Psyche Components in the Organization of Safety Systems: The Role of a Person in the Protection of Facilities and Information Resources: A Systematic Review

Maryna Dub1ORCiD, Nataliia Rebenok2 ORCiD, Oleksii Poliakov3 ORCiD, Artur Maziashvili4 ORCiD and Bohdan Morklyanyk5 ORCiD
1. Doctor of Pedagogical Sciences, Professor, Head of the Department of Psychology, Pedagogy and Social Work, Faculty of Humanities and Economics, Augustyn Voloshyn Carpathian University, Uzhhorod, Ukraine
2. Candidate of Juridical Sciences (PhD), Associate Professor of the Department of Psychology, Educational and Scientific Institute of Law and Psychology, National Academy of Internal Affairs, Kyiv, Ukraine Research Organization Registry (ROR)
3. Postgraduate Student, Teacher of the Department of Law Enforcement and Anti-corruption Activities, Educational and Scientific Institute of Law named after Prince Vladimir the Great, PJSC “Higher Educational Institution “Interregional Academy of Personnel Management”, Kyiv, Ukraine Research Organization Registry (ROR)
4. Postgraduate Student of the Department of “Economics and Management of Industrial and Commercial Business” / Assistant of the Department of Transport Communication, Faculty of Economics, Ukrainian State University of Railway Transport, Kharkiv, Ukraine
5. Professor of the Department of Information Technology, Military Academy, Kyiv, Ukraine
Correspondence to: Maryna Dub, marina.dub@ukr.net

Premier Journal of Science

Additional information

  • Ethical approval: N/a
  • Consent: N/a
  • Funding: No industry funding
  • Conflicts of interest: N/a
  • Author contribution: Maryna Dub, Nataliia Rebenok, Oleksii Poliakov, Artur Maziashvili and Bohdan Morklyanyk – Conceptualization, Writing – original draft, review and editing
  • Guarantor: Maryna Dub
  • Provenance and peer-review:
    Unsolicited and externally peer-reviewed
  • Data availability statement: N/a

Keywords: Human factors in cybersecurity, Emotional risk perception, Digital stress and information overload, Psychological resilience development, AI-enabled security management.

Peer Review
Received: 29 July 2025
Last revised: 18 September 2025
Accepted: 19 September 2025
Version accepted: 5
Published: 7 October 2025

Plain Language Summary Infographic
"Infographic on the role of psychological factors in security systems. Highlights emotions, social dynamics, resilience, and challenges like digital stress and cyberbullying, and offers strategies to integrate human psychology into data and facility protection."
Abstract

Background: The psychological background of security management is a multifaceted concept that integrates diverse strategies of interaction and responses to modern societal challenges. In an increasingly digital and complex world, individuals and organizations face various psychological and emotional factors that impact the perception of risk and the effectiveness of protective measures. Issues such as digital stress, cyberbullying, information manipulation, and data leakage demand deeper exploration from a psychological perspective. This study aims to explore the psychological mechanisms that influence the perception of threats and the formation of effective behavioral responses to ensure the protection of data and physical assets. The research particularly focuses on the role of emotions, social factors, and individual resilience in the context of security management.

Materials and Methods: The research methodology is based on a qualitative synthesis, incorporating analysis, comparison, systematization, generalization, and abstraction. These methods are applied to examine how emotional states and social contexts affect human behavior in response to potential security threats.

Results: The study substantiates that emotions significantly influence risk perception and behavioral strategies. It also emphasizes the role of social factors—values, stereotypes, norms, communication, and social support—in shaping security behavior. The analysis identifies current challenges, including digital stress, cyber addiction, and data breaches.

Conclusion: The findings highlight the importance of integrating psychological insights into security management strategies. Enhancing psychological resilience through healthy routines, time management, and social competence can significantly improve individual and organizational responses to security threats and contribute to more adaptive, robust protection systems.

Highlights

  • The document emphasizes that emotional states strongly affect how individuals assess and respond to cyber threats. Fear, stress, or panic can either heighten awareness or impair judgment, leading to risky behavior. Understanding these emotional influences is vital for designing effective security training and decision-making protocols.
  • Security breaches often stem from human factors such as poor password management, ignoring security warnings, or social media oversharing. Insider threats and negligence, such as avoiding multi-factor authentication or clicking on phishing links, are common. Thus, psychological training, awareness campaigns, and resilience development are essential components of cybersecurity.
  • The study promotes integrating AI (Artificial intelligence) tools, cloud technologies, digital communication systems, and Agile corporate principles to reduce the impact of human error. For example, AI-driven monitoring, password management via OAuth, and chatbots for training help automate and secure internal processes while maintaining employee adaptability.

Introduction

Psychological aspects of security processes form a multifaceted basis for an overall data and object protection strategy that combines various challenges and ways of interacting in today’s society. Increasing risks of cyber threats and leakage of confidential information, dynamics of psychological needs of modern people, large-scale information manipulation in the media space necessitates an upgrade of approaches to security guarantees, within which the human factor is given due attention. The consequences of cyberattacks usually exceed all predicted losses. The websites of government agencies that handle large volumes of data suffer the most. The financial sector, as well as the media, IT companies, and energy companies, are also subject to significant attacks.

In particular, it is worth mentioning the case when Russian hackers sent dangerous emails from a fake addressee (Amazon, Microsoft) to integrate their own malware into Ukrainian state and military databases. At the same time, the scale of the damage is quite difficult to assess. In 2023, Ukrainian mobile operator Kyivstar suffered a large-scale failure due to cyberattacks, estimated at billions of hryvnias. 40% of the company’s infrastructure was destroyed, including a number of servers and data, which caused a network failure.1 Another example of Russian cybercrime is the phishing attacks on German political parties. The hackers hid ransomware in a fake dinner invitation from the Christian Democratic Union of Germany in order to install a ‘backdoor’ on their victim’s computer.2

Active information and communication progress, social dynamics, global crisis challenges, and environmental threats have caused the emergence of new and complicated existing risks, which requires for deeper awareness their psychological basis, improvement of psychological strategies for maintaining stability, resilience of the individual and his active role in modern security strategies of interaction. These strategies relate both to individuals and to authorized bodies and institutions, as well as social communities within which a culture of security is developing. The issue has received considerable attention from researchers in an interdisciplinary context. The authors analyse the dynamics of the conditions for the development of an individual’s resilience to social dynamics and new threats, and study the possibilities of psychological resilience strategies.3,4,5 A number of researchers study innovative ways to protect data and objects in the digital environment.6,7 Integrating the concept of psychological wellbeing in the broader context of security strategies would allow improving existing concepts for protecting objects and data, minimizing human factor risks in security management, and ensuring readiness for new challenges of cyber threats and geopolitical dynamics.

Literature Review

The researched issues are within the scope of scientific interests of a number of modern scientists. In particular, Khando et al.,8 Chmyr et al.9 analyse the prospects for the formation of security management strategies based on the qualitative digital transformation of protection processes, outline the relationship between digitalization and human resource management. A number of publications are devoted to a systematic review of innovative experience in the field of cybersecurity.10,11,12 Researchers focus scientific research on determining the advantages of artificial intelligence tools in the field of security, determining the psychological strengths of an individual as a driving force for the development of the security potential of companies. In continuation, the publications of Culot et al.,13 Davis et al.14 highlight innovative aspects of strategic management in the field of security, including the development of digital inclusion. Li et al.,15 Curran,16 position IT technologies as key guarantors of data security in the conditions of ­increased cyber risks and uncertainty. The authors determine the digital foundation as the basis of security strategies, which creates the need to increase the ­digital competence of company personnel, develop employee resilience to the dynamics of the security environment, information digitization skills, and use cloud technologies and blockchain.

Dhillon et al.17 conduct a review in the field of information systems security, emphasizing the importance of preventive solutions for training company personnel and increasing their awareness in the field of data security. In continuation, Dovgy et al.18 determine the specifics of the impact of the “crisis of legitimacy” on security and stability in the context of the development and integration of global information space. A number of scholars analyse the diverse aspects of information security as a key component of security strategies at the current stage of development.19,20 Particular attention is paid to the capabilities of artificial intelligence in the aspect of risk management. The number of publications in the field of the researched issues confirms the relevance of scientific research on the psychological basis of security strategies. However, there are a number of gaps, the filling of which will allow a more complete understanding of the nature of the influence of psychological processes on the formation of security strategies in current development conditions. The main research questions of this study are to identify the contemporary contexts of the psychological foundations of security processes and to examine them in light of the specific features of modern organizational structures. The purpose of the study is an in-depth analysis of the main psychological aspects of security management in the context of modern challenges regarding data and object protection.

Materials and Methods

Research Design and Scope

The study is a systematic review. The study focuses on the specifics of the human factor influence on ensuring the effectiveness of security strategies in the conditions of the dynamics of the information environment. Considerable attention is paid to the potential for resilience and psychological adaptation, as well as the possibilities of managing them. Key recommendations for systematic reviews (PRISMA 202021) were used.

Data Collection and Sources

The study primarily implemented a systematic and comprehensive analysis of scientific publications, scientific papers and major global security trends based on industry statistical information. The analysis approach involved thematic coding. The keywords “security, security management, psychological aspects, resilience, cyber threats, privacy, protective strategies” were applied for search. Given the practical realities, the sample size was considered appropriate, providing sufficient scientific and statistical power. To reduce internal bias in the publications used for this study, a strategy of open access and data reuse was applied. This involved providing access to the full study data, including raw data and code, which made it possible to verify the results and conduct additional analysis if necessary, thereby reducing the impact of bias.

Systematic Review Protocol

A) Search Databases: The main materials for the study were selected industry publications indexed in leading ­scientific databases (Web of Science, Scopus), as well as ­statistics from official sources. The sample period is 2019–2025.

B) Full Search Series: For effective information retrieval during the study, search engines such as Google Scholar were used. Queries were formulated by selecting relevant keywords, and clarifying questions or commands were used to narrow down the search results. For a more in-depth analysis, results from various sources were reviewed, paying attention to the quality of the information. Search strings are phrases that were entered into search engines (Google Scholar) to find scientific information and research results. An effective search query for research involved identifying keywords: basic terms related to the research topic; synonyms and related terms to cover a wider range of sources; specific terms (names of methods, authors, terms, etc.). The keywords for the search were “security, security management, psychological aspects, resilience, cyber threats, privacy,” as well as related and synonymous terms. The date of the last search was July 2025. The number of records obtained in the databases was: Web of Science – 15, Scopus – 23.

C) Inclusion/exclusion Criteria: The criteria for inclusion and exclusion of publications were spatial and temporal indicators and the level of reliability of information. The criteria for assessing the quality of sources were the relevance and objectivity of the publication, the completeness of the topic coverage, and the authoritativeness.

D) Screening Flowchart: The general screening flowchart can be presented as follow (Figure 1).

Fig 1 | General screening flowchart
Source: Author’s development
Figure 1: General screening flowchart.
Source: Author’s development.

E) Critical evaluation tools and results: Critical evaluation tools included methods for verifying accuracy, analyzing sources, assessing relevance, and research methods. Internet search rules were applied, as well as analysis of the text for emotional words and manipulative headlines. An analysis of information sources was conducted: the authority and reliability of the source were assessed; attention was paid to the relevance of the information: whether it was still relevant. In addition, research methods were evaluated, which involved a critical approach to the methods used to obtain the information. Aspects of critical evaluation of research included verification of: relevance, novelty, and significance of the problem; compliance of the chosen methodology with the goals and objectives of the study; reliability and validity of results; logical soundness of conclusions and compliance with scientific standards, as well as potential implementation in practice.

F) The data extraction system included:

  • data collection, preliminary processing: ­sentences and words are selected, normalization and stop word removal are performed;
  • selection of entities that are significant in the ­context of the study;
  • extraction of relationships between selected entities;
  • structuring of information.

The quality assessment of the included studies involved checking their methodological rigor and reliability to understand how reliable the conclusions of these studies are for the future review. The Mixed Methods Assessment Tool (MMAT) was used—a validated tool for assessing the quality of studies included in a systematic review, which provides criteria and screening questions for assessing methodology and determining an overall quality score. The Mixed Methods Assessment Tool (MMAT) is designed to assess quantitative, qualitative, and mixed methods studies. A standardized and independent review was also used. The screening process involves double-blind peer review by two independent reviewers, whose names are not disclosed to the authors. In addition, the names of the authors of the manuscript are concealed from the reviewers. Reviewers evaluate the quality of the manuscript, its research methodology, rationale and conclusions, level of academic writing, and style. In addition, they are able to identify unethical behavior or plagiarism.

Comprehensive and reliable research of reliable data provided the basis for logical and correct synthesis. The results of the quality assessment were included in the conclusions of the systematic review, explaining how the quality of the research could affect the results of the review and the assessment of the effect. The quality of the research influenced the synthesis in the following aspects:

  1. accuracy and completeness of data (ensuring the accuracy and completeness of data, which is a necessary basis for correct synthesis);
  2. objectivity (to avoid subjective interpretation of results, as qualitative research provides unbiased data, allowing for the synthesis of a realistic picture of reality);
  3. verification of results (good research provides for the possibility of verification of the results obtained by other researchers. This ensures that the data collected is reliable and that the synthesis based on it will be reliable);
  4. structuring of knowledge (qualitative research reveals connections and patterns between facts, reflecting the essence of the phenomenon under study);
  5. absence of distortions (if the research is of poor quality, it may contain distortions caused by subjective factors, inappropriate methods, or errors in data processing, and therefore the synthesis will be incorrect).

Conflict of interest in the scientific research process is prevented by avoiding situations where a scientist has personal, financial, or other interests that may influence their professional activities, in particular the conduct and results of research. The process of removing duplicate studies involved identifying duplicate records using queries and then deleting them. Steps for removing duplicates: defining uniqueness criteria (study title, DOI, author), searching for duplicates (writing an SQL query), and deleting them. Overall, the study selection methodology was consistent with the general PRISMA21 diagram (Figure 2).

Fig 2 | PRISMA block diagram used in the study
Figure 2: PRISMA block diagram used in the study.
Limitations

The limitations of the study are due to the difficulty of experimentally verifying theoretical conclusions. In order to reduce the impact of bias and obtain more objective and reliable results, bias minimization methods were applied, including: strengthening transparency (providing complete information on the research methodology and data analysis process with the possibility of replicating the results); limiting the influence of cognitive biases; adherence to ethical considerations; use of automated data analysis tools to reduce the influence of researcher subjectivity on the analysis process. The review protocol was not registered prospectively, which is also considered a limitation of the study.

Language Restrictions gave Preference to English-language Publications

Assessment of the quality of included studies: verification of methodology, reliability, and compliance with established standards to ensure the validity of results; analysis of criteria for compliance with study design, implementation, validity of conclusions, and potential sources of bias. In order to reduce the impact of bias and obtain more objective and reliable results, methods to minimize bias were applied, including: enhancing transparency (providing complete information about the research methodology and data analysis process with the possibility of replicating the results); limiting the influence of cognitive biases; adherence to ethical considerations; use of automated data analysis tools to reduce the influence of researcher subjectivity on the analysis process. A categorical matrix was used as a methodological tool to reflect the logical and substantive connection between the object and subject of the study, harmonizing theoretical and practical aspects. It provided for five phases of implementation: studying and compiling cases for the program in order to develop engagement, combining practice with theory; measurement (conducting surveys that highlight any problem areas regarding behavior that creates psychological safety); building (key interventions and actions that create further momentum and improvement); support (practice and formation of behavioral habits); reflection (self-reflection and retrospection).

Analytical Basis and Methods

The research methodology is formed by a number of general scientific methods, in particular, analysis and synthesis, comparison, systematization, generalization, and abstraction. These methods allowed tracing the cause-and-effect relationships between the influence of individual psychological factors and the level of effectiveness of object and data protection strategies, determining the main criteria and definitions, identifying the most influential factors in the resilience and stability of security strategies. Additionally, with the help of scientific abstraction, the conceptual basis of security management mechanisms and strategies against the background of innovative threats was detailed. The study was conducted in accordance with ethical standards for research of this category. Institutional review is not required for any data presented.

Results

The processes of risk perception and awareness are seen a significant component of the security management psychology. They include individual’ understanding of potential risks and dangerous situations in order to timely identify the hazard, assess its likely consequences, and promptly make informed decisions to minimize, eliminate, or prevent safety threats. Psychological characteristics of a certain personality play an important role in the process of forming attitudes towards danger and behavioral responses in such situations. An individual develops under the active influence of the external environment, and deficiencies in the psychological development of a personality can directly manifest themselves in stressful situations.22 Inability to quickly allocate attention and isolate priority object or action, inadequate perception of risk, emotional imbalance, and underdeveloped endurance significantly increase security risks. At the same time, attentiveness, coordination, and emotional balance allow one to better cope with extreme situations and manage risks if necessary.23 Mental states significantly influence behavior in threatening situations, facilitating or hindering task solving (in particular, anxiety increases sensitivity to danger, as opposed to fatigue). Often, an increased security threat is caused by a special mental states, in particular, panic. In this case, concentration decreases, and the emotional background increases.

In addition, the psychological states of large groups of people have a significant impact on the security macroenvironment. In the context of psychological aspects of security management, a crowd is of great importance—an unstructured accumulation of people connected by a common object of attention and similar emotional states. Under such conditions, a favorable environment is formed for the development of mass and individual panic reactions, which poses a direct threat to the protection of data and objects. Human risks are mainly concentrated at the IT security edge, at the interface of cybercriminals and in the company’s private network. The main human factors of cybersecurity include: shady IT practices (connecting to corporate networks and devices without prior approval from the IT department); accidental data sharing or leakage; neglecting multi-factor authentication; ignoring security warnings; delaying software updates; neglecting secure communication protocols; inadvertently disclosing information on social media; insider threats (when an employee abuses his internal credentials to access confidential internal information).24

It is also worth noting that cybersecurity factors need to be taken into account in the psychological aspect of the security management strategy, including the development of risk awareness among company personnel through targeted training and coaching. In the psychology of security management, emotions play an important role. Namely emotions have the maximum influence on human assessment, perception, and response to danger and potentially risky situations. In particular, positive emotions can contribute to underestimation of risks, while at the same time negative emotions can lead to their exaggeration. Awareness of the emotions influence on the perception of risks enables guaranteeing a more objective assessment of potential hazards.25 In addition to influencing the perception of dangers and risks, emotions have a significant impact on human behavior in situations of increased risk. For example, the emotion of fear can stimulate caution and avoidance of danger, while its absence can cause more risky behavior. Namely the awareness of aspects of the emotions influence on human behavior forms the basis for the development of effective security strategies. Emotions, especially stress, can cause significant psychological and physiological changes that affect the ability to adequately respond to security threats. Stress reactions provoke dynamics in the level of concentration and attention, speed of response, determining the ability to promptly make informed decisions regarding security.

Among the main aspects of the social context that determine security processes, there are the direct influence of others, the perception of security in public space depending on the social context, and the presence of social support. Awareness of social influence allows one to gain greater autonomy and justification in own actions, while maintaining the necessary level of security.4 Some examples can be found, in particular, in the empirical studies by van der Kleij26 who, in close collaboration with the three financial institutions involved, developed a critical thinking algorithm that corresponds to typical stages of the incident response process, adding the necessary elements to the generally accepted strategy of critical information assessment skills. The concept proposed by the authors demonstrated the potential for a more complete understanding of the operational consequences of incidents and potential threats. To conduct an in-depth analysis of the cognitive elements of cybersecurity threat and incident managers’ (CTIMs) work, the authors use cognitive task analysis (CTA) and cognitive work analysis (CWA).

Another important aspect of the psychological foundation of security management is handling of ­passwords and restricting access to confidential information, as well as information filtering and differentiation skills. The ability to separate reliable information from unreliable one, to check the reliability of its sources of origin, being aware of the context allows maintaining emotional comfort and preventing the spread of fake or manipulative information. An example is the development of Hatzivasilis,27 which offers practical measures of password management and implementing a secure login process. Researchers conducted an empirical study of password usage habits in an IT company, ­military school, two accounting offices and universities in the province of Crete in Greece. Empirical research has shown that today the average user has about 50–70 accounts. Since most people are not aware of the large amount of information they own, they use simple and convenient ways of administration.

The vast majority (98%) ignore password management software solutions and do not use them. In addition, users do not update their passwords regularly. In addition, Hatzivasilis27 also emphasizes that mobile application security is a problem not only for individual users. Bring Your Own Device (BYOD) is an IT policy that allows employees to use their own personal mobile devices in the workplace. Organizations support this action because BYOD increases staff productivity and reduces equipment investments. However, BYOD often leads to data leakage. The author proposes an optimized password management policy that governs the creation, storage, processing, and transmission of passwords. Specifically, he offers a solution based on OAuth 2.0, – an open IETF (Internet Engineering Task Force) standard for authentication, which allows users to sign in to applications using existing accounts from trusted third parties such as Google, Facebook, Microsoft, and Yahoo. A web or mobile application uses the provider’s OAuth API (Application Programming Interface) to implement a sign-in service. OAuth can enhance security and engage targeted users if used properly. Small businesses that cannot invest a significant amount of their budgets in security can use OAuth services.

Employees are increasingly ignoring important notifications and resorting to risky actions, such as clicking on phishing emails or ignoring multi-factor authentication (MFA) prompts. This situation is exacerbated by frequent interruptions due to notifications and messages across different platforms.28 Cyberbullying is becoming a growing threat to both individuals and organizations. Cyberbullying can lead to data breaches and other security incidents. Phishing attacks, in particular, often use social engineering to put their victims in an emotional state. Technological dependence refers to the compulsive and excessive use of digital devices and online platforms, which leads to negative consequences for a person’s physical, psychological, and social wellbeing, but also to a decrease in attention to following all necessary cybersecurity procedures. Also, influence on an individual can be exerted through knowledge (manipulation of information) and through feelings (manipulation of emotions) and FOMO (Fear of Missing Out) effect. It is necessary to emphasize the need for digital optimization of the internal management of companies on security and human resources issues. This allows reducing the risks of the human factor and automating some processes. The general algorithm of digital optimization of the data and object security management system is given in Figure 3.

Fig 3 | Possibilities of digital optimization of the system of managing human factor in data and object protection
Source: Author’s development
Figure 3: Possibilities of digital optimization of the system of managing human factor in data and object protection.
Source: Author’s development.

Among the main opportunities for the digital upgrade of cybersecurity management in companies in the context of the human factor, depicted in Figure 1, the integration of digital communication networks and chatbots has special potential, involving AI tools and cloud solutions, real-time data analytics. These tools allow automating routine procedures, establishing additional protection for confidential information. In addition, it is important to integrate new approaches to corporate policy based on digital communication and Agile/Scrum principles. Among the key promising vectors of digital optimization of human factor management in security strategy, it is worth highlighting:5,21

  • Development of digital communication, which guarantees efficiency and multitasking of information transmission, with additional support for cyber protection;
  • Monitoring of the security strategy, which involves analysis and control over compliance with principles, performance indicators, coordination mechanisms, etc.;
  • Digital leadership, which aims to ensure effective interaction of all employees, feedback, corporate values;
  • Digital human capital: centralized collection of analytical data, integration of business applications, remote work, which increase staff mobility, manageability, and security.

Moreover, the potential of artificial neural networks within cybersecurity strategies for risk prediction is extremely important in the context of predicting the probability of a breach, assessing potential losses and determining the method of regeneration, inventorying IT assets. Security management concepts that involve the integration of artificial intelligence tools (Figure 4) increase the level of threat identification effectiveness, reduce response time and costs for security organization.

Fig 4 | Automation of particular security management processes to minimize the risk of human factor, %
Source: Davis et al.,14 Widarni and Bawono29
Figure 4: Automation of particular security management processes to minimize the risk of human factor, %.
Source: Davis et al.,14 Widarni and Bawono.29

At the same time, human capital continues to be involved in the security strategy, but in a slightly different functionality. The level of a person’s resistance to information manipulation, which poses a threat to the security of data and objects, is determined by situational factors of a specific situation (mental states, the presence of stress factors, extreme conditions, etc.), as well as extra- situational factors (stable psychological characteristics and individual characteristics of a person – distrust, critical thinking, suggestibility, negativism, etc.). Understanding the psychological components of security is considered critical for developing effective risk reduction and security strategies. The main components of a comprehensive conceptual framework are considered to be: risk psychology, stress resistance and resilience, risk information processing and decision-making under conditions of uncertainty and high stress, psychological safety, interaction and communication, and safety culture. The main forms of psychological intervention at the organizational level are:

  • individual consultations conducted by managers;
  • thematic webinars for the organization;
  • group counseling for participants to develop crisis management skills;
  • organization of psychological groups to analyze activities in conditions of increased stress and instability;
  • maintenance of special pages on social networks;
  • development and implementation of special methodological recommendations for the preventive prevention of negative psychological manifestations that may affect safety.

In the context of psychological aspects of security management, promising areas of optimization are seen as:

  • Developing skills in identifying, recognizing, and avoiding types of interactions that may pose potential harm to emotional stability and represent a direct or indirect threat to the protection of data or objects;
  • Creating support groups and practicing emotional interaction;
  • Development of resilience (maintaining physical health, planning and time management, positive thinking practice);
  • Development of skills for prompt and effective decision-making;
  • Training, improving competence and acquiring practical skills in security management.

Practical examples of work on improving psychological aspects of safety management include: psychological safety audits, which include assessing the working environment and psychological factors affecting safety in the workplace; targeted training and coaching that take into account the psychological characteristics of employees, their motivation, and their perception of risks; the introduction of human-based risk management systems; the integration of practical psychological support programs in situations that could potentially affect the psychological state of employees and safety aspects.

When comparing the proposed structure with existing models (including Protection Motivation Theory), there are some obvious differences. In particular, the Theory of Protection Motivation states that people seek to protect their self-esteem and avoid threats to their “self,” which can manifest itself in various forms of behavior, such as justifying their failures, searching for positive information about themselves, or avoiding situations that may threaten their well-being. The approach proposed in this study conveys the integration of the most effective strategies for preventive protection against human factor risks, which in most cases makes it impossible to use strategies to justify mistakes. Thus, the proposed approach goes beyond traditional models of information security culture among personnel and covers not only technical means and basic rules (confidentiality, integrity, availability), but also the human factor in its full manifestation:

  • ethical dilemmas (considering situations where security may conflict with other values, forming an ethical compass for personnel);
  • psychological resilience (focusing on psychological aspects that can affect security, such as stress, burnout, emotional manipulation by cybercriminals);
  • collective responsibility (creating an organizational culture where every employee feels like they’re part of a shared defense, not just an object of security policies);
  • adapting to new threats (especially social engineering);
  • integration of security into corporate culture as a component of strategic development;
  • continuous improvement (creating an environment where learning is a continuous process that takes into account both the professional and personal development of employees in the context of security).

Discussion

The issue of the psychological factors influence on security management is a cause of active debate in the modern scientific field. In particular, Anwar and Abdullah,23 Salas-Vallina et al.22 analyse the possibilities of enhancing the organizational foundations of improving the human capital of companies in the direction of internal information security. Rahman et al.30 explore the possibilities of Artificial Intelligence tools within the framework of network security strategies, maximum personalization of user experience, prevention of intrusions into confidential information arrays. The authors’ conclusions confirm the results of the current study in terms of the need to develop analytics, algorithmization, and automation processes in order to form competitive advantages in data protection and guarantees of data privacy security. Nobles,31 Widarni and Bawono29 proposed conceptual approaches to unifying the psychological standards of personnel involved in the implementation of security strategies as a basis for sustainable development and the principles of corporate social responsibility. Researchers are convinced that the level of security guaranteed by a company today is a determining factor in entering international markets and forming competitiveness.

At the same time, Michelberger and Kemendi32 consider information security in the context of protecting intellectual property rights and data confidentiality, proposing the integration of human capital management strategies of companies as the basis for effective prevention of intrusions into security systems. It is worth agreeing with scientists about the need to transform approaches to human capital management of companies against the background of increased risks of information threats. According to Salau et al.,33 who researches the contribution of digital human resource management to the effectiveness of companies’ security strategies, the key benefits of increasing staff resilience and psychological stability are minimizing the risk of data loss, saving time, and increasing the adaptability of companies’ human capital. The authors’ conclusions should be supplemented with a proposal for conducting targeted trainings and integrating a coaching system, which will increase staff competence in security issues, develop information security skills, and reduce the risks of the negative impact of the human factor on the protection of objects and data. In particular, Kolb cycle methodology is advisable as a basis for designing trainings, that would allow incorporating each employee’ personal experience with security issues, as well as continuous self-reflection and gaining new practical knowledge in security area.

Researchers Oswald et al.,25 Mer34 study the possibilities of HR (Human Resources) management in the context of company security and the functionality of headhunting companies, the scope of specialization of which includes the formation of human capital. Researchers see the basis of the psychological concept of human resources in security management as a digital upgrade involving cloud services, artificial neural networks, and digital recruiting. Popa,35 Piwowarski and Wawrzusiszyn21 emphasize that currently, there are no unified definitions in the scientific literature regarding approaches to the psychological basis of security management and its prerequisites. The authors interpret the phenomenon under study as an integral and a complex definition, which allows maintaining control, balance and resistance to threats, resilience to environmental dynamics, inner peace. It is worth agreeing with scientists in positioning the psychological basis of security management as a resource for effective countermeasure threats, improving the functionality of human capital regarding data and object protection.

The fundamental concepts of safety culture were laid down by scientists,36,37 whose work highlights the basic principles of achieving a complete safety culture, reducing uncertainty or even anxiety, which, as a result, leads to greater continuity, as less time is spent on various mutual adjustments within the group. In addition, researchers38,39 have identified Edgar Schein’s organizational culture model as the most influential model in the field of safety. The results of the current study and the analysis of the work of modern scientists demonstrate the relevance of personality-oriented concepts of human capital management within security strategies and the use of digitalization opportunities to minimize risks. Key areas of influence in the context of optimizing the psychological aspects of security management are seen in the creation of a flexible and adaptive system for developing skills to prevent direct and indirect threats to data or object protection, developing resilience, and skills for quick and effective decision-making by employees. The organizational structure must provide a sustainable concept for improving competence and acquiring practical skills in security management.

Conclusion

Psychological aspects of security management imply the effective development of self-awareness and communication skills, problem-oriented thinking and self-education skills, which reduces vulnerability to various threats. In the context of active digital development, critical thinking and the development of resilience become necessary, allowing to critically evaluate information, identify fraudulent intentions, protect confidentiality and maintain psychological stability in the online environment. The most common problems positioned in the studied area are digital stress and information overload, confidential data leakage, information manipulation. Company employees often use shady IT practices, ­engage in random data sharing, ignore MFA, secure communication protocols, and security alerts, postpone software updates, and become participants in unintentional social media disclosures or insider threats.

Security management currently requires the integration of effective strategies for developing resilience, including a healthy lifestyle, time management, positive thinking practices, and improving social competence. The results of the study have practical significance for optimizing data and object protection systems, facilitating adaptation to change, and developing the psychological resilience of human capital. The prospects for further research in this area can include research into the impact of personal motivation of human capital on the level of information security of companies.

References
  1. Microsoft. Digital defense report. 2022. https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2022
  2. Center for Strategic and International Studies (CSIS). Significant cyber incidents. 2025. https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents
  3. Tsyuman T, Nagula O. Psychological formula of safety as a conceptual basis for the formation of skills of safe behaviour of an individual. Pedagogical education: theory and practice. Psychol. Pedag. 2021;35(1):94–100. https://doi.org/10.28925/2311-2409.2021.3513
  4. da Silva LBP, Soltovski R, Pontes J, Treinta FT, Leitão P, Mosconi E, et al. Human resources management 4.0: literature review and trends. Comput Ind Eng. 2022;168:108111. https://doi.org/10.1016/j.cie.2022.108111
  5. Cartwright S, Cooper CL. The psychological impact of merger and acquisition on the individual: a study of building society managers. In: Managerial, Occupational and Organizational Stress Research. London: Routledge; 2024. p. 429–50. https://doi.org/10.4324/9781315196244-33
  6. Moustafa AA, Bello A, Maurushat A. The role of user behaviour in improving cyber security management. Front Psychol. 2021;12:561011. https://doi.org/10.3389/fpsyg.2021.561011
  7. McCrie R, Lee S. Security operations management. 4th ed. Oxford: Butterworth-Heinemann; 2021.
  8. Khando K, Gao S, Islam SM, Salman A. Enhancing employees information security awareness in private and public organisations: A systematic literature review. Comput Secur. 2021;106:102267. https://doi.org/10.1016/j.cose.2021.102267
  9. Chmyr Y, Moshnin A, Tsymbal B. Societal content and main determinants of “national security” phenomenon in the information and communication context. Contrib Political Sci. 2023;1367:25–41. https://doi.org/10.1007/978-3-031-33724-6_2
  10. Lysenko S, Liubchenko A, Kozakov V, Demianchuk Y, Krutik Y. Global cybersecurity: Harmonising international standards and cooperation. Multidiscip Rev. 2024;7. https://doi.org/10.31893/multirev.2024spe021
  11. Lysenko S, Bobro N, Korsunova K, Vasylchyshyn O, Tatarchenko Y. The role of artificial intelligence in cybersecurity: automation of protection and detection of threats. Econ Aff. 2024;69:43–51. https://doi.org/10.46852/0424-2513.1.2024.6
  12. Budhwar P, Chowdhury S, Wood G, Aguinis H, Bamber GJ, Beltran JR, et al. Human resource management in the age of generative artificial intelligence: perspectives and research directions on ChatGPT. Hum Resour Manag J. 2023;33(3):606–59. https://doi.org/10.1111/1748-8583.12524
  13. Culot G, Nassimbeni G, Podrecca M, Sartor M. The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda. TQM J. 2021;33(7):76–105. https://doi.org/10.1108/TQM-09-2020-0202
  14. Davis J, Agrawal D, Guo X. Enhancing users’ security engagement through cultivating commitment: the role of psychological needs fulfilment. Eur J Inf Syst. 2023;32(2):195–206. https://doi.org/10.1080/0960085X.2021.1927866
  15. Li W, Su Z, Li R, Zhang K, Wang Y. Blockchain-based data security for artificial intelligence applications in 6G networks. IEEE Netw. 2020;34(6):31–7. https://doi.org/10.1109/MNET.021.1900629
  16. Curran K. Cyber security and the remote workforce. Comput Fraud Secur. 2020;2020(6):11–2. https://doi.org/10.1016/S1361-3723(20)30063-4
  17. Dhillon G, Smith K, Dissanayaka I. Information systems security research agenda: Exploring the gap between research and practice. J Strateg Inf Syst. 2021;30(4):101693. https://doi.org/10.1016/j.jsis.2021.101693
  18. Dovgy S, Radchenko O, Radchenko O. “Legitimacy crisis” and its impact on the stability and security of the system of public authorities of the state during the formation of the global information space. Contrib Political Sci. 2023;1367:237–56. https://doi.org/10.1007/978-3-031-33724-6_14
  19. Hren L, Karpeko N, Kopanchuk O. Substantive essence and components of the societal phenomenon “Information Security” in the age of information society. Contrib Political Sci. 2023;1367:75–91. https://doi.org/10.1007/978-3-031-33724-6_5
  20. Habbal A, Ali MK, Abuzaraida MA. Artificial Intelligence Trust, risk and security management (AI TRISM): Frameworks, applications, challenges and future research directions. Expert Syst Appl. 2024;240:122442. https://doi.org/10.1016/j.eswa.2023.122442
  21. PRISMA 2020. 2025. https://www.prisma-statement.org/prisma-2020
  22. Salas-Vallina A, Alegre J, López-Cabrales Á. The challenge of increasing employees’ well-being and performance: How human resource management practices and engaging leadership work together toward reaching this goal. Hum Resour Manag. 2021;60(3):333–47. https://doi.org/10.1002/hrm.22021
  23. Anwar G, Abdullah NN. The impact of human resource management practice on organizational performance. Int J Eng Bus Manag. 2021;5. https://ssrn.com/abstract=3824689
  24. Kost E. Human factors in cybersecurity in 2025. Human Cyber Risk. 2025 Apr 7. https://www.upguard.com/blog/human-factors-in-cybersecurity
  25. Oswald FL, Behrend TS, Putka DJ, Sinar E. Big data in industrial-organizational psychology and human resource management: Forward progress for organizational research and practice. Annu Rev Organ Psychol Organ Behav. 2020;7(1):505–33. https://doi.org/10.1146/annurev-orgpsych-032117-104553
  26. van der Kleij R, Schraagen JM, Cadet B, Young H. Developing decision support for cybersecurity threat and incident managers. Comput Secur. 2022;113:102535. https://doi.org/10.1016/j.cose.2021.102535
  27. Hatzivasilis G. Password management: How secure is your login process? In: International Workshop on Model-Driven Simulation and Training Environments for Cybersecurity. Cham: Springer International Publishing; 2020. p. 157–77. https://doi.org/10.1007/978-3-030-62433-0_10
  28. FinTech Global. Overwhelmed by digital overload: the rising cybersecurity risks in today’s workplaces. 2023 Nov 27. https://fintech.global/2023/11/27/overwhelmed-by-digital-overload-the-rising-cybersecurity-risks-in-todays-workplaces/
  29. Widarni EL, Bawono S. Human capital, technology, and economic growth: a case study of Indonesia. J Asian Finance Econ Bus. 2021;8(5):29–35. https://doi.org/10.13106/jafeb.2021.vol8.no5.0029
  30. Rahman T, Rohan R, Pal D, Kanthamanon P. Human factors in cybersecurity: A scoping review. In: Proceedings of the 12th International Conference on Advances in Information Technology. 2021. p. 1–11. https://doi.org/10.1145/3468784.3468789
  31. Nobles C. Stress, burnout, and security fatigue in cybersecurity: a human factors problem. Holist J Bus Public Adm. 2022;13(1): 49–72. https://doi.org/10.2478/hjbpa-2022-0003
  32. Michelberger P, Kemendi Á. Data, information and IT security—software support for security activities. Probl Manag 21st Century. 2020;15(2):108–24. https://doi.org/10.33225/pmc/20.15.108
  33. Salau AO, Marriwala N, Athaee M. Data security in wireless sensor networks: Attacks and countermeasures. In: Mobile Radio Communications and 5G Networks: Proceedings of MRCN 2020. Singapore: Springer; 2021. p. 173–86. https://doi.org/10.1007/978-981-15-7130-5_13
  34. Mer A. Artificial intelligence in human resource management: Recent trends and research agenda. Digit Transform Strateg Resil Cyber Secur Risk Manag. 2023;111B:31–56. https://doi.org/10.1108/S1569-37592023000111B003
  35. Popa R. Psychological security—conceptual approaches. Psihol Rev Ştiinţ-Pract. 2023;43(2):90–9. https://doi.org/10.46728/pspj.2023.v43.i2.p90-99
  36. Geller ES. Ten principles for achieving a total safety culture. Professional safety. 1994;39(9):18. https://www.proquest.com/openview/7b7e271261a7b1c8d9535667df2b4dcd/1?pq-origsite=gscholar&cbl=47267
  37. Guldenmund F. Organisational safety culture principles. In Patient safety culture. CRC Press; 2018. p. 15–42.
  38. Reiman T, Rollenhagen C. Safety culture. Handbook of safety principles; 2017. р. 647–676. https://doi.org/10.1002/9781119443070.ch28
  39. Antonsen S. Safety culture: theory, method and improvement. CRC Press; 2017. https://doi.org/10.1201/9781315607498


Premier Science
Publishing Science that inspires