Abstract
Cyber deception can produce high-confidence evidence of unauthorized activity in industrial control systems (ICS) and operational technology (OT), but practitioners must consider the technology useful, safe, understandable, and supported before they will use it. This study reports a secondary quantitative analysis of a deidentified survey of United States-based ICS and OT professionals to determine whether psychological and instructional factors predict adoption readiness and effective utilization beyond education, experience, and sector. Hierarchical ordinary least squares regression with HC3 robust standard errors was conducted on 262 complete cases. The demographics-only model was not significant and explained 2.8 percent of outcome variance. Adding performance expectancy, self-efficacy, direct experience, social influence, instructional support, and security trust increased the explained variance to 64.3 percent. Self-efficacy and direct experience were the strongest unique predictors, followed by instructional support, performance expectancy, and security trust. Social influence was positive in bivariate analysis but was not significant in the full model. The findings indicate that credentials and general experience alone should not be treated as evidence of readiness to use cyber deception in safety-sensitive environments. Cybersecurity programs and workforce initiatives should emphasize hands-on deception laboratories, alert interpretation, role-specific playbooks, and tabletop exercises. Because several constructs were measured with only one or two items and the sample was concentrated in manufacturing, the findings should be interpreted as exploratory and validated with broader-sector samples and multi-item measures.
Included in
Educational Psychology Commons, Information Security Commons, Management Information Systems Commons, Technology and Innovation Commons