Assessing information security policy compliance: a managerial perspective on leadership and awareness
Purpose Insider non-compliance with information security policies (ISPs) remains a significant organisational risk. This study aims to examine how leadership styles and information security awareness (ISA) dimensions influence employees’ social cognitive beliefs (SCBs) and, ultimately, their information security policy compliance (ISPC) intention. Design/methodology/approach Guided by the theory of planned behaviour (TPB), a quantitative survey was conducted among professionals working in organisations with established ISPs. A total of 205 valid responses were analysed. Findings Attitude was the only TPB construct that significantly predicted ISPC intention. Ethical leadership emerged as the most consistent predictor of employees’ SCBs, whereas transformational leadership positively influenced subjective norms and self-efficacy. Transactional leadership showed no significant effects. Among the ISA dimensions, awareness of the benefits of security countermeasures positively influenced attitude, susceptibility awareness positively influenced self-efficacy and severity awareness negatively influenced self-efficacy. Research limitations/implications Due to the relatively small sample size and the predominance of South African participants, the results may not be fully applicable to larger populations. Practical implications Organisations should prioritise ethical leadership and benefit-oriented security awareness initiatives to strengthen employee compliance intentions. Social implications Leadership and awareness foster a culture of security-conscious employee behaviour. Originality/value This study integrates leadership styles and multidimensional ISA within a TPB framework, demonstrating that leadership and awareness influence ISPC intention through different cognitive pathways and highlighting attitude as the primary driver of compliance intention.
Authors
- Keshnee Padayachee (ORCID: https://orcid.org/0000-0001-7056-4723)
- Blessings Sithole (ORCID: https://orcid.org/0009-0009-5235-4963)
Institutions
- African Leadership Institute (ZA)
Publication Details
- Journal
- Information and Computer Security
- Published
- 2026-10-05
- DOI
- https://doi.org/10.1108/ics-05-2026-0290
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00