Bridging Policy and Practice: Integrated Model for Investigating Behavioral Influences on Information Security Policy Compliance

Mohammad Mulayh Alshammari, Yaser Hasan Al‐Mamary · Systems · 2025

Cybersecurity threats increasingly originate from human actions within organizations, emphasizing the need to understand behavioral factors behind non-compliance with information security policies (ISPs). Despite the presence of formal security policies, insider threats—whether accidental or intentional—remain a major vulnerability. This study addresses the gap in behavioral cybersecurity research by developing an integrated conceptual model that draws upon Operant Conditioning Theory (OCT), Protection Motivation Theory (PMT), and the Theory of Planned Behavior (TPB) to explore ISP compliance. The research aims to identify key cognitive, motivational, and behavioral factors that shape employees’ intentions and actual compliance with ISPs. The model examines seven independent variables of perceived severity: perceived vulnerability, rewards, punishment, attitude toward the behavior, subjective norms, and perceived behavioral control, with intention serving as a mediating variable and actual ISP compliance as the outcome. A quantitative approach was used, collecting data via an online survey from 302 employees across the public and private sectors. Structural Equation Modeling (SEM) with SmartPLS software (v.4.1.1.2) analyzed the complex relationships among variables, testing the proposed model. The findings reveal that perceived severity, punishment, attitude toward behavior, and perceived behavioral control, significantly and positively, influence employees’ intentions to comply with information security policies. Conversely, perceived vulnerability, rewards, and subjective norms do not show a significant effect on compliance intentions. Moreover, the intention to comply strongly predicts actual compliance behavior, thus confirming its key role as a mediator linking cognitive, motivational, and behavioral factors to real security practices. This study offers an original contribution by uniting three well-established theories into a single explanatory model and provides actionable insights for designing effective, psychologically informed interventions to enhance ISP adherence and reduce insider risks.

Read the paper · More papers on PaperTik