace subject matter experts
brought together to propose a series of policy recommendations that follow strategic
efforts.
Birkland (2006) identifies punctuations in policy caused by a disaster event that
leads to a change in a policy domain. An example of such an event is the deluge of
policies formulated to address terrorism following the 9/11 catastrophe, which led to
policy resulting in the creation of the Department of Homeland Security. In his example,
9/11, an outlier terrorist attack, caused a sudden shock to the political system, leading to a
hyper-focusing on possible terrorist events.
Baumgartner and Jones (2009) describe policy image as how a policy is
understood and discussed by the public, with punctuations occurring when a policy image
receives increased media attention and a change in the tone of the discourse around this
issue. To study punctuations in policy-making, the critical variables of interest of the PET
27
methodology include policy image and venue access to predict and explain policy change
and agenda setting (Baumgartner & Jones, 2009). In the study of punctuations in
policymaking following a disaster, Birkland (2006) and Baumgartner and Jones (2009)
used publicly available records of media coverage in frameworks to identify the systemic
public agenda that helps explain post-punctuation policy and agenda setting. This
experimental study analyzes different responses to fictional cyber threat news headlines to
quantify possible reactive public responses that may affect the policy image of
cybersecurity policy.
Aim and Hypothesis
This study hypothesizes that an intervening cyber threat will lead to an appraisal
of the threat in the form of risk perception and that a risk response will also follow the
risk perception. This study exposed participants to fictitious headlines of cyber
degradation, cyber espionage, and cyber disruption and measured risk perception and
response to test this hypothesis. The use of these cyber threat types offers a novel
approach to understanding cyber threat response as a typology, which is also supported by
empirical evidence, using a peer-reviewed dataset, and offers to inform a variation of
cyber realities experienced to date.
This study aims to increase understanding of cyber threat perception and how
societal cyber threats affect an individual’s perception of a cyber disaster. This study aims
to test the effect of Valeriano et al.’s (2018) cyber threat types at an individual level and
identify an ordered hierarchy of cyber threat types based on various risk factors. To
achieve this, the primary objective of this study is to understand whether different types
of cyber threats (degradation, disruption, or espionage) elicit significant differences when
28
compared to a control in risk perception and risk response. This study presents the
following research questions and hypotheses:
1) Do cyber operation types significantly affect psychological risk perception or risk
response factors when compared with a control?
Hypothesis 1: The conditions of cyber operation type will be significantly different
from control, as evidenced by a significant one-way ANOVA depending on the perception
of magnitude of effect of cyber disaster (H1a), likelihood of cyber disaster (H1b),
anticipated negative emotional response (H1c), willingness to utilize privacy technology
(H1d), organizational attitude towards cybersecurity (H1e), and intention to comply with
organizational cybersecurity (H1g).
2) Does cyber operations have a significant effect when compared with a control?
Hypothesis 2: Planned contrast will reveal that combined cyber threat conditions
will have a significantly greater effect when compared with the control condition
depending on the perception of magnitude of effect of cyber disaster (H2a), likelihood of
cyber disaster (H2b), and anticipated negative emotional response (H2c).
3) Does the cyber operation of degradation have the largest effect compared to cyber
espionage and cyber disruption?
Hypothesis 3: Planned contrast will reveal that the cyber degradation conditions
will have a significantly greater effect when compared with the combined condition of
cyber espionage and cyber disruption depending on the perception of magnitude of effect
of cyber disaster (H3a), likelihood of cyber disaster (H3b) and anticipated negative
emotional response (H3c).
4) Does the cyber operation of cyber espionage have a larger effect than cyber
disruption?
29
Hypothesis 4: Planned contrast will reveal that the cyber espionage conditions
will have a significantly greater effect when compared with the cyber disruption
condition depending on the perception of magnitude of effect of cyber disaster (H4a),
likelihood of cyber disaster (H4b) and anticipated negative emotional response (H4c).
Psychometric Paradigm of Risk Perception Framework
The risk perception factors used in this experimental survey are oriented in the
psychometric paradigm framework that measures risk perception of disasters (1987,
2000, 2016). Technological advances such as nuclear energy, vaccinations, aviation, and
countless others have allowed humans to modify their environment with the capacity to
create greater efficiencies and positive impacts. However, these technologies also create
new risks and unintended consequences (Slovic, 1987). Risk perceptions are the intuitive
risk judgment that citizens rely on to assess and evaluate community hazards, receiving
new information about the societal conditions of these hazards through news and other
public information sources (Slovic, 2016). Societies have an intuitive sense of what
constitutes too much risk. Societal risk perceptions can be predictably measured to guide
policymakers (Slovic et al., 2000). Research on risk perception is critical to applied
research because it aids policymakers in informing policy directions that are in the
interest of the public, improving communication with the public, informing educational
efforts, and predicting public responses (Slovic, 1987). The logic of this survey
experiment is that risk perception will vary depending on the resulting disaster type.
The societal perception of risk from a disaster is correlated with the measurement
of policy support to address or mitigate the disaster at a societal level (Slovic, 2016). This
relationship follows the simple logic that as the possibility of a disaster is recognized by a
society, the government is more likely to respond with policy measures that address the
30
disaster. Concerning cyber incidents, public and private organizations often bear the brunt
of the disaster (Cyberspace Solarium Commission, 2020). Cyber attacks target one
specific organization, but many times, these cyber incidents have spillover effects that
may result in the real possibility of a widespread disaster. Most notably, the Colonial
Pipeline ransomware attack was a temporary organizational disruption that resulted in
broader regional effects, including limiting fuel for automobile and air transportation
(Parfomak & Jaikaran, 2021). This study assumes that cyber incidents vary in magnitude
and likelihood of disaster depending on the cyber threat type. Data on state cyber conflict
supports the assertion that cyber threat type mainly depends on state cyber strategy with
states like China specializing in cyber espionage, Russia specializing in cyber disruption,
and the US specializing in cyber degradation (Valeriano et al., 2018, 2021). Diverse
model scenarios are necessary to illustrate and understand the possible public responses to
these disasters.
Lay people notably diverge in risk assessment compared to experts, with lay
people considering an emotional response, societal impact, and impact on future
generations as potential variables in their risk assessment (Slovic, 1987). After the impact
of an event, lay people perceive various intuitive and emotional risks to society, including
the psychological, political, social, and cultural factors associated with the disaster
(Kasperson et al., 1988; Slovic, 2016). The psychometric paradigm considers this
perception of community consequence as the social amplification of risk (Kasperson et
al., 1988; Slovic, 2016). Where lay people and experts do overlap in risk perception is the
cognitive assessment of destructiveness, magnitude, and likelihood of a future disaster
(Slovic et al., 2000). This study takes into account the emotional responses of laypeople.
To do so, it considers the responses of the feeling of dread to address the psychological
31
component of psychological risk perception. This study also considers how much a
disaster may signal a future disaster and the impact on future generations.
Understanding how negative emotional responses, specifically dread, influence
risk perception is one of the most critical factors for measuring laypeople's psychometric
risk perceptions. Dread is the characteristic most correlated with risk perception among
laypeople (Slovic, 1987, 2016). The risk-to-benefit tradeoff of technologies is vital in
explaining how individuals internalize and respond to risk however these internal
calculations also rely on an emotional assessment. For example, surgical medicine elicits
a positive emotional response, and individuals perceive these as low risk and high
benefit. In contrast, pesticides have a negative emotional response, and it is perceived as
a high risk with a relatively low benefit (Slovic & Peters, 2006). The ability to prevent
and mitigate the risk is also associated with a negative emotional response to a disaster.
The psychometric paradigm defines “dread as a perceived lack of control, dread,
catastrophic potential, fatal consequences and the inequitable distribution of risk and
benefit (Slovic, 1987).” Modeling psychometric risk perception is the combination of
measuring awareness of the consequences of a disaster and the corresponding negative
emotional response (Slovic, 2016).
In addition to social amplification, the signaling value of risk perception, or how
much one disaster signals the possible effect or likelihood of a future disaster, is an
important context that offers essential insight into how lay people perceive risk
(Kasperson et al., 1988; Slovic, 2016). Again, differing from experts, lay people include
other considerations such as catastrophic potential or threat to future generations (Slovic,
1987). As an example, while a terrorist event and an automobile accident may have an
equal number of casualties or injuries, a terrorist event signals the presence of new
32
information that is used in the calculation of risk perception to “logically'' conclude the
possibility of more terrorist attacks. In contrast, automobile accidents typically do not
signal a future incident.
Survey Experiments of Cyber Operations
Survey experiments offer a method of study for cybersecurity research questions.
A significant limitation of cyber research is that access to data is limited due to the
confidentiality of cyber attacks and the diffused nature of reporting (Valeriano, 2022).
Given the limitations of data collection and reporting requirements in the field of
cybersecurity, survey experiments have come to be standard for testing hypotheses around
cyber threats and cybersecurity behaviors.
Kostyuk and Wayne (2021) offered two types of data breach conditions, a personal
threat and a national threat, including a control condition. They found that the exposure of
a data breach operation with personal implications elicited more support for national
cybersecurity as a priority and a greater perception of threat in assessing the likelihood of
a cyber threat compared to control. Kostyuk and Wayne’s (2021) cyber threat study have
interesting implications for cyber espionage threats however, I would like to also see if
these types of implications are applicable for conditions of degradation and disruption as
well.
In a survey experiment on “cyber doom,” Gomez and Whyte (2021) ask whether
dread is as severe as presented in the public image. Gomez and Whyte (2021) present
threat types of manipulations to news headlines of cyber disaster events including
whether a state was dependent on information and communication technology, whether
news was presented in a negative or neutral context, and the count of headline articles
33
participants were exposed to. It is unclear if news articles focus on any one type of cyber
threat.
Gomez and Whyte’s (2021) findings suggest that the signaling of cyber doom may
be related to an emotional response, as described in Slovic’s Psychometric Paradigm and
the signaling of a possible disastrous cyber attack. Gomez & Whyte (2021) included two
levels of threat perception: threat to the individual, in the question of how much
individuals should prioritize cybersecurity for their day-to-day lives, and threat for the
polity, asking how much the government should prioritize cybersecurity. Using an
emoticon slider to measure affective response, they found that the content or tone of the
fictitious cyber attack news headlines affected affective response, which mediated the
perception of threat at the individual and national levels. This study also acknowledges
two levels of risk response: the individual response and the organizational response.
Gomez & Villar (2018) focus on cyber degradation with conditions of various
information of the causes and effects of a cyber operation directed towards an energy
facility. Gomez and Villar (2018) chose university students as a population of interest with
student not pursuing computer science degrees and the other group being students in a
computer science program. They measured trust in cyberspace as a pre- and post-
treatment measure to measure risk perception. They conclude that the effect of treatment
on both types of participants in trust in cyberspace provides evidence of dread however
they do note that there are limitations with the interpretation of the heuristics that activate
dread.
Snider et al. (2021) utilized a scale that measured threat perception, focusing on
the cognitive aspects of how a cyber attack may affect participants and their
communities. Snider et al. (2021) found that their threat perception scale was effective
34
for measuring a mediation between conditions of fictitious news videos of lethal and
nonlethal cyber attacks compared with control and support for national cyber policies.
This finding seems intuitive that exposure to a lethal cyber attack will be received with a
greater magnitude of effect when compared to a non-lethal cyber-attack; however, they
say nothing about how an outcome can be affected through the use of effective cyber
policy, and instead, they focus on support of a policy of offensive response.
Methods
American University Representative Participants
The total number of participants (n=933) analyzed in this dataset was 933. 1025
participants were recruited from a potential pool of 2,119 participants from the Prolific
survey service to participate in this experimental survey. Of the 1,025 participants, 92
were rejected for the following reasons:
● Forty-three participants did not complete the survey or had missing fields.
● Twenty-one participants answered “no” to the question “Are you currently
enrolled in an American University?”
● Five participants did not provide clear answers for their current university or
college (e.g., “A college in Colorado”).
● Thirteen participants identified schools not found in the DOE College Scord Card
Data (e.g., “The St. Irenaeus House of Orthodox Studies'').
● Ten participants were enrolled in a certification program and were not pursuing a
Bachelor's, Master's, or Ph.D. degree.
Participants were excluded if they answered “No, I will not.” or “I can’t promise either
way” to the commitment question. All participants agreed to a commitment request to
answer survey questions with thoughtful answers.
35
This study targeted a sample of participants dispersed throughout the United
States. This study assumes that participants have a common relationship with their
organization with fictional headlines describing an attack on their organization.
Universities provide a sample of American residents throughout the United States who
have a common relationship with their organization. Universities have required oversight
accreditation boards that review standards for participation in the higher education
process, which include a standard of compliance with FERPA requirements.
Participants were selected using the Prolific survey service. Prolific screeners
included a request for a balanced sample of male and female participants and participants
that answer “yes” to the question of being a current student (including only students who
are pursuing an Undergraduate Degree, a Masters Degree, or a Doctorate Degree). In
addition to the Prolific screeners, the questionnaire includes an item requesting
participants to confirm whether they were currently enrolled in an “American University”
and were requested to provide the formal name of their university. After receiving the
name of their university, their self-reported university submission was cross-checked in
the Department of Education (DOE) College Score Card Data Set
(https://collegescorecard.ed.gov/data/) to ensure that the university met DOE
accreditation standards to qualify for FAFSA.
Risk Perception Measures
This study measures subjective possibilities of risk with a perception of likelihood
of cyber disaster scale (α=.90). Perception of likelihood of cyber disaster is a three-item
scale modified from Kostyuk and Wayne’s (2021) “Cyber Threat Perception” scale.
Kostyuk and Wayne (2021) tested the perceived likelihood of future cyber attacks
following the exposure to news articles highlighting cyber attacks on the US Navy or the
36
participant’s university. Kostyuk and Wayne’s (2021) focus on likelihood of attack was
modified to include specific location (by city) and specific organization (University) to
measure the likelihood of attack on the participant’s location, university, and personal
resources or someone known to them.
This study measures the predicted outcomes of risk with a cognitive assessment of
risk in the perception of magnitude of effect of cyber disaster scale and an emotional
assessment of risk in the anticipated negative emotion scale. Perception of magnitude of
effect of cyber disaster (α=.71) is a four-item scale that measures the cognitive outcomes
of a cyber disaster. The cognitive portion of the “Cognitive-Affective Scale for Hurricane
Risk Perception (Trumbo et al., 2016)” was modified to create the perception of
magnititude of effect of cyber disaster scale. Trumbo et al. (2016) conducted a
confirmatory factor analysis using an item pool that, with an effort to reliability, capture
risk perception of hurricanes for the distinct dimension of cognitive appraisal.
Modifications were minimal and generally included changing the word “hurricane” to
“cyber attack” and included changing the context of “your location” to “your University.”
The perception of magnitude of cyber disaster scale measures how cyber threats elicit
people's understanding of possible cognitive perceptions of cyber disasters, including a
cognitive appraisal of catastrophic destruction, the possibility of death, financial threat,
and threat to future generations.
Anticipated negative emotional response was measured using a modified version
of the affective portion of the “Cognitive-Affective Scale for Hurricane Risk Perception
(Trumbo et al., 2016).” The anticipated negative emotional response scale is a four-item
scale (α=.90) of how a cyber operation elicits emotional responses including feeling
fearful, feeling worried, feeling dread, and feeling depressed. The concept of dread as an
37
emotional response to a disaster is a factor supported by the Psychometric Paradigm
(Slovic, 2016) to explain how lay people assess risk perception. While dread is directly
assessed in this measure, dread as a construct is highlighted as a measure of both the
perception of magnitude of effect, the feeling of dread, and the lack of control in response
to a disaster (Slovic, 1987).
Risk Response Measures
Risk responses include an individual response to risk in the form of greater use of
privacy technology and an organizational risk response in the form of a supporting
attitude toward and intention to comply with organizational cyber policy. Organizational
risk response measures include a four-item scale of attitude towards the organization’s
cybersecurity policy (α=.91) and a three-item scale of intention to comply with
organizational cybersecurity (α=.90). An individual risk response measure includes a five-
item scale of willingness to utilize privacy tools (α=.71).
This study used a three-item intention to comply with cybersecurity scale (α=.90)
to measure participants' intention to complete a behavior related to cybersecurity policy.
The “Intention to Comply with Information Security” scale (Bulgurcu et al., 2010) is
modified to construct the intention to comply with cybersecurity scale for this study. This
study also used an attitude toward an organization’s cybersecurity (α=.91) to measure
participants' attitude toward their organization’s cybersecurity policy. This scale is a
modified version of the “Attitude Towards Information Security” scale (Bulgurcu et al.,
2010). For both scales regarding information security, modifications were minimal,
including changes from “information security” to the word “cybersecurity.” Bulgurcu et
al. (2010) conducted a structural equation model to identify reliable factors that capture
the path of information security compliance, finding that attitude towards information
38
security was the essential mediating factor in the explanation of intention to comply with
information security policy measures.
The willingness to utilize individual privacy technology scale (α=.71) is a fiveitem
scale of likelihood. The scale of willingness to utilize privacy technology is a fiveitem
scale modified from Kostyuk & Wayne’s (2021) online behaviors scale - a scale described
as measuring an individual’s willingness to engage in cyber hygiene behaviors that
require additional time and cost and that was suggested by cybersecurity experts.
Participants were requested to identify their likelihood of adopting a privacy technology
on a 7-point scale ranging from extremely likely to extremely unlikely. An additional
response was included, requesting whether the participant had already used the various
privacy technology tools. If a participant already used the privacy technology tool for
their security behavior they were given the highest rating of 7 equivalent to extremely
likely.
Experimental design
Participants were randomly assigned to be in one of four groups: degradation,
espionage, disruption, and a control group. All cyber threat groups included a prompt
requesting participants to read fictional headlines of news articles; the control group
included a prompt requesting participants to think about recent headlines about cyber
incidents that they have read in the news. Each of the three cyber threat groups had
distinct headlines describing a cyber attack on the participant’s location, university, and
the United States in general. Following exposure to the cyber threat intervention,
participants were asked to complete a questionnaire measuring risk perception (societal
cyber risk, negative emotional response, and signaling value) and risk response (intention
to comply with organizational cybersecurity, attitude towards organizational
39
cybersecurity, and willingness to utilize individual privacy technology) to the headlines
they were exposed to.
Table 2.1
Cyber Threat Intervention Groups
Degradation Cyber Espionage Cyber Disruption Cyber Control
Threat Threat Threat
Please read the
following fictional
headlines that
describe various news
articles and consider
how these headlines
can affect you and your
University.
Please read the
following fictional
headlines that
describe various news
articles and consider
how these headlines can
affect you and your
University.
Please read the
following fictional
headlines that describe
various news articles
and consider how these
headlines can affect you
and your University.
Recently there
have been many
news articles
that describe
cyber threats.
Please think
about the
recent
headlines that
you have read
in the news and
consider how
these headlines
can affect you
and your
University.
Adversarial State
Operatives Are
Suspected of
Hacking [City Name]’s
Water Supply
Allowing Hackers to
Possibly Contaminate
Drinking Water.
Adversarial State
Operatives Are
Suspected of Hacking
[City Name]’s Public
Health Record System
Allowing Hackers to
Possibly Gain Access To
Personal Private
Information.
Adversarial State
Operatives Are
Suspected of Hacking
[City Name]’s City
Website Allowing
Hackers to Deface the
City's Homepage with
Lewd Photographs.
40
[University Name] [University Name]
Suspects That the Shut Suspects An Online
Down of the Breach of the
[University Name] [University Name]
Emergency Security Record System
System Was Caused Possibly Resulting in
by Adversarial Cyber Costly Losses of
Actors Resulting in Intellectual Property
Multiple False and Personal
Alarms. Information.
[University Name]
Suspects That the
Disabling of the
Student Web-based
Learning System Was
Caused by
Adversarial Cyber
Actors Resulting in
Students Being Unable
to Utilize the Online
Academic
Communication and
Submission System.
The US Department of US Office of US Federal
Energy Highlights
Concern That Their
Cybersecurity Protocol
Has Glaring Holes That
Could Result In Cyber
Attacks That Cause Wide
Spread Power Outage or
Operational Failure.
Personnel and
Management
Highlights Concern
That Their
Cybersecurity Protocol
Has Glaring Holes That
Could Result In A
Large Breach of
Personally Identifiable
Information of All Federal
Workers Including Those
On
Top Secret Missions.
Communications
Commission
Highlights Concern
That Their
Cybersecurity
Protocol
Has Glaring Holes
That
Could Result In
Failed
Communication Networks
For
Extended
Periods of
Time.
Procedures
Participants were solicited using the Prolific survey database. Participants
were informed of the study and requested to participate in the study facilitated by
a Qualtrics link. Participants were requested to agree to the study, commit to the
study, and answer questions regarding their university status. Participants were
then exposed to cyber threat headlines outlined in Table 1. Following exposure to
a cyber threat type treatment, participants were requested to complete a battery of
questionnaire items, including signaling value, cognitive perception of cyber
41
disaster, negative emotional response, willingness to utilize individual privacy
technology, intention to comply with organizational cybersecurity, and attitude
towards organizational cybersecurity scales. All scale scores were the average of
all scale items.
In addition to self-reported survey items, participants’ responses to what
university they attended were also reviewed. University information was verified
with the DOE College Scorecard data and additional information, including the
number of college years offered (4-year, 2-year, or Certificate), type of school
(Public, For-Profit, Nonprofit, Undergraduate Size, and category of school size
(Large, Medium, or Small) was collected.
Data analysis was completed using R-Studio. Threat groups were
reviewed for demographic variations across groups including age, gender,
political ideology, and years of university education. Anova, Levene’s test, One-
way test of means, and planned contrast were implemented to confirm
hypotheses.
Results
A total of 660 participants identified as undergraduate students (First Year
College Student - 66, Second Year College Student - 127, Third Year College
Student -
185, Fourth Year College Student - 203, Fifth Year College Student or more - 79)
and 273 identified as graduate students (Master’s Student - 191, and PhD Student
- 82) participated in this survey experiment. Based on the DOE College
Scorecard, the sample included 883 participants from a 4-Year College and 50
participants from a 2-Year
42
College. DOE College Scorecard size groupings included 543 large-sized
universities, 331 medium-sized universities, and 59 small-sized universities.
Variations based on the type of university included 712 participants attending a
public university, 212 participants attending a Non-profit university, and 9
participants attending a For-profit university. Locations of universities included
city (645), suburb (202), town (77), and rural (9) locations. Overall, this American
university sample offers a representation that favors 4year, public, large-sized
universities but also considers the variety of college offerings present in America.
This sample is of all levels of education and years as a university student.
Group Demographics
Threat groups were roughly equal, ranging from 233-241 participants per
group (Control - 234, Degrade - 236, Disrupt - 231, Espionage - 232). Male and
Female ratio was roughly equal (Female - 436, Male - 454, Non-Binary - 40,
Prefer Not to Answer - 3) with no significant variations exhibited across treatment
groups excluding the prefer not to answer group (χ2(6) = 5.61, p = 0.47). The
mean age of this dataset was 26.54 (sd =
9.30), ranging from 18-85 with no significant variations across treatment groups
by age (F(2, 925) = 0.19, p = 0.83). When asked about their political ideology this
data set was skewed towards a liberal affiliation (Liberal - 425, Slightly Liberal -
235, Moderate - 174, Slightly Conservative - 69, Conservative - 30), within this
skewed distribution, no significant variations were found across treatment groups
based on political ideology (χ2(12) = 9.28, p = 0.68). Participant’s undergraduate
university size ranged from 158 -
119,248 (Mean = 23,739, sd = 22,156).
43
ANOVA
The results from a one-way ANOVA show that there was a significant
effect of cyber threat on risk perception concerning the perception of magnitude
of effect of cyber disaster (F(3, 929) = 12.15, p < .001) (Supporting H1a) and
anticipated negative emotional response (F(3, 929) = 7.00, p <.001) (Supporting
H1c). Cyber threat intervention did not have a significant effect on risk perception
as it relates to the perception of likelihood of cyber disaster (F(3, 929) = 1.47,
p>.05) (Not Supporting H1b). The results from a one-way ANOVA show no
significant effect of cyber threat on risk response was revealed for willingness to
utilize privacy technology (F(3, 929) = 1.85, p>.05) (Not Supporting H1d),
organizational attitude towards cybersecurity (F(3, 929) = .79, p>.05) (Not
Supporting H1e), and intention to comply with organizational cybersecurity
(F(3, 929) = 1.95, p>.05) (Not Supporting H1g). Following the ANOVA test of
significance, normality for all groups was reviewed for magnitude of effect of
cyber disaster and anticipated negative emotional response (see Appendix B).
Planned Contrast
Results from an OLS regression using planned contrast of risk perception
variables of perception of magnitude of effect of cyber disaster, anticipated
negative emotional response, and perception of likelihood of cyber disaster were
tested to contrast various effects of cyber threat conditions. Planned contrasts
were utilized to confirm hypothesized differences among cyber threat groups in
risk perception factors. Contrasts first compared the control group against all
cyber conditions. For the second planned contrast, the control group was excluded
and the cyber degradation group was contrasted with the combination of cyber
44
espionage and cyber disruption groups. Then finally, both cyber degradation and
the control groups were excluded and cyber espionage was contrasted against the
cyber disruption group. Planned contrasts followed the hypothesis that control
would have the least effect on risk response, cyber degradation would have the
greatest effect on risk perception, and cyber espionage would have a greater effect
when compared with cyber disruption.
Table 2.2
Regression Using Planned Contrast of Risk Perception Variables
Planned Contrast Dependent Variable: Cyber Threat Type Intervention of
Cyber Threat
Intervention of
Risk Appraisal
Perception of Magnitude Perception of Anticipated Negative of Cyber
Disaster Likelihood of Cyber Emotional Response
Disaster
Control Vs. All -0.28 ***
(0.07)
-0.13
(0.10)
-0.15
(0.10)
Degradation Vs.
Espionage and
Disruption
0.35 ***
(0.08)
-0.14
(0.11)
0.41 ***
(0.11)
Espionage Vs.
Disruption
0.03
(0.09)
0.14
(0.13)
0.27 *
(0.13)
Intercept 4.86 ***
(0.03)
3.75 ***
(0.04)
4.22 ***
(0.04)
R-Square 0.03 0.001 0.02
p<.001 ***, p<.01 **, p<.05 *
Planned Contrast 1: Control Vs. All
The first planned contrast in Table 2.2, tested the hypothesis that the
control treatment had a lesser effect when compared with the combination of all
45
other cyber threats. Planned contrasts revealed that the control condition was
significantly less in perception of magnitude of effect of cyber disaster (b = 0.28,
t(933) = 3.84, p(one-tailed) <.001) when compared with all other conditions
(Supporting H2a). Planned contrasts revealed that the threat group conditions
did not significantly increase perception of likelihood of cyber disaster (b = 0.13,
t(933) = 1.23, p(one-tailed) p>.05) (Not Supporting H2b) or anticipated negative
emotional response (b = 0.15, t(933) = 1.46, p(one-tailed) p>.05) (Not
Supporting H2c).
Planned Contrast 2: Degradation Vs. Espionage and Disruption
The second planned contrast in Table 2.2, tested the hypothesis that the
degradation exposure had the greatest effect when compared with all other cyber
threat conditions. The degradation group increased perception of magnitude of
cyber disaster (b = 0.35, t(933) = 4.63, p(one-tailed) < 0.001) (Confirming H3a)
and anticipated negative emotional response (b=0.41, t(933) = 3.78, p(one-tailed)
<.001) (Confirming H3c) when compared to the combination of disruption and
espionage group. The degradation condition did not significantly increase
perception of likelihood of cyber disaster (b = 0.13, t(933) = -1.27, p(one-tailed)
p>.05) (Not Supporting H3b) when compared with the disruption and espionage
conditions.
Planned Contrast 3: Espionage Vs. Disruption
The third planned contrast in Table 2.2, tested the hypothesis that the
espionage condition would have a greater effect than the disruption condition. The
espionage treatment group significantly increased anticipated negative emotional
response (b = 0.27, t(933) = 2.14, p(one-tailed) < 0.05) (Confirming H4c) when
46
compared with the disruption condition. Planned contrasts revealed that the
espionage condition did not significantly increase perception of magnitude of
cyber disaster (b = 0.03, t(933) = 0.31, p(one-tailed) p>.05) (Not Supporting
H4a) or perception of likelihood of cyber disaster (b = 0.14, t(933) = 1.13, p(one-
tailed) p>.05) (Not Supporting H4b) when compared with the disruption and
espionage conditions.
Discussion
Cyber revolutionaries argue that cyber conflict will upend international
conflict (Kello, 2013). Contrastingly, some cyber experts argue that cyber as a
tool for state coercion largely depends on the capabilities of the offensive states
and the more extensive strategies endorsed by an adversarial state (Valeriano et
al., 2018). For example, China’s use of cyber espionage fits well with its more
extensive economic and technology strategies. Also, Russia’s use of cyber
disruption and disinformation fits well with its more extensive strategies to
disrupt regional states, such as the case of cyber use in Estonia and Ukraine. This
study reviews the continued use of their status quo strategies of espionage and
disruption and also, it explores the possibility that an adversarial state such as
China and Russia change their strategies toward the United States with increased
degradation operations. The motivation of this study was to test the entirety of
cyber strategies that can be used against America and the perception of risk and
risk response that may follow the various cyber operation types. The findings of
this study suggest that the support for a possible increased American response to
47
cyber conflict through a risk perception mechanism depends on the type of cyber
threat.
Cyber threats from adversarial state operatives have recently plagued
American government, businesses, and citizens. This new experience of
adversarial states easily interacting across international borders is unlike previous
historical experiences. As a result, the general public has become exposed to
cyber operations as a new type of experience. Experts often question the validity
of public opinion on cyber conflict and note that the public’s opinion is muddied
by a lack of knowledge of cyber threat consequences (Kostyuk & Wayne, 2021;
Valeriano et al., 2021). This study provides evidence that the public can perceive
a difference in cyber threat types. This difference is most prominent in cyber
degradation for the perception of magnitude of cyber disaster and anticipated
negative emotional response. In the area of anticipated negative emotional
response, espionage is significantly greater than disruption, indicating that the
public may be able to perceive a hierarchy of effects beginning with degradation,
followed by espionage, and concluding with disruption at least in the area of
emotional perception. However, the perception of differences has limits,
specifically in the public’s ability to perceive the likelihood of different cyber
threat types.
This study examines how university students in the United States perceive
cyber threats. The sample population is a group with a clear and well-defined
relationship with their organization. The relationship with their organization, in
this case, their university, offers a perception of threat that affects participants as
agents of the organization and their larger community network. Additionally,
48
universities must have cyber measures and policies in place to ensure the safety
and privacy of IT systems, data, and applications.
More broadly, this study offers implications for understanding how individuals
across the United States perceive threats to their organization and help inform the
implementation of a whole-of-nation approach to cyber deterrence.
ANOVA results indicate that university students differentiated between
control and a cyber threat type for magnitude of effect of a cyber disaster and
anticipated negative emotional response but did not do so for all other risk
response factors and the risk perception factor of perception of likelihood. These
findings suggest that the key differences between cyber threats are found in risk
perception and does not extend to risk response.
Degradation was found to be the most prominent threat type that is
perceived to be a risk to society and elicits both a cognitive assessment of
destructive effect and an emotional assessment of anticipated negative affect (see
purple circles of Figure 2.1) when compared with all other cyber threat types.
Figure 2.1
Comparison of Threat Types by Perception of Magnitude of Effect and Anticipated
Negative Emotional Response
49
This finding bridges Valeriano et al.’s (2018) assertion that degradation is the only
cyber threat type that elicits state coercion and highlights that individuals perceive
risk characteristics evidenced by the perception of a greater magnitude of effect
and negative emotional response on a micro level. The implications of the
individual’s ability to identify a significantly different type of cyber operation
suggest that degradation as a cyber operation type may contribute to the rise of
cybersecurity in America’s systemic agenda, should degradation be used against
Americans. The U.S. has no history of significant cyber degradation attacks to
date. Instead, the U.S. is one of the states that actively utilizes degradation cyber
operations and has the most success at coercion through cyber means (Valeriano
et al., 2018).
Cyber disruption and cyber espionage were slightly elevated compared to
a control in the perception of magnitude of effect (See orange circles of Figure
2.1). A significant planned contrast of all cyber operations compared with control
provides support that the introduction of headlines that describe cyber operations
increases the perception of magnitude of effect of a cyber disaster. The
implications of this finding suggest that if individuals are exposed to more news
of cyber threats, their perception of magnitude of effect will increase, especially
in the case of cyber degradation. Cyber disruption was not significantly different
from cyber espionage in the perception of magnitude of effect. This finding
makes intuitive sense as disruption and espionage are not expected to cause death
or destruction and only have a temporary effect.
Cyber degradation significantly differed from cyber espionage and cyber
disruption in anticipated negative emotional response (See the green circle of
50
Figure 2.1). Anticipated negative emotional response presents a hierarchy of
cyber operation risk perception, with cyber degradation having the greatest
emotional response, cyber disruption having the least emotional response, and
cyber espionage having a response in the middle. When compared with control in
anticipated negative emotional response, the negative effect of disruption skews
the collective effect of the combined cyber threat types, resulting in control not
being significantly different from the combination of all cyber operation types.
While not significant, this suggests that the combination of disruption and
espionage may be representative of the expectations of control only with a much
wider variance. In other words, participants anticipated the emotional variance of
disruption and espionage when thinking about cyber operations in the news thus
supporting the possibility that as individuals think about cyber threats in the news,
they think of an attack that is equivalent in emotional response to a combination
of either cyber disruption and espionage. This conclusion follows the evidence by
Valeriano et al. 's (2022) dataset that America is on the receiving end of disruption
and espionage. As such, this finding would be accurate with expectations
suggesting that the public accurately assesses anticipated negative emotional
response to a cyber disaster.
The lack of awareness of cyber attack consequences and the public’s
inability to respond accurately is a concern for cyber security scholars and experts
(Kostyuk & Wayne, 2021). The American public may perceive disruption threats
as a risk to society; however, a strong emotional response of fear or dread will
likely be significantly smaller when compared with espionage and even smaller
when compared with a degradation threat. In the case of comparing all types of
51
exposure against a control, I hypothesized that a treatment would have an effect.
These hypotheses were invalid for the perception of likelihood.
Those who study cyber issues are often interested in the future of cyber
conflict
(Clarke & Knake, 2019; Gartzke, 2013; Kello, 2013; Rid, 2013; Valeriano et al.,
2018). Scholars are also focused on the idea that human agents cognitively assess
a high risk of cyber threats but do little to change their behavior (Gomez &
Whyte, 2021; Kostyuk & Wayne, 2021). These findings yield several conclusions:
first, American university students can differentiate between threat types when
thinking about the possible outcomes of magnitude of effect and negative
emotional response, and second, even though they perceive the effect of threat
types differently, they perceive the likelihood of threat types occurrence as equal
across the board (See Figure 2.2) and in so far as no threat type rises to a level of
significance when compared against the control.
Figure 2.2
Perception of Likelihood of Cyber Disaster by Threat Type
52
One would assume that participants would identify that they are more likely to
experience an espionage or disruption attack than they are to experience
degradation. The results do not reveal that here. Participants assumed equal
likelihood even when exposed to a cyber degradation attack. Cyber degradation
threats are very limited in American cyber conflict history and relatively non-
existent compared to other states’ cyber conflict experience (Valeriano et al.,
2018). The American public, unexposed to degradation attacks, may be unable to
incorporate the signaling cues necessary to make sound policy decisions based on
the future likelihood of a cyber attack of the various cyber operation types as they
assign equal likelihood to all cyber threat types. The assignment of equal
likelihood may help explain why the public reports a great concern for a general
concept of a “cyber attack” they are both great in magnitude, emotional response,
and occur frequently when all types are muddied together likely in the eyes of the
public. While cyber degradation is relatively unlikely as an attack vector for
American businesses or government agencies, cyber attacks beneath the threshold
of conflict are prolific. The
American public should not be faulted for this miscalculation of perception of
likelihood. Instead, they should be educated as an objective of strategic policy.
This is a critical finding for policymakers in government and organizations as
they seek to prevent cyber attacks and organizational degradation in general.
Study Limitations
There are several important limitations that future research could address.
First, while this study represents an attempt to provide a dataset that is inferable
to the American public, university students are not immediately representative of
53
the American public in various important ways, including age and education. The
choice of university students was predicated on a targeted population with a
common relationship with their organization that could be found throughout
America. A large data set that is more representative of individuals in the U.S.
would enhance our understanding of individual behavior in relation to cyber
threats; however, controlling for a varied relationship with their organization will
need to be addressed.
While this study attempted to maximize inferability by incorporating
participants from universities across the country, a limitation of this study was the
ability to control for participant differences in organizational cybersecurity.
Another constraint in controlling for organizational variation is the inability to
control for remote versus oncampus students in the sample. On-campus
experiences provide both a cultural element and proximity that may be helpful in
measuring the perception of cyber disasters. Further study in cultural and
proximity elements would help explain variations within the organization that are
beyond this project's scope. Organizational differences were accounted for by
testing for demographic variation and size of undergraduate classes across groups.
Additionally, participants were checked for DOE Scorecard eligibility as an
American university that fit DOE Scorecard criteria. Further study of cyber threat
types in this population could control for organizational variation by pooling
participants from a handful of universities rather than across the country.
The cyber threat conditions of this study were designed to better
understand the
54
American systemic agenda in the domain of cybersecurity. Kindgon’s MSF
(2011), Baumgartner and Jones’ PET (2009), and Birkland’s disaster policy
framework (2006) include a measure of news media as a measure of a larger
systemic agenda. In Kingdon’s MSF (2011) approach, the public stream can be
affected by the type of cyber operation that is present in the news, and in
Baumgartner and Jones’ PET (2009) and Birkland’s (2006) approach, the salience
of news articles can be affected by the cyber operations that make news headlines.
This study highlights the possibility that when people think about headlines of
cyber espionage and cyber disruption, they think of cyber attacks reflect today's
news headlines (as prompted in the control condition). Baumgartner and Jones’
(PET) and Birkland’s (2006) disaster policy framework suggests that we may see
a punctuation in news articles if a cyber degradation event was successfully
executed. Kingdon’s (2011) MSF may also highlight this difference in a
qualitative approach, noting increased themes of anticipatory and reactionary
emotions and the concern for a disaster following a successful operation or even
well-published failure of cybersecurity from a cyber degradation attack on
American soil.
Further interest in policy would focus on a count of news articles or
qualitative research following a real-world disaster. As cyber incidents continue to
increase, there is little research on how news articles are correlated with a policy
response in cyber policy. A qualitative approach can also be taken with
individuals discussing risk themes following the various types of attacks. Finally,
news articles can be tracked alongside congressional hearings that address cyber
55
problems, with content analysis of congressional hearings offering a window to
the tone of the national cybersecurity domain.
Studies in cyber threats would also benefit from the inclusion of the
detectability of a cyber threat. Dread, as characterized by Slovic’s (2016)
psychometric risk paradigm, includes the combination of low detectability, the
experience of dread as an emotion, and a large magnitude of effect. The
component of dread in the form of detectability is a complicated factor to measure
in cybersecurity as individuals must utilize a method outside of their physical
senses to detect a cyber attack. A proxy for detectability may be in the form of
cybersecurity awareness or knowledge of cybersecurity tools; however, these are
not the same as a physical sensation of detectability such as the smell of gas, the
sensation of heat, or the visual cue of smoke that may alert an individual to a
possible fire. As a result of these challenges, this study measured anticipated
negative emotional response, specifically asking participants to rate their level of
“dread” as an emotional response to a cyber disaster, as a measure of dread.
Future research would benefit from methods that focus on psychometric risk with
a focus on dread as it relates to individual disaster response. Despite these
limitations, this study adds significant value to the research stream around risk
cyber strategy and cyber policy.
Conclusion
Cyber threat types can be differentiated by university students across
America in the risk perceptions of magnitude of effect and anticipated negative
emotional response. The findings I present in this chapter contributes to the
academic literature of IR specifically in the interest of cyber threats and
56
cybersecurity between nations. The experimental conditions were derived from
Valeriano et al.’s (2018) International Relations research that provide empirical
evidence of categorically different types of cyber threats in interstate cyber
conflict. The application of these findings supports the need for IR academics to
be specific in there descriptions of the type of cyber threats that elicit
cybersecurity, policy, and risk responses. As such specificity of cyber type effect
may have change the discussion and conclusion of the effects of cyber threats.
The destructive properties of the cyber degradation threat exhibited the
greatest risk perception compared to all other cyber threat types in this study.
When the control group was compared with cyber disruption threats, risk
perception, and risk responses were not as readily discerned by this sample,
suggesting that disruption is not significantly different from the control exposure.
Cyber espionage threats showed differentiation compared to a cyber disruption
threat, suggesting that espionage, while less of a threat than degradation, is
perceived to be a greater risk to society.
The larger contributions of the findings I present in this chapter are
applicable to the public discussion of cyber threats, specifically how cyber threats
affect society and what are appropriate policy alternatives that should be
discussed. The current cybersecurity policy image appears to be perceived as
stable with limited policymaking demanded and or needed. However, this study
demonstrates that a significant degradation attack in the news could result in a
significant negative public response concerning the policy image of American
security as it relates to national cybersecurity. A sudden upheaval of
cybersecurity’s policy image, coupled with attention in national policy venues,
57
could create a policy environment ripe for large punctuations in cybersecurity
policymaking. These findings suggest that the American public is savvy enough
to perceive the risk of different cyber threats. However, the findings also suggest
that a clear connection between cyber threats and a cybersecurity response is not
readily measured. This lack of a finding would suggest the importance of risk
perception can provide a mediation from cyber threat type towards a
cybersecurity response and begs the question does risk perception mediate a path
between cybersecurity response and cyber threat conditions. Further testing may
likely reveal that a path from cyber threat to risk response is mediated by risk
perception.
Most importantly, this study demonstrates that when lay people think
about the cyber threats they have read about in the news (the controlled
exposure), they significantly and consistently differ from the intervention of
degradation threats. This finding, coupled with the result that lay people do not
perceive significant differences in the likelihood of an attack, suggests that fault
in the risk calculation of lay people is in the lack of awareness of the probability
of different types of cyber operations occurring in America. Given the enhanced
and growing use of these types of tools by nations and other actors, this research
adds to our understanding of risk perception in the context of varied cyber threat
types. It appears that risk perception of cyber threat types is in an evolutionary
process that will need continued exposure to cyber events to solidify subjective
probabilities in the face of limited experience.
58
CHAPTER THREE
CYBER RISK: EXAMINING THE SIGNIFICANCE OF PSYCHOLOGICAL
RISK
PERCEPTION FACTORS FOR A CYBER RISK PERCEPTION FRAMEWORK
Abstract
Raising the collective cybersecurity response of American citizens is a key
strategy towards mitigating and protecting America from cyber attacks. Academic
scholarship in cybersecurity policy have focused on the risk perceptions of
individuals given various cyber threats however, these factors used to measure
risk among cybersecurity scholars are mixed with some focusing on negative
emotional responses, others focusing on pre and post measures of trust, and others
focusing on likelihood and magnitude of effect. I propose a holistic cyber risk
perception framework based on risk perception literature that will help explain
why individuals are motivated utilize cybersecurity tools for their personal
devices. In this chapter, I highlight a path model that supports hypotheses of
mediation of cyber threats through risk perception factors towards cybersecurity
responses, the significance of various cyber risk perceptions factors, and the use
of cybersecurity awareness to control for individual differences.
Introduction
The future of a technologically interconnected American society will
depend on how well the public can implement a larger cyber strategy (Clarke &
Knake, 2019). The Cyberspace Solarium Commission (CSC) is a bi-cameral, bi-
partisan congressional commission tasked to develop US Cyberspace strategy
outlines strategic recommendations reflecting a whole-of-nation approach that
includes private citizens and private businesses. The strategy pillar of the CSC’s
59
report with the most recommendations presents a case for denying benefits and
increasing costs to cyber adversaries (Cyberspace Solarium Commission, 2020).
To achieve this, the CSC recommends a path forward that includes the individual
in “the promotion of digital literacy, civics education, and public awareness to
build societal resilience to foreign, malign cyber-enabled information operations”
(Cyberspace Solarium Commission, 2020,
p. 5). The CSC’s unique approach to deterrence in the cyber realm asks for private
businesses and citizens to implement greater cyber hygiene to raise the overall
level of cybersecurity in the United States. To contribute to national strategy and
public implementation efforts, this study asks, what motivates American
individuals to implement greater cyber hygiene in response to cyber threats to
society?
Continued and persistent cyber attacks below the threshold of armed
conflict and the possibility of a cyber attack of significant consequence call for
substantial policymaking efforts to manage national cyber threats and bring the
nation to an acceptable level of risk (Cyberspace Solarium Commission, 2020;
Office of the Director of National Intelligence, 2021). To address cyber problems,
policymaking in cyberspace requires a complicated formulation that balances
addressing risk and increasing security with maintaining the efficiency and ease
of use of the Internet on a global scale (Hurwitz & Schaub, 2018). Understanding
cybersecurity risk responses requires the specification of type of cyber problem
and a measurement of the corresponding cybersecurity risk perception. Risk is
often formulated and articulated at the expert level, and the public's motivations
differ from subject matter experts' risk assessments (Fischhoff et al., 1978;
60
Loewenstein et al., 2001a; Slovic, 1987). The sharp divergence between the
public and experts in the area of cyber risk is exceptional, with cyber experts
arguing that lay people are problematically misinformed and overestimate the
realities of cyber operations and the possibility of a cyber war (Gartzke, 2013;
Rid, 2013; Valeriano et al., 2018, 2021). Specifically of interest is the "cyber
doom" narrative, which describes a public perception that a cyber attack can
cause a large and wide-scale catastrophe of critical infrastructure to an essential
information and communication system (Gomez & Whyte, 2021; Lawson,
2013).
While experts may characterize the public as misinformed, they are
exposed nonetheless to countless news reports of cyber attacks by state actors.
Individual exposure to foreign offensive operations has never been more
prevalent than in cyberspace. There is evidence that the metrics and data of cyber
operations perpetrated on individuals are systematically underreported, as reports
of offensive cyber operations occurring in commercial and government domains
capture the bulk of cybersecurity attention (Maschmeyer et al., 2021). This
systematic under-representation of reports of cyber operations at the individual
level represents a threat to American civil society and democracy (Maschmeyer et
al., 2021). With the American public exposed both in the news and with personal
experience to a malicious cyber incident, understanding why Americans perceive
risk is important in the planned strategic formulations of American cyberspace
strategy.
Various studies of cyber threats identify Slovic’s (2016) risk perception
factor of dread as a theoretical framework of interest and identify the need for risk
61
perception to mediate an introduced cyber condition (Gomez & Villar, 2018;
Gomez & Whyte, 2021; Kostyuk & Wayne, 2021a; Shandler & Gomez, 2023).
However, they focus on only one specific factor of risk and have not approached
risk from a holistic perspective. This study addresses this gap in literature by
examining risk perception and cybersecurity risk response factors and identifying
which factors are relevant for use in a cybersecurity risk perception framework.
By taking a holistic approach to risk perception researchers will be able to explain
why individuals engage in a cybersecurity risk response rather than simply testing
if there is a path that is mediated by risk perception.
Furthermore, if individual citizens are to implement cyber strategy,
understanding how risk perception motivates and guides decision-making given
various cyber contexts is important for future cyber policy in the United States.
Judging by expected rate of cybersecurity expenses it seems that the United States
will continue navigating through a future of ever-increasing cyber disasters
(Charlton, 2024). Individuals can implement a variety of cybersecurity
technology responses as a risk response to perceived threats. Using a sample of
college students, this study examines how individuals implement personal
cybersecurity technology as protection from societal concerns and examines the
psychological risk perception factors that contribute to the perception of a cyber
disaster.
Cybersecurity and the American Citizen
Cyber offense operations are portrayed as having the upper hand in the
offensedefense balance. However, in most cases, the cyber defense has the upper
hand with cybersecurity tools and methods offering sufficient cyber protection,
62
and the cyber offense is only favored for high-value, high-cost targets executed by
a few sophisticated state actors (Slayton, 2016). The reality of the cyber landscape
is that most cyber-attacks occur at a low level with most cyber intrusions being
easily defended against using good cyber hygiene. The increased threat of
offensive cyber operations by adversarial states is less about whether Americans
can defend against cyber threats and more about whether individuals can
effectively assess risk and make appropriate cybersecurity decisions, such as
sufficiently practicing the minimal standards necessary to manage cyber risk and
attending to cyber hygiene.
According to the Cybersecurity and Infrastructure Security Agency’s
(CISA) ransomeware FAQs page, ransomware can be described as malware that
captures digital information and holds it hostage in exchange for a cryptocurrency
ransom with ransomware affecting the computers of the American individuals and
businesses alike. Many of the notable news stories of cyber threats have come
from ransomware used by criminal organizations developed by state-funded
organizations. The WannaCry malware attributed to North Korea was a series of
ransomware attacks that affected 230,000 computers in over 100 countries
(Nakashima & Rucker, 2017). In another example of a state-sponsored
ransomware attack, Russian attributed NotPetya ransomware was designed to be
directed at Ukraine’s infrastructure; however, as the malware ran rampant, it
affected other systems and spilled out to various nations, targeting a variety of
critical infrastructure sectors (CISA, 2018; Nakashima, 2018). In 2021, a hacker
group known as DarkSide infiltrated the Colonial Pipeline transporting petroleum
across the East Coast, demanding $4.4M in cryptocurrency and causing national
63
concern regarding the energy sector's vulnerability (Wood, 2023). The
vulnerability displayed in the Colonial Pipeline cyber attack was an inflection
point that led to increased policy efforts to address cyber attacks related to
ransomware and critical infrastructure (Easterly, 2023).
Data breaches are also mired with state-sponsored activity. As an example,
a variety of notable data breaches attributed to China include the Office of
Personnel and Management (OPM) hack (Chaffetz, 2016), the Equifax hack
(Robbins & Sechooler, 2018), and the Marriott hack (Gressin, 2018). These data
breaches have compromised millions of individuals, requiring credit monitoring to
ensure against possible future intrusions. In the case of the 2015 OPM hack, 21.5
million Americans were affected (Chaffetz, 2016). The OPM hack resulted in an
Oversight Committee Report with findings indicating that the hack could have
been prevented if a greater budget had been allocated to cybersecurity and an
improved culture of cyber hygiene had been implemented (Pham, 2016). In what
is considered one of the most far-reaching data breaches, the Equifax data breach
resulted in an estimated 143 million Americans having their personal information
stolen (Robbins & Sechooler, 2018). In another example, an Iranian Advanced
Persistent Threat group called APT 39 targeted the personal information of a wide
net of citizens of the United States and various Middle Eastern countries in
telecommunications, government, and travel industries for monitoring and
tracking purposes (Hawley et al., 2023). As an indicator of the fallout of data
breaches, the Federal Trade Commission (FTC) reports that in 2020, there were
1.4 million reports of identity theft, double the rate in 2019 (Gressin, 2021). An
additional concern to the American citizen is the targeting of American towns and
64
cities. Recent trends of cyber attacks that focus on city locations include Atlanta,
GA, resulting in an estimated cost of $17 Million to taxpayers; Baltimore, MD,
leading to a restructuring of $6 Million in city resources; New Bedford, MA,
where hackers requested $5.3 Million; and Wilmer, TX a small town with 4,000
people with hackers demanding a $2.5 Million ransom (Cranley, 2020).
Ransomware and data breaches are not only costly and potentially
dangerous to American citizens, they are also largely preventable. CISA identifies
a variety of ways to protect against ransomware, all of which are implemented at
an individual level, including (1) updating software and patches (not using end-of-
life or end-of-service software or hardware), (2) not clicking on links or
attachments from unsolicited emails, (3) backing up data regularly including
backing up an off-line copy, and (4) following safe practices when connecting to
the internet
(https://www.cisa.gov/stopransomware/ransomware-faqs). In much of the same
types of recommendations for protecting personal information, CISA (2021)
recommends knowing what personal and sensitive information is and where it is
stored, employing multi-factor authentication (MFA), implementing cybersecurity
best practices, including encryption of sensitive information at rest and in transit,
and ensuring notification for when your account may be breached.
The National Security Cyberspace Dilemma
Cyberspace problems occur in what can be described as the “fifth
domain,” a man-made domain that does not have the physical properties of land,
sea, air, or space (Clarke & Knake, 2019). Problems occurring in a “fifth domain”
require specialized knowledge that is atypical of the physical laws with
65
programmers of cyberspace able to code their own rules of how interactions
occur. Furthermore, because of the necessity of specialized knowledge, lay people
are not intuitively knowledgeable about the risk and policy alternatives that
address cyberspace problems. With lay people associating increased risk to
society with the ability to control and detect a disaster (Slovic, 1987), the
calculations of cyber response with control and detectability appear volatile
compared to historical problems in the physical space.
With many cyber attacks occurring beneath the threshold of armed
conflict, there is international ambiguity about what types of repercussions are
internationally acceptable (Gartzke & Lindsay, 2015). Cyberspace problems, a
relatively new domain of state interaction, present difficult policy alternative
decisions that may have downstream effects on international relationships. The
wide variety of cyber operations, the covert nature of cyber signaling
consequences, and responding to cyber attacks is an ongoing learning process
(Borghard & Lonergan, 2017). In cyber conflict signaling what is an act of war
versus what carries diplomatic or economic consequences is debated. Taking a
purely top-down approach may be necessary; however, if the larger effectiveness
of cybersecurity is increased at a national level, there may be less problematic
issues in this domain to contend with.
Recently, the United States has begun to call out aggressors as a policy
response, as seen with Russia’s SolarWinds hack and China’s Microsoft Exchange
hack; these cyber acts are characterized as acts of espionage (Sanger et al., 2021).
To this end, the United States has not been able to signal or establish clear
policies for actions that will be taken if cyberspace operations result in espionage
66
or societal confusion, with no actual physical damage occurring. Alternatively, it
is commonly agreed that cyber attacks resulting in destruction should be met with
a kinetic response (Lin, 2018). Once again, given the possibility of solutions to
address cyber problems, it would be preferable to raise the overall national level
of cybersecurity than to engage in uncertain interactions with other nations.
While responding to state cyber attacks continues to be a slow learning
process, raising national cyber defense through greater cyber hygiene and
preventing cyber attacks offers a better route than responding with state means.
Reflecting on what a cyber win in cyberspace is, long-term strategies are
preferable to short-term wins (Healey, 2016). Estonia, for example, was attacked
by Russia in a series of denial-of-service attacks that lasted multiple days. As a
long-term response, Estonia established a posture of national excellence in
cybersecurity and now leads globally in national cybersecurity strategy and tactics
(Healey, 2016).
Psychometric Paradigm of Risk Perception Framework
Addressing risk perception for the public is predicted with an assessment
of the severity and the likelihood of the possible outcome plus error with
information processed through an expectation-based calculus (Slovic, 1987;
Slovic et al., 1981; Wogalter et al., 1999; Loewenstein et al., 2001). Considering
that the public is often without exact information and receives information from
public media such as print or digital news the consideration of error is important
(Slovic et al., 1981). The severity or magnitude of effect and subjective
probabilities or likelihood are the foundations of conventional risk perception
frameworks (Loewenstein et al., 2001b). In addition to these two fundamental
67
factors, risk perception theorists argue for adding an emotional or affective
measure to describe the affective heuristic that further helps to explain why the
public makes decisions about risk beyond the conventional approaches (Slovic et
al., 2004; Slovic & Peters, 2006). Loewenstein et. al. (2001) makes a distinction
between anticipatory and anticipated emotions, with anticipatory emotions being
the “immediate visceral reactions (pg. 267)” and anticipated emotions described
as the expected emotion to be experienced in the future when a threat presents
itself. Risk perception theories have mainly focused on anticipated outcomes in
the form of anticipated magnitude of effect and subjective probabilities (or
perceived likelihood), however, models of anticipated outcomes have
acknowledged the inclusion of anticipated emotions as an additional measure of
anticipated outcomes (as depicted in Figure 3.1 from Loewenstein et al., 2001).
Figure 3.1
Loewenstein et al.’s (2001) Consequentialist Risk Model
In the assessment of risk, Slovic et al. (2004) highlight the importance of
the “analytic system,” referred to as risk as analysis described as a slow, logical,
68
and calculated reasoning, and the “experiential system,” referred to as risk as a
feeling described as a fast, instinctive, and intuitive process. For an effective risk
analysis, both systems must operate in parallel and together form the basis for
effective reasoning. Emotions can sometimes indicate that the public’s assessment
may be desensitized due to over-exposure or limited due to a lack of experiential
history (Sloman, 1996; Slovic et al.,
2004). Peters and Slovic (1996) describe two factors of interest specific to the
psychological dimension of risk perception, including dread, which they describe
as a perception of risk that has a combination of a lack of control, the feeling of
dread, and a capacity for a large magnitude of effect and risk of the unknown
described as a risk that is new and having delayed harmful impacts. The key to
understanding risk measurement is that risk perception in lay people should be
characterized by a combination of factors that include using both risk assessment
systems and that describes a larger construct such as dread or risk of the
unknown.
Experts assess disaster and hazard risk differently from lay people, with
experts often focusing on quantitative, empirical data, whereas lay people also
factor empirical statistics in their risk assessment and include emotional and
societal perceptions of threats (Slovic, 1987). Included in laypeople’s assessment
is the signaling value, the societal discourse of discussion regarding disaster that
can change over time depending on the qualities of a society (Slovic, 2016).
Understanding how emotions or dread, new knowledge, and cognitive
assessments influence risk clarifies interpreting risk from a layperson's
perspective (Slovic, 2016). The concept of dread as an emotional response to a
69
disaster is supported by the Psychometric Paradigm (Slovic, 2016) to explain how
lay people assess risk perception. While dread is directly assessed in this measure,
dread as a construct is highlighted as a measure of both the perception of
magnitude of effect, the feeling of dread, and the lack of control in response to a
disaster (Slovic, 1987).
Aim and Hypothesis
This study hypothesizes that robust psychological risk perception factors
are necessary when modeling a risk response from an introduced cyber threat.
Understanding the factors that inform psychological risk perception is important
in explaining several interests of cybersecurity. The first interest is understanding
why lay people are motivated to participate in cybersecurity processes and
possibly contribute to larger strategic cybersecurity initiatives through the
perception of risk. The second interest is to explain what factors guide people to
perceive risk from different cyber threats. This study furthers cyber threat
perception literature and contributes to future cyber threat measures that explain
what motivates people to perform cybersecurity behaviors. In reviewing risk
perception factors, this study contributes more generally to psychology in
psychological risk perception and disaster management. As cyber disasters may
progress and occur in domains outside of a historically physical context,
understanding how cyberspace fits into the context of threat perception is
important for cyber threat perception, policy, and disaster research.
This study aims to model individual willingness to utilize privacy
technology to respond to a societal-level cyber disaster. Modeling individual
willingness to utilize privacy technology will offer to explain how societal cyber
70
threats as a public policy problem may influence the discourse of the
implementation of national cyber strategy. The objective of this study is to
demonstrate the use of psychological risk perception factors as a mediator for
different types of cyber operation conditions and individual cybersecurity
decisions. This study identifies the influence of anticipated negative emotional
response, perception of likelihood, perception of magnitude, and perception of
cybersecurity awareness on the intended individual use of privacy technology for
cybersecurity. Capturing emotional response specifically the response of dread, is
one of the factors correlated with societal perceptions of risk that differentiate the
assessment of risk in lay people from the assessment of risk in experts. Perception
of likelihood and perception of magnitude of effect are factors conventionally
used by risk management experts to assess risk. Finally, cybersecurity awareness
is a measure to control for selfreported individual differences in cyber knowledge.
The overarching question posed by this study is why do people engage in
individual privacy technology as a response to a societal cybersecurity concerns?
This study asks the following research questions and tests the following
hypotheses to address this overarching question:
1) Can conventional risk factors of cyber disaster model intended individual
cybersecurity actions?
Hypothesis 1: Conventional risk factors of perception of magnitude of
effect
(H1a) and likelihood of cyber disaster (H1b) will be significant factors in a
regression model of willingness to utilize privacy technology and will
71
significantly improve a model when compared with a model of cyber operation
conditions only.
2) Does adding an affective risk factor to a model of conventional risk
perception better explain and model intended individual cybersecurity
actions?
Hypothesis 2: Controlling for perception of magnitude of effect and
likelihood of cyber disaster, anticipated negative emotional response (H2) will be
a significant factor in a regression model of willingness to utilize privacy
technology and will significantly improve the modeling of risk perception when
compared with a model of cyber operation conditions and conventional risk
factors.
3) Does adding a cybersecurity awareness factor to a model of psychological
risk perception (magnitude, likelihood, and anticipated emotional
response) better explain and model intended individual cybersecurity
actions?
Hypothesis 3: While controlling for magnitude, likelihood, and anticipated
emotion, the factor of cybersecurity awareness will be a significant factor in a
regression model that (H3) and will significantly improve a model of willingness
to utilize privacy technology.
Finally, I pose a research question about the total model fit, following iterative
trimming of a saturated model, can a significant path that includes perceived
cybersecurity awareness and cyber threat conditions mediated by psychological
risk perception factors be fitted to willingness to utilize individual privacy
72
technology and is there evidence of mediation of cyber threats through risk
perception factors (See Figure 3.2)?
Figure 3.2
Saturated Risk Model
Related Work: Risk Perception and Surveys in Cyber Threats
Nascent studies of cyber threats identify Slovic’s (2016) psychological
risk perception as an often-cited theoretical framework of interest (Gomez &
Villar, 2018; Gomez & Whyte, 2021; Kostyuk & Wayne, 2021a; Shandler &
Gomez, 2023), specifically identifying Slovic’s construct of dread and emotional
aspects of lay people. The cyber threat literature utilizes survey experiments and a
formula of introduced threat conditions mediated by risk perception factors
towards a cognitive evaluation that includes an evaluation of policy or greater
cybersecurity efforts. Much of the cyber threat literature utilizes a single measure
of anticipated outcomes focusing on anticipated emotional responses.
73
Kostyuk and Wayne (2021) focus on the conditions of a data breach and
found that exposure to a data breach with a personal context led to a greater
perception of threat as measured by their threat perception scale. They also
measure the effect of data breach conditions on personal security behaviors and
policy preferences and find limited effects for both - surprisingly, they do not
hypothesize a mediation between threat perception and personal security
behaviors as reflected in this study. Their threat perception scale is a unique
measure as it combines likelihood and a hierarchy of concerns for disaster.
Kostyuk and Wayne (2021) offer several approaches to measure a cybersecurity
response. One approach is to measure the individual's willingness to utilize safer
online behavior. The measure of individual willingness to utilize safer online
behavior includes using privacy technology. Another approach is to measure
actual online behavior. In their study, they send emails that pose possible phishing
attempts while identifying participants that visit the websites linked in their email.
Kostyuk and Wayne’s (2021) analysis of findings suggests that introducing a
cyber threat has limited effects on behavior as a response.
Gomez and Villar (2018) describe their measure of dread as “an indication
of something impending (pg. 64).” They offer a cyber operation that attacks an
energy facility as an experimental condition of their study. To measure a response
to this introduced threat, they use a pre- and post-measure of how threatening
participants perceive cyberspace to be. To measure dread, they review changes in
trust in cyberspace with a pre- and post-measurement of trust in cyberspace
following their intervention.
74
Shandler & Gomez (2023) use the same measure as Gomez & Villar
(2018), which they describe as a measure of dread and also include a
psychological measure of anxiety and anger. Shandler & Gomez (2023) applied a
novel approach, asking participants in the state of North Rhine-Westphalia in
Germany to identify if they were aware of a real-world ransomware attack on the
Düsseldorf hospital that occurred one week before the survey. Shandler & Gomez
(2023) use a path model approach and found that respondents’ reports on their
dread and anger scales mediated negative confidence in the government regarding
exposure to the cyber attack.
In another study, Gomez & Whyte (2021) utilized an emoticon slider to
measure affective response and found that the content or tone of fictitious cyber
attack news headlines and the perception of threat was mediated by the affective
response. Gomez & Whyte (2021) also included two levels of threat: a threat to
the individual, in the question of how much cybersecurity should be prioritized
for their day-to-day lives, and a threat to the polity, asking how much government
should prioritize cybersecurity. These measurements are not of risk perception but
rather a response to risk, which were found to be mediated by their emoticon
slider.
Backhaus et al. (2020) and Snider et al. (2021) both offer an experimental
condition of lethal and non-lethal cyber terrorism attacks in the form of a
simulated news video. Backhaus et al. (2020) measured salivary cortisol as well
as emotional including anger and anxiety. Backhaus et al.’s (2020) approach
offered anticipatory emotional measurements in the use of cortisol measures and
also anticipated emotional measures in the use of anxiety and anger scales.
75
Backhaus et al.’s (2020) approach did not yield significant findings when
comparing treatment conditions. Snider et al. (2021) utilized a scale that
measured threat perception, focusing on the cognitive aspects of rating how a
cyber attack may affect participants and their nation. In a path model, Snider et al.
(2021) found that their threat perception scale effectively measured a mediation
between conditions of fictitious news videos of lethal and non-lethal cyber-attacks
compared with a control.
Addressing the gap in psychological risk perception measurement offers a
holistic approach to risk perception. It measures cognitive and affective responses
to explain why individuals perceive risk that leads to a cybersecurity response.
Differentiating from previous studies, this study uses multiple risk perception
measures. This study directly measures self-reports of the anticipated dread and
other negative emotions correlated with reporting emotional distress from
disasters. Measuring these various anticipated emotions helps to address the
psychological element or affect heuristic. This study uses the conventional risk
framework of a combination of perceptions of the magnitude of effect and
likelihood of a cyber disaster. Finally, this study uses self-reports of cybersecurity
awareness to control for individual differences in cyber knowledge that have
further implications for perceptions of the ability to control or mitigate a cyber
disaster.
Methods
Procedures
Prolific was utilized to recruit from participants who fit the study profile.
Several
76
Prolific screeners were utilized to create a pool of targeted participants eligible for
participation. The following screeners were requested: all participants in this
survey were requested to be located in the United States; participants are currently
students enrolled in a Bachelor, Master, or Ph.D. program; a balanced sample of
50% male and 50% female was requested. Participants were compensated $2.50
for a survey that was projected to be completed within 10 minutes, equating to
approximately $15/hour compensation.
Participants from Prolific’s pool who agreed to participate in this study
were provided with a consent form approved by an IRB at the beginning of their
survey. Before beginning the questionnaire, participants were asked to complete a
“commitment request,” confirming that they committed to providing thoughtful
answers to the survey questions. Demographic information, including age, gender,
years of university education, and political ideology (liberal-conservative) was
collected. Participants were also asked to confirm that they are current students of
a university in the United States and to provide the name of the university they
are enrolled in.
United States University Representative Participants
The total number of participants included in the analysis was 933.
Participants were selected using the Prolific survey service to capture this target
sample. Prolific screeners requested a balanced sample of male and female
participants, participants who answered “yes” to the question of being current
students, including only students who are pursuing an Undergraduate Degree
(BA/BSc/other), a Master's Degree
77
(MA/MSc/MPhil/other), or a Doctorate Degree (PhD/other)). 1,025 participants
were recruited from a potential pool of 2,119 participants from the Prolific survey
service to participate in this experimental survey. Of the 1,025 participants, 92
were rejected.
To ensure reliability, a commitment request was included in the beginning
of this survey. The commitment request asked participants to commit to
thoughtful answers and was utilized to request that participants take the survey
seriously. If participants answered “No, I will not.” or “I can’t promise either
way” to the commitment question, they would be excluded. All participants
agreed to a commitment request by answering “Yes” to the survey question.
The target of this study’s sample was to survey participants who are
geographically dispersed throughout the United States. Given that participants
were enrolled in a university, this study assumes that participants have a common
relationship with their organization with fictional headlines describing an attack
on their associated organization. University students were chosen to meet this
target. Universities provide a sample of American residents who are
geographically dispersed and who have a common relationship with their
organization. Universities have required oversight accreditation boards that
review standards for participation in the higher education process, which include
a standard of compliance with FERPA requirements that mandated a level of
cybersecurity and information security protect to individuals enrolled in
Universities The mandated cybersecurity and information security requirements
through such legislations as FERPA are an assumption that contributes to the
78
general expectations of cyber threat and cyber risk to the student of a university in
the United States.
Experimental design
State-level cyber operations can be categorized into three types: cyber
degradation, cyber espionage, and cyber disruption (Valeriano, 2018). Cyber
disruptions include website defacement and DDoS incidents to undermine public
confidence and challenge the existing policy choices of an adversary. Cyber
espionage is an attempt to exploit information asymmetry and achieve long-term
competitive gains through information. Cyber degradation is "coercive operations
designed to sabotage the enemy target networks, operations, or systems (12)."
Cyber degradation includes attacks on critical infrastructure that can result in
death and widespread injury. The attacker's persistence to utilize multiple
disruptive attacks toward a targeted system can differentiate cyber disruption from
cyber degradation, where disruption can be categorized as degradation if it is
systematic and with an effort to achieve a coercive end (Jensen et al., 2019). An
example of this is the persistent DDoS and website defacement attacks against
Estonia in 2007 through hacktivists mobilized and encouraged by Russia that
occurred over the course of multiple days.
Following the prescribed framework of Loewenstein et al.’s (2001) model
the dependent variable is characterized by a cognitive evaluation in the form of a
cybersecurity response which is precipitated by risk perception (the combination
of anticipated outcomes and subjective possibilities) which is also mediates the
contextual factors of the experiment (see Figure 3.3).
79
Figure 3.3
Psychological Risk Perception Model Framework for Cyber Threat
The model specified above follows several assumptions. First it is assumed that
contextual factors, in the type of cyber operation, have an effect on risk
perception. Second that risk perception has two types subjective probabilities and
anticipated outcomes. This model includes emotional (measured with anticipated
negative emotional response) and cognitive responses (perceived magnitude of
effect of cyber disaster). Third, that individual factors of knowledge (measured
with perceived cybersecurity awareness) will have an effect on all cognitive based
risk perceptions to include perception of likelihood and magnitude of cyber
disaster and will not have an effect on emotional responses. Fourth, when
specifying this model it is assumed that in the case of risk perception, subjective
80
probabilities precedes anticipated outcomes such that the outcomes are dependent
on whether the event occurs.
Participants were randomly assigned to be in one of four groups based on
threat type, including, degradation (N=236), espionage (N=232), disruption
(N=231), and a control group (N=234) (See Table 2.1). All cyber threat groups
included a prompt requesting participants to read fictional headlines that describe
news articles; the control group included a prompt requesting participants to think
about recent headlines about cyber incidents they have read in the news. Each of
the three cyber threat groups had distinct headlines describing a cyber attack on
the participant’s location, university, and the United States. Following exposure to
the cyber threat intervention, participants were asked to complete a questionnaire
measuring risk perception (perception of magnitude of effect of cyber disaster,
anticipated negative emotional response, and perception of likelihood of cyber
disaster) to the headlines they were exposed to. Before exposure, demographics
(age, political ideology, and gender) and perception of cybersecurity awareness
were also measured.
Dependent Variable
The measurement of a decision to utilize privacy technology is the
dependent variable of this study. The decision to utilize privacy technology is
seen as the desired outcome that is of interest to understanding individual use of
cybersecurity and a measure of cyber hygiene. As a dependent variable,
willingness to utilize individual privacy technology (α = .71) included a five-item
likelihood scale. The scale of willingness to utilize privacy technology is a five-
item scale modified from Kostyuk & Wayne’s (2021) online behaviors scale - a
81
scale described as measuring an individual’s willingness to engage in cyber
hygiene behaviors that require additional time and cost and was suggested by
other cybersecurity experts. Participants were requested to identify their
likelihood to adopt a privacy technology on a 7-point scale ranging from
extremely likely to extremely unlikely. An additional response was included
requesting if the participant already used the various privacy technology tools. If
participants already used the privacy technology tool for their current security
behavior, they were given the highest rating of 7 equivalent to extremely likely.
Independent Variables: Risk Perception Measures
Following the model framework of Loewenstein et al. (2001), this
research design includes independent variables of anticipated outcomes of
perceived magnitude of effect and anticipated negative emotions. Anticipated
outcomes include a cognitive appraisal of perceived magnitude of effect and an
emotional appraisal of anticipated negative emotional reaction. Both measures are
established measures modified from hurricane disaster scales. A measure of
subjective probabilities is identified in the perception of the likelihood of cyber
disaster. The subjective probability measure is modified from Kostyuk & Wayne’s
(2021) cyber threat perception scale. The cognitive appraisal of the perceived
magnitude of effect and the subjective probabilities of perception of the likelihood
of cyber disaster account for the conventional perception of risk. Adding the
anticipated negative emotional response component helps explain the affect
heuristic of risk perception. The combination of all three factors is referred to in
this study as psychological risk perception.
82
To address variations of knowledge about cybersecurity, the factor of
perceived cybersecurity awareness was added to the model to take into account
individual variations of cybersecurity knowledge. The individual factor of
cybersecurity awareness is assumed to be a non-emotive factor and, therefore is
associated with likelihood and magnitude rather than emotion. Figure 2 depicts
the model relationships specified for this study.
This study measured perception of likelihood of cyber disaster using a
three-item scale modified from Kostyuk and Wayne’s (2021) “Cyber Threat
Perception” scale (α= .90). Kostyuk and Wayne’s (2021) focus on likelihood of
attack was modified to include specific location (by city) and specific
organization (University), to measure the likelihood of attack on the participant’s
location, university, and personal resources or someone known to them.
This study measured perception of magnitude of cyber disaster using a
four-item scale that measures cognitive anticipated outcome of the scale of a
cyber disaster (α= .71). The perception of magnitude of cyber disaster was
constructed using a modified version of the cognitive portion of the “Cognitive-
Affective Scale for Hurricane Risk Perception (Trumbo et al., 2016).”
Modifications were minimal and generally included changing the word
“hurricane” to “cyber attack” and included changing the context of “your
location” to “your University.” The perception of magnitude of cyber disaster
scale measures how cyber threats elicit people's understanding of possible
cognitive perceptions of cyber disasters, including a cognitive appraisal of
catastrophic destruction, the possibility of death, financial threat, and threat to
future generations.
83
This study measured cybersecurity awareness using a four-item scale that
measures perceptions of cybersecurity knowledge (α= .90). Bulgurcu et al.’s
(2010) scale of information security was modified with “information security”
changed to “cybersecurity.” This scale includes self-reports of awareness of
cybersecurity threats, risk, and knowledge of problems. Cybersecurity awareness
was included as a measure that would help to account for differences in
knowledge of the cybersecurity landscape and general awareness of risk and
threat.
This study measured anticipated negative emotional response using a
modified version of the affective portion of the “Cognitive-Affective Scale for
Hurricane Risk Perception (Trumbo et al., 2016).” The anticipated negative
emotional response scale is a four-item measure (α= .90) of how a cyber operation
elicits emotional responses, including feeling fearful, feeling worried, feeling
dread, and feeling depressed. A descriptive statistics table (See Table 3.1)
highlights the mean, standard deviation, minimum, and maximum of all variables
in this study.
Table 3.1
Chapter 3 Descriptive Statistics
Variable Mean Std. Dev. Min Max
Willingness to utilize individual privacy 5.02 1.27 1 7
Perception of magnitude of cyber disaster 4.86 0.97 1.5 7
Perception of likelihood of cyber disaster 3.75 1.35 1 7
Anticipated negative emotional response 4.22 1.37 1 7
Cybersecurity awareness 5.21 1.14 1 7
84
Results
Baseline Threat Model and Conventional Risk Model
A chi-square test of a model that included only threat conditions was
compared with a model that included threat conditions along with perception of
likelihood of cyber disaster and perceived magnitude of effect to reveal a
significant improvement to the modeling of cognitive perception of cyber disaster
(F(2, 927) = 51.26, p<.001). The Conventional Risk Model of Table 3.3 examined
to review conventional risk assessment of cyber disaster and its effect on the
willingness of individuals to utilize privacy technology. Controlling for perceived
magnitude of effect, each 1-point increase in perception of likelihood is related to
0.30 point increase in willingness to utilize privacy technology t(933)=9.96,
p<.001 (Supporting H1a). Controlling for perception of likelihood, each 1-point
increase in perceived magnitude of effect is related to 0.16 point increase in
willingness to utilize privacy technology t(933)=5.33, p<.001 (Supporting
H1b).
Table 3.2
Psychological Risk Perception Models
Dependent Variable: Willingness to Utilize Privacy Technology for
Personal Use
Baseline Threat
Model
Conventional Risk
Model
Psychological
Risk Model
Awareness
Model
Perceived of Likelihood of Cyber
Disaster
0.16 ***
(0.03)
0.14 ***
(0.03)
0.12 ***
(0.03)
Magnitude of Effect of Cyber
Disaster
0.30 ***
(0.04)
0.21 ***
(0.05)
0.15 **
(0.05)
85
Anticipated Negative Emotional
Response
0.14 ***
(0.03)
0.16 ***
(0.03)
Perception of Cybersecurity
Awareness
0.26 ***
(0.03)
Degradation 0.24 *
(0.13)
0.08
(0.11)
0.07
(0.11)
0.06
(0.11)
Disruption 0.02
(0.12)
-0.04
(0.11)
-0.006
(0.11)
-0.07
(0.11)
Espionage 0.14
(0.13)
0.05
(0.11)
0.05
(0.11)
0.01
(0.11)
Model Improvement (F-statistic) 51.26 *** 18.03 *** 54.49 ***
Intercept 4.91 ***
(0.08)
2.93***
(0.22)
2.81 ***
(0.22)
1.84 ***
(0.25)
Observations 933 933 933 933
R-squared (Δ) 0.002 0.08 0.04 0.05
p<.001***, p<.01**, p<.05*
Psychological Risk Perception
The Psychological Risk model on Table 3.3 was examined to review the
psychological perception of risk and its effect on willingness to utilize privacy
technology. Controlling for anticipated negative emotional response and
perception of likelihood of cyber disaster, each 1-point increase in perceived
magnitude of effect is related to 0.21 point increase in willingness to utilize
privacy technology t(933)= 4.55, p<.001. Controlling for negative emotional
response and perceived magnitude of effect, each 1-point increase in perception
of likelihood of cyber disaster is related to 0.14 point increase in willingness to
utilize privacy technology t(933)= 4.75, p<.001. Controlling for perception of
86
likelihood of cyber disaster and perceived magnitude of effect, each 1-point
increase in negative emotional response is related to 0.14 point increase in
willingness to utilize privacy technology t(933)=4.28, p<.001 (Supporting H2).
A chi-square test of a model that included threat conditions, perception of
likelihood, and perceived magnitude of effect was also tested against a model that
included the same factors plus negative emotional response to reveal a significant
improvement to the model (F(1, 926) = 18.03, p<.001).
Psychological Risk Perception and Perception of Cybersecurity Awareness Model
The Awareness model on Table 3.3 was examined to review psychological
risk perception that controls levels of cybersecurity awareness. While controlling
for perceived magnitude of effect, negative emotional response, and cybersecurity
awareness, each 1-point increase in perception of likelihood of cyber disaster is
related to
0.12 point increase in willingness to utilize privacy technology t(933)=4.14,
p<.001.
While controlling for perception of likelihood of cyber disaster, negative
emotional response, and cybersecurity awareness, each 1-point increase in
perceived magnitude of effect, is related to 0.15 point increase in willingness to
utilize privacy technology t(933)=3.16, p<.01. While controlling for perception of
likelihood of cyber disaster, perceived magnitude of effect, and cybersecurity
awareness, each 1 point increase in negative emotional response, is related to 0.16
points increase in willingness to utilize privacy technology t(933)=4.91, p<.001.
While controlling for perception of likelihood of cyber disaster, negative
emotional response, and perceived magnitude of effect, each 1point increase in
cybersecurity awareness is related to 0.26 point increase in willingness to utilize
87
privacy technology t(933)=7.38, p<.001 (Supporting H3). A chi-square test of a
model of threat conditions, perception of likelihood, perceived magnitude of
effect, and negative emotional response was tested against a model that included
the same factors plus the perception of cybersecurity awareness was conducted to
reveal a significant improvement to the modeling of cognitive perception of cyber
disaster (F(1, 925) =
54.49, p<.001).
Path Significance
Five factors and the experimental condition of cyber operation types were
analyzed. A saturated model (See Figure 3.1) was iteratively trimmed of non-
significant relationships and was subjected to a path analysis (See Figure 3.8).
Figure 3.8
Path Model of Psychological Risk Perception
88
In a test of model fit, Model Chi-Square scaled test statistic was not significant
(χ2(7 degrees of freedom) = 5.22, p = 0.63). The non-significant model chi-square
indicates that the fit between the sample and fitted covariance matrices is not
significantly different, suggesting it is a good model fit. An alternative path model
was also specified that presents a path where anticipated outcome of magnitude of
effect precedes the anticipated outcome of emotional response (see Figure 3.9).
Figure 3.9
Alternative Path Model of Psychological Risk Perception
An alternative model also reveals a well fitted model with Model Chi Square
(p>.05),
CFI (CFI>.96), TLI (TLI>.95), and RMSEA (RMSEA<.05) model fit indicators
(see Table 3: Alternative Model Fit Indicators). Note that in this model the threat
conditions are mediated only by the perception of magnitude of effect.
89
Table 3.3
Alternative Fit Risk Model Indicators
Robust Measures
Model Chi Square CFI TLI RMSEA RMSEA 90% RMSEA≤0.05 RMSEA≥0.08 LL
UL
χ2(9) = 13.74, p > .05 0.99 0.98 0.024 [0.00, 0.047] 0.97 0.00
Mediation of Cyber Threats
The path presented in this model provides evidence that the introduced
conditions of cyber operation types have a significant effect on anticipated
negative emotional response χ2 (3 d.f.) = 25.18 (p<.0001) and perceived
magnitude of effect of cyber disaster χ2 (3 d.f.) = 23.42 (p<.0001) (See Figure
3.8: Mediation of Cyber Threats). To test the mediation of these effects a Causal
Mediation Analysis was conducted in R. Using non-parametric bootstrapping
(samples = 2000), full mediation is supported in the significant total (total effect =
.24 [.02, .46] p<.05) and indirect effects (ACME = .18 [.11, .27] p<.001) and non-
significant direct effect of threat type mediated by perceived magnitude of cyber
disaster on willingness to adopt privacy technology. Full mediation is also
supported in the total (total effect = .24 [.03, .48] p<.05) and indirect effects
(ACME = .10 [.04, .17] p<.001) and non-significant direct effect of threat type
mediated by anticipated negative emotional response on willingness to adopt
privacy technology.
90
Discussion
Risk perception is identified either as a dependent variable or a mediating
variable towards a dependent variable in the nascent study of cybersecurity, cyber
threats, and cyber policy (Gomez & Villar, 2018; Gomez & Whyte, 2021;
Kostyuk & Wayne, 2021a; Shandler et al., 2021; Shandler & Gomez, 2023;
Snider et al., 2021). The measurement of risk perception is important in almost
any effort to explain why individuals engage in cybersecurity behaviors and in
setting a systemic agenda of policies in response to a cyber threat. Adding to the
literature on risk perception, the present study makes three broad contributions.
First, I address a gap in the literature in identifying risk perception variables
significant for the cybersecurity domain. Second, administering a holistic
approach to risk perception that examines a cybersecurity risk response to risk as
a construct rather than a simple measure includes the examination of a mediating
risk perception factor to explain why the cyber risk is perceived. This study offers
risk perception variables that meet the criteria for the construct of psychological
risk perception, provides iterative evidence of significance of each additional
factor added to the modeling of risk perception, and offers a path analysis that is
fitted with mediation through risk perception. Finally, this study also addresses a
gap in the literature highlighting a framework cyber risk perception theory with
cyber operation conditions mediated by risk perception toward a risk
cybersecurity response.
Perception of magnitude of effect and likelihood of a cyber disaster
established a foundation of cyber risk perception based on a conventional risk
framework. A conventional approach to risk captures a cognitive system of risk
91
appraisal and is favored by risk experts (Slovic et al., 2004). Anticipated affective
response in negative emotional response was measured to establish a
psychometric measure that describes emotion and affect. Cybersecurity awareness
was included to offer a measurement akin to the ability to control a cyber threat
however, its greater utility is to offer to control differences in cybersecurity
awareness and understanding.
The findings of this study provide evidence that emotions play a role in
how lay people assess risk. The use of emotions offers to explain the divergence
between lay people and expert analysis or academic discourse. Dread and
emotional responses have been studied in cyber threat survey experiments
however, this study is the first to present a model that controls for cognitive
factors. In fact, this model displays a relationship between cognitive (in both
likelihood and magnitude) and emotional factors. The coupling of a cognitive
assessment and an emotional assessment provides a measure that can describe the
holistic psychological processes that motivate cyber disaster perceptions of lay
people. The addition of the emotional assessment factor significantly improved a
risk perception model, which helps explain such dynamics as a hypothesis of an
overreporting of dread.
Anticipated emotions as a factor that models one aspect of risk may help
to explain why individuals report a strong response to a cyber disaster followed
by a failure to provide an actionable response. As cyber threats elicit an emotional
effect the anticipated emotion, not yet experienced, may be fleeting and
temporary. Likewise, cognitive perception, which includes the likelihood and
magnitude of the effect, may also be limited to recalling the information elicited.
92
Limits of cognitive perceptions may be especially true if the cyber information is
not fully understood and if much of the information shared publicly is limited or
incomplete. This effect is proposed, given that the increased cybersecurity
awareness is associated with increased risk perception it seems that individuals
who are more aware of possible risks are better equipped to internalize
information.
This study utilized psychological risk perception factors inherently tied to
a societal disaster. In assessing psychological risk, participants were required to
assess the effect of a cyber disaster on themselves and their community in
assessing the destructive capabilities and likelihood of a cyber disaster that affects
society at large. Participants were exposed to headlines that suggested attacks on
their organization, general location, and national institutions. In this attempt, this
study offers a connection between a risk assessment of a cyber disaster that
affects society and the intended utilization and implementation of cybersecurity
tools at an individual level.
Individual responses to societal risk perceptions offer a two-fold result.
First, individuals increase their cybersecurity defense posture due to impacts on
their larger environment, and second, collectively, they may increase a national
cybersecurity defense posture. Applying psychological risk perception findings to
agenda setting in national policy and strategy implementation, individual citizens
will be motivated by societal conditions that influence the calculus of cognitive
and emotional perceptions of
risk.
93
Participants were influenced at the perceptual level, which then affected
their willingness to increase personal cyber security responses. Translating these
findings to strategic efforts, this application suggests that CSC’s (2020)
recommended pillar highlighting the increased use of individually implemented
technology and contributing to the overall increase of cyber hygiene and level of
cybersecurity defense of the United States as a nation will be motivated by a
psychological risk response found in new information that affects the assessment
of magnitude of effect and anticipated emotions of a cyber disaster. While the
type of media or avenues of messaging that include the influence of public figures
is beyond the scope of this study, this study provides evidence that understanding
mediums of information will be an important condition that can be measured
using psychological risk factors with different types of mediums contributing to
emotional or cognitive appraisals.
Balancing the pros and cons of cyber can also be a conundrum, with the
benefits and the negative aspects of interconnectedness intricately bound together.
Negative emotional response is a factor that helps to explain whether individuals
balance their concern for a major cyber attack with the benefits of an
interconnected society. For example, individuals enjoy the benefits of social
media with personalized news feeds while accepting the negative aspects of social
media, such as misinformation or disinformation (Veliz, 2020). In another more
studied example, Baumgartner and Jones (2009) reviewed the policy image of
nuclear energy initially understood as an alternative fuel source was positively
received by the public; however, when greater concerns of a possible disaster
94
were brought to light, a greater agenda for nuclear energy regulations was brought
forward to the larger public discussion.
While the evidence of a “cyber pearl harbor” has been highlighted by
decisionmakers (Bumiller & Shanker, 2012), experts argue that this event is
unlikely and is not supported by empirical evidence of cyber-state relationships
(Valeriano et al., 2018). Valeriano et al. (2018) assert that the likelihood of a
degradation cyber attack in the United States is low, while espionage and
disruption are relatively high. The lack of evidence for an event that results in
death or large-scale destruction of property occurring on American soil does not
change the fact that cyber degradation events do occur, however infrequently. As
seen in the 9/11 disaster response, policy entrepreneurs may frame a single,
improbable event to such an effect that the response to a disaster remains long
after the crisis concludes (Birkland, 2006). Policymakers should be attentive to
the public's concerns and consider the experts' guidance. Given the sharp
divergence of perceived risk between experts and the public, cyber policy
decisions should be guided by mitigating the risk of greater probability,
proactively addressing possible emotionally distressing risks, and addressing
irrational and emotionally driven perceptions.
A Holistic Approach to Risk Perception in Cybersecurity
Risk perception in cyber threats, cybersecurity, and cyber policy to date
are unidimensional, do not clearly define the construct of dread, and have limits
in their explanatory ability. I do not seek to critique other measures of dread,
threat, or risk perception. Rather, it attempts to identify whether a holistic
framework of psychological risk perception will provide a robust measure that
95
can be applied to future cybersecurity issues to offer maximum explanatory
ability. The findings provide evidence that a combination of factors that
accurately describe psychological risk perception to help identify how lay people
differ from experts in the experience of risk perception and to explain the risk
experience of the public. Using a holistic approach that includes the conventional
risk perception factors, a scale of anticipated emotion (that directly includes
dread), and perceived cybersecurity awareness, the approach of using multiple
risk perception factors is better equipped to explain why individuals perceive
cybersecurity threats and what factors also activate a cybersecurity response when
compared with other studies of cyber threats that review cybersecurity responses.
Methodological Considerations
In an attempt to expand the inferability of this research, control of
different types of students and organizations was limited to students in
universities in the United States rather than students of a specific university and
the cyber policy of one specific university. Following these findings, a further
inquiry will benefit from a narrowed understanding of organizational policy from
a specific organization or, for the case of this project a specific university. This
study reviews different cyber threat types against each other, but a future study
can include a ranking of different types of disasters. To move the cyber literature
forward, this study attempted to review the perception of disaster differences
depending on the cyber threat type. Future risk assessment studies should include
the juxtaposition of various timely man-made disasters that may include
pandemic risk, nuclear energy risk, genetically modified organism risk, etc.
96
Conclusion
The findings presented in this chapter are interdisciplinary in nature with
contributions to psychology and risk perception literature, cybersecurity literature,
and IR literature. Psychology and risk perception contributions include the use of
a risk perception and the modeling of factors typically offered to model
psychological responses to a societal disaster. Cybersecurity contributions include
the use of cybersecurity responses of individuals and the use of privacy
technology as a dependent variable of interest. Finally, the necessity of the
interdisciplinary nature is highlighted as I the models of this chapter provide
evidence that the effect of the IR interest of cyber threats requires risk perception
factors as a mediating variable towards cybersecurity response. The larger
implications of this chapter are academic in nature as they offer evidence for a
risk perception to be used as a framework for understanding the effects of cyber
threats and cybersecurity – which can be used in future study and analysis of the
resulting effects of societal cyber threat and disasters on policy and cybersecurity
response.
This survey experiment aimed to examine the effect of various cyber
operations on conventional and emotional risk perception variables and to identify
the relevant factors in modeling psychological risk perception for the express
purposes of modeling cybersecurity intended behaviors. Using a model that
includes risk factors outlined by Loewenstein et al. (2001), this study presents a
psychological risk perception model that helps explain why university students
respond to societal cyber threats at an individual level. The findings of this study
can be applied generally to understanding what factors motivate American
97
citizens connected to organizations to change their behaviors in response to
societal cyber threats and to understand what motivates individuals to implement
cyber defense strategies and support responsive cyber policy at a national level.
The conclusion of this study can be summed up as the rational judgment
of cyber risk must include a measurement of a less rational factor - the emotional
response to a societal problem. The findings of this survey experiment provide
clear evidence that psychological risk perception factors fully mediate a diverse
range of possible cyber disaster conditions in a path toward a response to the risk.
Conventional risk perception, using perceptions of magnitude of effect and
likelihood of cyber disaster was found to offer a model of risk perception.
However, anticipated negative emotional response and the perception of
cybersecurity awareness significantly improved the model. The significance of
additional factors, specifically the likelihood factor, in modeling public responses
to risk perception may help explain the controversy identified by cyber experts
that lay people incorrectly judge the risk of cyber attacks (Gartzke, 2013;
Valeriano et al., 2018). The models of this study offer evidence that the public
makes varied judgments of cyber types based on how they perceive risk,
perceived risk through both an emotional and a cognitive lens, and judge
themselves to be at different levels of awareness of cybersecurity. Multiple risk
perception factors are important beyond the simple modeling of cybersecurity and
the revelation of multiple significant risk factors. To examine these factors and
help explain why lay people perceive cybersecurity risk is the true reason this
study advocates a holistic risk perception approach.
98
99
CHAPTER FOUR
CYBERSECURITY RESPONSES: THE INFLUENCE OF OFFENSIVE
CYBER
OPERATIONS AND ORGANIZATIONAL CYBER POLICY ON ATTITUDE
AND
INTENTION TO COMPLY WITH ORGANIZATIONAL CYBERSECURITY
POLICY
Abstract
The 2020 Cyberspace Solarium Commission report recommends an American
national cybersecurity strategy that acknowledges the need for greater
cybersecurity practices to be adopted and facilitated by public and private
organizations. Motivating factors for cyberspace strategy include the
pervasiveness of cyber threats and the effectiveness of cybersecurity defense
technologies. While cyber threats are often studied through a risk perception lens,
understanding cybersecurity threats at an organizational level is a gap in the
current cybersecurity literature. Using protection motivation theory and the theory
of planned behavior, I analyze path models of attitude towards organizational
cybersecurity and intention to comply with organizational cybersecurity policy
through a path of threat and coping appraisals. I offer two models of
organizational cybersecurity attitude and compliance, a first model that utilizes
the current framework of risk perception alone and a second model that uses risk
perception factors and includes coping appraisals. The results show that
combining coping and threat appraisals provides a model that explains more
variance than risk perception alone.
100
Introduction
Cyber operations from China, Russia, Iran, and North Korea on American
businesses have resulted in billions of dollars in losses to the American economy -
arguably trillions if intellectual property losses are taken into account (The White
House, 2018). These losses and the defense of critical infrastructure are the main
motivating factors for formulating strategic cyber policy in America (The White
House, 2018). As cyber attacks on private businesses have grown in scope and
frequency, academic literature reflecting the implementation of cybersecurity in
organizations has had limited success due to a lack of reporting standards and the
associated negative publicity of cybersecurity data (Valeriano, 2022). Much of the
cybersecurity textbooks (see Schaub, 2018; Schneider et al., 2020; Whyte &
Mazanec, 2018) and academic cybersecurity literature related to cyber policy
have focused on a macro, top-down study of national security and international
relations. In a bottom-up or micro-approach, recent academic cybersecurity
literature on cyber policy focuses on cyber threats and the response of individuals
utilizing survey experiment methods (see Gomez, 2021; Gomez & Villar, 2018;
Gomez & Whyte, 2021; Gross et al., 2017; Kostyuk & Wayne, 2021; Shandler et
al., 2021; Shandler & Gomez, 2023).
Cybersecurity literature and recommendations of cyber policy have
focused on top-down and bottom-up approaches; however, there is a gap in
literature at the meso level found within organizations - where actual cyber policy
is implemented. Ajzen’s (1991) theory of planned behavior (TOPB) and Rogers’
(1975) protection motivation theory (PMT) are used as a lens to examine
individuals in organizations through their attitudes and intentions to comply with
101
organizational policy. Ajzen’s (1991) TOPB is effective at modeling the intention
to use information technology in the workplace with employees making decisions
about new technology (Morris et al., 2005), employees adopting self-service
technology (Marler et al., 2009), information security compliance (Bulgurcu et
al., 2010a), and teachers adopting new technology for the classroom (Lee et al.,
2010). Rogers’ (1975) PMT is effective in topics of intention to comply with
organizational threats relating to natural disasters (Vaughan, 1993), nuclear
responses
(Axelrod & Newton, 1991), and information security policy compliance (Herath
& Rao, 2009; Ifinedo, 2012; Johnston & Warkentin, 2010; Li et al., 2022; Meso et
al., 2013; Mou et al., 2022).
According to ISO/IEC 27032:2023, cybersecurity is defined as
“safeguarding of people, society, organizations and nations from cyber risks.”
Cybersecurity is a subset of information security (Taherdoost, 2022). The study of
organizational-level information security policy is oriented toward understanding
policy compliance through a lens of expected utility-type theories, which
premoniately include deterrence theory, protection motivation theory, and theory
of planned behavior (Cram et al., 2017). PMT (Maddux & Rogers, 1983; Rogers,
1975) and TOPB (Ajzen, 1991) are both expected utility models that have been
used extensively to explain the intention to comply with information security
policy (Baskerville & Siponen, 2002; Mou et al., 2022). PMT and TOPB have
also been effectively applied using a fusion approach where the combination of
various factors of both theories explains the intention to comply with information
security policy (Hooper & Blunt, 2020; Ifinedo, 2012; Siponen et al., 2010).
102
Quantitative study of real-world cybersecurity is difficult due to data
collection limitations and hesitancy to disclose cyber incidents directed at private
organizations
(Valeriano, 2022). The dirth of real-world data has resulted in much of the
quantitative findings of cybersecurity originating from experimental surveys. By
examining cybersecurity at the organizational level, I address several gaps in
academic cybersecurity and cyber policy literature. In this study, I examine the
relationship of cyber threats and organizational factors to review the effect of
societal-level threats on organizational policy. By using TOPB and PMT, I
examine the relevance of cybersecurity effectiveness as a system of factors that
helps explain organizational cybersecurity compliance. To achieve these ends, a
path model of cybersecurity threats and policy is fitted to explain attitudes toward
organizational cybersecurity policy modeled through the combination of threat
and coping appraisals.
American Enterprise and Cyber Threats
Growing cyber offensive operations on American businesses and civilians
in cyberspace present in various forms, including cyber espionage, state-
sanctioned criminal activity, information operations, and even the possibility of
disruption to critical infrastructure (Office of the Director of National
Intelligence, 2021). The Chinese attributed Equifax data breach resulted in an
estimated 143 million Americans having their personal information stolen
(Robbins & Sechooler, 2018). The Equifax breach is one of the most far-reaching
data breaches to date. A hack of this magnitude highlights the responsibility of
American companies to protect American citizens in cyberspace. North Korea's
103
attack on Sony offers a case study of how state actors can utilize cyber means of
state coercion across the private sector, bypassing the conventional limitations of
state power to change the behavior of a non-conventional adversary (Whyte,
2016). The breadth of China’s Equifax hack and the audaciousness of North
Korea’s attack against Sony is one of many examples of how cyber operations
appear to be changing the landscape of conventional state interaction in the spaces
of private industry.
In 2024, the US Security and Exchange Commission’s (SEC) Twitter
account fell victim to a SIM swap hack, a hack that could have been prevented if
the SEC had not disabled their multi-factor authentication (MFA) six months
earlier (Cluley, 2024). The simple hack of the SEC’s Twitter account resulted in a
fictitious tweet regarding cryptocurrency that the hacker sent out from the SEC’s
account. The failure to use MFA and the ability of malicious actors to display the
ability to capture the credentials of the SEC’s Twitter account was an
embarrassment to the SEC as a government agency tasked to oversee and
implement protection for investors and fair markets. The Office of Personnel and
Management (OPM) hack of 2014, attributed to China, was reported to be
preventable with better cyber hygiene and cybersecurity monitoring as hackers
used compromised credentials to create a back door, move through the OPM
network, and gain access to 4.2 million personnel records (Chaffetz, 2016). The
cyber attacks on the SEC and OPM are one of many examples of widely
publicized attacks perpetrated on US government agencies that were preventable
with better cyber hygiene.
104
According to the Cybersecurity and Infrastructure Security Agency’s
(CISA) ransomware FAQ page, ransomware is described as malware that captures
digital information and holds it hostage in exchange for a cryptocurrency ransom,
with ransomware affecting the computers of American individuals and businesses
alike. Many notable news stories of cyber threats have come from ransomware
used by criminal organizations developed by state-funded organizations. The
Wannacry malware attributed to North Korea was a series of ransomware attacks
that affected 230,000 computers in over 100 countries (Nakashima & Rucker,
2017). In another example of a state-sponsored ransomware attack, Russian
attributed Notpetya ransomware was designed to be directed at Ukraine’s
infrastructure, but as the ransomware ran rampant, it affected other systems and
spilled out to various nations, affecting a variety of critical infrastructure sectors
(CISA, 2018; Nakashima & Rucker, 2017).
CISA’s Ransomware FAQ page also identifies a variety of ways to protect
against ransomware all of which are implemented at an individual level including:
(1) updating software and patches (not using end-of-life or end-of-service software
or hardware), (2) not clicking on links or attachments from unsolicited emails, (3)
backing up data regularly including backing up an off-line copy, and (4) following
safe practices when connecting to the internet
(https://www.cisa.gov/stopransomware/ransomware-faqs). In much of the same
recommendations for protecting personal information, (CISA, 2021) recommends
knowing what personal and sensitive information is and where it is stored,
employing multi-factor authentication (MFA), implementing cybersecurity best
105
practices, including encryption of sensitive information at rest and in transit, and
ensuring notification for when your account may be branched.
The American Cyberspace Strategy & Organizations
A majority of the state-sanctioned cyber operations occur in the private
sector, calling into question both the responsibility of the United States
government to protect private businesses and America’s private corporation's
responsibility to manage national security and defense (Demchak, 2020; Farwell,
2018). Some private corporations that utilize cyberspace manage critical
infrastructure essential to American society's daily functioning and have greater
societal responsibility than others to ensure their organization's cybersecurity
(Corallo et al., 2020). By virtue of operational technology, attacks on critical
infrastructure present the possibility of a larger magnitude of effect of disaster,
possibly resulting in actual physical consequences, including physical harm and
death (Izycki & Vianna, 2021). CISA (2019) sees critical infrastructure and
cybersecurity as a top priority for America and has made several
recommendations for improving the cooperation between private entities, the
foremost of which is better communication.
The Cyberspace Solarium Commission’s Final Report (2020) was the
first-ever attempt to provide strategic guidance for the United States to address
evolving threats and emerging technological vulnerabilities nationally. The
President and Congress tasked the Commission to answer two fundamental
questions: What strategic approach will defend the United States against
cyberattacks of significant consequences? And what policies and legislation are
required to implement that strategy? After conducting interviews with over 300
106
subject matter experts in cyberspace, the CSC endorsed a new strategy of layered
cyber deterrence. This strategy aims to reduce the probability and impact of
cyberattacks of significant consequence. To achieve the goal of layered cyber
deterrence, the CSC’s largest effort includes directly addressing the entire
cyberspace ecosystem, including the general public and private sectors, to
promote a resilient and secure
America’s cyberspace network.
Within society, there is a level of acceptable risk for any given
circumstance, with consequences described as societal conditions (Kraft &
Furlong, 2018). Societal conditions are a way of describing an expected and
acceptable risk. For example, there is an expected number of car accidents as an
expected of outcome of driving. The conditions of society are tolerated until they
reach a problematic level, at which point public demands are made on
policymakers to formulate and implement an alternative (Birkland, 2019).
Whereas society had previously tolerated the risk inherent in an activity, an
exogenous shock, such as in a noteworthy news event, has changed the perception
of individuals as new information is made public (Kingdon, 2011). When
considered from a cyber policy perspective, the increasing trends identified in the
news of cyber operations have made evident the need for new policy alternatives
to address a growing societal problem of the need for national cyber strategy and
cyber defense. This conclusion that cyber policy is a new societal problem begs
the question of how to conduct a societal response. Herein, the CSC recommends
a whole-of-nation approach where organizations and individuals raise the level of
107
cyber defense in a distributed cybersecurity defensive layer over the entirety of
the public and private sectors.
Implementing a national cybersecurity strategy requires understanding
how organizations can implement strategy objectives through organizational
cyber policy. As a leading example, the Cyber Space Commission’s (CSC) Report
(Cyberspace Solarium Commission, 2020) presents a Layered Cyber Deterrence
(LCD) approach that is motivated by preventing Advanced Persistent Threats
(APT) from other nation-states through a whole-of-nation approach. The CSC’s
report (2020) makes a case for deterring cyber threats through a whole-of-nation
approach that includes efforts beyond typical government implementation with
recommendations for private businesses and American citizens. To date, many of
the CSC-recommended strategic initiatives have been adopted by Congress
(Cyberspace Solarium Commission, 2021). Improving policy in cyberspace
requires a better understanding of how individuals in organizations perceive the
combination of the need for cybersecurity and cyber risk to develop attitudes and
intentions to comply with organizational cyber policy.
Theory of Planned Behavior and Organizational Cybersecurity
Rather than focus on a national policy preference, this study highlights
policy and governance at an organizational level, arguing that organizations move
the needle in actual cybersecurity implementation. This makes several
assumptions: (1) individuals use cyberspace as agents of organizations; (2)
individuals are targeted in cyber attacks to infiltrate organizational IT systems;
and (3) organizations make cyber policies for human agents to address cyber risk.
To address organizational-level cybersecurity, the TOPB (Ajzen, 1991) is utilized
108
to examine the dependent variables of attitude and intention toward organizational
cyber policy.
Ajzen (2020) describes attitude as readily accessible beliefs of
consequences of a behavior, subjective norms as the perceived social pressure to
perform the behavior, and perceived behavioral control as the factors that help or
hinder the execution of a behavior. The TOPB states that the intentions of
individuals to perform behaviors can be predicted from the attitudes of
individuals toward the behavior, subjective norms, and perceived behavioral
control (Ajzen, 1991). This scope of this study is concerned with the attitude of
individuals and the relationship between attitude and intention to perform the
behavior.
Bulgurcu et al. (2010) research on information security using the TOPB
most represents the orientation of this study. Bulgurcu et al. (2010) focuses on
attitude towards information security with a model framework of two systems of
factors that explain attitude: (1) beliefs about outcomes and (2) beliefs about the
overall assessment of consequences. These two systems of factors help to explain
attitude, which in turn explains the intention to comply with organizational
information security. This study modifies this model framework using societal-
level risk perception to capture an assessment of consequences and organizational
cyber policy efficacy to capture beliefs about outcomes.
The TOPB can be differentiated from the theory of reasoned action
(Ajzen, 1980)in the assumption that there is a level of control that an individual
can exert on a behavior which in turn leads to a greater ability to execute the
behavior. Ajzen (1980) argues that perceived control or the things that make the
109
execution of a behavior more or less successful, will affect whether the behavior
is executed. In this novel approach to capturing outcomes of organizational
cybersecurity, conditions of control in the form of different types of cyber policy
were utilized for this study. Cyber policy types were presented as the policy to use
different types of cybersecurity technologies.
Various efforts have been made to incorporate the TOPB into using new
technology in the workplace (Ajzen, 2020). The TOPB helps to explain various
aspects of technology adoption and use in an organizational setting. Three factors
guide the TOPB by helping to explain the intention to perform a behavior:
Attitude towards a behavior, subjective norms, and perceived behavioral control
(Ajzen, 1991). The utility of the TOPB is in the explanation of these variables. As
an example, (Morris et al., 2005) found that variables exhibited differences
depending on gender and age. Morris et al. (2005) concluded that attitude was
important for men, but all three variables were important for women, and these
gender differences were reduced among younger workers, suggesting that the
gender gap was decreasing over time. This reduced gender gap, and the difference
between men and women is beneficial for explaining organizational factors and
displays how the factors of the TOPB can be used to move beyond simply
identifying a model of significance.
To address inconsistencies in understanding the use of technology for
teachers, the TOPB was used to study the use of computers to deliver and create
lesson plans (Lee et al., 2010). Attitude towards behavior was found to be the
most important factor - being twice as influential as subjective norms and three
times as effective as perceived behavioral control, suggesting that attitudes of
110
teachers were one of the most important elements to understanding the use of new
technology in the classroom (Lee et al., 2010).
In a study regarding employee self-service technology TOPB was used to
understand technology not directly associated with job performance (Marler et al.,
2009). The aspects of attitude related to perceived usefulness and aspects of
subjective norms related to managerial pressure were the most important factors
that led to adopting nonmandatory technology (Marler et al., 2009). Another
interesting finding from the study was that managerial pressure was stronger
when a post-implementation model was compared to a pre-implementation
(Marler et al., 2009).
The study by Bulgurcu et al. (2010) offers a window to examining
cybersecurity as it is focused on information security with an emphasis on
attitudes and compliance intentions, acknowledging that employees are among the
weakest links of organizations when it comes to ensuring the security of the
organization's information. While subjective norms and perceived behavioral
control are included, attitude is the focus of Bulgurcu et al.’s (2010) study,
emphasizing a system of factors that contribute to assessing consequences and
beliefs about outcomes. Bulgurcu et al.’s (2010) study examined a system of
factors of assessments of consequences and beliefs about outcomes, which
mediated attitudes towards compliance on the path to intention to comply with
information security policy. Much like Bulgurcu et al.’s (2010), I focus on the
pathways of a system of factors that contributing to attitude which then
contributes to intention.
111
Protection Motivation Theory
Rogers’ (1975) Protection Motivation Theory (PMT) is a theoretical
framework frequently used to model the intention to engage organizational
information security policy. PMT is derived from an expected utility framework
where the combination of threat and coping ability results in a calculus based on
behavioral expectations (Maddux & Rogers, 1983; Rogers, 1975). PMT posits
that the combination of threat and coping appraisals results in a change in attitude
and the intention to engage in a preventative activity (Maddux & Rogers, 1983;
Rogers, 1975). The framework of PMT, originally a model framework for health
and disease prevention, identifies that threat appraisal sufficiently motivates
attitudes and intentions toward a behavior change.
Rogers (1975) postulates that three components motivate the intention to
adopt a recommended preventative behavior: the perceived severity of the event,
the probability of the event's occurrence (perceived vulnerability), and the
efficacy of the protective response. Maddux & Rogers (1983) extend the PMT to
include a fourth factor of selfefficacy, differentiating self-efficacy from response
efficacy noting that together they form the basis for coping appraisal. PMT was
originally established to address the use of preventative healthcare behaviors
(Maddux & Rogers, 1983) however PMT has become more prevalent beyond
health sciences (Floyd et al., 2000).
In a study that fused PMT and TOPB, Ifinedo (2012) found that attitude
towards compliance with policy was the most important factor in explaining
intention to comply with security policies. In another study that fused PMT and
TOPB Siponen et al. (2010) found that factors normative beliefs, threats, and self-
112
efficacy, were significantly related to compliance with information security, but
rewards and response efficacy were found to be insignificant in a relationship
with compliance. Finally, Hooper & Blunt (2020) also fused PMT and TOPB and
found that self-efficacy and threat severity were the only significant motivating
factors for the intention to comply with organizational security policy. While the
use of TOPB and PMT reliably yields significant results and are the preferred
theoretical framework for studying organizational information security policy,
mixed results have been identified as problematic regarding information security
policy and intention to comply (Mou et al., 2022). What is common among the
approaches is that threats, efficacy, and attitude toward compliance are often
found to be significantly related to compliance, and rewards or response costs are
not found to be significant (Mou et al., 2022).
Aim and Hypothesis
My aim of this study is to apply a risk perception framework, TOPB, and
PMT to modeling attitudes toward organizational cybersecurity policy. The first
model utilizes a psychological risk perception framework to model the dependent
variable of attitude towards organizational cyber policy. The second model adds
coping appraisal to threats and models the dependent variable of intention to
comply with organizational cyber policy. As part of this objective, I highlight the
relationship between risk perception at a societal level and the effectiveness of
organizations in mitigating risk at an organizational level. Additionally, I review
multiple conditions of cyber threats and organizational cyber policy that inform
pathways toward dependent variables.
I ask the following research questions and tests the following hypotheses:
113
Model 1
1) Following the trimming of non-significant effects, can a significant path
that includes cyber threat conditions mediated by psychological risk
perception factors be fitted to attitude towards organizational
cybersecurity?
Hypothesis 1: Relationships tested in a saturated model (see H1a-H1o of
Figure
4.1), developed using a risk perception framework (Loewenstein et al., 2001;
Slovic, 1987a), will identify a full mediation of cyber threat types to attitude
towards organizational cybersecurity policy using risk perception factors.
Figure 4.1
Psychological Risk Perception Model Framework for Cyber Threats on
Organizational Agents
Model 2
2) Can a combined model that includes threat and coping appraisals help
explain attitude and intention (see Figure 4.2: PMT/TOPB for
Cybersecurity Model) be fitted in a path model?
114
Hypothesis 2: A fusion model of theory of planned behavior and
protection motivation theory relationships tested in a saturated model (see H2a-
H2s of Figure 4.2), will identify a full mediation of organizational cyber policy to
attitude towards organizational cybersecurity policy using perception of
organizational cybersecurity policy effectiveness.
Figure 4.2
Saturated PMT Combined Model
H1a-o: Psychological Risk Perception
Risk perception was used as a system of factors representing beliefs about
consequences. (Loewenstein et al., 2001) model framework of psychological risk
perception, which includes cognitive and emotive anticipated outcomes and a
measure of subjective probabilities, is utilized. Loewenstein’s model framework
115
(Figure 4.3) identifies the importance of emotion in the perception of risk for lay
people through an affect heuristic, as popularized by Slovic (1987) (see
Figure3.1). Anticipated negative emotional response and conventional risk factors
- the perception of likelihood of a cyber disaster and the magnitude of effect of
cyber disaster were risk perception factors used to measure beliefs about
consequences. This survey experiment also introduced different conditions of
cyber operation type with (Valeriano et al., 2018) cyber operation typology of
cyber degradation, cyber espionage, and cyber disruption presented as conditions
to test risk perception differences.
Much of the interest in cybersecurity concerning cyber policy resides in
threat perception and cyber policy responses. Studies of cyber threats often
identify Slovic (2016) risk perception as a theoretical framework of interest
(Gomez & Villar, 2018; Gomez & Whyte, 2021; Kostyuk & Wayne, 2021;
Shandler & Gomez, 2023).
Experimental studies are often utilized to explore individual risk and larger,
national policy responses to introduced cyber threats. Organizational
cybersecurity policy is not currently an area of interest for cyber policy. No
experimental survey studies have been conducted regarding policy and cyber
threats.
Kostyuk & Wayne’s (2021) study comes closes to examining
organizational policy as they examine the response of university students exposed
to a condition that suggests an attack on their school. They do not examine the
cybersecurity at an organizational level. In their study, they introduced conditions
of a data breach. They found that exposure to a data breach with a personal
116
context led to a greater perception of cyber threat and a greater hierarchy of
national concerns for disaster when compared with a control. In an effort to
measure actual cybersecurity behavior they offered a training on cyber hygiene
following the survey and then sent a follow-up email with a simulated phishing
campaign monitoring whether participants clicked on the phishing link. Kostyuk
& Wayne’s (2021) analysis of findings suggests that while individuals indicate an
increase in threat perception and hierarchy of national policy concerns, actual
behavior as a response is very limited.
The model specified in this approach is modified to capture the larger
assessment of societal consequences as an assessment of consequences rather than
simply organizational consequences (see Figure 4.1). This approach is supported
by findings in the area of public risk perception that note that societal disasters
have an effect referred to as signaling value, where new information regarding a
societal disaster leads to a new calculation of risk in the organizations and
institutions that individuals are a part of (Kasperson et al., 1988). As individuals
learn about or experience a disaster at a societal level, the calculus associated with
making decisions is modified to account for factors inherent in the perception of
risk.
H2a-c: Valeriano’s Cyber Threat Types → Threat Appraisal
Valeriano et al.’s (2018) outlines the realities of cyber operations and
asserts that cyber operations fall into three categories: cyber degradation, cyber
espionage, and cyber disruption. Valeriano et al.’s (2018) three types of cyber
operations are used strategically by different states to affect a variety of coercive
ends. Cyber operations have varied effects depending on type with disruption
117
being temporary, espionage having possible downstream effects that may not be
immediately detectable, and degradation having the possibility of wider scale and
focused destruction. In addition to varied effects, there are also varied
probabilities to cyber operations, with degradation operations being less likely
and disruption and espionage being more probable depending on the attacking
and defending states. As such, it is crucial to assess whether risk measurements
depend on the different types of cyber operations rather than simply assuming all
cyber incidents are alike. It is hypothesized that the degradation threat will have
the greatest effect on threat appraisal factors, followed by the espionage threat,
then the disruption threat compared with the control condition.
H2d-e: Organizational Cyber Policy → Coping Appraisal
A meta-analysis of organizational information security policies reveals
three types of policies: corporate security policy at the management level,
organizational security policy that addresses system users, and technical security
for system designers (Baskerville & Siponen, 2002). Of the three types of security
policies studied, organizational security policy comprises of the majority of the
bulk of the focus with much of the interest being on understanding the intention to
comply with the organizational security policy (Cram et al., 2017). Organizational
security policies are issue-specific policies that guide the daily activity of users of
information systems (Cram et al., 2017). I utilize these definitions for this study to
organizational cybersecurity policies as organizational security policies that guide
the user’s interactions in an information system accessing the internet.
Furthermore, in the presentation of MFA and cybersecurity team, MFA is
described as a cybersecurity policy that offers greater selfefficacy where whereas
118
the cybersecurity team is presented as a cybersecurity policy that offers efficacy at
an organizational level. It is hypothesized that the presentation of different
organizational cybersecurity policies will affect perceptions of organizational
cybersecurity effectiveness with MFA favoring organizational cybersecurity
effectiveness (individuals) and the cybersecurity team favoring organizational
cybersecurity effectiveness (organizations).
H2f1-5: An Interaction Effect Between Cyber Threat and Cyber Policy Conditions
In the application of two conditions, testing the interaction between cyber
threat conditions and organizational cybersecurity policy initiatives is imperative.
The hypothesized interaction between cyber threat and cyber policy is based a
rational assumption that individuals will perceive that the resolution of risk
depending on type of cyber threat will be better addressed depending on the type
of cyber policy proposed. Rational Choice Theory has been applied to
understanding organizational security policy compliance with the understanding
that individuals will balance the cost and benefits of their options (Bulgurcu et al.,
2010). It is assumed that individuals will be able to perceive that greater
authentication in the form of a cybersecurity initiative of MFA that protects
individual accounts would be increasingly beneficial when presented with an
espionage threat condition. Likewise, one could rationally assume that an
organizational cybersecurity team of skilled individuals that detect network
intrusion would be a preferred initiative for a degradation attack. In the case of
using MFA for espionage threats or having an organizational cybersecurity team
for degradation threats, it is hypothesized that the benefits will be perceived in the
119
form of greater organizational cybersecurity policy effectiveness and a reduction
of threat perception depending on the threat and coping strategies presented.
H2j-o: Threat Appraisal + Coping Appraisals → Intention to Comply with
Organizational Cybersecurity
Security policy compliance refers to the actions or inactions that align
with the expectations of user activity of an organization's IT (Guo, 2013).
Compliance or noncompliance in the form of intention to comply or actual
behavior is the focal academic interest of information security policy (Cram et al.,
2017). Academica for information security policy has exhibited a strong
preference for expected utility frameworks as Deterrence theory, PMT, TOPB,
and Rational choice theory (Cram et al., 2017).
PMT is used as a framework to outline the relationship between threat and
coping appraisals to a protection motivation in the form of intention to comply. I
use a PMT framework to describe threat and coping appraisals which
independently chart paths towards a motivation to protect the individual and the
organization which the individual is an agent of. The path of threat appraisal, in
the form of perceived severity and vulnerability, leads to a fear response which
then leads to protection motivation (attitude and intention) while the path of
coping appraisals (response and self-efficacy) takes a separate path directly to
motivation protection. Mou et al.’s (2022) Protection Motivation Model for
Information Systems Research (see Figure 4.3) displays the relationship between
threat appraisals, coping appraisals, fear, and protection motivation.
120
Figure 4.3
Mou et al.’s (2022) protection motivation model for IS research model
To address a transition from organizational information security I modify the
information security approach to fit cybersecurity parameters. I define perceived
severity (the severity of effect to an information system) as the perception of the
magnitude of effect of the cyber disaster, perceived vulnerability (the likelihood
of effect to an information system) as the perception of likelihood of a cyber
disaster, and fear as the anticipated negative emotional response. Coping
appraisals fall under two categories: organizational cybersecurity effectiveness for
individuals and for organizations. Coping appraisals are differentiated by the
effectiveness of organizational cybersecurity to protect the organization's
individuals and to protect the organization itself. I propose that these coping
appraisals better represent cybersecurity policy and though modified are also
representative of responsiveness and self-efficacy.
H2p-s: Beliefs of Outcomes and Assessment of Consequences → Attitude towards
cybersecurity policy → Intention to Comply with Organizational Cybersecurity
The study by Bulgurcu et al. (2010) provides a helpful cybersecurity
framework as it is focused on information security with an emphasis on attitudes
121
and compliance intentions. Bulgurcu et al.’s (2010) acknowledges that employees
are among the weakest links of organizations when it comes to ensuring security.
Attitude is the focus of Bulgurcu et al.’s (2010) study, emphasizing factors that
include the assessment of consequences and beliefs about outcomes. Bulgurcu et
al.’s (2010) study examined a system of factors of assessments of consequences
and beliefs about outcomes, which mediated attitudes towards compliance on the
path to intention to comply with information security policy. Guo (2011) also
presents a model that is predicated on attitude mediating intention to not comply
with information security policy. Much like Bulgurcu et al.’s (2010) study, the
hypotheses of this study focuses on the pathway of a system of factors, with threat
appraisals and coping appraisals contributing to attitude which should then lead to
intention.
Methods
Procedures
Prolific was utilized to collect participants who fit the study profile.
Several Prolific screeners were utilized to create a pool of targeted participants
eligible for participation. The following screeners were requested: all participants
in this survey were requested to be located in America; participants are currently
students enrolled in a Bachelor, Masters, or PhD program; a balanced sample of
50% male and 50% female was requested. Participants were provided with
monetary compensation of $2.50 for a survey that was projected to be completed
within 10 minutes, equating to approximately $15/hour compensation.
Participants from Prolific’s pool who agreed to participate in this study
received a consent form approved by an IRB committee. Before beginning the
122
questionnaire, participants were asked to complete a “commitment request,”
confirming that they committed to providing thoughtful answers to the survey
questions. Demographic information including age, gender, years of university
education, and political status (liberal-conservative), was collected. Participants
were also asked to confirm that they are current students of an American
university and to provide the name of the university they are enrolled in.
Participants were randomly assigned to cyber policy and cyber threat
groups. Following exposure to a cyber threat and cyber policy treatments,
participants were requested to complete a battery of questionnaire items including
perception of likelihood, perception of magnitude of effect, anticipated negative
emotional response, organizational cybersecurity effectiveness to protect
individuals and organizations, attitude towards organizational cyber policy, and
intention to comply with organizational cyber policy.
United States University Representative Participants
The total number of participants included in the analysis was 933.
Participants were selected using the Prolific survey service to capture this target
sample. Prolific screeners requested a balanced sample of male and female
participants, participants who answered “yes” to the question of being current
students, including only students who are pursuing an Undergraduate Degree
(BA/BSc/other), a Master's Degree
(MA/MSc/MPhil/other), or a Doctorate Degree (PhD/other)). 1,025 participants
were recruited from a potential pool of 2,119 participants from the Prolific survey
service to participate in this experimental survey. Of the 1,025 participants, 92
were rejected.
123
To ensure reliability, a commitment request was included in the beginning
of this survey. The commitment request asked participants to commit to
thoughtful answers and was utilized to request that participants take the survey
seriously. If participants answered “No, I will not.” or “I can’t promise either
way” to the commitment question, they would be excluded. All participants
agreed to a commitment request by answering “Yes” to the survey question.
The target of this study’s sample was to survey participants who are
geographically dispersed throughout the United States. Given that participants
were enrolled in a university, this study assumes that participants have a common
relationship with their organization with fictional headlines describing an attack
on their associated organization. University students were chosen to meet this
target. Universities provide a sample of American residents who are
geographically dispersed and who have a common relationship with their
organization. Universities have required oversight accreditation boards that
review standards for participation in the higher education process, which include
a standard of compliance with FERPA requirements that mandated a level of
cybersecurity and information security protect to individuals enrolled in
Universities The mandated cybersecurity and information security requirements
through such legislations as FERPA are an assumption that contributes to the
general expectations of cyber threat and cyber risk to the student of a university in
the United States.
Experimental design
Prolific participants were directed to a survey questionnaire facilitated
through Qualtrics. Participants were randomly assigned to both cyber threat
124
groups and cyber policy groups. Participants were randomly assigned to be in one
of four groups based on threat type including, degradation (n=236), espionage
(n=232), disruption (n=231), and a control group (n=234) (see Table 2.1). All
cyber threat groups included a prompt requesting participants to read fictional
headlines that describe news articles; the control group included a prompt
requesting participants to think about recent headlines about cyber incidents they
have read in the news. Each of the three cyber threat groups had distinct headlines
describing a cyber attack on the participant’s location, university, and the United
States in general.
The type of cyber operation included the exposure of three different types
of cyber operation conditions. Psychological risk perception factors in a path to
the dependent variable are assumed to mediate contextual conditions. Cyber
operation types of cyber degradation, cyber disruption, cyber espionage were
derived from Valeriano et al.’s (2018) typology of state cyber operation. Cyber
disruptions include website defacement and Distributed Denial-of-service (DDoS)
incidents with the goal of undermining public confidence and challenging the
existing policy choices of an adversary. Cyber espionage is an attempt to exploit
information asymmetry and achieve long term competitive gains through
diplomatic, economic, and/or secret information. Cyber degradation is "coercive
operations designed to sabotage the enemy target networks, operations, or
systems (pg. 12)."
Participants were also randomly assigned to be in one of three groups
based on cyber policy type including MFA (n=311), cybersecurity Monitoring
Team (n=311), and a control group (n=311). All cyber policy groups included a
125
prompt informing participants to read the cyber policy and think about how this
policy can address the problem of cyber threats; the control group included a
prompt requesting participants to think about policies participants are aware of
and consider how policies address the problem of cyber threats. The cyber policy
groups presented different approaches to cybersecurity including the ways that
individuals can play a role in protecting the organization and ways that the
organization can protect individuals followed by a statement of why the policy is
used and an explanation of how technology of the policy worked.
The organizational policy that supports MFA, which requires individuals
to authenticate their identity through various means, was presented as a proactive
policy that requires individuals to participate in the cybersecurity process. The
organizational policy that supports the use of a cybersecurity team, an
organizational team that uses system monitoring tools to monitor network traffic
and respond to cybersecurity issues, was presented as a policy that is reactive and
does not require individuals to participate in the cybersecurity process. It is
assumed that the perception of greater agency or the perception of control of
cybersecurity will influence the cyber policy conditions of technology. In other
words, individuals with greater agency will endorse the greater effectiveness of an
organization's cybersecurity. With better outcomes, as evidenced by cybersecurity
proficiency, they will have better attitudes toward cyber policies.
Type of cyber policy included the exposure of two different types of cyber
policy conditions and a control. Contextual conditions are assumed to be
mediated by psychological risk perception factors and perceptions of
organizational cyber effectiveness in a path to the dependent variable. Cyber
126
policy types using MFA and a cybersecurity monitoring team for the organization
were used to test whether different policy types affected attitude and intention to
comply with cyber policy. The prompt using an MFA was crafted to emphasize
the agency of individuals and the ability of individuals to control their
authentication method and contribute to a proactive, larger cybersecurity strategy.
The prompt of a cybersecurity monitoring team was crafted to emphasize
traditional efforts of monitoring, preventing, and responding to cyber intrusions
with no mention of how individuals can contribute to larger cybersecurity efforts.
Table 4.1
Cyber Policy Intervention Groups
MFA Cyber Policy Cybersecurity Monitoring
Team Cyber Policy
Control Cyber Policy
There is policy in place to
address the cybersecurity of
your organization. Please read
the following policy and
consider how this policy can
help to address the problem of
cyberthreats.
There is policy in place to
address the cybersecurity of
your organization. Please read
the following policy and
consider how this policy can
help to address the problem of
cyberthreats.
There is policy in place to
address the cybersecurity of
your organization. Please
think about the various
policies you are aware of and
consider how these policies
can help to address the
problem of cyber threats.
If [University Name] uses
Two-FactorAuthentication
(2FA) it will allow you to play
a large role in
maintaining the cybersecurity
of your organization protecting
you and all members of your
university.
If [University Name] has a
cybersecurity team, the team
can play a large role in
maintaining the cybersecurity
of your organization protecting
you and all members of your
university.
Two-Factor authentication is
used to authenticate the
identity of all organizational
members including students
and faculty.
Your organization's
cybersecurity team can
deploy a defensive approach
that focuses on prevention,
detection, and response of
attacks on your organization.
127
Two-factor authentication
requires something you know
(such as a password) and
something you have (such as
a mobile phone) as an added
layer of security to prevent
Defensive-oriented
cybersecurity uses traditional
methods to keep networks safe
from cyber crime. The tactics
rely on a thorough
understanding of a system
anyone else from accessing environment and how to
your account. Two-factor analyze it to detect
potential authentication is the most network flaws.
effective method of
account takeover
prevention, helping to
protect both you and
the university.
Dependent Variables
Organizational risk response measures included a three-item scale of
intention to comply with organizational cybersecurity policy (Cronbach’s α=.90)
and a four-item scale of attitude towards the organizational cybersecurity policy
(Cronbach’s α=.91). Bulgurcu et al.’s (2010a) “Intention to Comply with
Information Security” scale was modified to measure a risk response of
participant’s compliance with cybersecurity. Bulgurcu et al.’s (2010a) “Attitude
Towards Information Security” scale was also modified to measure the risk
response of attitude towards an organizational cybersecurity. Bulgurcu et al.
(2010) conducted a structural equation model to identify reliable factors that
capture the path of information security compliance, finding that attitude towards
information security was the essential mediating factor in the explanation of
intention to comply with information security policy measures. Scale
modifications were minimal, with “information security” changed to
“cybersecurity.”
128
Table 4.2
Chapter 4 Descriptive Statistics
Variable Mean Std.Dev. Min Max
Intention to comply with organizational
cybersecurity policy
6.04 0.81 3 7
Attitude towards the organizational
cybersecurity policy
5.89 0.82 2 7
Perception of magnitude of cyber disaster 4.86 0.97 1.5 7
Perception of likelihood of cyber disaster 3.75 1.35 1 7
Anticipated negative emotional response 4.22 1.37 1 7
Cybersecurity awareness 5.21 1.14 1 7
Organizational cybersecurity effectiveness to
protect (individual)
5.75 0.93 1.25 7
Organizational cybersecurity effectiveness to
protect (organization)
5.00 0.96 1.75 7
Psychological Risk Perception Covariates
Loewenstein et al. (2001) psychological risk perception framework was
used to capture the system of factors associated with the assessment of
consequences. This approach includes a cognitive appraisal of perceived
magnitude of effect, an emotional appraisal in anticipated negative emotional
reaction, and a measure of subjective probabilities with perception of likelihood
of cyber disaster. Both measures are established measures modified from
129
hurricane disaster scales (Trumbo et al., 2016). The perception of magnitude of
cyber disaster scale is a four-item scale that measures cognitive anticipated
outcome of possible scale of a cyber disaster (Cronbach’s α= .71).
Modifications were minimal and generally included the changing of the word “hurricane”
to “cyber attack” and included changing the context of “your location” to “your
University.” The anticipated negative emotional response scale (Cronbach’s α= .90) is a
four item measure of how a cyber operation elicits emotional responses including feeling
fearful, feeling worried, feeling dread, and feeling depressed.
Perception of likelihood of cyber disaster scale (Cronbach’s α= .90) a
three-item scale modified from Kostyuk and Wayne’s (2021) “Cyber Threat
Perception” scale was used to measure subjective probability of cyber disaster.
Kostyuk and Wayne’s (2021) focus on likelihood of attack was modified to
include specific location (by city) and specific organization (University), to
measure the likelihood of attack on the participant’s location, university, and
personal resources or someone known to them. The combination of all three
factors are referred to as psychological risk perception with the perceived
magnitude of effect and perception of likelihood of cyber disaster accounting for
the conventional perception of risk and negative emotional response helping to
explain the affect heuristic of risk perception (Loewenstein et al., 2001).
Cybersecurity Effectiveness Covariates
In a novel effort to capture beliefs about organizational cybersecurity
effectiveness, two scales were created for this study. Scales were designed to
capture how individuals perceived organizational policy effectiveness,
measuring perceptions of organizational cyber policy effectiveness at the
130
organizational and individual levels. The organizational cybersecurity
effectiveness to protect individual scale (Cronbach’s α= .91) measures how
much an individual perceives that their organization contributes to their own
safety and well-being. The scale included the following prompt and four
questions: Thinking about the policies that [University Name] has in place to
address cyber attacks described in the headlines, how much do you agree with
the following statements: (1) My organization has cyber policies that protect
individuals who are using the internet. (2) My organization’s cyber policy
protects me. (3) My organization’s cyber policy keeps me and my personal
resources secure. (4) My organization has cyber policies that are for my good.
To address the proactive ability of an organization to prepare for cyber
attacks by taking measures to defend or protect against cyber attacks, the
organizational cybersecurity effectiveness to protect organizations scale
(Cronbach’s α= .79) measures an individual’s perception of an organization's
effort to defend against cyber attacks. The scale included the following prompt
and four questions: Thinking about your university's ability to protect itself
from a cyber attack. How much do you agree with the following statements:
(1) My university is very vulnerable to the type of cyber attacks described in
the headlines. (2) My university is able to defend against most of the
cyberattacks described in the headlines. (3) My university prioritizes being
secure from the cyber attacks described in the headlines. (4) My university
takes precautions to prevent cyberattacks described in the headlines.
131
Model 1
Following the model framework of Loewenstein et al. (2001), this
research design includes anticipated outcomes of perceived magnitude of effect
and anticipated negative emotions. Anticipated outcomes include a cognitive
appraisal of the perceived magnitude of effect and an emotional appraisal of
anticipated negative emotional reaction. Both measures are established measures
modified from hurricane disaster scales. A measure of subjective probabilities is
identified in the perception of the likelihood of cyber disaster. The subjective
probability measure is modified from Kostyuk & Wayne’s (2021) cyber threat
perception scale. The cognitive appraisal of the perceived magnitude of effect and
the subjective probabilities of perception of the likelihood of cyber disaster
account for the conventional perception of risk. Adding the negative emotional
response component helps explain the affect heuristic of risk perception. The
combination of all three factors is referred to in this study as psychological risk
perception.
The measurement of a decision to utilize privacy technology and the
outcome of increased cybersecurity, which are the next measures of Loewenstein
et al.’s (2001)) framework, are beyond the scope of this study. Feelings as an
anticipatory emotion are also beyond the scope of this survey experiment,
requiring a measure of a physiological response. The type of cyber operation,
including the exposure of three different types of cyber operation conditions and
control, provided contextual factors for this experiment. Psychological risk
perception factors in a path to the dependent variable are assumed to mediate
cyber threat conditions. Cyber operation types of cyber degradation, cyber
132
disruption, and cyber espionage were derived from (Valeriano et al., 2018))
typology of state cyber operation. The dependent variable of attitude toward
cybersecurity policy was chosen as a key factor associated with the TOPB.
Model 2
The risk perception framework (Loewenstein et al., 2001; Slovic, 1987b)
is articulated as a measure of threat appraisal that includes perceived likelihood,
perceived magnitude of effect, and anticipated negative emotion that explains a
cognitive response. These measures of risk perception mirror PMT’s (Maddux &
Rogers, 1983; Rogers,
1975) definition of perceived severity (magnitude of effect) and perceived
vulnerability (perceived likelihood). Mou et al.’s (2022) meta-analytic model of
protection motivation model for IS research (see Figure 4.4) includes fear as a
mediator for threat appraisal and coping appraisals directly related to protection
motivation factors. I modify the Protection Motivation Model for IS research and
apply the factors for the relevant context of cybersecurity compliance.
Floyd et al.’s (2000) meta-analysis of PMT is used as a benchmark for
defining
PMT factors. The threat-appraisal process includes maladaptive response rewards
(intrinsic and extrinsic) and the perception of threat (severity and vulnerability).
Threats are theorized to increase the probability of selecting an adaptive response.
The copingappraisal process evaluates the ability to cope with and avert the
appraised threat. Factors comprising the coping-appraisal process are efficacy
variables (both response efficacy and self-efficacy) and response costs. Response
efficacy is the belief that the adaptive response will work and that taking the
133
protective action will effectively protect the individual or others. Self-efficacy is
the perceived ability of the person to carry out the adaptive response. Response
costs are any costs (e.g., monetary, personal, time, effort) associated with taking
the adaptive coping response. It is theorized the stronger the perception of
response efficacy and self-efficacy increases the probability of selecting an
adaptive response. In contrast, response costs will decrease the probability of
selecting the adaptive response.
I utilize perceptions of magnitude and the likelihood of cyber disasters as
threat appraisals and anticipated negative emotion as a mediator to protection
motivation. I also use organizational cybersecurity effectiveness at two levels the
individual and the organizational to adjust to the context of cybersecurity with
organizational cybersecurity effectiveness (individuals) substituting the factor of
self-efficacy and organizational cybersecurity effectiveness (organizations)
substituting the factor of response efficacy. Furthermore, the conditions of
cybersecurity policy and cyber operation threat types provide context for threat
and coping appraisals. In Mou et al.’s (2022) meta-analytic structural equation,
response cost was found not to provide additional assistance to a meta-analytic
model and, therefore, was not included. Protection motivation factors include
both attitude towards cybersecurity policy and intention to comply with
cybersecurity policy. While attitude is a TOPB factor it is a mediator for intention
to comply (Bulgurcu et al., 2010b). Figure 5 presents a model replicating the
Protection
Motivation Model for IS Research modified for cybersecurity (see Figure 4.4).
134
Figure 4.4
Protection Motivation Model for Cybersecurity Research
To map out the relationship between policy, human agents, and
organizations through the framework of PMT/TOPB, the human agent exists
within the organization, with the agent subject to organizational policy
compliance and a balance of collective goals. Following the model framework of
Bulgurcu et al. (2010b), attitude is a key factor in the understanding of intention
to perform a behavior as outlined in the TOPB with intention to perform
135
behavior being the behavior most associated with actual completion of behavior
(Ajzen, 2020).
Model Trimming
Iterative trimming, beginning with a saturated model, was initiated to
complete three path models. Two saturated models were constructed: a risk
perception model and a combined model. The first model was specified using a
risk perception framework. The risk perception model introduced three cyber
threat conditions and used conventional and affective measures of risk perception
in a path towards intention to comply with organizational cybersecurity policy
and a third model combined the two theories using a modified TOPB and PMT.
The combined saturated models were determined from an order that included the
perception of a problem, in this case, psychological risk perception to the
perceived ability to control the problem to an attitude towards a problem, all of
which was assumed to contribute to the intention to perform a behavior.
The saturated model was specified in the Lavaan Package from R Studio.
Cyber Policy and Cyber Threat conditions were introduced to all model factors. In
addition to the main effects, interactive effects between Cyber Policy and Cyber
Threat Conditions were also introduced. Non-significant effects were iteratively
removed depending on the significance and given the hypothesized specifications
of the model. Conditions were iteratively removed depending on whether all
manipulations were non-significant.
Significant conditions were tested using a Wald Test of model fit.
136
Results
Model 1: Risk Perception Model Path Analysis
Five factors and the experimental cyber threat conditions were subjected
to a path analysis. The saturated model was iteratively trimmed of non-significant
factors and yielded a significant model (See Figure 4.5).
Figure 4.5
Psychological Risk Perception Model
In a test of model fit, the Model Chi-Square scaled test statistic was not
significant (χ2(10 degrees of freedom) = 13.83, p = 0.18). The non-significant
model chi-square indicates that the fit between the sample and fitted covariance
matrices is not significantly different, confirming the model's fit.
An omnibus test for the effect of threat conditions on perceived magnitude
of effect of cyber disaster is significant χ2 (3 d.f.) = 37.18 (p<.0001), indicating
that there is a significant difference between at least one of the three threat
conditions and the control condition (Supporting H1b).An omnibus test for the
137
effect of threat conditions on anticipated negative emotional response is
significant χ2 (3 d.f.) = 8.86 (p<.05) indicating that there is a significant
difference between at least one of the three threat conditions and the control
condition (Supporting H1c). Cyber threat conditions did not have a significant
effect on perception of likelihood of cyber disaster, attitude towards cybersecurity
policy, and intention to comply with cybersecurity policy (Rejecting
Support of H1a, H1d, and H1e).
Perceived magnitude of cyber disaster was found to be significantly
correlated with perceived likelihood of cyber disaster. Participants with the cyber
degradation condition (Degrade) were found to be 0.51 (SE = 0.08) points higher
in perceived magnitude of cyber disaster than participants with the control
condition (z value = 5.67, p < 0.001). Each 1-point increase in perception of
likelihood of the control condition is related to a .18 (SE = 0.02) point increase in
perceived magnitude of cyber disaster (z value = 7.54, p < .001) (Supporting
H1f).
Participants with the cyber degradation condition (Disrupt) were -0.22 (SE
= 0.11) points higher in anticipated negative emotional response, than participants
with the control condition (z value = 8.86, p < 0.05). In addition to the threat
conditions and controlling for perception of magnitude, each 1-point increase in
perception of likelihood of the control condition is related to a 0.13 (SE = 0.03)
point increase in anticipated negative emotional response (z value = 3.78, p
< .001) (Supporting H1g). While controlling for perception of likelihood, each 1-
point increase in perception of magnitude is related to a 0.60 (SE = 0.05) point
138
increase in perceived magnitude of cyber disaster (z value = 13.12, p < .001)
(Supporting H1h).
Cyber threat conditions are fully mediated by perceived magnitude of
cyber disaster and anticipated negative emotional response in a path to attitude
towards cybersecurity policy. While controlling for negative emotional response,
each 1-point increase in perceived magnitude of cyber disaster is related to 0.16
(SE = 0.03) points increase in attitude toward organizational cyber policy (z value
= 5.19, p < .001)
(Supporting H1j). While controlling for perceived magnitude of cyber disaster,
each 1point increase in anticipated negative emotional response is related to 0.08
(SE = 0.02) points increase in attitude toward organizational cyber policy (z value
= 3.30, p < .01) (Supporting H1k). Perception of likelihood of cyber disaster and
attitude towards cybersecurity policy did not reveal a significant relationship
(Rejecting Support of H1i).
Finally attitude towards cybersecurity policy had a significant relationship
with intention to comply with cybersecurity policy (Supporting H1m). All other
factors did not reveal a significant relationship with intention to comply with
cybersecurity policy
(Rejecting Support of H1l, H1n, and H1o).
Model 2: Combined Model Path Analysis
Seven factors and the experimental conditions were subjected to a path
analysis, which simultaneously fits the factor measurement model (see Figure
4.6).
139
Figure 4.6
Combined Model Path Analysis
In a test of model fit, the model chi-square scaled test statistic was significant
indicating a possible concern for the fitting of this model. Given the greater
sensitivity of the chisquare test to higher degrees of freedom, other model
indicators were also examined (See
Table 4.3).
Table 4.3
Model Fit Fusion Model Indicators
Model Chi Square
Robust Measures
CFI TLI RMSEA 90% CI RMSEA≤0.05
LL UL
RMSEA≥0.08
χ2(29) = 55.08 p
> .001
0.98 0.97 0.04 [0.02, 0.05] 0.97 0.00
140
In another measure of model fit, dividing the Model Chi-Square and the Model
Degrees of Freedom is 2.12. Both CFI and TLI are within a range that is
acceptable with this model’s CFI revealed to be less than .96 and TLI less
than .95. A RMSEA revealed a good model fit. While there appears to be mixed
support for this model fit, CFI, TFI, and RMSEA support the model fit
hypothesis.
Using an iterative trimming process, main effects and interaction effects
were included in a fully saturated model. Interaction effects between cyber threats
and cyber policy conditions were tested against all factors. Perceived magnitude
of effect of cyber disaster and anticipated negative emotional response were found
to have significant effects in the cyber threat conditions. An omnibus test for the
effect of threat conditions on anticipated negative emotional response is
significant χ2 (3 d.f.) = 8.86 (p<.05) indicating that there is a significant
difference between at least one of the three threat conditions and the control
condition (Supporting H2a). An omnibus test for the effect of threat conditions
on perceived magnitude of effect of cyber disaster is significant χ2 (3
d.f.) = 37.19 (p<.001), indicating that there is a significant difference between at
least one of the three threat conditions and the control condition (Supporting
H2b). Cyber threat conditions were insignificant for the perceived likelihood of
cyber disaster (Rejecting Support of H2c). The non-significant main effects of
the cyber threat condition were trimmed from the model.
The main effects for cyber policy conditions were also tested. An omnibus
test for the effect of policy conditions on organizational cybersecurity
effectiveness to protect individuals is significant χ2 (2 d.f.) = 13.91 (p<.001),
141
indicating that there is a significant difference between at least one of the two
policy conditions and the control condition (Supporting H2d). No main effects
of cyber policy conditions were significant across all other factors (Rejecting
Support of H2e). The non-significant main effects of the cyber policy condition
were trimmed from the model. No interaction effects were significant across all
factors (Rejecting Support of H2fa-e). Non-significant interaction effects were
trimmed, and then the main effects were trimmed, beginning with a saturated
model
(see Appendix F for plots of interactions).
This path analysis begins with the perception of risk. Beginning the path
of perceived magnitude of cyber disaster, participants with the cyber degradation
condition (Degrade) were 0.51 (SE = 0.09) points higher in perceived magnitude
of cyber disaster, than participants with the control condition (z value = 5.68, p <
0.01). Each 1-point increase in perception of likelihood of the control condition is
related to a 0.18 (SE = 0.02) point increase in perceived magnitude of cyber
disaster (z value = 7.54, p < .001) (Supporting H2g).
Following the path of threat appraisal, anticipated negative emotional
response was found to be significantly correlated with perceived magnitude of
cyber disaster and perceived likelihood of cyber disaster. Participants with the
cyber disruption condition (Disrupt) were found to be -0.22 (SE = 0.11) points
higher in anticipated negative emotional response than participants with the
control condition (z value = -1.96, p < 0.05). While controlling for perception of
likelihood, each 1-point increase in perceived magnitude of cyber disaster of the
control condition is related to a .60 (SE = 0.05) point increase in anticipated
142
negative emotional response (z value = 13.12, p < .001) (Supporting H2h).
While controlling for perceived magnitude of cyber disaster, each 1point increase
in perception of likelihood is related to a 0.13 (SE = 0.03) point increase in
participated negative emotional response (z value = 3.78, p < .001) (Supporting
H2i).
In a separate path of coping appraisal, participants with the Multi-factor
Authentication condition (MFA) were 0.19 (SE = 0.05) points higher in
organizational cybersecurity effectiveness (individuals), than participants with the
control condition (z value = 3.48, p < 0.001). Each 1-point increase in
organizational cybersecurity effectiveness (organizations) of the control condition
is related to .64 (SE = 0.03) points increase in organizational cybersecurity
effectiveness (individuals) (z value = 23.78, p <
.001) (Supporting H2j).
Following the factors of threat and coping appraisal, a path to attitude
towards cyber policy is analyzed. Cyber threat conditions are fully mediated by
perceived magnitude of cyber disaster and anticipated negative emotional
response and cyber policy conditions are fully mediated by organizational
cybersecurity effectiveness (individuals) in a path to attitude. While controlling
for all other factors, each 1-point increase in anticipated negative emotional
response is related to 0.07 (SE = 0.02) points increase in attitude toward
organizational cyber policy (z value = 3.45, p < .001) (Supporting H2k).While
controlling for all other factors, each 1-point increase in perceived magnitude of
cyber disaster is related to 0.12 (SE = 0.03) points increase in attitude toward
organizational cyber policy (z value = 4.48, p < .001) (Supporting H2l). While
143
controlling for all other factors, each 1-point increase in perceived likelihood of
cyber disaster is related to 0.04 (SE = 0.02) points increase in attitude toward
organizational cyber policy (z value = 2.45, p < .05) (Supporting H2m). While
controlling for all factors, each 1-point increase in organizational cybersecurity
effectiveness (organizations) is related to 0.11 (SE = 0.03) points increase in
attitude toward organizational cyber policy (z value = 3.30, p < .001)
(Supporting H2n). While controlling for all factors, each 1-point increase in
organizational cybersecurity effectiveness (individuals) is related to 0.35 (SE =
0.04) points increase in attitude toward organizational cyber policy (z value =
9.88, p < .001) (Supporting H2o). Cyber policy conditions are fully mediated by
organizational cybersecurity effectiveness (individuals) and cyber threat
conditions are fully mediated by perceived magnitude of cyber disaster and
anticipated negative emotional response towards attitude toward organizational
cyber policy.
While controlling for organizational cybersecurity effectiveness
(individuals), each 1-point increase in attitude towards organizational
cybersecurity is related to 0.53 (SE = 0.04) points increase in intention to comply
with organizational cybersecurity (z value = 13.52, p < .001) (Supporting H2q).
While controlling for attitude towards organizational cybersecurity, each 1-point
increase in organizational cybersecurity effectiveness (individuals) is related to
0.18 (SE = 0.03) points increase in intention to comply with organizational
cybersecurity (z value = 6.02, p < .001) (Supporting H2r). The non-significant
relationships between anticipated negative emotional response and organizational
cybersecurity effectiveness (organizations) were trimmed from the model
144
(Rejecting Support of H2p and H2s). Negative emotional response, perceived
magnitude of cyber disaster, perceived likelihood of cyber disaster, and
organizational cybersecurity effectiveness (organizations) were fully mediated by
attitude toward cyber security.
Discussion
To explain organizational cybersecurity policy, I present a path model
towards attitude and intention to execute cybersecurity policy. This study
contributes to several academic areas, including cybersecurity, information
security, risk perception, and national cybersecurity policy implementation and
strategy. The larger implications of this study contribute to the application and
implementation of cybersecurity policy in the form of nationwide defense
facilitated through organizational policy. Introducing cyber threats and policies
offers a model that represents the various contexts that an individual in an
organization may encounter.
The approach to modeling national policy implementation that I present in
this study accomplishes several goals. First, I show that both a risk perception
framework and the frameworks of PMT and TOPB can be used to fit models for
organizational cybersecurity, a subset of information security. The findings of this
study contributes to the academic cybersecurity literature by applying TOPB and
PMT, the leading information security policy frameworks (Cram et al., 2017), to
organizational cybersecurity policy. Second, by including perceptions of
cybersecurity efficacy I show that models are greatly improved rather when
compared with only risk perception factors. Mou et al.’s (2022) PMT model
framework of information security was used to couple independent paths of threat
145
and coping appraisals. In explanations of why individuals intent to comply with
cybersecurity policy the results shows that threat and coping appraisals are
exclusive and contrary to expectations do not interact. Third, I focus on attitude,
as it was identified by Bulgurcu et al., (2010) as the focal explanatory factor that
contributes to information security compliance and apply this approach to
cybersecurity. Bulgurcu et al. (2010) approach to the TOPB focused on attitude
and the factors that helped explain attitude in a path towards intention to comply
with information security. In explaining why individuals intend to comply with
cybersecurity policy, attitude towards cybersecurity policy is the most important
factor compared to threat and coping appraisals. Finally, the collective factors of
PMT were shown to have a significant path relationship with attitude and a
mediated relationship with intent.
Model 1: Risk Assessment
While risk perception factors are often used in cybersecurity survey
experiments, I offer a holistic approach to risk perception utilizing three risk
perception factors that collectively contribute to explaining organizational
cybersecurity responses. By incorporating dependent variables of organizational
cybersecurity policy, I diverge from other cyber threat studies by reflecting
organizational outcomes. The dependent variable of intention to comply and
actual compliance behaviors are the focal variables studied in organizational
information security policy (Cram et al., 2017). In these results I highlight a
significant path from risk appraisal to attitude towards cyber policy and attitude
towards intention to comply with cyber policy.
146
Loewenstein et al.’s (2001) psychological risk perception model
framework was used to help explain an assessment of the consequences of this
path toward attitude. Unique to this study, psychological risk perception diverges
from conventional approaches to measuring organizational factors as it is a
societal-level assessment of consequences rather than consequences at an
organizational level. Risk perception as a societal-level measurement was chosen
for several reasons. Strategic efforts, such as efforts outlined by the CSC, call for
private business implementation as a response to larger societal threats. This
study’s combined model ensures organizational attitudes and intentions include a
societal threat context. Also, much of the literature related to cyber threats focuses
on psychological risk perception therefore, psychological risk perception was
chosen as a standard of measurement of cyber threats used by other experts to test
a gap in literature where psychological risk perception and cyber threats can be
correlated with organizational responses.
This first model serves as a baseline for comparison for a possible second
model that includes cybersecurity effectiveness. In a second model I offer the
addition of cybersecurity effectiveness as a system of factors that provide a
second path towards organizational variables. Comparing the models provides
evidence that coping appraisals of efficacy offered more explanation of the
variance than threat appraisals of risk perception (see the explained variance of
attitude of Figure 6 (R2=0.08) and explained variance of attitude of Figure 7
(R2=0.30)).
147
Charting a Path
The aim was to test the relationship between societal risk and
organizational implementation in attitudes and intent. Identifying if relationships
such as risk at a societal level can motivate organizational change through attitude
and intention to comply with cyber policy was found to be present for this path
model. The CSC’s (2020) recommendations to the President and the US Congress
included a whole-of-nation approach to national cybersecurity risk. The results
revealed that the threat appraisal in factors fully mediates cyber operation
conditions towards the attitude towards cybersecurity policy (see bold arrows of
Figure 4.7).
148
Figure 4.7
Full Mediation of Cyber Threat and Cyber Policy Towards Attitude and Intention
In a model that observes anticipated emotions following perceived magnitude of
cyber disaster, anticipated emotions accounted for a negative effect compared to
the control condition of disruption. Additionally, perceived magnitude of cyber
disaster accounted for a significant positive effect compared to the control
condition of degradation. The full mediation of cyber operations through societal
risk perception factors suggest that cyber threats can affect attitudes toward
organizational cybersecurity policy.
This path highlights the limitations of the measurement of a cyber threat
on an outcome variable that bypasses risk perception and intends to measure a
behavioral change. Rid (2013)argues that the limited effectiveness of cyber means
to result in a physically destructive end will limit the ability of cyber attacks,
149
which contrasts with the public the perception of cyber threats as having highly
destructive capabilities. It may be
150