Assessing information security policy compliance: a managerial perspective on leadership and awareness

Purpose Insider non-compliance with information security policies (ISPs) remains a significant organisational risk. This study aims to examine how leadership styles and information security awareness (ISA) dimensions influence employees’ social cognitive beliefs (SCBs) and, ultimately, their information security policy compliance (ISPC) intention. Design/methodology/approach Guided by the theory of planned behaviour (TPB), a quantitative survey was conducted among professionals working in organisations with established ISPs. A total of 205 valid responses were analysed. Findings Attitude was the only TPB construct that significantly predicted ISPC intention. Ethical leadership emerged as the most consistent predictor of employees’ SCBs, whereas transformational leadership positively influenced subjective norms and self-efficacy. Transactional leadership showed no significant effects. Among the ISA dimensions, awareness of the benefits of security countermeasures positively influenced attitude, susceptibility awareness positively influenced self-efficacy and severity awareness negatively influenced self-efficacy. Research limitations/implications Due to the relatively small sample size and the predominance of South African participants, the results may not be fully applicable to larger populations. Practical implications Organisations should prioritise ethical leadership and benefit-oriented security awareness initiatives to strengthen employee compliance intentions. Social implications Leadership and awareness foster a culture of security-conscious employee behaviour. Originality/value This study integrates leadership styles and multidimensional ISA within a TPB framework, demonstrating that leadership and awareness influence ISPC intention through different cognitive pathways and highlighting attitude as the primary driver of compliance intention.

Authors

Institutions

Publication Details

Journal
Information and Computer Security
Published
2026-10-05
DOI
https://doi.org/10.1108/ics-05-2026-0290
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Assessing information security policy compliance: a managerial perspective on leadership and awareness

Keshnee Padayachee, Blessings Sithole
Information and Computer Security
Information and Cyber Security
article

Assessing information security policy compliance: a managerial perspective on leadership and awareness

Keshnee Padayachee, Blessings Sithole
article en

Abstract

Purpose Insider non-compliance with information security policies (ISPs) remains a significant organisational risk. This study aims to examine how leadership styles and information security awareness (ISA) dimensions influence employees’ social cognitive beliefs (SCBs) and, ultimately, their information security policy compliance (ISPC) intention. Design/methodology/approach Guided by the theory of planned behaviour (TPB), a quantitative survey was conducted among professionals working in organisations with established ISPs. A total of 205 valid responses were analysed. Findings Attitude was the only TPB construct that significantly predicted ISPC intention. Ethical leadership emerged as the most consistent predictor of employees’ SCBs, whereas transformational leadership positively influenced subjective norms and self-efficacy. Transactional leadership showed no significant effects. Among the ISA dimensions, awareness of the benefits of security countermeasures positively influenced attitude, susceptibility awareness positively influenced self-efficacy and severity awareness negatively influenced self-efficacy. Research limitations/implications Due to the relatively small sample size and the predominance of South African participants, the results may not be fully applicable to larger populations. Practical implications Organisations should prioritise ethical leadership and benefit-oriented security awareness initiatives to strengthen employee compliance intentions. Social implications Leadership and awareness foster a culture of security-conscious employee behaviour. Originality/value This study integrates leadership styles and multidimensional ISA within a TPB framework, demonstrating that leadership and awareness influence ISPC intention through different cognitive pathways and highlighting attitude as the primary driver of compliance intention.

Information and Computer Security
African Leadership Institute (ZA)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.