Please use this identifier to cite or link to this item:
http://hdl.handle.net/11189/10399| Title: | An analysis of cybersecurity policy compliance in organisations | Authors: | Okigui, Hugues Hermann Cronjé, Johannes C. Francke, Errol |
Keywords: | Cybersecurity policies;Compliance challenges;Insider threats;Phishing attempts;Actor-Network Theory (ANT) | Issue Date: | 2024 | Publisher: | National Research Institute | Source: | Okigui, H.H., Cronjé, J.C. & Francke, E.R. 2024. An analysis of cybersecurity policy compliance in organisations. Applied Cybersecurity & Internet Governance, 3(2): 303-321. [https://doi.org/10.60097/ACIG/191942] | Journal: | Applied Cybersecurity & Internet Governance | Abstract: | In the contemporary digital landscape, cyber-attacks and incidents have placed cyber-security at the forefront of priorities in organisations. As organisations face cyber risks, it becomes imperative to implement and comply with various cyber-security policies. However, due to factors such as policy complexity and resistance from employees, compliance can be a challenging task. The study, which took a comprehensive approach, investigated the variables that affect an organisation's adherence to cyber-security policies. The findings of this study provide insights into the challenges and factors influencing compliance with cyber-security policies in organisations. A case study design was chosen as part of a qualitative approach to answer the research question. For data gathering, semi-structured interviews were performed, and existing documents were also considered when available to supplement interviews. The gathered data was meticulously organised, coded, and analysed using the Actor-Network Theory perspective, with a focus on its four moments of translation: problematisation, interessement, enrolment, and mobilisation. The analysis revealed that insider threats and phishing attempts are the two cyber threats that affect organisations; behavioural challenges and enforcement limitations are factors that influence and contribute to the non-compliance of cyber-security policy; phishing exercises and policy development processes are used to enforce cyber-security policies. | URI: | http://hdl.handle.net/11189/10399 | ISSN: | 2956-4395 (Online) | DOI: | https://doi.org/10.60097/ACIG/191942 |
| Appears in Collections: | FID - Journal Articles (DHET subsidised) |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| An_Analysis_of_Cybersecurity_Policy.pdf | 1.71 MB | Adobe PDF | View/Open |
Page view(s)
108
Last Week
2
2
Last month
checked on Aug 29, 2026
Download(s)
35
checked on Aug 29, 2026
Google ScholarTM
Check
Altmetric
Items in Digital Knowledge are protected by copyright, with all rights reserved, unless otherwise indicated.