A Multi-Wave Assessment of Information Security Awareness in Personal Device Use among Brazilian Users

  • Arthur C. Souza UERJ
  • Lucila M. S. Bento UERJ

Resumo


Information Security Awareness (ISA) instruments for Brazilian users are scarce, multi-wave evidence remains scarce, and the Knowledge–Attitude–Behavior (KAB) model has been validated mainly in corporate settings. We propose a self-assessment instrument applied across three waves (n = 173). The composite ISA score remained stable (∼65/100), but platformautomated behaviors (OS updates, MFA) improved while agency-dependent behaviors (password rotation, non-reuse, reporting) stagnated. Path analysis showed a dominant direct knowledge–behavior effect (β = 0.46), with attitudinal mediation explaining only 14.5%, contrasting with prior corporate findings. Self-declared concern declined despite intensified cyber-fraud reporting, plausibly reflecting security fatigue. Awareness campaigns should prioritize actionable knowledge over appeals to concern.

Referências

Aljedaani, B., Ahmad, A., Zahedi, M., and Babar, M. A. (2021). Security awareness of end-users of mobile health applications: An empirical study. In 17th EAI International Conf. on Mobile and Ubiquitous Systems, pages 125–136.

Bashofi, I. and Salman, M. (2022). Cybersecurity maturity assessment design using NIST CSF, CIS controls v8 and ISO/IEC 27002. In 2022 IEEE Intl. Conf. on Cybernetics and Computational Intelligence, pages 58–62.

Bauer, S. and Bernroider, E. W. N. (2017). From information security awareness to reasoned compliant action: Analyzing information security policy compliance in a large banking organization. SIGMIS Database, 48(3):44–68.

Bitton, R., Boymgold, K., Puzis, R., and Shabtai, A. (2020). Evaluating the information security awareness of smartphone users. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, pages 1–13.

Brasil (2018). Lei nº 13.709, de 14 de agosto de 2018. lei geral de proteção de dados pessoais. Diário Oficial da União, Brasília, DF.

Center for Internet Security (2024). CIS Critical Security Controls Version 8.1.

Chumaera, M. M., Safitri, S., and Ayu, M. A. (2022). Assessing students’ information security awareness through the knowledge, attitude, and behavior model. In 2022 IEEE 8th International Conference on Computing, Engineering and Design (ICCED), pages 1–6.

CNN Brasil (2025). Brasil foi um dos principais alvos de ataques digitais na américa latina em 2025. CNN Brasil, tecnologia. Dados de telemetria de ataques digitais na América Latina.

Collins, D. (2003). Pretesting survey instruments: an overview of cognitive methods. Quality of Life Research, 12(3):229–238.

Datafolha (2025). 24 milhões foram vítimas de golpe do pix ou boleto falso. Levantamento Datafolha. Dados reproduzidos em reportagem do G1 sobre golpes com Pix e boletos falsos.

de Segurança Pública, F. B. (2025a). 19º anuário brasileiro de segurança pública 2025. Relatório técnico. Dados consolidados de 2024 sobre criminalidade, incluindo fraudes e crimes digitais.

de Segurança Pública, F. B. (2025b). Fraudes financeiras no brasil geram perdas de cerca de r$ 10 bilhões em 2024. Relatório de Identidade e Fraude 2025. Dados citados em relatórios setoriais e cobertura de imprensa.

DeMaio, T. J. and Rothgeb, J. M. (1996). Cognitive interviewing techniques: In the lab and in the field. In Schwartz, N. and Sudman, S., editors, Answering questions: Methodology for determining cognitive and communicative processes in survey research, pages 177–195. Jossey-Bass, San Francisco.

Egelman, S. and Peer, E. (2015). Scaling the security wall: Developing a security behavior intentions scale (SeBIS). In Proceedings of the 33rd Annual ACM Conf. on Human Factors in Computing Systems, pages 2873–2882.

Federal, S. (2025). Mais de 24 milhões de pessoas foram vítimas de golpes pelo pix em um ano. Rádio Senado. Matéria baseada em pesquisa do DataSenado e dados do Fórum Brasileiro de Segurança Pública.

Georgiadou, A., Mouzakitis, S., and Askounis, D. (2022). Working from home during COVID-19 crisis: a cyber security culture assessment survey. Security Journal, 35:486–505.

Gioulekas, F., Stamatiadis, E., Tzikas, A., et al. (2022). A cybersecurity culture survey targeting healthcare critical infrastructures. Healthcare, 10(2).

Hanus, B., Windsor, J. C., and Wu, Y. (2018). Definition and multi-dimensionality of security awareness: Close encounters of the second order. SIGMIS Database, 49:103–133.

Henklain, M. H. O., Lobo, F. L., Feitosa, E. L., Cavalcante, L. G. D., Alencar, J. V. R. d., Bríglia, V. J. C., Araújo, G. M. d., and Alves, G. d. S. (2024). Caracterização de conhecimentos e comportamentos de cibersegurança: Estudo exploratório com dados predominantes do extremo norte brasileiro. In Anais do XXIV Simpósio Brasileiro de Cibersegurança (SBSeg), pages 76–91. SBC.

ISO (2022). ISO/IEC 27001:2022 – information security, cybersecurity and privacy protection – information security management systems – requirements. International Organization for Standardization.

Karjalainen, M. (2011). Improving Employees’ Information Systems (IS) Security Behaviour: Toward a Meta-Theory of IS Security Training and a New Framework for Understanding Employees’ IS Security Behaviour. PhD thesis, The University of Oulu, Finland.

Kruger, H. A. and Kearney, W. D. (2006). A prototype for assessing information security awareness. Computers & Security, 25(4):289–296.

Labs, F. (2026). 2026 global threat landscape report. Technical report, Fortinet. Threat intelligence report on global cyber attack trends.

Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., and Zwaans, T. (2017). The human aspects of information security questionnaire (HAIS-Q): Two further validation studies. Computers & Security, 66:40–51.

Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., and Jerram, C. (2013). The development of the human aspects of information security questionnaire (HAIS-Q). In Proceedings of the 24th Australasian Conference on Information Systems (ACIS), Melbourne, Australia.

Pascoe, C., Quinn, S., and Scarfone, K. (2024). The nist cybersecurity framework (csf) 2.0.

Pósa, T. and Grossklags, J. (2022). Work experience as a factor in cyber-security risk awareness: A survey study with university students. Journal of Cybersecurity and Privacy, 2(3):490–515.

Salem, Y., Moreb, M., and Rabayah, K. S. (2021). Evaluation of information security awareness among palestinian learners. In 2021 International Conference on Information Technology (ICIT), pages 21–26.

Senthilkumar, K. and Easwaramoorthy, S. (2017). A survey on cyber security awareness among college students in tamil nadu. IOP Conference Series: Materials Science and Engineering, 263(4).

Sobel, M. E. (1982). Asymptotic confidence intervals for indirect effects in structural equation models. Sociological Methodology, 13:290–312.

Tariq, M. A., Brynielsson, J., and Artman, H. (2014). The security awareness paradox: a case study. In Proceedings of the 2014 IEEE/ACM International Conf. on Advances in Social Networks Analysis and Mining, pages 704–711.

Verizon (2025). 2025 data breach investigations report. Technical report, Verizon, New York, NY. Análise de mais de 12 mil violações de dados em 139 países.

Wahyudiwan, D. D. H., Sucahyo, Y. G., and Gandhi, A. (2017). Information security awareness level measurement for employee: Case study at ministry of research, technology, and higher education. In 2017 3rd International Conference on Science in Information Technology (ICSITech), pages 654–658.

Wash, R., Rader, E., and Fennell, C. (2017). Can people self-report security accurately? agreement between self-report and behavioral measures. In Proc. of the 2017 Conf. on Human Factors in Computing Systems, pages 2228–2232.
Publicado
01/09/2026
SOUZA, Arthur C.; BENTO, Lucila M. S.. A Multi-Wave Assessment of Information Security Awareness in Personal Device Use among Brazilian Users. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 16-31. DOI: https://doi.org/10.5753/sbseg.2026.29309.