Question
What does the 2025 "Signal-Leak" affair illustrate about the human factor in information security?
Answer
Even at the highest security level, humans bypass approved channels for convenience — top US officials discussed an imminent military strike in a Signal group chat that accidentally included a journalist.
The case: members of the US administration (including the Secretary of Defense) coordinated military strike details — launch times, weapons platforms, targets — in a consumer messaging app, and a journalist had accidentally been added to the group. The Pentagon launched an investigation.
Why it's the perfect human-factor case study:
- No technology failed. Signal's encryption worked exactly as designed. The breach was 100% human behavior: wrong tool for the classification level, no membership verification, convenience over procedure.
- Hierarchy is no protection — these were principals with maximal clearance and maximal training. Awareness is not solved by seniority.
- Shadow IT at the top: choosing a handy unofficial channel over cumbersome official ones is exactly what employees everywhere do when secure processes have high friction (→ Handlungskosten, in PMT terms).
Tip: Use cases like this in awareness campaigns — real, recent, prominent incidents make threats real (Bedrohung real machen) far better than abstract warnings.
Go deeper:
Social engineering (security) — Wikipedia — Wie menschliche Schwächen statt Technik ausgenutzt werden; der Signal-Leak ist ein rein menschlicher Fehlgriff.
Note saved — thanks!
Question
What is the Protection Motivation Theory (PMT), and which two appraisal processes does it describe?
Answer
PMT (Rogers, 1975) says our protective behavior results from two unconscious evaluations: a threat appraisal ("how dangerous is this really?") and a coping appraisal ("can I do something about it — and can I pull it off?").
* PMT: a threat appraisal and a coping appraisal each combine their factors, feed Protection Motivation, and result in protective behaviour. *
The model:
- Bedrohungseinschätzung (threat appraisal) — evaluating the danger itself
- Bewältigungseinschätzung (coping appraisal) — evaluating my options against it
- Schutzmotivation (protection motivation) — the result of both processes: my intention to act (or not act) protectively
Originally developed to explain how fear appeals change attitudes (health campaigns: smoking, seatbelts), PMT became the standard model for security behavior: why do people ignore warnings, skip updates, or click phishing links? Because either the threat doesn't feel real to them, or they don't believe they can cope with it.
Tip: Remember the two questions verbatim — "Wie gefährlich ist das wirklich?" and "Was kann ich dagegen tun und schaffe ich das?" Every awareness measure should move the answer to at least one of them.
Go deeper:
Protection motivation theory — Wikipedia — Rogers Modell (1975/1983) mit Threat- und Coping-Appraisal, auch in der Informationssicherheit.
Note saved — thanks!