When technology is not enough: the role of internal communication in cybersecurity
DOI:
https://doi.org/10.34630/tth.v6i1.7267Keywords:
Cybersecurity, Culture, Internal Communication, Employee BehaviourAbstract
Organisations continue to strengthen their cybersecurity through technological investment, yet many security incidents still arise from routine employee practices. This article examines that limitation and argues that technology alone does not secure organisational environments. A more effective response depends on the interaction between internal communication, organisational culture, and employee behaviour. This interaction is reflected in internal communication that shapes how security requirements are interpreted and enacted in daily work, a shared culture that normalises protective conduct, and employee involvement in the enactment of secure behaviour. Drawing on literature on cybersecurity, organisational culture, and internal communication, the article frames digital protection as a socio-technical issue rather than a purely technical one. The discussion shows that risk often emerges when formal rules fail to connect with everyday routines. For that reason, cybersecurity should be managed as an organisational process in which technical measures, communication practices, and behavioural alignment are treated as mutually dependent.References
Alhogail, A. (2015). Design and validation of information security culture framework. Computers in Human Behavior, 49, 567–575. https://doi.org/10.1016/j.chb.2015.03.054
Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behaviour: A practice perspective. Computers & Security, 98, 102003. https://doi.org/10.1016/j.cose.2020.102003
Aschwanden, R., Messner, C., Höchli, B., & Holenweger, G. (2024). Employee behaviour: The psychological gateway for cyberattacks. Organisational Cybersecurity Journal: Practice, Process & People, 4(1), 32–50. https://doi.org/10.1108/OCJ-02-2023-0004
Barlow, J. B., Warkentin, M., Ormond, D., & Dennis, A. (2018). Don’t even think about it! The effects of antineutralization, informational, and normative communication on information security compliance. Journal of the Association for Information Systems, 19(8),735–777. https://aisel.aisnet.org/jais/vol19/iss8/3/
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. https://doi.org/10.2307/25750690
Da Veiga, A., & Martins, N. (2015). Improving the information security culture through monitoring and implementation actions illustrated through a case study. Computers & Security, 49, 162–176. https://doi.org/10.1016/j.cose.2014.12.006
Da Veiga, A., Astakhova, L. V., Botha, A., & Herselman, M. (2020). Defining organisational information security culture—Perspectives from academia and industry. Computers & Security, 92, 101713. https://doi.org/10.1016/j.cose.2020.101713
Goo, J., Yim, M. S., & Kim, D. J. (2014). A path to successful management of employee security compliance: An empirical study of information security climate. IEEE Transactions on Professional Communication, 57(4), 286–308. https://doi.org/10.1109/TPC.2014.2374011
Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615–660. https://doi.org/10.1111/j.1540-5915.2012.00361.x
Men, L. R., & Stacks, D. W. (2014). The effects of authentic leadership on strategic internal communication and employee–organization relationships. Journal of Public Relations Research, 26(4), 301–324. https://doi.org/10.1080/1062726X.2014.908720
Petrič, G., & Just, J. N. (2025). Information security culture and phishing-reporting model: Structural equivalence across Germany, UK, and USA. Journal of Cybersecurity, 11(1), tyaf011. https://doi.org/10.1093/cybsec/tyaf011
Pollini, A., Callari, T. C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., & Guerri, D. (2022). Leveraging human factors in cybersecurity: An integrated methodological approach. Cognition, Technology & Work, 24(2), 371–390. https://doi.org/10.1007/s10111-021-00683-y
Rice, C., & Searle, R. H. (2022). The enabling role of internal organisational communication in insider threat activity: Evidence from a high-security organization. Management Communication Quarterly, 36(3), 467–495. https://doi.org/10.1177/08933189211062250
Saeed, S. (2023). Digital workplaces and information security behaviour of business employees: An empirical study of Saudi Arabia. Sustainability, 15(7), 6019. https://doi.org/10.3390/su15076019
Shahbaznezhad, H., Kolini, F., & Rashidirad, M. (2021). Employees’ behaviour in phishing attacks: What individual, organisational, and technological factors matter? Journal of Computer Information Systems, 61(6), 539–550. https://doi.org/10.1080/08874417.2020.1812134
Tkalac Verčič, A., Galić, Z., & Žnidar, K. (2023). The relationship of internal communication satisfaction with employee engagement and employer attractiveness: Testing the joint mediating effect of social exchange quality indicators. International Journal of Business Communication, 60(4), 1313–1340. https://doi.org/10.1177/23294884211053839
Vodafone. (2023). Cyber security factsheet. Vodafone Group. https://reports.investors.vodafone.com/view/919554535/9/
Wuersch, L., Neher, A., Maley, J. F., & Peter, M. K. (2024). Using a digital internal communication strategy for digital capability development. International Journal of Strategic Communication, 18(3), 167–188. https://doi.org/10.1080/1553118X.2024.2330405
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 The Trends Hub, Revista de Tendências em Comunicação e Ciências Empresariais

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.