Understanding Smartphone Security Compliance Behaviour of Employees: Assessing the Impact of Organisational Leadership and Threat Perception in the UK

Authors

  • Hasnat Khan University of law Author

DOI:

https://doi.org/10.67265/jsrd.26.v2.i2.02

Keywords:

Organisational Leadership , Threat Perception, Cybersecurity Behaviour , UK Employees, Smartphone Security Compliance

Abstract

The increasing adoption of smartphones within organisations in the United Kingdom has significantly increased cybersecurity risks, particularly regarding compliance with mobile security policies. Notwithstanding the introduction of technology and cyber awareness campaigns, compliance with cybersecurity standards remains relatively poor in the United Kingdom. The objective of this research paper is to examine the effect of organisational leadership and the employees' threat perception of cybersecurity issues on their cybersecurity compliance behaviour. This study employed a qualitative systematic literature review (SLR) using the PRISMA framework to examine peer-reviewed journal articles and case studies published between 2021 and 2025. The study identifies leadership support, awareness training, and perceived cyber threats as major predictors of employee compliance behaviour. The findings indicate that transformational leadership significantly strengthens employee cybersecurity compliance through secure behavioural modelling, effective communication, and policy reinforcement. Additionally, employee perceptions of cybersecurity threats have been found to be a major determinant of employee behaviour regarding cybersecurity compliance.

References

Adil, K. (2025). Leveraging advanced data techniques in HR analytics: Revolutionizing workforce management. Journal of Social Research Dynamics, 1(1), 37–47. https://doi.org/10.67265/jsrd.v1.i1.04

Aldossary, A. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal, 11(28).

Almansoori, M., Al-Emran, M. and Shaalan, K. (2023). Investigating the determinants of cybersecurity compliance behaviour: A systematic review. Computers & Security, 124, 102982. https://doi.org/10.1016/j.cose.2022.102982

Alotaibi, F. and Furnell, S. (2023). Cybersecurity compliance and human factors: Understanding employee behaviour in organisations. Information & Computer Security, 31(4), 567–583. https://doi.org/10.1108/ICS-10-2022-0156

Bongiovanni, I. (2023). The human factor in cybersecurity: Exploring the role of leadership in shaping security culture. Journal of Cybersecurity, 9(1), tyad012. https://doi.org/10.1093/cybsec/tyad012

Chatterjee, S., Chaudhuri, R. and Vrontis, D. (2021). Does remote work flexibility enhance organisation performance? Moderating role of organisation policy and top management support. Journal of Business Research, 139, 1509–1521. https://doi.org/10.1016/j.jbusres.2021.10.020

Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M. and Baskerville, R. (2013). Future directions for behavioral information security research. Computers & Security, 32, 90–101. https://doi.org/10.1016/j.cose.2012.09.010

Debb, S. M. and McClellan, M. K. (2021). Perceived vulnerability as a determinant of increased risk for cybersecurity risk behaviour. Cyberpsychology, Behavior, and Social Networking, 24(9), 605–611. https://doi.org/10.1089/cyber.2021.0043

Delso-Vicente, A. T., Diaz-Marcos, L., Aguado-Tevar, O. and García de Blanes-Sebastián, M. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal, 11(1), 28.

Duzenci, A., Kitapci, H. and Gok, M. S. (2023). The role of decision-making styles in shaping cybersecurity compliance behavior. Applied Sciences, 13(15), 8731. https://doi.org/10.3390/app13158731

European Union Agency for Cybersecurity (ENISA). (2023). ENISA Threat Landscape 2023. ENISA. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

Ganesh, S. S., Ndulue, C. and Orji, R. (2022). Evaluating the effectiveness of a gamified cybersecurity awareness program based on Protection Motivation Theory. Computers & Security, 113, 102571. https://doi.org/10.1016/j.cose.2021.102571

Hadlington, L. (2017). Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours. Heliyon, 3(7), e00346. https://doi.org/10.1016/j.heliyon.2017.e00346

Hadlington, L. and Chivers, S. (2020). Segmentation analysis of susceptibility to cybercrime: Exploring individual differences in information security awareness and personality factors. Policing: A Journal of Policy and Practice, 14(2), 479–492. https://doi.org/10.1093/police/pay027

Hwang, I., Seo, R. and Hu, S. (2025). Boosting employee information security compliance: The contingent roles of task–technology and person–organization fits. Humanities and Social Sciences Communications, 12, 563. https://doi.org/10.1057/s41599-025-04718-x

IBM Security. (2024). Cost of a Data Breach Report 2024. IBM Corporation. https://www.ibm.com/reports/data-breach

Ifinedo, P. (2022). The effects of antecedents and mediating factors on cybersecurity protection behaviour. Computers in Human Behavior Reports, 5, 100165. https://doi.org/10.1016/j.chbr.2021.100165

Khan, M. A. U. R. (2025). Enhancing participation of people aged 75+ in clinical and applied health research through inclusive, technology-enabled methodologies. Journal of Social Research Dynamics, 1(2), 1–14. https://doi.org/10.67265/jsrd.v1.i2.01

Knapova, L., Kruzikova, A., Dedkova, L. and Smahel, D. (2021). Who is smart with their smartphones? Determinants of smartphone security behavior. Cyberpsychology, Behavior, and Social Networking, 24(9), 584–592. https://doi.org/10.1089/cyber.2020.0599

Kraushaar, J. M. and Bohnet-Joschko, S. (2022). Smartphone use and security compliance among healthcare professionals: A behavioural perspective. BMC Medical Informatics and Decision Making, 22, 105. https://doi.org/10.1186/s12911-022-01835-7

Kshetri, N. (2023). Cybercrime and Cybersecurity in the Global South. Springer. https://doi.org/10.1007/978-3-031-29170-6

Lutfi, A. (2022). Understanding the intention to adopt cloud-based accounting information systems in SMEs. Journal of Enterprise Information Management, 35(6), 1831–1854. https://doi.org/10.1108/JEIM-12-2020-0513

Maritime decision-makers and cyber security: Deck officers' perception of cyber risks towards IT and OT systems. International Journal of Information Security, 23, 1721–1739.

Oladipo, O., Abdulsalam, Y., Misra, S. and Maskeliūnas, R. (2024). Cybersecurity behaviour in FinTech: Examining psychological and human factors influencing compliance. Heliyon, 10(2), e24015. https://doi.org/10.1016/j.heliyon.2024.e24015

Parsons, K., McCormac, A., Butavicius, M., Pattinson, M. and Jerram, C. (2014). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q). Computers & Security, 42, 165–176. https://doi.org/10.1016/j.cose.2013.12.003

Renaud, K. and Weir, G. R. S. (2023). Cybersecurity and human behaviour: The role of organisational and technical controls. Computers & Security, 128, 103134. https://doi.org/10.1016/j.cose.2023.103134

Rogers, R. W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. T. Cacioppo and R. E. Petty (Eds.), Social psychophysiology: A sourcebook (pp. 153–176). Guilford Press.

Safa, N. S., Von Solms, R. and Furnell, S. (2022). Information security policy compliance model in organisations. Computers & Security, 120, 102819. https://doi.org/10.1016/j.cose.2022.102819

Tejay, G. P. S. and Winkfield, M. (2025). Does leadership approach matter? Examining behavioral influences of leaders on employees' information security compliance. Information Systems Frontiers. https://doi.org/10.1007/s10796-025-10592-4

ul-Haq, S. (2025). Cybersecurity challenges in mobile payment apps: Threats and solutions. Journal of Social Research Dynamics, 1(2), 54–71. https://doi.org/10.67265/jsrd.v1.i2.05

Ur Rehman, M. (2025). Integrating total quality management and human resources management in hospitality: A case study of Swissotel Hotel & Resort. Journal of Social Research Dynamics, 1(1), 24–36. https://doi.org/10.67265/jsrd.v1.i1.03

Vance, A., Siponen, M. and Pahnila, S. (2012). Motivating IS security compliance: Insights from habit and protection motivation theory. Information & Management, 49(3–4), 190–198. https://doi.org/10.1016/j.im.2012.04.002

Verizon. (2023). 2023 Data Breach Investigations Report (DBIR). Verizon Enterprise.

Verizon. (2024). 2024 Data Breach Investigations Report (DBIR). Verizon Business. https://www.verizon.com/business/resources/reports/dbir/

Vrhovec, S. and Markelj, B. (2024). We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers. arXiv. https://arxiv.org/abs/2404.04725

Zahid, M. E. (2025). The impact of influencer marketing on consumer loyalty and repeat purchase behavior. Journal of Social Research Dynamics, 1(2), 15–27. https://doi.org/10.67265/jsrd.v1.i2.02

Downloads

Published

2026-06-29