Managing cybersecurity vigilance through people, process, and technology: A mixed-methods study

Authors

  • Bondan Widiawan Universitas Terbuka, Jakarta, Indonesia
  • Ali Muktiyanto Universitas Terbuka, Jakarta, Indonesia
  • Martino Wibowo Universitas Terbuka, Jakarta, Indonesia
  • Ami Pujiwati Universitas Terbuka, Jakarta, Indonesia

DOI:

https://doi.org/10.61255/jeemba.v4i5.1672

Keywords:

cybersecurity vigilance, people-process-technology, cybersecurity governance, digital literacy, structural equation modeling

Abstract

Purpose - This study examines how the People, Process, and Technology (PPT) pillars jointly shape cybersecurity vigilance in Indonesian university settings and whether formal process becomes behaviorally consequential through human capability.

Design/methodology/approach - A quantitatively dominant mixed-methods design combined survey data from 1,684 respondents with interviews involving nine cybersecurity experts. Covariance-based structural equation modeling was conducted in IBM SPSS AMOS, while expert evidence was used for explanatory triangulation.

Finding/Results - People and Technology were significantly associated with vigilance, whereas Process had no significant direct relationship. Process operated indirectly through People (indirect effect = 0.402; Sobel Z = 4.331; p < .001). Digital literacy and perceived regulatory reinforcement strengthened selected PPT-vigilance relationships.

Originality/Value - The study reframes PPT as an interdependent organizational governance architecture rather than three competing pillars. It shows that formal process requires human internalization and that technical, behavioral, and regulatory conditions should be managed as an integrated cybersecurity capability.

Abstract views: 22 , PDF downloads: 10

Downloads

Download data is not yet available.

References

Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003. doi:10.1016/j.cose.2020.102003

Alsharida, R. A., Al-rimy, B. A. S., Al-Emran, M., & Zainal, A. (2023). A systematic review of multi perspectives on human cybersecurity behavior. Technology in Society, 73, 102258. doi:10.1016/j.techsoc.2023.102258

Amin, M. A. S., Prybutok, V., & Rishat, M. A. S. A. (2025). The role of self-efficacy in IT employee cybersecurity safety behavior. International Journal of Human–Computer Interaction. Advance online publication. doi:10.1080/10447318.2025.2607558

Badan Siber dan Sandi Negara. (2025). Lanskap Keamanan Siber Indonesia 2024 [Indonesia cybersecurity landscape 2024]. Retrieved from https://www.bssn.go.id/

Baltuttis, D., Teubner, T., & Adam, M. T. P. (2024). A typology of cybersecurity behavior among knowledge workers. Computers & Security, 140, 103741. doi:10.1016/j.cose.2024.103741

Bandura, A. (1997). Self-efficacy: The exercise of control. W. H. Freeman.

Boss, S. R., Galletta, D. F., Lowry, P. B., Moody, G. D., & Polak, P. (2015). What do users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quarterly, 39(4), 837–864. doi:10.25300/MISQ/2015/39.4.5

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. doi:10.2307/25750690

Chaudhary, S. (2024). Driving behaviour change with cybersecurity awareness. Computers & Security, 142, 103858. doi:10.1016/j.cose.2024.103858

Compeau, D. R., & Higgins, C. A. (1995). Computer self-efficacy: Development of a measure and initial test. MIS Quarterly, 19(2), 189–211. doi:10.2307/249688

Creswell, J. W., & Plano Clark, V. L. (2018). Designing and conducting mixed methods research (3rd ed.). SAGE.

Fatoki, J. G., Shen, Z., & Mora-Monge, C. A. (2024). Optimism amid risk: How non-IT employees’ beliefs affect cybersecurity behavior. Computers & Security, 141, 103812. doi:10.1016/j.cose.2024.103812

Fetters, M. D., Curry, L. A., & Creswell, J. W. (2013). Achieving integration in mixed methods designs—Principles and practices. Health Services Research, 48(6 Pt 2), 2134–2156. doi:10.1111/1475-6773.12117

Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. doi:10.1177/002224378101800104

Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106–125. doi:10.1057/ejis.2009.6

Hu, L.-t., & Bentler, P. M. (1999). Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria versus new alternatives. Structural Equation Modeling: A Multidisciplinary Journal, 6(1), 1–55. doi:10.1080/10705519909540118

International Telecommunication Union. (2024). Global Cybersecurity Index 2024 (5th ed.). Retrieved from https://www.itu.int/pub/D-HDB-GCI.01-2024

Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549–566. doi:10.2307/25750691

Ng, B.-Y., Kankanhalli, A., & Xu, Y. (2009). Studying users’ computer security behavior: A health belief perspective. Decision Support Systems, 46(4), 815–825. doi:10.1016/j.dss.2008.11.010

Nonaka, I., & Toyama, R. (2003). The knowledge-creating theory revisited: Knowledge creation as a synthesizing process. Knowledge Management Research & Practice, 1(1), 2–10. doi:10.1057/palgrave.kmrp.8500001

Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., & Jerram, C. (2014). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q). Computers & Security, 42, 165–176. doi:10.1016/j.cose.2013.12.003

Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879–903. doi:10.1037/0021-9010.88.5.879

Prümmer, J., van Steen, T., & van den Berg, B. (2024). A systematic review of current cybersecurity training methods. Computers & Security, 136, 103585. doi:10.1016/j.cose.2023.103585

Republic of Indonesia. (2022). Law of the Republic of Indonesia Number 27 of 2022 concerning Personal Data Protection. Retrieved from https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022

Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). Guilford Press.

Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502. doi:10.2307/25750688

Vance, A., Siponen, M., & Pahnila, S. (2012). Motivating IS security compliance: Insights from habit and Protection Motivation Theory. Information & Management, 49(3–4), 190–198. doi:10.1016/j.im.2012.04.002

Workman, M., Bommer, W. H., & Straub, D. (2008). Security lapses and the omission of information security measures: A threat control model and empirical test. Computers in Human Behavior, 24(6), 2799–2816. doi:10.1016/j.chb.2008.04.005

Zhao, X., Lynch, J. G., Jr., & Chen, Q. (2010). Reconsidering Baron and Kenny: Myths and truths about mediation analysis. Journal of Consumer Research, 37(2), 197–206. doi:10.1086/651257

Zwilling, M., Klien, G., Lesjak, D., Wiechetek, Ł., Cetin, F., & Basim, H. N. (2022). Cyber security awareness, knowledge and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82–97. doi:10.1080/08874417.2020.1712269

Downloads

Published

2026-08-15

How to Cite

Widiawan, B., Muktiyanto, A., Wibowo, M., & Pujiwati, A. (2026). Managing cybersecurity vigilance through people, process, and technology: A mixed-methods study. Journal of Economics, Entrepreneurship, Management Business and Accounting, 4(5), 577–590. https://doi.org/10.61255/jeemba.v4i5.1672