Personality and Workplace Cybersecurity

Lee Hadlington, Chloe Ryding · 2025

In this chapter, we explore the factors influencing cybersecurity behaviours in the workplace, emphasizing that individuals do not operate in isolation. These factors shape employees’ perceptions of their worth within an organisation and their approach to cybersecurity. Employees motivated by financial gain may not prioritise cybersecurity, while those aligned with the company’s values are more likely to engage in effective practices. We focus on organisational culture and individual perceptions of roles, rather than specific risky behaviours. The chapter highlights the interplay between psychological traits and situational factors. Personality traits interact with social influences, such as norms and organisational values, to shape cybersecurity behaviours. We discuss the Big Five personality traits – openness to experience, neuroticism, agreeableness, conscientiousness, and extraversion – and their links to cybersecurity. For example, high openness may lead to curiosity-driven cybercrime susceptibility, while high neuroticism may lower self-efficacy in cybersecurity. Agreeableness is linked to higher phishing susceptibility, and conscientiousness to both protective behaviours and spear-phishing susceptibility. Extraverts may exhibit lax cybersecurity behaviours. We also examine the Dark Triad – Machiavellianism, narcissism, and psychopathy – and their influence on cybersecurity. These traits are linked to malicious insider threats and counterproductive behaviours. Machiavellian individuals may manipulate others to bypass security, narcissists’ overconfidence can lead to phishing susceptibility, and psychopaths’ lack of empathy makes them prone to unethical behaviours. Finally, we address the limitations of using personality assessments in the workplace, emphasizing the importance of validity and reliability. We recommend a triangulated approach, combining personality measures with other methods to understand cybersecurity behaviours comprehensively.

Read the paper · More papers on PaperTik