How attitude, shared tacit assumptions, espoused values, subjective norms, behavioural intention and knowledge influence information security culture

Abstract Threat vectors to information assets of firms continue to multiply especially with rapid advances in ICT capabilities. Financial services firms are one of the prime targets of information security breaches because of the increased probability of the miscreants realising pecuniary benefits. The cultivation of information security culture is viewed as the most effective safeguard of warding off information security breaches. This study examined the impact that knowledge, attitude, shared tacit assumptions, subjective norms, espoused values and behavioural intention exert on financial services information security culture. The study’s participants were drawn from four financial services firms in Zimbabwe. The questions that constituted the questionnaire that was sent to the respondents were derived from the extent literature on information security culture. The regression analysis performed on the responses to the questionnaire showed that knowledge, attitude, subjective norms, shared tacit assumptions and behavioural intention are all significant predictors of financial services information security culture. However, the study established that espoused values are not a significant predictor of financial services information security culture. The study suggested that financial services should leverage the constructs that the study established to be significant predictors of financial services information security culture especially improving their employees’ information security knowledge and attitudes which in turn influence the other constructs.

Authors

Institutions

Publication Details

Journal
International Journal of Information Security
Published
2026-09-18
DOI
https://doi.org/10.1007/s10207-025-01134-9
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

How attitude, shared tacit assumptions, espoused values, subjective norms, behavioural intention and knowledge influence information security culture

Annelie Jordaan, Joseph Mupokosera
International Journal of Information Security
Information and Cyber Security
article

How attitude, shared tacit assumptions, espoused values, subjective norms, behavioural intention and knowledge influence information security culture

Annelie Jordaan, Joseph Mupokosera
article en

Abstract

Abstract Threat vectors to information assets of firms continue to multiply especially with rapid advances in ICT capabilities. Financial services firms are one of the prime targets of information security breaches because of the increased probability of the miscreants realising pecuniary benefits. The cultivation of information security culture is viewed as the most effective safeguard of warding off information security breaches. This study examined the impact that knowledge, attitude, shared tacit assumptions, subjective norms, espoused values and behavioural intention exert on financial services information security culture. The study’s participants were drawn from four financial services firms in Zimbabwe. The questions that constituted the questionnaire that was sent to the respondents were derived from the extent literature on information security culture. The regression analysis performed on the responses to the questionnaire showed that knowledge, attitude, subjective norms, shared tacit assumptions and behavioural intention are all significant predictors of financial services information security culture. However, the study established that espoused values are not a significant predictor of financial services information security culture. The study suggested that financial services should leverage the constructs that the study established to be significant predictors of financial services information security culture especially improving their employees’ information security knowledge and attitudes which in turn influence the other constructs.

International Journal of Information SecurityVol. 25(5)
Vaal University of Technology (ZA), Tshwane University of Technology (ZA)
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

How attitude, shared tacit assumptions, espoused values, subjective norms, behavioural intention and knowledge influence information security culture — Annelie Jordaan, Joseph Mupokosera · International Journal of Information Security (2026) | TGRS Research Map | TGRS