Thesis
The disconnect between cyber knowledge and cyber behaviour by Malaysian youngsters
- Creator
- Rights statement
- Awarding institution
- University of Strathclyde
- Date of award
- 2026
- Thesis identifier
- T18046
- Person Identifier (Local)
- 201980544
- Qualification Level
- Qualification Name
- Department, School or Faculty
- Abstract
- The pervasive and escalating threat landscape in cyberspace has underscored the critical role of human factors as the most significant vulnerability in cybersecurity defences. While technical solutions advance, a persistent gap between cybersecurity knowledge and protective behaviours remains a central challenge, particularly among digitally native but often overconfident youngsters. This research addresses a critical lacuna in the literature by moving beyond a generalised view of cybersecurity awareness to investigate how specific domains of knowledge and behavioural components interact to influence the cyber hygiene of young adults in Malaysia, a nation with one of the highest cybercrime rates in Southeast Asia. A sequential, multimethod design was employed. First, a large-scale survey (N=765) assessed five distinct domains of cybersecurity knowledge: password, software/system, human, organisational, and social security; and their relationship with behavioural determinants framed by the Theory of Planned Behaviour (TPB): attitudes, subjective norms, and perceived behavioural control. This quantitative phase was followed by a controlled phishing simulation experiment, where a stratified random sample of survey participants was targeted by one of three ethically-designed phishing emails. This innovative design allowed for a critical comparison between participants' perceived security intentions (measured in the survey) and their actual behavioural responses (observed in the simulation). The findings reveal a critical paradox. While survey results indicated a moderately positive self-assessment of cybersecurity knowledge and strong behavioural intentions, the phishing simulation demonstrated a significant vulnerability, with a substantial portion of participants succumbing to the attacks. Quantitative analysis identified that knowledge domains related to human security (e.g., recognising suspicious emails and websites) and organisational security were the most significant predictors of secure behavioural intentions. However, the experimental phase crucially demonstrated that these intentions did not reliably translate into behaviour. Furthermore, demographic analysis revealed that educational level, rather than age or gender, was the most significant moderator, with higher education correlating with both greater knowledge and, paradoxically, in some cases, a higher susceptibility to certain types of phishing attempts in real-world contexts, suggesting potential overconfidence among more educated individuals. It is important to note that the phishing simulations used in this study were designed to be recognisable to vigilant users; the finding regarding education and susceptibility is discussed as a potential trend requiring further investigation rather than a definitive conclusion based solely on the simulation results. The thesis makes three primary contributions. First, it provides empirical evidence for a domain-specific understanding of cybersecurity knowledge, moving the field beyond monolithic constructs. Second, it critically demonstrates the stark discrepancy between perceived and actual cybersecurity behaviour within a youngster cohort, challenging the efficacy of awareness measures that rely solely on self-reporting. Third, it validates the application of the TPB in a cybersecurity context while highlighting its limitations in predicting actual behaviour without observational data. The study concludes that effective cybersecurity interventions for youngsters must not only disseminate knowledge but also actively address the behavioural biases and overconfidence that contribute to the knowledge-behaviour gap, recommending a shift towards experiential, simulation-based training integrated into educational curricula. This research offers a robust methodological framework and substantive findings for policymakers, educators, and security professionals aiming to build a more resilient digital society.
- Advisor / supervisor
- Renaud, Karen
- Resource Type
- DOI
- Funder
Relations
Items
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
PDF of thesis T18046 | 2026-09-18 | Public | Download |