A Knowledge Management-Driven Framework for Strengthening Social Engineering Awareness in Public Sector Cybersecurity
摘要
Social engineering attacks remain one of the most pervasive cybersecurity threats, exploiting human vulnerabilities rather than technical weaknesses. Despite existing security awareness programs, the lack of structured knowledge retention mechanisms leads to suboptimal long-term awareness. This study introduces the Social Engineering Awareness Model driven by Knowledge Management (SEAM-KM), an AI-integrated framework that enhances cybersecurity resilience through real-time learning mechanisms, knowledge repositories, and structured training programs. A quantitative survey of 150 Malaysian public sector enforcement personnel was conducted, utilizing exploratory factor analysis (EFA), multiple regression modeling, and ANOVA to assess the impact of KM integration on cybersecurity awareness. Results indicate that structured KM-based training significantly enhances knowledge retention (β = 0.52, p < 0.001), threat identification (β = 0.47, p < 0.001), and behavioral adaptation (β = 0.45, p < 0.01). The findings validate the extension of Nonaka and Takeuchi’s SECI Model into cybersecurity, demonstrating that tacit-to-explicit knowledge conversion strengthens proactive defense mechanisms. This study contributes to academia and policy by (i) proposing a scalable KM-driven cybersecurity training model, (ii) providing empirical evidence on AI-enhanced security behavior reinforcement, and (iii) offering strategic recommendations for public sector cybersecurity resilience. Future research should explore longitudinal adoption of SEAM-KM in diverse government agencies, cross-sector validation, and the integration of real-time AI-driven threat monitoring for proactive cybersecurity interventions.