Please use this identifier to cite or link to this item:
http://hdl.handle.net/11189/10399| Title: | An analysis of cybersecurity policy compliance in organisations | Authors: | Okigui, Hugues Hermann Cronjé, Johannes C. Francke, Errol |
Keywords: | Cybersecurity policies;Compliance challenges;Insider threats;Phishing attempts;Actor-Network Theory (ANT) | Issue Date: | 2024 | Publisher: | National Research Institute | Source: | Okigui, H.H., Cronjé, J.C. & Francke, E.R. 2024. An analysis of cybersecurity policy compliance in organisations. Applied Cybersecurity & Internet Governance, 3(2): 303-321. [https://doi.org/10.60097/ACIG/191942] | Journal: | Applied Cybersecurity & Internet Governance | Abstract: | In the contemporary digital landscape, cyber-attacks and incidents have placed cyber-security at the forefront of priorities in organisations. As organisations face cyber risks, it becomes imperative to implement and comply with various cyber-security policies. However, due to factors such as policy complexity and resistance from employees, compliance can be a challenging task. The study, which took a comprehensive approach, investigated the variables that affect an organisation's adherence to cyber-security policies. The findings of this study provide insights into the challenges and factors influencing compliance with cyber-security policies in organisations. A case study design was chosen as part of a qualitative approach to answer the research question. For data gathering, semi-structured interviews were performed, and existing documents were also considered when available to supplement interviews. The gathered data was meticulously organised, coded, and analysed using the Actor-Network Theory perspective, with a focus on its four moments of translation: problematisation, interessement, enrolment, and mobilisation. The analysis revealed that insider threats and phishing attempts are the two cyber threats that affect organisations; behavioural challenges and enforcement limitations are factors that influence and contribute to the non-compliance of cyber-security policy; phishing exercises and policy development processes are used to enforce cyber-security policies. | URI: | http://hdl.handle.net/11189/10399 | ISSN: | 2956-4395 (Online) | DOI: | https://doi.org/10.60097/ACIG/191942 |
| Appears in Collections: | FID - Journal Articles (DHET subsidised) |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| An_Analysis_of_Cybersecurity_Policy.pdf | 1.71 MB | Adobe PDF | View/Open |
Page view(s)
22
Last Week
2
2
Last month
checked on Dec 29, 2025
Download(s)
6
checked on Dec 29, 2025
Google ScholarTM
Check
Altmetric
Items in Digital Knowledge are protected by copyright, with all rights reserved, unless otherwise indicated.