When technology is not enough: the role of internal communication in cybersecurity

Authors

DOI:

https://doi.org/10.34630/tth.v6i1.7267

Keywords:

Cybersecurity, Culture, Internal Communication, Employee Behaviour

Abstract

Organisations continue to strengthen their cybersecurity through technological investment, yet many security incidents still arise from routine employee practices. This article examines that limitation and argues that technology alone does not secure organisational environments. A more effective response depends on the interaction between internal communication, organisational culture, and employee behaviour. This interaction is reflected in internal communication that shapes how security requirements are interpreted and enacted in daily work, a shared culture that normalises protective conduct, and employee involvement in the enactment of secure behaviour. Drawing on literature on cybersecurity, organisational culture, and internal communication, the article frames digital protection as a socio-technical issue rather than a purely technical one. The discussion shows that risk often emerges when formal rules fail to connect with everyday routines. For that reason, cybersecurity should be managed as an organisational process in which technical measures, communication practices, and behavioural alignment are treated as mutually dependent.

References

Alhogail, A. (2015). Design and validation of information security culture framework. Computers in Human Behavior, 49, 567–575. https://doi.org/10.1016/j.chb.2015.03.054

Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behaviour: A practice perspective. Computers & Security, 98, 102003. https://doi.org/10.1016/j.cose.2020.102003

Aschwanden, R., Messner, C., Höchli, B., & Holenweger, G. (2024). Employee behaviour: The psychological gateway for cyberattacks. Organisational Cybersecurity Journal: Practice, Process & People, 4(1), 32–50. https://doi.org/10.1108/OCJ-02-2023-0004

Barlow, J. B., Warkentin, M., Ormond, D., & Dennis, A. (2018). Don’t even think about it! The effects of antineutralization, informational, and normative communication on information security compliance. Journal of the Association for Information Systems, 19(8),735–777. https://aisel.aisnet.org/jais/vol19/iss8/3/

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. https://doi.org/10.2307/25750690

Da Veiga, A., & Martins, N. (2015). Improving the information security culture through monitoring and implementation actions illustrated through a case study. Computers & Security, 49, 162–176. https://doi.org/10.1016/j.cose.2014.12.006

Da Veiga, A., Astakhova, L. V., Botha, A., & Herselman, M. (2020). Defining organisational information security culture—Perspectives from academia and industry. Computers & Security, 92, 101713. https://doi.org/10.1016/j.cose.2020.101713

Goo, J., Yim, M. S., & Kim, D. J. (2014). A path to successful management of employee security compliance: An empirical study of information security climate. IEEE Transactions on Professional Communication, 57(4), 286–308. https://doi.org/10.1109/TPC.2014.2374011

Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615–660. https://doi.org/10.1111/j.1540-5915.2012.00361.x

Men, L. R., & Stacks, D. W. (2014). The effects of authentic leadership on strategic internal communication and employee–organization relationships. Journal of Public Relations Research, 26(4), 301–324. https://doi.org/10.1080/1062726X.2014.908720

Petrič, G., & Just, J. N. (2025). Information security culture and phishing-reporting model: Structural equivalence across Germany, UK, and USA. Journal of Cybersecurity, 11(1), tyaf011. https://doi.org/10.1093/cybsec/tyaf011

Pollini, A., Callari, T. C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., & Guerri, D. (2022). Leveraging human factors in cybersecurity: An integrated methodological approach. Cognition, Technology & Work, 24(2), 371–390. https://doi.org/10.1007/s10111-021-00683-y

Rice, C., & Searle, R. H. (2022). The enabling role of internal organisational communication in insider threat activity: Evidence from a high-security organization. Management Communication Quarterly, 36(3), 467–495. https://doi.org/10.1177/08933189211062250

Saeed, S. (2023). Digital workplaces and information security behaviour of business employees: An empirical study of Saudi Arabia. Sustainability, 15(7), 6019. https://doi.org/10.3390/su15076019

Shahbaznezhad, H., Kolini, F., & Rashidirad, M. (2021). Employees’ behaviour in phishing attacks: What individual, organisational, and technological factors matter? Journal of Computer Information Systems, 61(6), 539–550. https://doi.org/10.1080/08874417.2020.1812134

Tkalac Verčič, A., Galić, Z., & Žnidar, K. (2023). The relationship of internal communication satisfaction with employee engagement and employer attractiveness: Testing the joint mediating effect of social exchange quality indicators. International Journal of Business Communication, 60(4), 1313–1340. https://doi.org/10.1177/23294884211053839

Vodafone. (2023). Cyber security factsheet. Vodafone Group. https://reports.investors.vodafone.com/view/919554535/9/

Wuersch, L., Neher, A., Maley, J. F., & Peter, M. K. (2024). Using a digital internal communication strategy for digital capability development. International Journal of Strategic Communication, 18(3), 167–188. https://doi.org/10.1080/1553118X.2024.2330405

Published

2026-07:-27

How to Cite

Pereira , D. (2026). When technology is not enough: the role of internal communication in cybersecurity. The Trends Hub, Revista De Tendências Em Comunicação E Ciências Empresariais, 6(1). https://doi.org/10.34630/tth.v6i1.7267