Determinants of Security Behavior Intention in State-Owned Enterprises: Applying Protection Motivation Theory to Phishing Emails

Okta Pratama, Riadi Arief Aladin, Budiarto Lim, Arta Moro Sundjaja · International Journal of Safety and Security Engineering · 2025

The increasing prevalence of cyber security threats underscores the need to understand employee behavior to prevent phishing-related risks and effectively promote a sustainable working environment.This issue is particularly critical for state-owned enterprises (SOEs), especially those operating in sensitive industries.Our study explores the factors influencing the behavior intentions of SOE employees to avoid clicking on phishing email links.The research adopts a quantitative approach, utilizing Structural Equation Modelling (SEM) for data analysis using SmartPLS 4.1.0software.A sample size of 189 respondents was determined using the G-Power Calculator and selected through purposive sampling.The results reveal that self-efficacy, perceived vulnerability, and perceived severity significantly influence security behavior intention.Furthermore, threat awareness was identified as a significant predictor of response efficacy, perceived vulnerability, and self-efficacy.Security knowledge was found to play a crucial role in shaping perceived severity, perceived vulnerability, and response efficacy.However, three hypotheses were not supported, specifically the relationships between threat awareness and perceived severity, security awareness and self-efficacy, and response efficacy and security behavior intention.These findings underscore the need for organizations to address the gaps by reinforcing practical training and targeted intervention for strengthening employee perception of severity perception, self-efficacy, and security behavior intention.The study highlights the importance of implementing robust cybersecurity awareness campaigns and policies within organizations prone to cyber threats.By fostering a culture of vigilance and improving employees understanding of the severity and vulnerability of phishing attacks, organizations can enhance their resilience against cyber threats and mitigate potential risks effectively.

Read the paper · More papers on PaperTik