This master’s thesis explores the psychological and communication-related factors that influence employees’ information security behavior in organizations. The theoretical foundation is the Theory of Planned Behavior, which explains behavior through attitudes, subjective norms, and perceived behavioral control. The model is extended by incorporating a communication perspective through two constructs: employee voice and horizontal
communication about information security among colleagues. The analysis of secondary data from the KREPKI research project shows that perceived behavioral control, subjective norms, and employee voice are statistically significant predictors of information security behavior. In contrast, attitudes and peer conversations did not demonstrate a statistically significant impact. A key finding is that employee voice also exerts an indirect influence by shaping subjective norms, attitudes, and perceived control. The results suggest that effective information security management must go beyond technical solutions and include supportive organizational conditions that enable secure and responsible employee behavior. An open organizational climate that encourages the expression of concerns and enables employee participation in
security decisions significantly contributes to building resilient security oriented organizations. These findings have important practical implications for the development of strategies that strengthen employees’ psychological readiness and promote their active role in co-creating a culture of information security.
|