Cybersecurity research podcast
MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity
Researchers combined a systematic scoping review with AI-assisted, human-validated screening to organize human factors, their interactions, and measurement instruments in cybersecurity. MORPHEUS can support risk diagnosis and targeted interventions. Separately, cited studies associate missing information, time, tools, and training with incorrect or delayed configuration correction, while absent periodic audits, continuous monitoring, and education may leave cloud misconfigurations unresolved.
Episode 31 Aug 2026 · Paper 12 Jul 2026 · ACM Transactions on Computer-Human Interaction · VERSION of RECORD
Research summary
A technical explanation of the paper's research question, method, reported findings and limitations. The resulting framework organizes 50 human factors across 6 dimensions. Factors closer to a security decision sit in the cognition, affect, and behavior core; affect here means emotional state. More distant influences include personality, demographics, and…
Provides a structured way to diagnose human-driven exposure to phishing, weak password practices, malware, and misconfiguration, with an instrument inventory that may support risk assessment. Operational value is limited by the absence of deployment results or comparative intervention evidence.
Paper details
Authors: Giuseppe Desolda (University of Bari Aldo Moro) , Francesco Greco (University of Bari Aldo Moro) , Rosa Lanzilotti (University of Bari Aldo Moro) , Cesare Tucci (University of Bari Aldo Moro)
Transcript
Highlighting follows the podcast. Select any word to seek.
MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity. MORPHEUS stands for Multidimensional framework for Organizational Resilience and Psychology-based Human factors for Effective Understanding of Security. Giuseppe Desolda and colleagues published the work in ACM Transactions on Computer-Human Interaction in 2026. It addresses fragmented research that treats human vulnerabilities as isolated, static traits. This episode focuses on how MORPHEUS connects human factors and their interactions with ways to measure them. It also explains why MORPHEUS remains a diagnostic framework rather than proof that an intervention works.
Existing approaches cover useful but limited slices of human-related security risk. Some focus on a single threat such as insiders or a single pressure such as time. Others examine organizational arrangements or the password lifecycle. The NIST Cybersecurity Framework classifies relevant behaviors at a high level but is not designed to explain fluid and situation-specific decisions. A broader framework is needed to cover human factors across common threats, investigate how those factors interact, and support their measurement. The intended benefit is more actionable insight for building a stronger cybersecurity defense.
The research question is straightforward: which human factors play a critical role in cyberattacks? The work turns that into identifying factors tied to selected threats, mapping how those factors interact, and finding validated instruments that can measure them. Its scope covers three forms of phishing: phishing, smishing, and spear phishing. It also covers malware downloads and risks around passwords or system configuration. The practical promise is a path from the vague label of human error toward a diagnosis of what may influence risky behavior and what could be measured before choosing a response.
First, the team conducted a systematic scoping review. This is a structured search and screening process used to map concepts across cybersecurity and psychology. It also covered human-computer interaction and behavioral science. Google Scholar was the primary search engine. The team also followed references backward and later citations forward. The manual phase ended with 88 unique publications. The taxonomy also incorporated factors identified by earlier reviews. For the larger task of finding relationships and measurement tools, AI systems retrieved candidates by meaning rather than keyword matching alone. Two researchers then independently verified every candidate and resolved disagreements before accepting it.
The resulting framework organizes 50 human factors across 6 dimensions. Factors closer to a security decision sit in the cognition, affect, and behavior core; affect here means emotional state. More distant influences include personality, demographics, and social or organizational context. This distinction does not mean a distant factor directly causes an incident. It models how background conditions may shape what someone thinks, feels, or does, and how those states relate to susceptibility across the selected threats. The design therefore moves beyond treating human weaknesses as a flat collection of independent traits.
When the researchers checked their proposed structure against relationships reported in earlier studies, they mapped 302 interactions among human factors. Of those, 82.8% followed the expected flow from background influences toward cognition, emotion, or behavior. They also grouped recurring relationships into mechanisms, including feedback loops. That percentage supports consistency between the architecture and much of the mapped literature. It does not establish that the framework prevents incidents or that every relationship will reproduce in a particular organization.
The evidence has several boundaries. The unified framework has not been tested over time in a real enterprise, so its overall effectiveness has not been quantified. The interactions come from studies using different methods, populations, and threat settings. The use of Google Scholar, selected umbrella terms, and a defined set of threats means that specialized or differently worded research may have been missed. Each AI-retrieved publication had to pass manual validation before acceptance, but that checking cannot detect relevant studies the retrieval systems never returned.
MORPHEUS includes 99 validated measurement solutions and 8 operational scenarios for risk diagnosis and intervention. The researchers describe these measurement tools as psychometric instruments for assessing human factors. One cautious operational use is to treat the framework as a hypothesis organizer. That would mean identifying the threat and behavior of concern, tracing plausible interacting factors, choosing an instrument, and testing locally whether the measurement and proposed response are useful. Validation of the individual instruments should not be read as validation of the entire framework in your enterprise.
Desolda and colleagues contribute an integrated way to connect a human-factor taxonomy, documented interactions, and available measurements across several security threats. Researchers and security practitioners may find it useful for human-centric risk diagnosis, choosing measurements, and planning targeted interventions. Use MORPHEUS as a structured starting point, not as an enterprise-validated causal model or a proven mitigation package. It remains uncertain whether external cues activate the mapped factors as proposed. Whether feedback loops persist over time also remains to be established. It is also unknown whether interventions improve enterprise outcomes.