Every public-health campaign and every safety brief in the world is built on the same gamble: that a sufficiently scary statistic, repeated loudly enough, will move behavior. Most of those campaigns fail, and they fail in a specific, predictable, mathematically describable way.
Kim Witte’s Extended Parallel Process Model (EPPM) is the theory that explains exactly why. It is the most useful single page in the entire fear-appeal literature: a one-equation diagnostic that tells you, before you spend a dollar, whether your audience will adopt the protective behavior you are recommending or scroll past it while telling themselves a story about why the threat does not apply to them. The equation is one comparison and one rule. The rule has been operating in the background of every cigarette warning label, every COVID-era public service announcement, every cybersecurity training video, and every climate-action ad since 1992. Most teams never noticed.
If you have ever shipped a fear-based message and watched the metrics underperform the business case, EPPM tells you what just happened, and gives you a redesign path. Threat without efficacy is not motivation. It is repression in the technical sense: the audience experiences the fear, then spends their attention defending against the message instead of acting on it. That is not a creative-execution problem. It is a structural problem. EPPM names the structure.
Speed Run Notes
- EPPM is one ratio: Perceived Threat vs Perceived Efficacy. Threat above Efficacy triggers Fear Control (defensive avoidance). Efficacy above Threat triggers Danger Control (protective behavior).
- Most fear campaigns fail not because fear is the wrong lever but because they crank threat without lifting efficacy. That stacks the model toward defensive avoidance instead of protective action.
- The model has four constructs: Severity, Susceptibility, Response Efficacy, Self-Efficacy. Three of the four are coping or efficacy variables. The lopsided architecture is the design clue.
- Witte’s clean separation of two parallel processes (fear control about feelings, danger control about the threat) predicts why audiences who report being “very worried” still take zero action.
- The map: HIGH threat with LOW efficacy = boomerang. HIGH with HIGH = adoption. LOW with LOW = dismissal. LOW with HIGH = capacity sitting unused, waiting for a trigger.
- Octalysis read: efficacy lives in Core Drives 2, 3, and 4 (Accomplishment, Empowerment, Ownership). Threat is one Core Drive (CD8 Loss and Avoidance). The design budget should mirror the model.
In This Article
- What Is the Extended Parallel Process Model?
- Threat Appraisal: Severity and Susceptibility
- Coping Appraisal: Response Efficacy and Self-Efficacy
- The Critical Ratio: Why Fear Backfires
- What Witte Got Right
- Where EPPM Falls Apart
- What’s Really Happening Inside the Brain
- EPPM vs Other Theories
- EPPM in the Real World
- The Elephant in the Room
- How to Apply EPPM with the Octalysis Framework
Author Credibility: Yu-kai Chou

Yu-kai Chou created the Octalysis Framework after studying gamification since 2003, years before the term entered mainstream vocabulary. As a Human-Systems Architect & Behavioral Designer, his framework has been applied by LEGO, Microsoft, Porsche, Coca-Cola, Salesforce, and MrBeast, impacting over 1.5 Billion Users.
Chou has taught the Octalysis methodology at Harvard, Stanford, Yale, Tesla, Google, BCG, and IDEO.
His work has been cited by Harvard, Stanford, MIT, Forbes, Wall Street Journal, Wired, US Department of Energy, NIST, NSF, NCBI, US Department of Education, ClinicalTrials.gov, and Google Scholar — with 3,700+ more academic publications. Explore his books here.
What Is the Extended Parallel Process Model?
The Extended Parallel Process Model (EPPM) was published by communication scholar Kim Witte in 1992 in Communication Monographs. The paper had a specific job. Three previous generations of fear-appeal theories, the drive theory of the 1950s, the parallel response model of the 1970s, and Protection Motivation Theory (PMT) in 1975, had each captured a piece of how fear-based messages worked, and each had drowned in the same contradiction. Sometimes fear produced action. Sometimes it produced apathy. Sometimes it produced active rejection of the message itself. The same campaign that pushed one audience toward the vaccine pushed the next audience into the conspiracy thread. No theory could predict which.
EPPM consolidated the field’s best constructs and added the one move every prior theory had missed: an explicit equation that decides which behavioral pathway gets activated. The equation is the comparison between Perceived Threat and Perceived Efficacy. The pathway is either Danger Control (act on the message) or Fear Control (act on the feeling of fear).
That comparison sounds small. It is the entire model. Once you have it, you can look at any fear-based message and predict what it will do in any audience. Without it, you are designing in the dark and crossing your fingers that the metrics break in your favor.
The two parallel processes
“Parallel” in the model name is doing real work. Witte borrowed it from Howard Leventhal‘s 1970 parallel response model, which proposed that when humans encounter a threat, two cognitive processes run side by side: one evaluates the danger (what is the threat and what should I do about it?), one regulates the emotional response (how do I feel about this and how do I make the feeling go away?). The processes are not sequential and they are not hierarchical. They run in parallel, on different mental tracks, often producing different conclusions.
Danger control is the productive track. It produces what behavioral designers want: a person reading a vaccine ad and going to schedule the appointment, a person reading a phishing warning and double-checking the URL, a person reading a smoking statistic and reaching for the nicotine patch. The behavior tracks the message because the cognitive system has decided the message describes a real threat that the person can do something about.
Fear control is the destructive track. It produces what behavioral designers see when their campaigns underperform: the audience reports being scared, then does nothing, then reports feeling worse about themselves, then in the worst case actively attacks the source of the message. The fear is real. The behavior does not track the message because the cognitive system has decided the easiest way to make the fear stop is to make the message itself less believable.
The destructive nature of fear control is what makes EPPM a high-stakes diagnostic. A campaign that fails by producing no response is wasted money. A campaign that fails by producing fear control is worse than wasted. It leaves the audience more resistant to the next message than they were before the first one was sent.
The model in one sentence
Witte’s structural claim: when an audience perceives a threat, they enter one of three states. If perceived threat is below a minimum activation threshold, they ignore the message (no response). If perceived threat clears the threshold but perceived efficacy is high enough to cover it, they engage in danger control and adopt the recommended behavior. If perceived threat clears the threshold but perceived efficacy is not high enough to cover it, they engage in fear control and reject the message. The ratio is the entire predictor.
Threat Appraisal: Severity and Susceptibility
Threat appraisal in EPPM is the audience’s answer to two questions: how bad is this thing? and how likely is it to happen to me specifically? Witte adopted the two-construct structure from earlier health-behavior theories. The Health Belief Model (HBM) had used these same constructs since 1974. EPPM treats their product as the threat-side input to the model. Either construct at zero zeroes out the entire threat side. A condition with high severity but zero perceived susceptibility (cancers I have never heard of in populations unlike me) does not register as a threat. A condition with high susceptibility but zero perceived severity (a cold I will catch this winter) does not register either. Both have to be present.
Severity: how bad is the consequence?
Severity is the perceived magnitude of harm. The design question is not whether the harm is statistically severe in the data, but whether the audience perceives it as severe in their own model of the world. The distinction matters because severity is constructed, not measured. A young adult reading a heart-disease statistic does not feel the same severity a 55-year-old reads from the same number, and a heart-disease researcher with a parent in cardiac care reads it differently still. Severity is the audience’s read, not the data’s read.
Design moves that lift perceived severity reliably: concrete imagery over abstract statistics, named individual cases over population aggregates, time-anchored consequences (“by 60 you will…”) over open-ended ones, and the explicit articulation of what is lost when the worst case lands. The 2008 Texas-DOT “Drive Sober or Get Pulled Over” campaign and the FDA’s “The Real Cost” anti-tobacco campaign both pushed severity through specific, embodied imagery rather than statistics. The same number told as a different kind of story.
Susceptibility: how likely is it to happen to me?
Susceptibility is perceived personal relevance. It is where most fear campaigns die quietly. The receiver looks at the statistic, agrees that the statistic is bad, and then files the threat under someone else’s problem. That filing decision is susceptibility set to zero, and once susceptibility is zero, perceived threat is zero regardless of how severe the campaign team has made the consequence look.
The susceptibility problem gets worse as the threat gets statistically rarer. A campaign about a high-prevalence threat (seasonal flu, screen time, household sugar consumption) can lean on broad framing because the audience already knows people in the affected set. A campaign about a lower-prevalence threat (a specific cancer, a specific cybersecurity exploit, a specific structural failure mode) has to do the susceptibility work explicitly: name the demographic, name the behavior pattern that puts the audience inside the demographic, and close the loop with “this means you.” Without that step, the most severe statistic in the world bounces off the receiver.
Why severity dominates the popular memory of fear appeals
Walk through the cultural archive of famous fear-based campaigns (the bloody-windshield drink-driving ads, the corpses-with-cigarettes Australian tobacco campaigns, the climate-collapse footage in environmental documentaries) and the common thread is severity, often turned up to a level that audiences described as unwatchable. The campaigns are remembered for severity because severity is the construct that creates the visceral reaction the campaign team measures and the press writes about. The problem is that severity in isolation is exactly the input pattern EPPM predicts will trigger fear control. The Australian and Texan and FDA examples worked when they did because the campaigns paired severity with explicit efficacy moves: a quit-line phone number, a designated-driver app, a real action available now. The campaigns that became known for severity alone and underperformed are the ones the case studies do not write about.
Coping Appraisal: Response Efficacy and Self-Efficacy
Coping appraisal is the audience’s answer to two parallel questions about the recommended behavior: will it actually work? and can I actually do it? Witte took both constructs from Rogers’s 1983 revision of Protection Motivation Theory, which itself had borrowed self-efficacy from Albert Bandura’s 1977 paper. The two are independent: an audience that believes the behavior works but cannot perform it has zero coping appraisal; an audience that can perform a behavior but does not believe it works has the same zero. Both have to clear a threshold for coping appraisal to rise above the threat appraisal in the EPPM ratio.
Response Efficacy: does the recommended behavior actually work?
Response efficacy is the audience’s belief that the recommended action will reduce the threat. This is where most campaign teams get lazy. They assert that the behavior works (“Get vaccinated. It works.”) without doing the cognitive labor of demonstrating it. Assertion is not evidence. Audiences in the post-2020 information environment have been told too many things “work” by parties with conflicts of interest. A campaign that wants response efficacy has to earn it.
The design moves that build response efficacy: specific numbers from credible sources cited inline (“the seatbelt reduces fatal-injury risk by 45% in front-seat occupants, per the National Highway Traffic Safety Administration meta-analysis”), named experts or institutions that the audience already trusts, before-and-after demonstrations where the audience can see the mechanism, and analogies to behaviors the audience already believes work (“flossing prevents gum disease the same way handwashing prevents colds: both interrupt a transmission step”).
The response-efficacy gap is the single most common diagnostic failure across the campaigns I review. Teams design for severity and susceptibility, hit publish, and never measure whether the audience actually believes the recommended behavior is the right tool for the problem. If you only run one survey item against your audience before launching a fear-based campaign, run the response-efficacy item: “Do you believe [recommended action] meaningfully reduces [threat]?” A “no” answer means the campaign is already dead.
Self-Efficacy: can I actually do it?
Self-efficacy is the audience’s belief that they personally have the skill, resources, and access to perform the recommended action. Bandura’s 1977 paper established the construct in clinical psychology; it has shown up in nearly every behavior-change theory since because the construct is so empirically robust that ignoring it is malpractice. A behavior the audience cannot perform, for reasons of cost, time, skill, access, or social cost, does not happen no matter how high response efficacy and threat appraisal are.
Self-efficacy is also the most engineering-friendly construct in the model. Severity and susceptibility live in the audience’s worldview. Response efficacy lives in the audience’s trust map. Self-efficacy lives in the design surface. You can lift it directly: pre-fill the form, schedule the appointment, mail the kit, embed the protective behavior into an existing routine, scaffold the first action into a starter step that takes under five minutes. Every one of those moves is a self-efficacy lift, and every one of them is in the design team’s direct control.
The asymmetry that defines EPPM
Look at the four constructs and one structural feature stands out: three of the four are coping or efficacy variables. Witte’s model has Severity, Susceptibility, Response Efficacy, and Self-Efficacy, and only the first is about threat magnitude. Both halves of the appraisal pair (threat and coping) get equal weight in the ratio, but the cognitive work the audience has to do on the coping side is doubled. The model is telling you, structurally, where the design budget should go. Threat lives in one construct. Coping lives in three. A campaign whose creative budget is 90% threat imagery and 10% coping guidance is upside-down relative to the structure of the theory it claims to be using.
The Critical Ratio: Why Fear Backfires
The ratio is the simplest part of EPPM and the part most teams ignore. Perceived Threat (Severity by Susceptibility) gets compared to Perceived Efficacy (Response Efficacy by Self-Efficacy). The audience’s behavior tracks the comparison, not the absolute level of either side.
The Efficacy-Threat map gives you four quadrants, and three of them are diagnostically interesting.

High Threat with High Efficacy: Danger Control
This is the win condition. The audience reads the message, finds the threat credible and personal, finds the recommended action believable and doable, and engages in danger control. They book the appointment, install the patch, change the password, switch to the new behavior. This is the quadrant every campaign team is aiming at, and it is also the quadrant the design choices have to actively engineer the audience into. The 2008 UK NHS “Catch It. Bin It. Kill It.” flu campaign during the 2009 H1N1 season hit this quadrant by pairing a severe-enough threat (pandemic flu) with a high-efficacy recommendation: three concrete actions, all doable within five seconds, all available at any pharmacy in the country. The Singapore COVID-19 TraceTogether rollout in 2020 hit the same quadrant for the same reason.
High Threat with Low Efficacy: Fear Control
This is the boomerang quadrant, and it is where campaigns built on severity-first creative die. The audience perceives the threat, cannot perceive a credible coping pathway, and resolves the cognitive load by making the threat itself less believable. Defensive avoidance shows up in the data as falling click-through rates, rising unsubscribe rates, hostile open-text feedback, and in worst cases organized counter-messaging from the audience. The Sumatran tsunami-warning communications that ran in the immediate post-2004 period had this problem. The threat was real, the recommended action (“evacuate to higher ground within 15 minutes of feeling an earthquake”) was geographically impossible for most coastal residents to perform, and the audience disengaged from the warning system entirely. Witte and Allen’s 2000 meta-analysis catalogued the same pattern across dozens of public-health campaigns.
Low Threat with Low Efficacy: No Response
This is the cheapest failure. The audience ignores the message. The behavior does not change because the message never registered as worth thinking about. Most awareness-only campaigns live here. The audience can name the threat in a survey item but never gives it enough cognitive load to enter the appraisal process. Awareness is not the same as appraisal. A campaign that has lifted awareness but not threat is a campaign that has not yet entered the EPPM model at all.
Low Threat with High Efficacy: Capacity Sitting Unused
The fourth quadrant is the easy missed opportunity. The audience can perform the protective action with full self-efficacy and high response efficacy, and they have not been motivated to do it because the threat side has not been activated. Routine flu shots, dental check-ups, password-manager adoption, and most “you really should do this” hygiene behaviors live in this quadrant for most audiences most of the time. The design move is not to crank threat globally, that risks pushing the audience into Fear Control, but to add a momentary, situated, personally-relevant cue at the action point. The bank text message that says “Your last login was from a new device” is a low-grade situational threat injected at the moment a high-efficacy action (review or reset password) is one tap away.
Why the ratio, not the absolute level, predicts behavior
The audience does not weigh threat against some abstract calibration of how bad threats are. They weigh threat against their available coping. A moderately severe threat with high efficacy will outperform a catastrophic threat with low efficacy nearly every time. This is the design lesson Witte’s equation hands you for free: when the campaign metrics underperform the business case, the diagnosis almost always lives on the coping side, not the threat side. Coping is the design surface. Threat, once it crosses the activation threshold, is essentially fixed by the topic.
What Witte Got Right
Witte’s 1992 paper made four structural moves that the prior fear-appeal literature had each touched but never integrated. Putting all four in one model is the reason EPPM still earns shelf space in 2026 textbooks instead of joining the discarded drive-reduction models in the history section.
First, the parallel-process framing took fear out of the linear-funnel logic that had dominated the field since the 1950s. Fear is not a switch the audience flips between “calm” and “motivated to act.” Fear runs cognitive evaluation (about the threat) and emotional regulation (about the feeling) at the same time, in parallel, and either pathway can dominate based on the inputs. That two-track architecture is what lets EPPM predict why audiences sometimes feel scared and act, sometimes feel scared and freeze, sometimes feel scared and attack the messenger.
Second, the explicit efficacy-threshold rule turned a literature of competing meta-analyses into a single diagnostic. Before EPPM, papers argued about whether fear appeals worked on average. After EPPM, the right question was whether the audience’s efficacy beliefs cleared their threat beliefs in this specific message in this specific population. Witte’s contribution was not “fear appeals work” or “fear appeals don’t work.” It was the equation that decided which.
Third, integrating self-efficacy gave the model a designable surface. Self-efficacy is the construct in the behavior-change literature that the design team can move most directly. Pre-filled forms, scaffolded first steps, embedded reminders, friction reduction in the protective behavior: all of these are self-efficacy lifts and all of them are inside the design team’s direct control. By putting self-efficacy in the model alongside response efficacy, Witte handed designers a lever that had been missing from the original Protection Motivation Theory specification.
Fourth, the model named and validated fear control as a real behavioral pathway, not a creative failure. Before EPPM, a campaign that produced defensive avoidance was treated as a campaign that “didn’t communicate the threat strongly enough.” Witte’s correction: defensive avoidance is the audience communicating something back, specifically that the threat has overwhelmed the available coping resources. The campaign is not under-threat. It is over-threat relative to its own efficacy provisioning. That reframe changes the entire remediation path.
Where EPPM Falls Apart
EPPM is the best fear-appeal model in the literature. It is also a 1992 model. Three of its limits matter for any team building on it today.
The threshold problem
EPPM tells you that perceived threat has to clear a minimum activation threshold or there is no response, and that perceived efficacy has to clear perceived threat or the audience goes into fear control. The model does not tell you where either threshold sits. The thresholds are population-specific, topic-specific, and culture-specific, and the model offers no method for measuring them other than running the campaign and observing the behavioral outcome. That means EPPM is a strong diagnostic for failures already in progress and a relatively weak predictor before the first message ships. The 2010 So & Popova adaptation tried to formalize the threshold function and produced a more measurable specification, but the field has not yet converged on a standardized instrument.
The flat-construct problem
EPPM treats Severity, Susceptibility, Response Efficacy, and Self-Efficacy as flat constructs with single perceived values. In practice each of the four splits into multiple sub-perceptions that interact non-linearly. Severity for an audience reading about cancer fragments into severity-now (immediate symptoms), severity-then (long-term consequences), severity-to-self vs severity-to-loved-ones, and severity in the abstract vs severity vividly imagined. Self-efficacy fragments into instrumental self-efficacy (do I have the skill), resource self-efficacy (do I have the access), and social self-efficacy (can I do it without losing standing in my social group). Treating each construct as a single number washes out the diagnostic power the model offers. Later refinements, particularly the 2013 Maloney, Lapinski & Witte review, pushed the field toward construct-fragmenting versions of the model, but the canonical 1992 EPPM you find in textbooks is still the flat-construct version.
The temporal-decay problem
EPPM is a snapshot model. It tells you what the audience’s appraisal looks like at the moment of message receipt, and predicts the behavioral response in that moment. It does not have a built-in account of what happens to the appraisal a week later, a month later, a year later. Real protective behaviors require sustained appraisal. The audience has to keep perceiving the threat as credible and the coping as available, and EPPM as published treats sustainment as out of scope. The cybersecurity-training literature is the clearest example of this gap: a fear-based phishing-awareness campaign can hit Danger Control at the moment of training and produce strong post-training behavior, then drift toward Fear Control three months later when the threat has not materialized in the trainee’s inbox and the protective behavior feels like an expensive false alarm. Witte’s model does not predict the drift. The Periodic Training and Reinforcement literature does, but it is bolted on, not native to EPPM.
What’s Really Happening Inside the Brain
EPPM was written in 1992, before functional neuroimaging was routine in social-psychology departments. The model’s two-track architecture has held up well in the subsequent three decades of neuroscience, and the brain mechanisms have given the model a physical substrate it did not have when Witte published.
The threat-detection pathway runs through the amygdala and is largely subcortical. Joseph LeDoux’s work, summarized in his 1996 book The Emotional Brain, traced the “low road” that lets a threat trigger autonomic arousal: heart rate up, attention narrowed, vigilance heightened, before conscious processing has finished. That low road is what makes severity-driven imagery hit so hard. The audience experiences the fear before they have decided what to do with it.
The coping-appraisal pathway runs through prefrontal regions, particularly the ventromedial prefrontal cortex (vmPFC) and the anterior cingulate cortex (ACC). Etkin, Egner, and Kalisch’s 2011 review in Trends in Cognitive Sciences traced the regulatory loop that the prefrontal cortex runs over amygdala-driven threat response. When the prefrontal regulation succeeds, the threat appraisal stays in proportion to the available coping resources, and danger control wins the parallel race. When the prefrontal regulation fails (because cognitive load is too high, because the coping pathway is unclear, because the audience is fatigued or depleted), the amygdala-driven response stays dominant, and the cognitive system reaches for whatever fear-control move is cheapest. The cheapest fear-control move is almost always to deny the message.
The anterior insula adds the interoceptive layer. A. D. Craig’s 2009 review in Nature Reviews Neuroscience located the integration of bodily-state signals (the felt experience of the fear in the chest, the throat, the gut) in the anterior insula and traced how that interoceptive signal feeds back into the appraisal loop. The audience does not just read the fear-based message intellectually; they feel the fear bodily, and the felt experience is itself an input to the next appraisal cycle. This is why severity imagery works on the threat side but also why it overwhelms the coping side so easily. The bodily fear signal is processed faster than the cognitive coping evaluation, and the audience often reaches a fear-control conclusion before they have finished reading the coping recommendation.
The design implication of the neuroscience is the same as the design implication of the model: efficacy has to do more work, faster, than the audience instinctively expects, because it is competing against a faster and physically older threat-processing system. Putting the coping recommendation late in the message, or at small visual scale, or after the audience has already absorbed several seconds of threat imagery, is asking the prefrontal cortex to win a race it is wired to lose.
EPPM vs Other Theories
EPPM is not the only behavior-change theory in the toolkit. Knowing where it sits relative to its closest relatives helps you pick the right tool for the right diagnostic question.
EPPM vs Protection Motivation Theory (PMT)
EPPM is the direct successor to Protection Motivation Theory (Rogers, 1975; revised 1983). Both models share the threat-appraisal by coping-appraisal architecture. The two material differences: PMT was a linear model. Threat appraisal multiplied by coping appraisal produced protection motivation, and protection motivation produced behavior. EPPM made the model non-linear by introducing the threshold rule and the explicit Fear Control pathway. PMT could not predict when a fear appeal would backfire; EPPM can. In practice, PMT is the better model for routine health-behavior contexts where defensive avoidance is rare. EPPM is the better model whenever the campaign is operating on a controversial topic, a politically charged threat, or a population that has been previously fatigued by similar messages, anywhere the audience might reach for a fear-control move.
EPPM vs the Health Belief Model (HBM)
The Health Belief Model (Rosenstock, 1974) shares the severity and susceptibility constructs but lacks the explicit efficacy threshold. HBM treats perceived benefits and perceived barriers as additive inputs to the action decision, where EPPM treats them multiplicatively against the threat side. The practical difference: HBM will tell you which barriers to remove. EPPM will tell you whether removing them is enough. For a campaign designer, HBM is the better tool for diagnosing the barriers; EPPM is the better tool for diagnosing the appraisal ratio. The two models are complementary, not competitive.
EPPM vs the Theory of Planned Behavior (TPB)
The Theory of Planned Behavior (Ajzen, 1991) operates a level upstream of EPPM. TPB predicts behavioral intention from attitudes, subjective norms, and perceived behavioral control. EPPM predicts behavioral pathway selection from threat and efficacy appraisal. If TPB tells you whether the audience plans to take the protective action, EPPM tells you whether the fear-based message will move the plan from intention to behavior or from intention to defensive avoidance. The two compose: TPB gives you the intention forecast, EPPM gives you the message-effect forecast.
EPPM vs Inoculation Theory
Inoculation Theory (McGuire, 1961) is the audience-side resistance model that sits opposite EPPM in the persuasion-vs-resistance pair. Inoculation predicts how to build resistance to future persuasion attempts by exposing the audience to weakened counter-arguments now. EPPM predicts how the audience will respond to a single fear-based attempt. When you are designing a counter-misinformation strategy, both theories are in play: inoculation pre-treats the audience, EPPM evaluates the threat-coping balance of each subsequent message. Used together, they give a campaign team a defensible architecture for long-running fear-based communication.
EPPM in the Real World
The model lives in four high-stakes application surfaces. Each one has a recognizable success pattern and a recognizable failure pattern, and the diagnostic in every case is the same ratio.
Public health
Public health is the model’s home turf. The decades-long anti-tobacco campaigns are the clearest paired example. The “smoking kills” generation of warning labels, graphic lung imagery, mortality statistics, terminal-illness photography, pushed severity hard and was, on average, an EPPM Fear Control failure. Audience smokers reported feeling worse about themselves after exposure and reported smoking the same amount or more. The “Truth” campaign in the United States (1998 onward) and Australia’s “Quit Now” campaign (2010 onward) restructured the efficacy side: every severity moment in the creative was paired with a specific, low-effort, free-of-charge protective action (text-to-quit lines, smartphone apps that tracked the first hour of cessation, peer-support communities). The result was a measurable shift toward Danger Control and a measurable reduction in smoking prevalence in the targeted cohorts. The structure of the change followed the structure of the model.
Cybersecurity
Phishing-awareness training is built on EPPM whether or not the trainers know it. The threat side (organizational data breach, personal identity theft) is severe and increasingly personal; the response-efficacy side (mouse-over the link, check the domain, report suspicious mail) is well-specified; the self-efficacy side is where most programs collapse. Trainees know what they should do, believe it would work, and still do not do it because the in-context cost (pausing a busy workflow to mouse-over a sender domain in a moment of low cognitive availability) feels too high. The cybersecurity training programs that hit Danger Control hardest are the ones that have lowered self-efficacy cost: one-click “report phish” buttons in the mail client, automated link rewriting that reveals destination URLs at hover time, and gamified streaks for clean weeks that recruit Core Drive 2 (Development & Accomplishment) into the maintenance phase.
Climate communication
Climate communication is the field where EPPM has been most consistently violated and where the model’s predictions are most clearly visible in the failure data. Decades of severity-forward climate messaging (sea-level imagery, extinction statistics, doomsday-by-date framing) pushed audiences into Fear Control at scale. The Global Warming’s Six Americas segmentation (Yale Program on Climate Change Communication, 2009 onward) tracked the populations that flipped from “Concerned” to “Disengaged” or “Doubtful” as the severity messaging intensified without proportional efficacy lifts. The campaigns that have moved into Danger Control are the ones that have built up coping appraisal first: Project Drawdown’s solution-catalog framing, the Inflation Reduction Act’s individual-incentive communication strategy, EV-adoption campaigns that lead with charging-network density rather than CO2 statistics. The ratio is the same, the lesson is the same.
Cybercrime and consumer fraud
Bank phishing and romance-scam warnings live in a quadrant where severity is high and susceptibility is variable. The campaigns that work do not crank severity further (the audience already knows scams are devastating); they push susceptibility (“scam attempts targeting people over 55 rose 87% in 2024”) and bolt a one-tap self-efficacy lift onto the immediate moment of risk (“if you got this text, forward it to 7726, your carrier blocks the sender across the network”). The structure mirrors the bank-text-message pattern from the Low Threat with High Efficacy quadrant: situational threat injection at the moment of high-efficacy action availability.
The Elephant in the Room
The honest line about EPPM and the entire fear-appeal literature is the one neither the model nor most textbooks state out loud: fear is a tool whose primary effect is to inflate the importance of the message in the audience’s mind, and a tool whose secondary effect is to inflate the perceived expertise of the messenger. Both effects are mostly invisible in the official literature because both effects look like reasons to use fear-based messaging, and both effects are deeply suspect in any ethical review.
When a campaign team designs a fear appeal, the in-room argument is almost always that the audience needs to feel the gravity of the threat to act. Sometimes that is true. Often it is also true that the campaign team needs the audience to feel the gravity of the threat in order to justify the campaign team’s budget, scope, and continued employment. Severity inflates relevance. Relevance inflates funding. The funding incentive is real, and the literature is mostly silent about it.
The same inflation runs on the messenger side. An expert who delivers a fear-based message is positioned, in the audience’s mind, as the one with the answers, even when the answers are routine and the threat has been overstated. The cybersecurity-vendor-FUD problem (a vendor whose business model depends on customer fear inflating perceived urgency above the technical reality) is the cleanest visible case. Public-health communications and climate communications run versions of the same dynamic, less visibly.
EPPM does not solve the ethical problem. What EPPM does do is force the campaign team to do the coping work as honestly as the threat work, and a campaign that has done the coping work honestly is much harder to weaponize. If the protective behavior is real, available, and self-evidently effective, the audience does not need the fear cranked to act. A campaign team that finds itself relying on severity escalation to drive action is, in EPPM terms, a team whose coping side is undercooked. The model points at the structural fix and at the ethical check simultaneously: strengthen the coping side until severity escalation is no longer the lever you are reaching for.
How to Apply EPPM with the Octalysis Framework
The Octalysis Framework gives EPPM a design surface. EPPM names the appraisal constructs; Octalysis names the motivational engines that move each one. The mapping below is the unique-to-Yu-kai design contribution: a per-Core-Drive read of which EPPM construct each Core Drive activates, plus a six-step audit that turns the model into a planning instrument.
Core Drive 8 (CD8): Loss & Avoidance, the threat-appraisal engine
Core Drive 8 is the canonical threat-side recruitment driver. Severity and susceptibility both live in CD8 territory. The calibration test for CD8 in an EPPM context: the receiver leaves the message thinking about the protective action, not about how to neutralize the message. If they cannot articulate the recommended action they have not engaged in danger control; if they can articulate it but disbelieve it they are already in fear control. CD8 is necessary for any fear-based message to clear the threat threshold, and CD8 is dangerous to lean on past the point where coping appraisal can keep up.
Core Drive 2 (CD2): Development & Accomplishment, the response-efficacy engine
Response efficacy lifts when the audience can do the math themselves. CD2 design surfaces (progress indicators, before/after demonstrations, measurable feedback, trusted third-party validation) are the way the campaign earns the response-efficacy belief instead of asserting it. The most common design error is asserting response efficacy through repetition (“It works. It really works.”) instead of demonstrating it through evidence. CD2 builds when the receiver can verify the claim, not when the campaign repeats it.
Core Drive 4 (CD4): Ownership & Possession, the self-efficacy engine
Self-efficacy is a CD4 design surface. Make the receiver the protagonist of the protective behavior. Scaffold the action into a starter step takeable in under five minutes. Make prior small wins visible. Give the protective behavior the texture of an asset the receiver is building, not a task the campaign is imposing. The smoking-cessation apps that won the EPPM Danger Control quadrant in the 2010s all leaned on CD4 in the maintenance phase: streak counters, savings dashboards, lung-recovery visualizations that turned the absence of smoking into a visible asset accumulating in the receiver’s account.
Core Drive 3 (CD3): Empowerment of Creativity & Feedback, the response-cost engine
Response cost is the friction in the way of the protective action. CD3 in EPPM mode means subtractive design: pre-fill the form, schedule the appointment, mail the kit, automate the recurring action, embed the protective behavior into an existing routine. Every step of friction removed lifts both response efficacy (“the campaign clearly believes this works enough to make it easy”) and self-efficacy (“I can do this; the path is already clear”). The cybersecurity training programs that moved trainees into Danger Control did it by collapsing the response-cost gap to a single button. CD3 plus CD4 together carry most of the coping side of the appraisal ratio.
Core Drive 5 (CD5): Social Influence & Relatedness, the susceptibility engine
Susceptibility moves when the audience sees people they identify with experiencing the threat. CD5 in EPPM is the social-proof move on the threat side: peer testimonials, identity-matched case studies, descriptive-norm framing (“87% of users in your role experienced an attempted phishing attack last quarter”). The CD5 design move on susceptibility is the one most often skipped by campaign teams who lean on data without sourcing the data from the audience’s own reference class. A statistic about “Americans over 65” does not move susceptibility for a 67-year-old in Phoenix unless the campaign closes the loop and shows other 67-year-olds in Phoenix being affected.
Core Drive 1 (CD1): Epic Meaning & Calling, the message-source-credibility engine
Source credibility runs underneath the entire EPPM appraisal. An audience that does not trust the messenger does not engage in either threat or coping appraisal at face value. CD1 in EPPM means anchoring the campaign in a mission the audience already believes in. Public-health agencies that pre-existing audience trust enjoy a structural EPPM advantage over commercial actors making the same claim. Brands that fund fear-based campaigns without first building CD1-grade institutional credibility are paying the messenger-trust tax and seeing the appraisal ratio compress on both sides.
Core Drive 7 (CD7): Unpredictability & Curiosity, the attentional-on-ramp engine
Threat-based messages have to clear the attentional gate before the appraisal model fires at all. CD7 design moves (narrative open loops, unexpected framings, pattern interrupts) buy the first three seconds of cognitive load that the rest of the message needs to do its work. CD7 is not part of the EPPM appraisal itself, but it is what gets the message into the cognitive workspace where EPPM can operate.
The EPPM x Octalysis Audit (six steps)
The audit turns the per-Core-Drive map into a planning instrument. It is the same diagnostic shape as the audits for Protection Motivation Theory and the Behavior Change Wheel, adapted to the EPPM construct set.
- Specify the protective behavior at TACT resolution (Target, Action, Context, Time). “Adults aged 18 to 34 in the United States get a single seasonal flu shot at a pharmacy by November 15.” A behavior specified at less than TACT resolution cannot have its EPPM constructs measured.
- Baseline-measure all four EPPM constructs in the target population: severity, susceptibility, response efficacy, self-efficacy. Use survey items if you have a research budget. Use behavioral proxies (search-volume diagnostics, customer-support transcripts, pre-test focus groups) if you do not. Do not assume any construct.
- Identify the bottleneck appraisal pathway. In the published meta-analytic record (Floyd, Prentice-Dunn & Rogers 2000; Witte & Allen 2000) the bottleneck is on the coping side in roughly 90% of campaigns. If you are confident the bottleneck is on the threat side, double-check the measurement.
- Assign Core Drive design surfaces to each construct gap. Threat gap, CD8 plus CD5. Response-efficacy gap, CD2. Self-efficacy gap, CD3 plus CD4. Source-credibility gap, CD1. Attentional gap, CD7. The lopsided structure of the EPPM constructs means the design surface mix should also be lopsided toward coping.
- Run the maladaptive-rewards inventory. Borrowed from Rogers’s 1983 Protection Motivation Theory revision: what does the audience currently get from the unprotective behavior? CD5 community? CD7 stress relief? CD8 short-term loss avoidance? Decide replace/substitute/accept-loss for each reward. A campaign that ignores the maladaptive-rewards inventory is asking the audience to accept a net-loss of motivational currency on switching to the protective behavior, and the campaign will fail in the second adoption month even if it wins the first one.
- Pilot at smallest viable scale that separates Danger Control outcomes from Fear Control outcomes. Engagement is not behavior. Self-reported worry is not behavior change. A campaign that has lifted “concern” without lifting protective behavior is a campaign that has moved the audience into the Fear Control quadrant under a friendlier name. Measure the protective behavior directly.
The audit is positioned as the difference between an EPPM-grounded campaign and a fear-appeal campaign that calls itself EPPM-grounded. Most campaigns in the second category violate steps 2, 3, and 5.
Practical Steps: A Designer’s Checklist Before You Ship
- Write down the protective behavior in one sentence at TACT resolution. If you cannot, your campaign does not yet have a target outcome.
- Survey the audience on response efficacy specifically. Single item: “Do you believe [recommended action] meaningfully reduces [threat]?” A “no” majority means the campaign is dead on arrival; rebuild the response-efficacy case before touching the creative.
- Audit your creative budget against the construct structure. If more than 60% of the creative real estate is threat imagery, the campaign is structurally upside down. Rebalance toward coping or expect Fear Control.
- Make the protective action available within the message. A one-tap, one-click, one-call action attached directly to the moment of message exposure outperforms a deferred action by a wide margin in every measured population.
- Run the maladaptive-rewards inventory before approving the creative. If the audience gives up CD5 community or CD7 stress relief on switching to the protective behavior, design a substitute. If you cannot, downscope the campaign.
- Build a measurement loop that separates engagement from behavior. Click-through, time on page, and self-reported concern are all leading indicators of Fear Control. Protective behavior adoption is the only metric that confirms Danger Control.
- Schedule a six-week and a six-month re-measurement. EPPM is a snapshot model and the temporal-decay problem is real. A campaign that hits Danger Control at week one and Fear Control at month three has not yet succeeded.
EPPM Was the Beginning, Not the End
Witte handed the field a single equation and a clear test. Three decades later, the equation still holds. What the equation does not do is design the message for you. The construct definitions are 1992-era. The threshold function is unspecified. The temporal model is missing. The honest read of EPPM is that it is the best diagnostic we have for fear-based communication and the worst place to stop your design thinking.
Use it for the diagnostic and bring the rest of your toolkit to the design. Pair EPPM with the Octalysis Framework for the design surface. Pair it with the Behavior Change Wheel for the intervention selection. Pair it with Inoculation Theory for the resistance map. Pair it with the Six Americas segmentation if you are working in climate. Pair it with the cybersecurity reinforcement literature if you are working in security training. The model is a diagnostic, not a complete behavior-change architecture, and treating it as the latter is how teams ship campaigns that test cleanly in the appraisal survey and fail in the field.
Witte’s gift to the field was the equation. The remaining work belongs to the designer.
Frequently Asked Questions
Is EPPM the same as Protection Motivation Theory?
No. EPPM is the direct successor and shares the threat-appraisal by coping-appraisal architecture, but EPPM adds two structural moves PMT did not have: a minimum-threat activation threshold and an explicit Fear Control pathway that PMT could not predict. PMT will tell you the protection motivation level; EPPM will tell you whether the message will produce protective behavior or defensive avoidance at that level.
Does EPPM say fear appeals do not work?
No. EPPM says fear appeals work when perceived efficacy clears perceived threat and fail when it does not. The model is not anti-fear; it is anti-undercooked-coping. A campaign with strong coping appraisal and a moderate threat appraisal outperforms a campaign with weak coping appraisal and a catastrophic threat appraisal in nearly every published comparison.
How much fear is the right amount?
The wrong question. EPPM does not specify an absolute fear level. It specifies a ratio. The right amount of fear is the amount that crosses the audience’s activation threshold while staying below the audience’s coping ceiling. Both thresholds are population-specific and topic-specific. The only reliable method is to baseline-measure the constructs in the target population before designing the creative.
Can EPPM predict campaign success before launch?
Partially. With baseline measurements of all four constructs in the target population, EPPM gives you a strong prediction of pathway selection. Without the baseline measurements, EPPM gives you a diagnostic framework for explaining what went wrong after the fact. The model is more powerful as a pre-launch design instrument than the field generally treats it.
What is the single most common design error in fear-based campaigns?
Asserting response efficacy instead of demonstrating it. Campaign teams tell the audience the recommended action works and assume the audience will believe them. EPPM and the post-2020 trust environment both say the audience will not. Response efficacy has to be earned through specific numbers, credible sources, and demonstrable mechanism, not asserted through repetition.
Does EPPM apply to non-health contexts?
Yes. The model has been validated in cybersecurity training, financial-fraud prevention, climate communication, organizational safety communication, and political-persuasion contexts. The constructs are domain-general; the thresholds are domain-specific. Any communication that recruits CD8 Loss & Avoidance and asks the audience to adopt a protective behavior is in EPPM territory.
What happens if perceived threat is extremely high and perceived efficacy is also extremely high?
You get strong, durable Danger Control. The published cases of campaign success at the extreme of both constructs (the UK NHS pandemic-flu communication, the Singapore TraceTogether rollout, the strongest anti-tobacco quitline campaigns) all hit the High by High quadrant and produced behavior change durable past the campaign window. The risk is overshooting threat past the coping ceiling, which is why the constructs should be measured before the creative is finalized.
How is EPPM different from nudging?
Nudging (Thaler & Sunstein, 2008) operates on choice architecture without changing appraisal. It makes the protective behavior easier or more likely without lifting the audience’s perceived threat or perceived efficacy. EPPM operates on appraisal. The two are complementary: a well-designed campaign uses EPPM to design the message and nudge-style choice architecture to lower the response-cost barrier at the moment of action. Sludge, Sunstein’s 2022 model of friction that impedes beneficial action, is the inverse problem and lives in the same toolkit.
What’s the relationship between EPPM and behavioral fatigue?
EPPM is the snapshot model; behavioral fatigue is the temporal-decay problem the snapshot model does not address. An audience repeatedly exposed to high-threat, moderate-efficacy messages over a long period drifts toward Fear Control even when each individual message would have produced Danger Control in isolation. The fatigue is a coping-side resource depletion, not a threat-side desensitization. The remediation is to lift coping appraisal (often via CD3 friction reduction and CD4 ownership), not to crank threat further.
If I can run only one survey item before launch, what should I measure?
Response efficacy. “Do you believe [recommended action] meaningfully reduces [threat]?” A negative-majority answer means the campaign is structurally dead before the creative has been seen. Threat appraisal is fixed by the topic; coping appraisal is where the campaign lives or dies. Response efficacy is the single highest-leverage construct in the model.
References
- Witte, K. (1992). Putting the fear back into fear appeals: The extended parallel process model. Communication Monographs, 59(4), 329 to 349. Canonical EPPM paper introducing the appraisal threshold plus Fear Control / Danger Control distinction.
- Witte, K., & Allen, M. (2000). A meta-analysis of fear appeals: Implications for effective public health campaigns. Health Education & Behavior, 27(5), 591 to 615. Foundational empirical synthesis confirming EPPM predictions across 100+ studies.
- Witte, K. (1994). Fear control and danger control: A test of the Extended Parallel Process Model. Communication Monographs, 61(2), 113 to 134. First experimental validation of the parallel-pathway claim.
- Leventhal, H. (1970). Findings and theory in the study of fear communications. In L. Berkowitz (Ed.), Advances in Experimental Social Psychology, Vol. 5 (pp. 119 to 186). Academic Press. The original parallel-response model EPPM extended.
- Rogers, R. W. (1975). A Protection Motivation Theory of fear appeals and attitude change. Journal of Psychology, 91(1), 93 to 114. Direct predecessor with the threat by coping appraisal structure.
- Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. T. Cacioppo & R. E. Petty (Eds.), Social Psychophysiology (pp. 153 to 176). Guilford Press. Revision adding self-efficacy and maladaptive rewards.
- Floyd, D. L., Prentice-Dunn, S., & Rogers, R. W. (2000). A meta-analysis of research on Protection Motivation Theory. Journal of Applied Social Psychology, 30(2), 407 to 429. 65-study meta-analysis establishing the coping-over-threat empirical pattern.
- Bandura, A. (1977). Self-efficacy: Toward a unifying theory of behavioral change. Psychological Review, 84(2), 191 to 215. Self-efficacy origin paper.
- Rosenstock, I. M. (1974). Historical origins of the Health Belief Model. Health Education Monographs, 2(4), 328 to 335. HBM canonical reference with the severity / susceptibility constructs EPPM inherited.
- Maloney, E. K., Lapinski, M. K., & Witte, K. (2011). Fear appeals and persuasion: A review and update of the Extended Parallel Process Model. Social and Personality Psychology Compass, 5(4), 206 to 219. Modern review and theoretical update.
- So, J. (2013). A further extension of the Extended Parallel Process Model (E-EPPM): Implications of cognitive appraisal theory of emotion. Health Communication, 28(1), 72 to 83. Threshold-function specification work.
- Popova, L. (2012). The Extended Parallel Process Model: Illuminating the gaps in research. Health Education & Behavior, 39(4), 455 to 473. Comprehensive critique and gap analysis.
- Ajzen, I. (1991). The theory of planned behavior. Organizational Behavior and Human Decision Processes, 50(2), 179 to 211. TPB canonical reference.
- Fogg, B. J. (2009). A behavior model for persuasive design. Proceedings of the 4th International Conference on Persuasive Technology. B=MAP model often used alongside EPPM.
- LeDoux, J. (1996). The Emotional Brain: The Mysterious Underpinnings of Emotional Life. Simon & Schuster. Amygdala-driven low road for threat processing.
- Etkin, A., Egner, T., & Kalisch, R. (2011). Emotional processing in anterior cingulate and medial prefrontal cortex. Trends in Cognitive Sciences, 15(2), 85 to 93. Prefrontal regulation of amygdala threat response.
- Craig, A. D. (2009). How do you feel, now? The anterior insula and human awareness. Nature Reviews Neuroscience, 10(1), 59 to 70. Interoceptive integration of bodily fear signals.
- Sunstein, C. R. (2022). Sludge: What Stops Us from Getting Things Done and What to Do about It. MIT Press. The friction-on-beneficial-action mirror of nudge.
- Thaler, R. H., & Sunstein, C. R. (2008). Nudge: Improving Decisions About Health, Wealth, and Happiness. Yale University Press. Choice-architecture complement to EPPM design moves.
- Chou, Y.-K. (2015). Actionable Gamification: Beyond Points, Badges, and Leaderboards. Octalysis Media. Octalysis Framework canonical reference for the per-Core-Drive EPPM design surface mapping.
Related Reading
- The Octalysis Framework: the eight Core Drives that pair with each EPPM construct.
- The Behavioral Framework Library: the full library of behavioral models in the Yu-kai canon.
- Protection Motivation Theory: EPPM’s direct predecessor, with the original threat-coping architecture.
- The Health Belief Model: origin of the severity and susceptibility constructs EPPM uses.
- Inoculation Theory: the audience-side resistance pair to EPPM’s threat-side appraisal.
- COM-B and the Behavior Change Wheel: the diagnostic upstream of any behavior-change campaign.
- Sludge: the friction-on-beneficial-action concept that maps to EPPM response cost.



