AI Insight
This study investigated factors influencing employee compliance with information security policies by combining three theoretical frameworks: Task-Technology Fit, technology threat avoidance theory, and Theory of Planned Behavior. Analysis of data from 288 employees in Saudi Arabia revealed that task-technology fit, self-efficacy, social influence, and perceived policy effectiveness positively predict security compliance intentions and behavior, while perceived costs reduce compliance intention. Surprisingly, perceived security threats did not significantly influence compliance behavior.
Why it matters
The findings provide organizations with actionable insights for improving information security policy compliance by focusing on enhancing task-technology alignment, building employee self-efficacy, leveraging social influence, and demonstrating policy effectiveness while minimizing compliance costs. This is particularly relevant as cybersecurity threats continue to grow and organizations increasingly depend on employee adherence to security protocols.
Understand the Science
IntroductionThe integrity of organizational information systems fundamentally relies on the psychological commitment of users to adhere to security protocols. Informational security policy (ISP) depends on users’ compliance to protect their organization’s information and technology assets against security threats.MethodsDrawing on the intersection of cognitive and behavioral psychology, this study examines information security policy compliance (ISPC) behavior by integrating the Task–Technology Fit (TTF) model, technology threat avoidance theory (TTAT), and the Theory of Planned Behavior (TPB). This study proposes a comprehensive research model to elucidate the cognitive factors and motivational drivers that shape an employee’s behavioral intention to comply. Utilizing a partial least squares structural equation modeling (PLS-SEM) approach, we empirically tested the model with data from 288 employees across public and private sectors in Saudi Arabia.ResultsThe results show that Task and technology characteristics significantly drive task-technology fit, which, along with self-efficacy, social influence, and policy effectiveness, positively predicts security compliance intentions and subsequent behavior. Conversely, compliance intention is hindered by perceived costs, while the influence of perceived security threats remains statistically insignificant. The study discusses key theoretical and applied insights, providing a roadmap for future research in the field.