Psychological drivers of compliance intention–The roles of professionals’ motivational profiles and personality traits in following information systems security policies at work
Thomas Keller, Julia Isabella Warwas, Josef Guggemos, Verena Zengerle · Computers & Security · 2026
Cybersecurity is becoming increasingly important in organizations. Many data breaches and successful cyberattacks occur when employees ignore, bypass, or inconsistently apply security rules. While existing research has focused on personality traits to explain compliance with information systems security policies (ISSP), it has largely neglected the domain-specific motivational regulation of behavior. Yet, sustaining effortful and sometimes inconvenient security practices depends not only on stable personality traits but also on how employees motivationally regulate their behaviors in this domain, highlighting the need to consider both constructs when explaining ISSP compliance intention. The present study addresses this gap by using the five-factor model of personality and self-determination theory (SDT) to examine how stable traits and distinct motivational qualities relate to ISSP compliance intention. In a cross-sectional online survey, 218 office employees from small and medium-sized enterprises reported their personality traits, security-related work motivation, and ISSP compliance intention. We tested the multidimensional structure of the adapted motivation measure using confirmatory factor analysis and identified qualitatively distinct motivational profiles through latent profile analysis. To examine the incremental contributions of structural characteristics, personality traits, and motivational profiles to ISSP compliance intention, we conducted hierarchical multiple regression analyses. The results support a multidimensional structure of motivational regulation and yield three profiles that differ in their extent of self-regulated behavior in pursuit of internalized goals. Structural characteristics (company size) and personality traits (agreeableness, conscientiousness) were significantly associated with ISSP compliance intention (R² = 0.257). Motivational profiles accounted for additional variance (ΔR² = 0.08; final R² = 0.333), with autonomous profiles (i.e., profiles characterized by internalized and self-endorsed reasons for secure behavior) reporting higher ISSP compliance intention than the amotivated profile. Based on these findings, the study outlines how SDT-based interventions can support employees’ psychological needs for autonomy, competence, and social relatedness, thereby fostering more internalized and enduring ISSP compliance.