Managing cybersecurity vigilance through people, process, and technology: A mixed-methods study
DOI:
https://doi.org/10.61255/jeemba.v4i5.1672Keywords:
cybersecurity vigilance, people-process-technology, cybersecurity governance, digital literacy, structural equation modelingAbstract
Purpose - This study examines how the People, Process, and Technology (PPT) pillars jointly shape cybersecurity vigilance in Indonesian university settings and whether formal process becomes behaviorally consequential through human capability.
Design/methodology/approach - A quantitatively dominant mixed-methods design combined survey data from 1,684 respondents with interviews involving nine cybersecurity experts. Covariance-based structural equation modeling was conducted in IBM SPSS AMOS, while expert evidence was used for explanatory triangulation.
Finding/Results - People and Technology were significantly associated with vigilance, whereas Process had no significant direct relationship. Process operated indirectly through People (indirect effect = 0.402; Sobel Z = 4.331; p < .001). Digital literacy and perceived regulatory reinforcement strengthened selected PPT-vigilance relationships.
Originality/Value - The study reframes PPT as an interdependent organizational governance architecture rather than three competing pillars. It shows that formal process requires human internalization and that technical, behavioral, and regulatory conditions should be managed as an integrated cybersecurity capability.
Abstract views: 22
,
PDF downloads: 10
Downloads
References
Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003. doi:10.1016/j.cose.2020.102003
Alsharida, R. A., Al-rimy, B. A. S., Al-Emran, M., & Zainal, A. (2023). A systematic review of multi perspectives on human cybersecurity behavior. Technology in Society, 73, 102258. doi:10.1016/j.techsoc.2023.102258
Amin, M. A. S., Prybutok, V., & Rishat, M. A. S. A. (2025). The role of self-efficacy in IT employee cybersecurity safety behavior. International Journal of Human–Computer Interaction. Advance online publication. doi:10.1080/10447318.2025.2607558
Badan Siber dan Sandi Negara. (2025). Lanskap Keamanan Siber Indonesia 2024 [Indonesia cybersecurity landscape 2024]. Retrieved from https://www.bssn.go.id/
Baltuttis, D., Teubner, T., & Adam, M. T. P. (2024). A typology of cybersecurity behavior among knowledge workers. Computers & Security, 140, 103741. doi:10.1016/j.cose.2024.103741
Bandura, A. (1997). Self-efficacy: The exercise of control. W. H. Freeman.
Boss, S. R., Galletta, D. F., Lowry, P. B., Moody, G. D., & Polak, P. (2015). What do users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quarterly, 39(4), 837–864. doi:10.25300/MISQ/2015/39.4.5
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. doi:10.2307/25750690
Chaudhary, S. (2024). Driving behaviour change with cybersecurity awareness. Computers & Security, 142, 103858. doi:10.1016/j.cose.2024.103858
Compeau, D. R., & Higgins, C. A. (1995). Computer self-efficacy: Development of a measure and initial test. MIS Quarterly, 19(2), 189–211. doi:10.2307/249688
Creswell, J. W., & Plano Clark, V. L. (2018). Designing and conducting mixed methods research (3rd ed.). SAGE.
Fatoki, J. G., Shen, Z., & Mora-Monge, C. A. (2024). Optimism amid risk: How non-IT employees’ beliefs affect cybersecurity behavior. Computers & Security, 141, 103812. doi:10.1016/j.cose.2024.103812
Fetters, M. D., Curry, L. A., & Creswell, J. W. (2013). Achieving integration in mixed methods designs—Principles and practices. Health Services Research, 48(6 Pt 2), 2134–2156. doi:10.1111/1475-6773.12117
Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. doi:10.1177/002224378101800104
Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106–125. doi:10.1057/ejis.2009.6
Hu, L.-t., & Bentler, P. M. (1999). Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria versus new alternatives. Structural Equation Modeling: A Multidisciplinary Journal, 6(1), 1–55. doi:10.1080/10705519909540118
International Telecommunication Union. (2024). Global Cybersecurity Index 2024 (5th ed.). Retrieved from https://www.itu.int/pub/D-HDB-GCI.01-2024
Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549–566. doi:10.2307/25750691
Ng, B.-Y., Kankanhalli, A., & Xu, Y. (2009). Studying users’ computer security behavior: A health belief perspective. Decision Support Systems, 46(4), 815–825. doi:10.1016/j.dss.2008.11.010
Nonaka, I., & Toyama, R. (2003). The knowledge-creating theory revisited: Knowledge creation as a synthesizing process. Knowledge Management Research & Practice, 1(1), 2–10. doi:10.1057/palgrave.kmrp.8500001
Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., & Jerram, C. (2014). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q). Computers & Security, 42, 165–176. doi:10.1016/j.cose.2013.12.003
Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879–903. doi:10.1037/0021-9010.88.5.879
Prümmer, J., van Steen, T., & van den Berg, B. (2024). A systematic review of current cybersecurity training methods. Computers & Security, 136, 103585. doi:10.1016/j.cose.2023.103585
Republic of Indonesia. (2022). Law of the Republic of Indonesia Number 27 of 2022 concerning Personal Data Protection. Retrieved from https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022
Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). Guilford Press.
Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502. doi:10.2307/25750688
Vance, A., Siponen, M., & Pahnila, S. (2012). Motivating IS security compliance: Insights from habit and Protection Motivation Theory. Information & Management, 49(3–4), 190–198. doi:10.1016/j.im.2012.04.002
Workman, M., Bommer, W. H., & Straub, D. (2008). Security lapses and the omission of information security measures: A threat control model and empirical test. Computers in Human Behavior, 24(6), 2799–2816. doi:10.1016/j.chb.2008.04.005
Zhao, X., Lynch, J. G., Jr., & Chen, Q. (2010). Reconsidering Baron and Kenny: Myths and truths about mediation analysis. Journal of Consumer Research, 37(2), 197–206. doi:10.1086/651257
Zwilling, M., Klien, G., Lesjak, D., Wiechetek, Ł., Cetin, F., & Basim, H. N. (2022). Cyber security awareness, knowledge and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82–97. doi:10.1080/08874417.2020.1712269
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Bondan Widiawan, Ali Muktiyanto, Martino Wibowo, Ami Pujiwati

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
















Email: fadhila.della@gmail.com, andika.isma@unm.ac.id