Investigating the Mediating Role of Cybersecurity Awareness in Bridging Cognitive Factors and Secure Behavioural Intentions: A Quantitative Approach Using PLS-SEM

Authors

  • Muhammad Agreindra Helmiawan Informatics, Faculty of Information Technology, Sebelas April University, Indonesia
  • Yanyan Sofiyan Information System, Faculty of Information Technology, Sebelas April University, Indonesia
  • Esa Firmansyah Information and Communication Technology, Asia e University, Malaysia
  • Dody Herdiana Informatics, Faculty of Information Technology, Sebelas April University, Indonesia
  • Irfan Fadil Informatics, Faculty of Information Technology, Sebelas April University, Indonesia
  • Titik Khawa Abdul Rahman Information and Communication Technology, Asia e University, Malaysia

DOI:

https://doi.org/10.52436/1.jutif.2026.7.4.5716

Keywords:

Cybersecurity Awareness, Protection Motivation Theory, Response Efficacy, Secure Behavioral Intentions, Self-Efficacy

Abstract

Cybersecurity threats have become increasingly sophisticated, rendering the human element a critical vulnerability despite advanced technical safeguards. This study investigates the cognitive drivers of cybersecurity awareness and secure behaviour through the lens of Protection Motivation Theory (PMT), specifically examining the mediating role of Cybersecurity Awareness (CA). A quantitative approach using Partial Least Squares Structural Equation Modelling (PLS-SEM) was employed to analyse data from students and faculty members in a higher education setting. The findings substantiate that Self-Efficacy (β=0.412,p<0.05) and Response Efficacy (β=0.385,p<0.05) are significant predictors of CA, with the model achieving a robust R2 value of 0.703. Crucially, the mediation analysis identifies CA as a vital cognitive bridge that translates internal confidence into Secure Behavioural Intentions. These results offer an integrated framework for developing targeted intervention strategies in academic institutions. For the field of Informatics, this research underscores the urgency of designing human-centric security systems that prioritize psychological empowerment to foster sustainable digital resilience against an evolving threat landscape.

Downloads

Download data is not yet available.

References

E. Pasipamire, “Building a Culture of Cybersecurity Awareness in Libraries: A Systematic Review of Best Practices and Frameworks,” European Conference on Information Warfare and Security Eccws, pp. 510–519, 2025, doi: 10.34190/eccws.24.1.3608.

R. A. Alsharida, “A systematic review of multi perspectives on human cybersecurity behavior,” Technol. Soc., vol. 73, 2023, doi: 10.1016/j.techsoc.2023.102258.

N. Veerasamy, “PROTECTION MOTIVATION THEORY (PMT) AS A DRIVING FORCE FOR CYBERSECURITY AWARENESS,” Proceedings of the International Conferences on Digital Transformation and Innovation Management 2025 and ICT Society and Human Beings 2025 Part of the Multi Conference on Computer Science and Information Systems 2025, pp. 162–169, 2025, [Online]. Available: https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105022059728&origin=inward

N. S. Sulaiman, “Cybersecurity practices among Malaysian government employees: the role of protection motivation theory and responsibility norms,” Asian Education and Development Studies, pp. 1–23, 2025, doi: 10.1108/AEDS-07-2024-0148.

A. Jayatilaka et al., “Evaluation of Security Training and Awareness Programs: Review of Current Practices and Guideline,” arXiv (Cornell University), Apr. 2021, doi: 10.48550/arxiv.2112.06356.

B. Uchendu, J. R. C. Nurse, M. Bada, and S. Furnell, “Developing a cyber security culture: Current practices and future needs,” Comput. Secur., vol. 109, p. 102387, Apr. 2021, doi: 10.1016/j.cose.2021.102387.

N. F. Khan, “Evaluating protection motivation based cybersecurity awareness training on Kirkpatrick’s Model,” Comput. Secur., vol. 125, 2023, doi: 10.1016/j.cose.2022.103049.

T. Tam, “Counting the Cyber-security Awareness-Action Gap from Australasian Small Business’s Perspectives,” Annual Review of Cybertherapy and Telemedicine, vol. 23, pp. 289–294, 2025, [Online]. Available: https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105023886451&origin=inward

S. Haag, M. Siponen, and F. Liu, “Protection Motivation Theory in Information Systems Security Research,” 2021, doi: 10.1145/3462766.3462770.

H. Chen, O. Turel, and Y. Yuan, “E-waste information security protection motivation: the role of optimism bias,” 2021, doi: 10.1108/ITP-09-2019-0458.

P. Bayl-Smith, “Response to a phishing attack: persuasion and protection motivation in an organizational context,” Information and Computer Security, vol. 30, no. 1, pp. 63–78, 2022, doi: 10.1108/ICS-02-2021-0021.

N. S. Sulaiman, “Cybersecurity Behavior among Government Employees: The Role of Protection Motivation Theory and Responsibility in Mitigating Cyberattacks,” Information Switzerland, vol. 13, no. 9, 2022, doi: 10.3390/info13090413.

J. Kowal, “Towards the Model of Internal Motivation and Organizational Cyber Threats,” Americas Conference on Information Systems Amcis 2025, vol. 1, pp. 401–410, 2025, [Online]. Available: https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105025425718&origin=inward

M. A. Helmiawan, E. Firmansyah, D. Herdiana, Y. H. Akbar, A. Subiyakto, and T. K. A. Rahman, “Quantitative Analysis of the Key Factors Driving Cybersecurity Awareness Among Information Systems Users,” Jurnal Teknik Informatika (Jutif), vol. 6, no. 4, pp. 1897–1910, Aug. 2025, doi: 10.52436/1.jutif.2025.6.4.4861.

Z. Ghaderi, “Exploring Cybersecurity Threats to Solo Female Travelers,” J. Travel Res., 2025, doi: 10.1177/00472875251361466.

M. Owen, “Optimism bias in susceptibility to phishing attacks: an empirical study,” Information and Computer Security, vol. 32, no. 5, pp. 656–675, 2024, doi: 10.1108/ICS-02-2023-0023.

S. Alsulami, “The Effectiveness of Education and Fear Appeal to Prevent Spear Phishing Attacks,” 2024 Cyber Awareness and Research Symposium Cars 2024, 2024, doi: 10.1109/CARS61786.2024.10778693.

T. Zulhelmi, V. S. Asih, and M. A. Helmiawan, “Analysis of the Application of Blockchain and Artificial Intelligence to Overcome Accounting Fraud in Islamic Banking,” Indonesian Journal of Economics and Management, vol. 4, no. 1, pp. 184–193, 2023.

M. A. Helmiawan, I. Fadil, Y. Sofiyan, and E. Firmansyah, “Security model using intrusion detection system on cloud computing security management,” 2021 9th International Conference on Cyber and IT Service Management (CITSM …, 2021.

M. A. Helmiawan, E. Julian, Y. Cahyan, and A. Saeppani, “Experimental evaluation of security monitoring and notification on network intrusion detection system for server security,” 2021 9th International Conference on Cyber and IT Service Management (CITSM …, 2021.

M. R. M. A. H. Alneyadi, “FACTORS INFLUENCING USER’S INTENTION TO ADOPT AI-BASED CYBERSECURITY SYSTEMS IN THE UAE,” Interdisciplinary Journal of Information Knowledge and Management, vol. 18, pp. 459–486, 2023, doi: 10.28945/5166.

R. R. Gopireddy, “Human-Centric Cybersecurity: Addressing the Human Element in Cyber Defense and Ethical Considerations in Cybersecurity,” Journal of Artificial Intelligence & Cloud Computing, vol. 1, no. 4, pp. 1–5, Apr. 2022, doi: 10.47363/jaicc/2022(1)e118.

F. Jimmy, “Emerging threats: The latest cybersecurity risks and the role of artificial intelligence in enhancing cybersecurity defenses,” Valley International Journal Digital Library, 2021, [Online]. Available: https://pdfs.semanticscholar.org/ee4c/c97d11f7c827fc1a8a059e584d739ad87cf8.pdf

G. S. Nadella and H. Gonaygunta, “Enhancing Cybersecurity with Artificial Intelligence: Predictive Techniques and Challenges in the Age of IoT,” International Journal of Science and …, 2024, [Online]. Available: https://ijsea.com/archive/volume13/issue4/IJSEA13041007.pdf

N. F. Khan, N. Ikram, H. Murtaza, and M. A. Asadi, “Social media users and cybersecurity awareness: predicting self-disclosure using a hybrid artificial intelligence approach,” Kybernetes, 2023, doi: 10.1108/K-05-2021-0377.

A. A. Bouramdane, “Cyberattacks in smart grids: challenges and solving the multi-criteria decision-making for cybersecurity options, including ones that incorporate artificial …,” Journal of Cybersecurity and Privacy, 2023, [Online]. Available: https://www.mdpi.com/2624-800X/3/4/31

L. Li, “The effects of antecedents and mediating factors on cybersecurity protection behavior,” Computers in Human Behavior Reports, vol. 5, 2022, doi: 10.1016/j.chbr.2021.100165.

N. Humaidi, “Procedural Information Security Countermeasure Awareness and Cybersecurity Protection Motivation in Enhancing Employee’s Cybersecurity Protective Behaviour,” 10th International Symposium on Digital Forensics and Security Isdfs 2022, 2022, doi: 10.1109/ISDFS55398.2022.9800834.

A. Alshammari, “The Influences of Employees’ Emotions on Their Cyber Security Protection Motivation Behaviour: A Theoretical Framework,” International Conference on Enterprise Information Systems Iceis Proceedings, vol. 2, pp. 524–531, 2024, doi: 10.5220/0012681600003690.

O. Pratama, “Determinants of Security Behavior Intention in State-Owned Enterprises: Applying Protection Motivation Theory to Phishing Emails,” International Journal of Safety and Security Engineering, vol. 15, no. 3, pp. 443–453, 2025, doi: 10.18280/ijsse.150304.

M. A. Helmiawan, D. Herdiana, E. Firmansyah, A. I. N. Sholihah, S. W. Putri, and S. Septiana, “Cybersecurity Awareness and its Impact on the Association Between Technology Use and Adolescent Mental Health,” in 2025 13th International Conference on Cyber and IT Service Management (CITSM), IEEE, Sep. 2025, pp. 1–6. doi: 10.1109/CITSM67730.2025.11291394.

T. S. Rachmayanti, “Understanding What Motivates Students to Use Digital Platforms for Cybersecurity Learning and Awareness: A Conceptual Model,” 2024 International Conference on Information Technology Systems and Innovation Icitsi 2024 Proceedings, pp. 517–522, 2024, doi: 10.1109/ICITSI65188.2024.10929266.

D. V Tran, “From awareness to behaviour: understanding cybersecurity compliance in Vietnam,” International Journal of Organizational Analysis, vol. 33, no. 1, pp. 209–229, 2025, doi: 10.1108/IJOA-12-2023-4147.

N. Humaidi, “Procedural Information Security Countermeasure Awareness and Cybersecurity Protection Motivation in Enhancing Employee’s Cybersecurity Protective Behaviour,” 10th International Symposium on Digital Forensics and Security Isdfs 2022, 2022, doi: 10.1109/ISDFS55398.2022.9800834.

L. W. Wong, “The role of cybersecurity and policy awareness in shifting employee compliance attitudes: Building supply chain capabilities,” Int. J. Inf. Manage., vol. 66, 2022, doi: 10.1016/j.ijinfomgt.2022.102520.

S. Alsulami, “The Effectiveness of Education and Fear Appeal to Prevent Spear Phishing Attacks,” 2024 Cyber Awareness and Research Symposium Cars 2024, 2024, doi: 10.1109/CARS61786.2024.10778693.

Y. Alhelaly, “When expectation fails and motivation prevails: the mediating role of awareness in bridging the expectancy-capability gap in mobile identity protection,” Comput. Secur., vol. 134, 2023, doi: 10.1016/j.cose.2023.103470.

E. T. Al-Shammari, “Integrating Protection Motivation Theory With Cultural Context: A Framework for Cybersecurity Education,” Journal of Cases on Information Technology, vol. 27, no. 1, 2025, doi: 10.4018/JCIT.368146.

Additional Files

Published

2026-08-18

How to Cite

[1]
M. A. Helmiawan, Y. Sofiyan, E. Firmansyah, D. Herdiana, I. Fadil, and T. K. A. Rahman, “Investigating the Mediating Role of Cybersecurity Awareness in Bridging Cognitive Factors and Secure Behavioural Intentions: A Quantitative Approach Using PLS-SEM”, J. Tek. Inform. (JUTIF), vol. 7, no. 4, pp. 3816–3825, Aug. 2026.