Non-technical determinants of information security policy compliance: An integrated PMT-TPB model with psychological ownership, trust, and social influence
Mohammad Mulayh Alshammari, Yaser Hasan Al‐Mamary · Computers in Human Behavior Reports · 2026
Many assume personal attitudes are the main driver of information security policy (ISP) compliance, but this also rests on stewardship and norms inside organizations. With a focus on Saudi Arabia, a high power-distance, collectivist context, we integrate Protection Motivation Theory and the Theory of Planned Behavior with psychological ownership, trust in management, and social influence, we test a direct path from response efficacy to behavior. We surveyed 628 employees across Saudi organizations and analyzed the data with PLS-SEM (SmartPLS 4). Results show that intention is the strongest predictor of compliance behavior. Trust, psychological ownership, social influence, security awareness, and self-efficacy raise intention. Response efficacy, security awareness, and more weakly, perceived severity, shape attitude; perceived vulnerability does not. Response efficacy also increases compliance directly. Mediation tests indicate that intention carries most effects from stewardship, efficacy, awareness, and norms to behavior. These results fit a context where norms and stewardship weigh more than personal attitudes in forming intentions. The study offers theoretical and practical implications: build ownership and trust, leverage peer norms, as well as strengthen awareness and efficacy to raise compliance.