Information Security Awareness in the Insurance Sector: Cognitive and Internal Factors and Combined Recommendations

被引:1
|
作者
Djotaroeno, Morgan [1 ]
Beulen, Erik [2 ]
机构
[1] Dux Grp, Consultant Proc & Informat Management, NL-3011 TA Rotterdam, Netherlands
[2] Univ Manchester, Management Sci & Mkt, Manchester M15 6PB, England
关键词
security awareness; information security awareness; cyber awareness; individual factors; employee awareness; situation awareness; security consciousness; insurance sector; POLICY COMPLIANCE; SITUATION AWARENESS; IMPACT; RESILIENCE; REQUIREMENTS; ANTECEDENTS; MANAGEMENT; BEHAVIOR;
D O I
10.3390/info15080505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybercrime is currently rapidly developing, requiring an increased demand for information security knowledge. Attackers are becoming more sophisticated and complex in their assault tactics. Employees are a focal point since humans remain the 'weakest link' and are vital to prevention. This research investigates what cognitive and internal factors influence information security awareness (ISA) among employees, through quantitative empirical research using a survey conducted at a Dutch financial insurance firm. The research question of "How and to what extent do cognitive and internal factors contribute to information security awareness (ISA)?" has been answered, using the theory of situation awareness as the theoretical lens. The constructs of Security Complexity, Information Security Goals (InfoSec Goals), and SETA Programs (security education, training, and awareness) significantly contribute to ISA. The most important research recommendations are to seek novel explaining variables for ISA, further investigate the roots of Security Complexity and what influences InfoSec Goals, and venture into qualitative and experimental research methodologies to seek more depth. The practical recommendations are to minimize the complexity of (1) information security topics (e.g., by contextualizing it more for specific employee groups) and (2) integrate these simplifications in various SETA methods (e.g., gamification and online training).
引用
收藏
页数:29
相关论文
共 18 条
  • [11] Employee Information Security Awareness in the Power Generation Sector of PT ABC
    Fadlika, Ridwan
    Ruldeviyani, Yova
    Butarbutar, Zenfrison Tuah
    Istiqomah, Relaci Aprilia
    Fariz, Achmad Arzal
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (04) : 594 - 603
  • [12] Understanding information security awareness: evidence from the public healthcare sector
    Neri, Martina
    Benevento, Elisabetta
    Stefanini, Alessandro
    Aloini, Davide
    Niccolini, Federico
    Carducci, Annalaura
    Federigi, Ileana
    Dini, Gianluca
    INFORMATION AND COMPUTER SECURITY, 2024,
  • [13] Security Culture and Security Awareness as the Basic Factors for Security Effectiveness in Health Information Systems
    Shahri, Ahmad Bakhtiyari
    Ismail, Zuraini
    Rahim, Nor Zairah Ab.
    JURNAL TEKNOLOGI, 2013, 64 (02):
  • [14] Study on Information Security Awareness using the Behavioral-Cognitive Internet Security Questionnaire
    Solic, Kresimir
    Velki, Tena
    Fosic, Igor
    Vukovic, Marin
    ACTA POLYTECHNICA HUNGARICA, 2024, 21 (04) : 49 - 68
  • [15] Exploring factors that influence information security awareness implementation and maintenance
    Beranek, Ladislav
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON STRATEGIC MANAGEMENT AND ITS SUPPORT BY INFORMATION SYSTEMS, 2015, : 348 - 355
  • [16] Factors Influencing Information Security Awareness of Phishing Attacks from Bank Customers' Perspective: A Preliminary Investigation
    Asfoor, Ayman
    Rahim, Fiza Abdul
    Yussof, Salman
    RECENT TRENDS IN DATA SCIENCE AND SOFT COMPUTING, IRICT 2018, 2019, 843 : 641 - 654
  • [17] The determinants of an information security policy compliance culture in organisations: the combined effects of organisational and behavioural factors
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    INFORMATION AND COMPUTER SECURITY, 2022, 30 (04) : 583 - 614
  • [18] SOCIO-ECONOMIC FACTORS ON SECTOR-WIDE SYSTEMATIC RISK OF INFORMATION SECURITY BREACHES: CONCEPTUAL FRAMEWORK
    Ali, Syed Emad Azhar
    Lai, Fong-Woon
    Hassan, Rohail
    9TH INTERNATIONAL ECONOMICS AND BUSINESS MANAGEMENT CONFERENCE (IEBMC 2019), 2020, 100 : 501 - 512