People may be less willing to follow cybersecurity advice when it takes too much time, according to a study of 1,006 adults in the United States. However, when participants considered measures they could take to protect themselves, perceived effectiveness and confidence became more important.
The study, “Protection motivation and cybersecurity intentions: a visual conjoint experiment”, was published in the Journal of Experimental Criminology.
The findings suggest that organisations may improve cybersecurity participation by making protective steps easier to complete, rather than relying only on warnings about online threats.
Study tested websites and security recommendations
Researchers Travis Carter and Rachel L. McNealey conducted an online experiment in early 2025. The sample was stratified to reflect national population estimates, although the authors noted that it differed slightly from the US General Social Survey.
Participants viewed three hypothetical utility websites. Five visual features were randomised, including the web address, font, advertisement, privacy notice and secure-connection indicator. They were then shown recommendations to enable two-factor authentication, change a password and activate a fictional safe-browser mode.
Most of the website’s visual cues did not significantly change perceived risk. A shortened web address was the exception, with participants regarding it as riskier than the alternatives.
Convenience shaped stated compliance
The time required to complete a recommended action was the main factor associated with whether participants said they would comply. Recommendations described as quick were more likely to receive a positive response.
A different pattern emerged when people considered their own motivation to stay safe online. In that setting, perceived effectiveness and confidence in completing the task were more closely linked to their intentions.
“Our findings suggest that people are not always aware of what puts them at risk online,” Carter said in a University of Nebraska Omaha summary of the research.
Businesses may need to reduce user effort
The results indicate that companies should consider the amount of time and effort required when asking customers or employees to adopt a security measure. A shorter sign-in or verification process may encourage more people to complete it.
Clear explanations still matter. When users are acting to protect themselves, they may be more responsive if they understand why a measure works and feel capable of carrying it out.
The authors cautioned that the study measured intentions in hypothetical situations, not behaviour during a real cyberattack. They also described the findings as preliminary and noted the limitations of using a single online experimental method. Further research would be needed to establish whether the same patterns appear in workplaces and real consumer services.