Coping with input stage challenges in information security policy development: Information security managers’ perspectives in a hybrid work environment
Mai Nguyen, Sara Rungård, Shang Gao · Computers & Security · 2026
The purpose of this paper is to investigate how information security managers cope with the challenges in the input stage when developing an information security policy (ISP) in the context of hybrid work in the financial sector. To address this, an empirical study was conducted using semi-structured interviews with eight information security managers in Sweden’s financial sector. The data is analyzed through qualitative thematic analysis. The lens of institutional theory was also applied to interpret the results. According to the results, 18 challenges and their associated solutions for five selected inputs (i.e., risk assessment, industry standards and guidelines, regulations, existing policies and organizational business requirements) within the input stage of the ISP development are identified. For example, one recurring challenge at the input stage of an organization’s risk assessment is the potential intrusion into employees’ privacy when work occurs in their homes. Risks that are easy to identify and evaluate in a controlled office environment often become less visible or more difficult to assess in home-based settings. This creates uncertainty during the input stage because organizations must address these dispersed and varied risks without intruding on employees’ private lives. This study advances the understanding of the input stage’s challenges in the ISP development process in a hybrid work environment. While previous research has primarily examined the ISP’s input stage in traditional office-based contexts, hybrid work introduces additional complexity. According to the results, organizations must balance essential information security requirements with increasing demands for workplace flexibility. They need to ensure that security expectations remain clear and actionable, yet adaptable enough to accommodate employees working remotely. This tension between maintaining operational security and supporting flexibility poses a significant challenge at the input stage related to organizational business requirements when developing effective ISPs for hybrid work. Furthermore, through the lens of institutional theory, the results indicate that some inputs are more strongly affected by isomorphism (i.e., coercive influence), whereas mimetic and normative influences appear less directly associated with specific inputs. Additionally, a primary practical implication is the encapsulated knowledge on the challenges managers may face and the associated solutions in the input phase of ISP development in the context of hybrid work in the financial sector. Managers can adopt and adapt the suggested solutions to further strengthen their work practices in the input stage of the ISP development.