The Human Component of Information Security: A Review of Predictors of Cybersecurity Policy Compliance

8 min read
September 11, 2026

By Nick Dinesh

Introduction

In the current digital era, organizational security has shifted from the server room to the individual workstation. While technical defenses such as sophisticated firewalls, multi-factor authentication, and automated intrusion detection systems remain essential. Technical controls aren’t totally sufficient to guarantee protection against modern cyber threats. Recent empirical evidence suggests a staggering reality: human behavior is a factor in approximately 74 percent of all data breaches (Greavu-Şerban et al., 2025). This statistic has shifted the scholarly conversation from a purely technocentric focus to a human centric paradigm. In this new view, the employee is seen either as the weakest link or, more optimistically, as a human firewall.

The need for this research lies in the persistent security paradox. This is a phenomenon where employees demonstrate high levels of security awareness yet continue to engage in risky digital behaviors. To address this, scholars have turned to complex behavioral models to understand the drivers of Information Security Policy (ISP) compliance. This literature review synthesizes current and past research to argue that the scholarly conversation is no longer debating whether the human factor matters, but rather how psychological, organizational, and cognitive variables interact to determine compliance. The following sections explore the state of this conversation through four primary themes: the foundational role of psychological theories, the influence of organizational culture and leadership, the evolving dimensions of cybersecurity awareness, and the disruptive impact of cognitive heuristics and biases.

Foundational Psychological Theories (PMT, TPB, and OCT)

At the core of the current research into cybersecurity behavior are three dominant psychological frameworks: Protection Motivation Theory (PMT), the Theory of Planned Behavior (TPB), and Operant Conditioning Theory (OCT). Scholars increasingly utilize integrated models that combine these theories to provide a more holistic understanding of employee intentions.

Protection Motivation Theory (PMT) is arguably the most frequently cited framework in the articles that made up this review. It posits that individuals protect themselves based on two cognitive appraisals: threat appraisal and coping appraisal. Li et al. (2019) explain that "Protection Motivation Theory (PMT) provides a robust framework for understanding how employees' threat and coping appraisals and influence their cybersecurity behavior". Under threat appraisal, employees evaluate the perceived severity of a cyberattack and their perceived vulnerability to it. However, high threat appraisal alone does not guarantee compliance. Coping appraisal, which consists of self-efficacy (the belief in one's ability to perform the security task) and response efficacy (the belief that the task actually works), must also be present. If an employee feels a threat is severe but believes the security measures are too difficult to implement, they may experience a paralysis that leads to non-compliance.

Complementing PMT is the Theory of Planned Behavior (TPB), which focuses on the precursors to behavioral intention. Ghaleb and Pardaev (2025) find that "attitudes and perceived behavioral control are the strongest predictors of information security compliance behavior". TPB suggests that an employee’s intention to follow an Information Security Protocol (ISP) is driven by their attitude toward the policy, the subjective norms (peer pressure), and their perceived control over the situation. This theory ties directly into the organizational theme because subjective norms are heavily influenced by the professional environment.

Finally, Operant Conditioning Theory (OCT) introduces the role of external consequences. Alshammari and Al-Mamary (2025) note that "the integrated model, combining TPB, PMT, and OCT, provides a comprehensive view," specifically identifying that perceived punishment and reinforcement are key drivers of compliance. This suggests that while internal motivation (PMT) is vital, the organizational "carrot and stick" approach remains a necessary component of policy enforcement. The scholarly consensus suggests that these theories do not operate in isolation. Instead, PMT provides the internal motivation, TPB shapes the social intention, and OCT provides the external structure that guides behavior.

Organizational Culture and Leadership

If psychological theories provide the internal mechanics of compliance, organizational culture and leadership provide the fuel. The literature consistently identifies the environment as a moderating factor that can either activate or suppress an employee’s motivation to follow security protocols.

A recurring sub-theme in the research is the importance of top management support. Delso-Vicente et al. (2025) emphasize that "top management support and a security-first culture are pivotal in fostering an environment where compliance is the norm". When leadership views cybersecurity as a core business value rather than an IT burden, employees are more likely to internalize those values. This process is often facilitated by trust.

Ghaleb and Pardaev (2025) argue that "trust in senior management acts as a mediator," ensuring that the intended organizational culture translates into the individual’s daily habits. If employees do not trust that their leaders have their best interests in mind, they may view restrictive ISPs as a sign of micromanagement rather than protection.

Furthermore, the research explores the Psychological Contract, which refers to the unwritten, reciprocal expectations between an employee and their employer. Foroudi and Fakhreddin (2026) state that "fulfilling ideological psychological contracts fosters Organizational Citizenship Behavior (OCB)," which correlates with higher levels of security vigilance. In this context, cybersecurity is seen as a voluntary act of good citizenship rather than a forced chore. When the organization fulfills its promises (such as providing resources, well-being, and a positive climate), employees reciprocate by protecting the organization's digital assets.

Social influence, or subjective norms, also plays a critical role. Alshammari and Al-Mamary (2025) describe this as "the perceived social pressure from important others like supervisors and peers". Li et al. (2019) reinforce this by stating that "peer behavior serves as an important cue to action". If an employee observes their respected colleagues bypassing security rules to save time, they are likely to adopt the same behavior, regardless of their individual training. This suggests that culture is not just what is written in the policy, but what is practiced in the workplace every day. Or rather, “Monkey see, monkey do.”

Multi-Dimensional Cybersecurity Awareness

The scholarly conversation has moved beyond viewing awareness as a binary state of knowing or not knowing a policy. Contemporary researchers argue that awareness is a multi-dimensional competency that must be developed across several domains.

Ünsal and Ocak (2026) contribute significantly to this theme by developing the Organizational Cybersecurity Awareness Scale (OCAS). Their research identifies four distinct dimensions of awareness: (1) Personal Awareness and Proactive Approach, (2) Legal and Regulatory Awareness, (3) Technical Protection and Implementation, and (4) Organizational Policy Awareness. This model suggests that an employee might be highly aware of organizational policies but lack the technical protection skills to implement them. Similarly, they may understand the technical aspects but lack the legal awareness to understand the consequences of a breach.

In the context of Micro, Small, and Medium Enterprises (MSMEs), the stakes of awareness are particularly high. Ye (2026) found that "cybersecurity awareness was the strongest predictor of management effectiveness". This is critical because MSMEs often lack the financial resources to implement expensive technical controls. In these environments, awareness acts as a resource-based advantage. However, Ye (2026) also highlights that "economic constraints exert a significant adverse effect on security management," creating a tension where employees must do more with less.

The goal of this multi-dimensional awareness is to build competence. Li et al. (2019) note that "when employees are aware of their company’s information security policy and procedures, they are more competent in managing their security tasks". However, the literature also warns of the knowing-doing gap. Delso-Vicente et al. (2025) observe that "awareness alone is insufficient to guarantee secure behavior without continuous reinforcement". This gap leads directly into the fourth theme, which covers the cognitive limitations that prevent even the most aware employees from acting securely.

Heuristics, Cognitive Biases, and the Security Paradox

The most significant disruptor in the relationship between awareness and compliance is the inherent nature of human cognition. Despite knowing the rules (awareness) and having the motivation (psychological theories) and the environment (culture), employees still fall victim to cyberattacks due to heuristics and cognitive biases.

Greavu-Şerban et al. (2025) utilize dual-process theory to explain this phenomenon, noting that "users often rely on System 1 (intuitive) thinking rather than System 2 (analytical)". System 1 is fast, automatic, and emotional, while System 2 is slow, effortful, and logical. Most cybersecurity training targets System 2, but in high-pressure workplace environments, System 1 often takes control. This makes employees susceptible to social engineering attacks that exploit heuristics such as urgency, authority, and liking. For instance, an employee may instinctively click a malicious link in an email that appears to come from the CEO and requires immediate action, even if they have been trained to check the sender's address and consider if the tone of the email matches the sender’s.

This cognitive override creates what researchers call the Cybersecurity Paradox. Greavu-Şerban et al. (2025) explain that "risk awareness influences protective behaviors, but a security paradox remains; many users recognize risks yet fail to act accordingly". This paradox is further compounded by perceived barriers. As Li et al. (2019) suggest, if security measures are perceived as too time-consuming, employees will find a shortcut that is good enough for productivity but insufficient for security. Such as downloading sensitive documents to insecure personal devices, or inserting unknown USB drives into company laptops.

Ye (2026) also notes this paradox in the context of MSMEs, describing it as a struggle between balancing technology, costs, and compliance. In these scenarios, the cognitive load of managing complex security protocols while simultaneously meeting high performance targets leads to decision fatigue. When cognitive resources are depleted, employees are more likely to default to risky, heuristic-driven behaviors. The consensus among scholars is that security systems must be designed to be error-tolerant and account for the fact that System 1 thinking is the human default. “Cybersecurity effectiveness in MSMEs emerges not from high-end investments but from feasible, context-sensitive combinations of awareness, governance, baseline technology readiness, and compliance.” Ye (2026)

Conclusion

The synthesis of these eight sources reveals a complex, multi-layered answer to the question of what drives cybersecurity policy compliance. Compliance is not a simple byproduct of technical implementation or basic training; it is a behavioral output determined by the alignment of psychological motivation, organizational trust, multi-dimensional awareness, and cognitive capacity.

To summarize the current state of the scholarly conversation, psychological theories like PMT and TPB prove that internal appraisals of threat and self-efficacy are the primary movers of intention. Organizational culture and leadership trust act as the environment that either fosters or inhibits these psychological motivations. Awareness must be broad and competency based, particularly in resource-constrained MSMEs, to be effective. Finally, cognitive biases serve as the primary interference, often causing a break in the chain between awareness and action.

While the literature has made significant strides in mapping these connections, several research gaps remain. First, there is a need for more longitudinal studies to determine how continuous reinforcement (Delso-Vicente et al., 2025) actually changes System 1 habits over time. Second, as Foroudi and Fakhreddin (2026) point out, the rapid adoption of Artificial Intelligence (AI) in the workplace introduces new uncertainties that may disrupt existing psychological contracts and introduce novel social engineering vulnerabilities. Finally, while scale development for public institutions (Ünsal & Ocak, 2026) is a vital step, more research is required to understand how these behavioral models apply across diverse global cultures and the shift toward remote work. Future research should prioritize security by design approaches that utilize behavioral nudges to make the secure choice the easiest choice for the intuitive human mind. Some may refer to this as “idiot proofing”, but the vast majority of human thought is automatic, so systems must be designed around this reality instead of relying on false assumptions.

References

Alshammari, M. M., & Al-Mamary, Y. H. (2025). Bridging Policy and Practice: Integrated Model for Investigating Behavioral Influences on Information Security Policy Compliance. Systems.

Delso-Vicente, A.-T., Diaz-Marcos, L., Aguado-Tevar, O., & García de Blanes-Sebastián, M. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal.

Foroudi, P., & Fakhreddin, F. (2026). Bridging beliefs and actions: Unraveling the impacts of ideological psychological contract fulfillment on employee citizenship behavior in the workplace. Journal of Managerial Psychology.

Ghaleb, M. M. S., & Pardaev, J. (2025). Controlling Cyber Crime through Information Security Compliance Behavior: Role of Cybersecurity Awareness, Organizational Culture and Trust in Management. International Journal of Cyber Criminology.

Greavu-Şerban, V., Constantin, F., & Necula, S.-C. (2025). Exploring Heuristics and Biases in Cybersecurity: A Factor Analysis of Social Engineering Vulnerabilities. Systems.

Li, L., He, W., Xu, L., Ash, I., Anwar, M., & Yuan, X. (2019). Investigating the impact of cybersecurity policy awareness on employees’ cybersecurity behavior. International Journal of Information Management.

Ünsal, N. Ö., & Ocak, M. A. (2026). Development of Organizational Cybersecurity Awareness Scale (OCAS). Hacettepe University Journal of Education.

Ye, W. (2026). Strengthening Cybersecurity in Small and Medium-Sized Enterprises: Balancing Technology, Costs, Compliance, and Employee Awareness. SAGE Open.

Advertisement

Cooper ad

Get Email Notifications

No Comments Yet

Let us know what you think