Centre for Information Technology (CfIT), Waikato Institute of Technology, Hamilton 3240, New Zealand
Abstract: In this paper, we present secondary research on recommended cybersecurity practices for
social media users from the user’s point of view. Through following a structured methodological
approach of the systematic literature review presented, aspects related to cyber threats, cyber aware-
ness, and cyber behavior in internet and social media use are considered in the study. The study
presented finds that there are many cyber threats existing within the social media platform, such
as loss of productivity, cyber bullying, cyber stalking, identity theft, social information overload,
inconsistent personal branding, personal reputation damage, data breach, malicious software, service
interruptions, hacks, and unauthorized access to social media accounts. Among other findings, the
study also reveals that demographic factors, for example age, gender, and education level, may not
necessarily be influential factors affecting the cyber awareness of the internet users.
1. Introduction
The structure of this article is organized with several sections. Section 2 of this article
discusses the research methodology. Then, the themes and subthemes of the literature re-
lated to the article are further discussed in the following order: cyber threats on the internet
are discussed in Section 2.1; cyber threats on social media are discussed in Section 2.1.1;
cybersecurity on the internet is discussed in Section 2.2; user awareness when using the
internet is discussed in Section 2.2.1; user behavior when using the internet is discussed in
Section 2.2.2; cybersecurity in social media is discussed in Section 2.3; user awareness when
using social media is discussed in Section 2.3.1; user behavior when using social media is
discussed in Section 2.3.2. Next, Section 3 discloses the discussion along with the findings
of the literature. Then, in Section 4, the limitations of the systematic literature review are
discussed. Finally, the article is concluded with Section 5—future development—which
illustrates the formation of main and sub research questions for the future research work,
followed by Section 6, which provides our conclusion.
2. Methodology
Searching through the literature is a significant component of a systematic review. The
commonly used literature search component is the preferred reporting items for systematic
reviews and meta-analyses (PRISMA) statement ([7] Rethlefsen et al., 2021). The PRISMA
statement is used in this research article to filter the most relevant literature. The PRISMA
statement is a road map that supports authors explaining what was carried out, what was
found, and what are they planning to do next ([8] Rafael, Ferran, Edoardo, and Craig, 2021).
Additionally, the PRISMA checklist is a tool that can be used to guide systematic review
reporting ([9] Rice, Kloda, Shrier, and Thombs, 2016). The PRISMA statement consists of
4-stage flow diagram and 27 check list items ([10] Moher, Liberati, Tetzlaff, and Altman,
2009). The adaptability of this article to the PRISMA statement is depicted in Table 1 and
Figure 1, accordingly.
When searching the literature, more than 10,000 probable articles were found using
Wintec OneSearch and Google Scholar online databases with the help of relevant keywords
and “AND” and “OR” operators. The main keywords used in the search of relevant
articles were as follows: cyber threats, cybersecurity, cyber security, social media, user
awareness, and user behavior. From that pool, only 2500 articles were revealed to be
suitable, after removing duplicates. Then, only 339 of the most relevant articles were
screened, and 170 articles were omitted from that pool due to ineligibility of the abstract.
Next, 169 relevant articles were filtered from the pool of screened articles, and 126 of them
2.1. Cyber
Cyber Threats
Threats on on the
the Internet
The evolution of cybercrimes in
evolution of cybercrimes in the
the IT
IT industry
industry dates
dates back
1970s. ItIt has
evolved from just spam at that time to much more advanced forms, such as viruses
from just spam at that time to much more advanced forms, such as viruses andand
malware, in in the
the present
present day day ([11]
([11] Jobs,
Jobs, 2016;
2016; as
as cited
cited by
Frederick, Jacobson,
Jacobson, andand
Monticone, 2017). The word “Cybercrimes” covers a vast range of virtual illegalactivities
2017). The word “Cybercrimes” covers a vast range of virtual illegal activities
performedby bycybercriminals
cybercriminalsvia viaany source
any sourceof internet-connected
of internet-connected electronic device
electronic ([12]([12]
device Ali,
2019). Experts
Ali, 2019). Expertssay say
cybercriminals often aim
often aimforfor
easy targets
easy targetswith
even though they possess many sources, as well as a high level of knowledge on on
though they possess many sources, as well as a high level of knowledge howhow the
the technology works and its vulnerabilities. The reason for this is that they can easily
technology works and its vulnerabilities. The reason for this is that they can easily com-
commence the hacking with less effort with that kind of user ([13] Shryock, 2019). Gullible
mence the hacking with less effort with that kind of user ([13] Shryock, 2019). Gullible users
users often become targets of hackers and cybercriminals use creative and different ways
often become targets of hackers and cybercriminals use creative and different ways to collect
to collect personal data from them ([14] Ramakrishnan and Tandon, 2018). The internet has
personal data from them ([14] Ramakrishnan and Tandon, 2018). The internet has become
become an essential part of society and it has become the core of connecting and sharing
an essential part of society and it has become the core of connecting and sharing information
information in modern days. This has led the internet to become a target of various cyber
in modern days. This has led the internet to become a target of various cyber threats, ranging
3. Discussion
Based on the aforementioned literature, it was found that there are many cyber
threats existing within social media platforms, such as loss of productivity, cyberbullying,
cyberstalking, identity theft, social information overload, inconsistent personal branding,
J. Cybersecur. Priv. 2022, 2 8
personal reputational damage, data breach, malicious software, service interruptions, hacks,
unauthorized access to social media accounts ([18] van Zyl, 2009; Krasnova et al., 2009;
Hogben, 2007; Krasnova et al., 2009; Boyd, 2008; Argenti and Druckenbiller, 2004; Aula,
2010; Boyd, 2008; Hogben, 2007; Rivera et al., 2015; as cited by Goh et al., 2016), cracking
a password ([19] Eddolls, 2016), fake accounts, sexual harassments ([20] van Schaik et al.,
2017), spam attacks, malware attacks, Sybil attacks, impersonation, hijacking, fake requests,
image retrieval and analysis ([21] Zhang and Gupta, 2018), spear phishing attacks ([22]
Bossetta, 2018), and social engineering ([23] Wilcox, Bhattacharya, and Islam, 2014; as cited
by Aldawood and Skinner, 2019).
All users should have enough current and updated cyber awareness and cyber be-
havior to safeguard themselves from the aforementioned cyber threats. Tragically, most
users have failed to achieve an acceptable level of protection compared with the increasing
rate of threats ([14] Ramakrishnan and Tandon, 2018). People who post information on-
line might not think of security risks associated with this behavior. However, this action
can voluntarily reveal more personal information to unknown people than they expected
([46] Nyblom et al., 2020). It is also revealed that most social media users are unaware of
the risks and vulnerabilities associated with those platforms unless they have experienced
those in their real lives ([50] Atiso and Kammer, 2018). Hence, it is always recommended
that users take enough precautions to safeguard themselves from cybercrimes from their
point of view, since the most powerful user privacy protection strategy in social media
platforms falls into users’ own hands. Only they can control what they publish, and to
whom, on those platforms ([48] Pensa and Di Blasi, 2017).
When it comes to factors affecting cyber awareness, it was discovered that age, gender,
and education level may or may not affect the cyber awareness of internet users. Older
adults had higher information security awareness (ISA) scores than young adults. A small
significant difference was found in the ISA score related to gender, where females had
higher ISA scores compared with males ([29] McCormac et al., 2017). In contrast to this
citation, another research article stated otherwise, finding that males have more cyber
hygiene knowledge than females; however, surprisingly, there was no difference in cyber
hygiene knowledge among different age groups ([30] Cain et al., 2018). In the research,
it was found that higher education levels lead to higher information security awareness
of the users—higher education levels or information security training reduces risky user
behavior ([31] Ogutcu et al., 2016). However, in a multinomial regression analysis, it was
found that people with higher education and who are not living in their own housing are
more likely to fall into the cybercrime victims category ([32] Oksanen, and Keipi, 2013, as
cited by Nalaka and Diunugala, 2020).
Several items of the literature support the idea that cyber awareness has an impact
on cyber behavior. Research results show that higher awareness was connected with a
lower number of reported online risky behaviors ([37] Schilder, Brusselaers, and Bogaerts,
2016). Lack of understanding regarding appropriate cybersecurity actions can lead end
users to inappropriate cyber behavior ([30] Debatin et al., 2009; Goodhue, and Straub,
1991; Hu, Hart, and Cooke, 2006; Straub, and Welke, 1998; as cited by Cain et al., 2018).
The research findings revealed that user awareness improvements lead to better security
behavior ([39] Furnell, Khern-am-nuai, Esmael, Yang, and Li, 2018). Security awareness
impacts user behavior when protecting against risks in information security ([40] Herath,
and Rao, 2009; Thomson, and Solms, 1998; Puhakainen, and Siponene, 2010; as cited by
Torten, Reaiche, and Boyle, 2018). On the other hand, a study conducted by the Global
Cybersecurity Capacity Centre at the University of Oxford found that campaigns on
cybersecurity awareness were unsuccessful in changing behavior ([41] Bada et al., 2015;
as cited by Chang and Coppel, 2020); additionally, they found that cyber behavior has an
impact on the vulnerability level that users face. In another study, it was identified that
the cybersecurity behavior of the respondents potentially makes them vulnerable to cyber
threats ([38] Muniandy, Muniandy, and Samsudin, 2017).
5. Future Works
5. Future Works
The present research was mainly focused on identifying recommended cybersecurity
The for
practices present research
social media was mainly
users focused
from users’ on identifying
points recommendeditcybersecurity
of view. Additionally, intended to
identify the factors affecting users’ awareness on social mediaAdditionally,
practices for social media users from users’ points of view. it intended to
platforms’ security-related
features and impact of social media users’ awareness on their behavior in social media
platforms. However, above topics are not significantly addressed in the past literature, to
the best of the authors’ knowledge. There were not enough studies found to identify the
J. Cybersecur. Priv. 2022, 2 10
impact of social media users’ secure behavior on their vulnerability level in the platform.
Therefore, it may be worthwhile to carry out further research, considering these variables
(including their correlations), to identify recommended cybersecurity practices for social
media users from users’ points of view. The limitations mentioned earlier are also areas
worth investigating.
6. Conclusions
Cybersecurity, within the context of social media, is a timely topic to be discussed
considering its large user base all around the world. There are many cyberattacks existing
in the current social media sphere, according to the literature discussed in this article.
Although there is an in-built security framework within the different social media platforms,
it may not be enough to protect the social media users from cyber attacks. This is due to
human error, where there is the possibility of opening backdoors for commencing cyber
attacks. User awareness and user behavior play a major role to reduce the impact of human
errors. The impact of factors, such as age, gender, and the education level of the users on
their cyber awareness in social media platforms’ security features is not clear, based on
the current literature found. However, the impact of cyber awareness over cyber behavior
is backed by several studies, discussed in the article. Additionally, there is not enough
evidence to prove the impact of users’ secured cyber behavior on their vulnerability level
on social media platforms. Hence, further research is crucial to identify the factors affecting
user awareness, users’ secure behavior, and users’ vulnerability level on social media
platforms. Moreover, it is significant to discover recommended cybersecurity practices for
social media users, based on the impact of the aforementioned variables.
