Information security culture and phishing-reporting model: structural equivalence across Germany, UK, and USA

Gregor Petrič, John N Just · Journal of Cybersecurity · 2025

Abstract The reporting of phishing emails plays a critical role in enhancing organizational resilience to cyber threats. Timely reporting enables organizations to adapt dynamically to potential attacks, mitigating potential financial costs, and disruptions to business operations. While phishing susceptibility has been extensively examined in research, studies on the drivers and barriers to employees’ reporting of suspicious emails remain limited. Even fewer studies have examined how organizational processes and characteristics, particularly information security culture (ISC), shape this proactive protective behaviour. This study aims to investigate (a) how ISC factors—IS-supportive norms, the quality of IS-related communication, awareness and understanding of IS policies, IS knowledge, attitudes to IS, and sense of responsibility—influence the reporting of phishing emails and (b) whether the proposed research model exhibits cross-cultural structural equivalence. Data were collected via an online survey panel, sampling employees from medium and large organizations in Germany (n = 306), the UK (n = 205), and the USA (n = 506). A multigroup structural equation-modelling approach was employed to analyse the data. The findings highlight the pivotal role of IS-supportive norms, policy awareness, and knowledge in shaping employees’ attitudes and sense of responsibility, which, in turn, positively influence phishing email reporting. The quality of IS-related communication processes emerged as a complex and double-edged factor: while accessible and effective two-way communication fostered phishing email reporting, it simultaneously reduced employees’ sense of responsibility and led to less favourable attitudes towards IS. Overall, the ISC and phishing-reporting model demonstrated good cross-cultural stability. IS-supportive norms, communication quality, awareness of policies, and knowledge influence employees’ attitudes, sense of responsibility, and phishing reporting (directly or indirectly) consistently across countries. However, notable differences were also observed. For example, in Germany, attitudes towards IS were a stronger predictor of phishing reporting, whereas in the UK and USA, a sense of responsibility was more influential. The study advances the understanding of ISC as a determinant of phishing email reporting and offers practical recommendations for strengthening organizational strategies that promote reporting behaviour and improve resilience against cyber threats.

Read the paper · More papers on PaperTik