Understanding Smartphone Security Compliance Behaviour of Employees: Assessing the Impact of Organisational Leadership and Threat Perception in the UK
DOI:
https://doi.org/10.67265/jsrd.26.v2.i2.02Keywords:
Organisational Leadership , Threat Perception, Cybersecurity Behaviour , UK Employees, Smartphone Security ComplianceAbstract
The increasing adoption of smartphones within organisations in the United Kingdom has significantly increased cybersecurity risks, particularly regarding compliance with mobile security policies. Notwithstanding the introduction of technology and cyber awareness campaigns, compliance with cybersecurity standards remains relatively poor in the United Kingdom. The objective of this research paper is to examine the effect of organisational leadership and the employees' threat perception of cybersecurity issues on their cybersecurity compliance behaviour. This study employed a qualitative systematic literature review (SLR) using the PRISMA framework to examine peer-reviewed journal articles and case studies published between 2021 and 2025. The study identifies leadership support, awareness training, and perceived cyber threats as major predictors of employee compliance behaviour. The findings indicate that transformational leadership significantly strengthens employee cybersecurity compliance through secure behavioural modelling, effective communication, and policy reinforcement. Additionally, employee perceptions of cybersecurity threats have been found to be a major determinant of employee behaviour regarding cybersecurity compliance.
References
Adil, K. (2025). Leveraging advanced data techniques in HR analytics: Revolutionizing workforce management. Journal of Social Research Dynamics, 1(1), 37–47. https://doi.org/10.67265/jsrd.v1.i1.04
Aldossary, A. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal, 11(28).
Almansoori, M., Al-Emran, M. and Shaalan, K. (2023). Investigating the determinants of cybersecurity compliance behaviour: A systematic review. Computers & Security, 124, 102982. https://doi.org/10.1016/j.cose.2022.102982
Alotaibi, F. and Furnell, S. (2023). Cybersecurity compliance and human factors: Understanding employee behaviour in organisations. Information & Computer Security, 31(4), 567–583. https://doi.org/10.1108/ICS-10-2022-0156
Bongiovanni, I. (2023). The human factor in cybersecurity: Exploring the role of leadership in shaping security culture. Journal of Cybersecurity, 9(1), tyad012. https://doi.org/10.1093/cybsec/tyad012
Chatterjee, S., Chaudhuri, R. and Vrontis, D. (2021). Does remote work flexibility enhance organisation performance? Moderating role of organisation policy and top management support. Journal of Business Research, 139, 1509–1521. https://doi.org/10.1016/j.jbusres.2021.10.020
Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M. and Baskerville, R. (2013). Future directions for behavioral information security research. Computers & Security, 32, 90–101. https://doi.org/10.1016/j.cose.2012.09.010
Debb, S. M. and McClellan, M. K. (2021). Perceived vulnerability as a determinant of increased risk for cybersecurity risk behaviour. Cyberpsychology, Behavior, and Social Networking, 24(9), 605–611. https://doi.org/10.1089/cyber.2021.0043
Delso-Vicente, A. T., Diaz-Marcos, L., Aguado-Tevar, O. and García de Blanes-Sebastián, M. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal, 11(1), 28.
Duzenci, A., Kitapci, H. and Gok, M. S. (2023). The role of decision-making styles in shaping cybersecurity compliance behavior. Applied Sciences, 13(15), 8731. https://doi.org/10.3390/app13158731
European Union Agency for Cybersecurity (ENISA). (2023). ENISA Threat Landscape 2023. ENISA. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023
Ganesh, S. S., Ndulue, C. and Orji, R. (2022). Evaluating the effectiveness of a gamified cybersecurity awareness program based on Protection Motivation Theory. Computers & Security, 113, 102571. https://doi.org/10.1016/j.cose.2021.102571
Hadlington, L. (2017). Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours. Heliyon, 3(7), e00346. https://doi.org/10.1016/j.heliyon.2017.e00346
Hadlington, L. and Chivers, S. (2020). Segmentation analysis of susceptibility to cybercrime: Exploring individual differences in information security awareness and personality factors. Policing: A Journal of Policy and Practice, 14(2), 479–492. https://doi.org/10.1093/police/pay027
Hwang, I., Seo, R. and Hu, S. (2025). Boosting employee information security compliance: The contingent roles of task–technology and person–organization fits. Humanities and Social Sciences Communications, 12, 563. https://doi.org/10.1057/s41599-025-04718-x
IBM Security. (2024). Cost of a Data Breach Report 2024. IBM Corporation. https://www.ibm.com/reports/data-breach
Ifinedo, P. (2022). The effects of antecedents and mediating factors on cybersecurity protection behaviour. Computers in Human Behavior Reports, 5, 100165. https://doi.org/10.1016/j.chbr.2021.100165
Khan, M. A. U. R. (2025). Enhancing participation of people aged 75+ in clinical and applied health research through inclusive, technology-enabled methodologies. Journal of Social Research Dynamics, 1(2), 1–14. https://doi.org/10.67265/jsrd.v1.i2.01
Knapova, L., Kruzikova, A., Dedkova, L. and Smahel, D. (2021). Who is smart with their smartphones? Determinants of smartphone security behavior. Cyberpsychology, Behavior, and Social Networking, 24(9), 584–592. https://doi.org/10.1089/cyber.2020.0599
Kraushaar, J. M. and Bohnet-Joschko, S. (2022). Smartphone use and security compliance among healthcare professionals: A behavioural perspective. BMC Medical Informatics and Decision Making, 22, 105. https://doi.org/10.1186/s12911-022-01835-7
Kshetri, N. (2023). Cybercrime and Cybersecurity in the Global South. Springer. https://doi.org/10.1007/978-3-031-29170-6
Lutfi, A. (2022). Understanding the intention to adopt cloud-based accounting information systems in SMEs. Journal of Enterprise Information Management, 35(6), 1831–1854. https://doi.org/10.1108/JEIM-12-2020-0513
Maritime decision-makers and cyber security: Deck officers' perception of cyber risks towards IT and OT systems. International Journal of Information Security, 23, 1721–1739.
Oladipo, O., Abdulsalam, Y., Misra, S. and Maskeliūnas, R. (2024). Cybersecurity behaviour in FinTech: Examining psychological and human factors influencing compliance. Heliyon, 10(2), e24015. https://doi.org/10.1016/j.heliyon.2024.e24015
Parsons, K., McCormac, A., Butavicius, M., Pattinson, M. and Jerram, C. (2014). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q). Computers & Security, 42, 165–176. https://doi.org/10.1016/j.cose.2013.12.003
Renaud, K. and Weir, G. R. S. (2023). Cybersecurity and human behaviour: The role of organisational and technical controls. Computers & Security, 128, 103134. https://doi.org/10.1016/j.cose.2023.103134
Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. T. Cacioppo and R. E. Petty (Eds.), Social psychophysiology: A sourcebook (pp. 153–176). Guilford Press.
Safa, N. S., Von Solms, R. and Furnell, S. (2022). Information security policy compliance model in organisations. Computers & Security, 120, 102819. https://doi.org/10.1016/j.cose.2022.102819
Tejay, G. P. S. and Winkfield, M. (2025). Does leadership approach matter? Examining behavioral influences of leaders on employees' information security compliance. Information Systems Frontiers. https://doi.org/10.1007/s10796-025-10592-4
ul-Haq, S. (2025). Cybersecurity challenges in mobile payment apps: Threats and solutions. Journal of Social Research Dynamics, 1(2), 54–71. https://doi.org/10.67265/jsrd.v1.i2.05
Ur Rehman, M. (2025). Integrating total quality management and human resources management in hospitality: A case study of Swissotel Hotel & Resort. Journal of Social Research Dynamics, 1(1), 24–36. https://doi.org/10.67265/jsrd.v1.i1.03
Vance, A., Siponen, M. and Pahnila, S. (2012). Motivating IS security compliance: Insights from habit and protection motivation theory. Information & Management, 49(3–4), 190–198. https://doi.org/10.1016/j.im.2012.04.002
Verizon. (2023). 2023 Data Breach Investigations Report (DBIR). Verizon Enterprise.
Verizon. (2024). 2024 Data Breach Investigations Report (DBIR). Verizon Business. https://www.verizon.com/business/resources/reports/dbir/
Vrhovec, S. and Markelj, B. (2024). We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers. arXiv. https://arxiv.org/abs/2404.04725
Zahid, M. E. (2025). The impact of influencer marketing on consumer loyalty and repeat purchase behavior. Journal of Social Research Dynamics, 1(2), 15–27. https://doi.org/10.67265/jsrd.v1.i2.02
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Social Research Dynamics

This work is licensed under a Creative Commons Attribution 4.0 International License.
All articles published in this journal are licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
This license allows anyone to:
-
Share — copy and redistribute the material in any medium or format
-
Adapt — remix, transform, and build upon the material for any purpose, even commercially
Under the following terms:
-
Attribution — You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
Full license details: https://creativecommons.org/licenses/by/4.0/
Authors retain copyright of their work and grant the journal the right of first publication.