Toward a Persona‐Driven Approach in Cybersecurity: Insights From a Systematic Literature Review
Daria Levaniuk, Bilal Naqvi, Antti Knutas, Muhammad Azeem AkbarABSTRACT
In recent years, developing secure yet usable systems has been one of the top concerns in cybersecurity research and practice. Research indicates that many data breaches and other cybercrimes directed toward exploiting human factors could be prevented by an inclusive and human‐centered cybersecurity design. When it comes to human‐centered design, the use of the persona approach can assist in considering the users' needs and aspirations while designing and developing cybersecurity systems and services. In addition, personas can be useful to mitigate the risks of several attacks, increase security awareness, and also enable a better understanding of hacker behavior by modeling different threat scenarios. We conducted a systematic literature review (SLR) of 63 research articles from 2013 to 2024 across three digital databases (ACM, Scopus, and Web of Science). The study focuses on (1) key persona types proposed in the cybersecurity domain; (2) the areas of cybersecurity in which these personas have been proposed; and (3) opportunities and future directions for utilizing the persona approach to address cybersecurity issues. The findings identified the following four types of security personas: attackers, end‐users, security workers, and others. Further analysis revealed a distribution matrix and a taxonomy presenting security awareness and threat modeling and mitigation as future research directions and opportunities that exist for improvement of the state of the art of social‐media security and privacy, and integrating AI to Cybersec areas. The findings also have implications for practice, including improvements in developmental approaches, training and awareness programs, and increased resilience to cyber‐attacks.