Identifying Gaps in the Evaluation of Security Education, Training and Awareness (SETA) Programs: A Systematic Literature Review

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Many organisations are dedicated to enhancing their security by investing heavily in Security Education, Training, and Awareness (SETA) programmes to protect their platforms and personnel better. However, measuring the effectiveness of these initiatives remains a considerable challenge. This study presents a systematic literature review conducted following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) methodology to examine how SETA effectiveness is currently assessed and to identify significant gaps in existing approaches. The review reveals that many evaluations still depend on self-reported data, knowledge tests, or participation rates, which offer limited insight into whether secure behaviours are genuinely being adopted or sustained. Moreover, current assessment practices often neglect the impact of emerging threats, such as AI-driven phishing and deepfakes, and seldom consider the long-term behavioural effects of SETA programmes. Although innovative methods employing behavioural metrics, psychological engagement, and mixed-method approaches demonstrate strong potential, they remain underutilised. The findings underscore the necessity for more meaningful, behaviour-oriented, and context-aware evaluation frameworks that mirror real-world security challenges and foster more robust organisational security cultures.

Original languageEnglish
Title of host publicationAdvancing Innovative Cybersecurity Solutions and Approaches to Protect Digital Ecosystems - 1st IFIP TC 9, TC 11 International Conference in Cybersecurity, IFIP-UNIVEN-CSIR ICC 2025, Proceedings
EditorsJabu Mtsweni, Jackie Phahlamohlaka, Modimowabarwa Kanyane, Willard Munyoka, Kerry-Lynn Thomson, Lynn Futcher, Joey Jansen van Vuuren
PublisherSpringer Science and Business Media Deutschland GmbH
Pages141-153
Number of pages13
ISBN (Print)9783032130747
DOIs
Publication statusPublished - 2026
Event1st IFIP TC 9, TC 11 International Conference in Cybersecurity, IFIP-UNIVEN-CSIR ICC 2025 - Tshwane, South Africa
Duration: 11 Dec 202512 Dec 2025

Publication series

NameIFIP Advances in Information and Communication Technology
Volume777 IFIPAICT
ISSN (Print)1868-4238
ISSN (Electronic)1868-422X

Conference

Conference1st IFIP TC 9, TC 11 International Conference in Cybersecurity, IFIP-UNIVEN-CSIR ICC 2025
Country/TerritorySouth Africa
CityTshwane
Period11/12/2512/12/25

Keywords

  • SETA Effectiveness assessment
  • Security Education
  • Training and Awareness (SETA)
  • behavioural change

ASJC Scopus subject areas

  • Information Systems and Management

Fingerprint

Dive into the research topics of 'Identifying Gaps in the Evaluation of Security Education, Training and Awareness (SETA) Programs: A Systematic Literature Review'. Together they form a unique fingerprint.

Cite this