<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-24-1573</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v24i1.1573</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A model to reduce insider cybersecurity threats in a South African telecommunications company</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-5926-8069</contrib-id>
<name>
<surname>Silaule</surname>
<given-names>Carol B.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-5310-2906</contrib-id>
<name>
<surname>Makhubele</surname>
<given-names>Lean M.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-0519-4655</contrib-id>
<name>
<surname>Mamorobela</surname>
<given-names>Stevens P.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>Department of Informatics, Faculty of Information and Communication Technology, Tshwane University of Technology, Pretoria, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Carol Silaule, <email xlink:href="csilaule@gmail.com">csilaule@gmail.com</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>17</day><month>10</month><year>2022</year></pub-date>
<pub-date pub-type="collection"><year>2022</year></pub-date>
<volume>24</volume>
<issue>1</issue>
<elocation-id>1573</elocation-id>
<history>
<date date-type="received"><day>10</day><month>05</month><year>2022</year></date>
<date date-type="accepted"><day>03</day><month>08</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022. The Authors</copyright-statement>
<copyright-year>2022</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution License.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>Cybersecurity breaches have become a growing challenge in today&#x2019;s digital economy. Organisations are faced with the responsibility of protecting their information resources from cybersecurity threats, and insider threats are one of them. Organisations have sophisticated technologies to protect themselves against these attacks, and their employees are often less guarded when it comes to protecting valuable company information systems.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>This research was aimed to develop and conceptualise a model to reduce cybersecurity insider threats in a South African telecommunication organisation.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>This study was conducted using a survey research approach, where close-ended questionnaires were utilised to collect data from respondents. The collected data was then analysed using IBM Statistical Package for Social Science (SPSS).</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>The findings of the study indicated that personal norms in the domain of cybersecurity have a positive influence on individuals&#x2019; attitude towards engaging in cybersecurity misbehaviour, and this has a significant relationship with their reduction of insider threats (RIT).</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>This study suggests that management should give close and thoughtful attention to factors that encourage their employees to engage in cybersecurity misbehaviour. As an efficient and effective approach to mitigate the risk of cybersecurity insider threats, identification and classification of these factors should be followed by proper planning with a goal of reducing their negative effect on employees&#x2019; behaviour.</p>
</sec>
</abstract>
<kwd-group>
<kwd>cyberspace</kwd>
<kwd>cybersecurity</kwd>
<kwd>cyberthreats</kwd>
<kwd>insider threats</kwd>
<kwd>cybersecurity misbehaviour</kwd>
<kwd>information resources</kwd>
<kwd>telecommunications</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>Over the past 10 years, the internet and the broader concept of cyberspace has provided businesses with new opportunities for competitive advantage against their competitors and a direction for further economic growth (Sid <xref ref-type="bibr" rid="CIT0026">2017</xref>). These opportunities pose risks that arise because of the rapidly changing cyberthreat landscape and requires organisations to implement flexible and adoptable cybersecurity frameworks (Sid <xref ref-type="bibr" rid="CIT0026">2017</xref>). The emerging cybersecurity risks may arise from insider threats (Rodbert <xref ref-type="bibr" rid="CIT0022">2020</xref>). Insider threats can violate the organisation&#x2019;s security policy, either intentionally through malicious acts or through unintentional nonmalicious acts. Both actions can cause harm and significantly increase the probability of serious damage to the confidentiality, integrity or availability of the organisation&#x2019;s information systems or infrastructure and might result in compromising the security infrastructure of the organisation (Nurse et al. <xref ref-type="bibr" rid="CIT0018">2014</xref>).</p>
<p>Organisations are more focused on boosting the technology investment to protect themselves against external cyberattacks, and not enough emphasis is put on the insider threat aspects (Safa et al. <xref ref-type="bibr" rid="CIT0023">2019</xref>). Effective cybersecurity measures cannot be realised when the roles of users are not taken into consideration, as threats and attacks from employees may have a negative impact on the operation of the organisation&#x2019;s computer systems (Lamba et al. <xref ref-type="bibr" rid="CIT0015">2019</xref>). Furthermore, Clarke (<xref ref-type="bibr" rid="CIT0006">2018</xref>) found that organisations are not putting enough effort towards reducing cybersecurity insider threats to improve their security posture and foster organisational culture change in security behaviour. Even though organisations consider cybersecurity insider threats as a risk to their business operations, there is a necessity to have a full view and interdisciplinary approach that considers the technological aspect of cybersecurity insider threats along with the human or insider element, which is difficult for organisations to detect, prevent or reduce. It is with this in mind that the study focused on the human or insider element by adopting the situational crime prevention (SCP) and social bond (SB) theories as a basis to develop a model to reduce cybersecurity insider threats in a South African telecommunication company. The study addressed the following research questions:</p>
<list list-type="order">
<list-item><p>What are the factors of SCP and social bond theories (SBT) that deter employees from engaging in cybersecurity insider threats?</p></list-item>
<list-item><p>What influence does employees&#x2019; reduction of intention to misbehaviour (RIM) have on cybersecurity insider threat reduction?</p></list-item>
<list-item><p>Which factors of SCP and SBT best explain the reduction of insider threats (RIT)?</p></list-item>
</list>
<p><xref ref-type="fig" rid="F0001">Figure 1</xref> illustrates the research model of the study.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Research model on the reduction of cybersecurity insider threats.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-24-1573-g001.tif"/>
</fig>
</sec>
<sec id="s0002">
<title>Literature review</title>
<p>Kemper (<xref ref-type="bibr" rid="CIT0014">2017</xref>) defines cybersecurity as the &#x2018;preservation of the confidentiality, integrity and availability of information in cyberspace&#x2019;. According to Von Solms and Van Niekerk (<xref ref-type="bibr" rid="CIT0028">2018</xref>), cybersecurity deals with protecting digital assets such as hardware, network systems and processed information, which is stored by internetworked information systems in organisations, and it goes over and above the limitations of traditional information security to include the protection of the person who accesses the information on the cyberspace, as the person might be a potential target of cyberattacks or even unknowingly participating in cyberattacks.</p>
<sec id="s20003">
<title>Role of insiders in cybersecurity</title>
<p>Insider threats remain a significant problem within organisations, especially as industries&#x2019; reliance on technology continues to grow (Dupuis <xref ref-type="bibr" rid="CIT0009">2016</xref>). Insiders pose a great threat to organisation security infrastructure because they have the knowledge on the organisation&#x2019;s security protocols and authorised access to the organisation resources (Al &#x0026; Happa <xref ref-type="bibr" rid="CIT0001">2018</xref>). Insider threats can be posed either intentionally (malicious) or unintentionally (nonmalicious). An intentional or malicious insider is an employee with privileged access who intentionally seeks to perform a malicious act against the organisation which entrusted them with their valuable information assets, for example, revealing organisational secrets or deliberately causing sabotage to an organisation (Nurse et al. <xref ref-type="bibr" rid="CIT0018">2014</xref>). An unintentional or nonmalicious insider is described as an employee with access to an organisation&#x2019;s network, system or data without any malicious intent associated with their action that causes harm or significantly increases the probability of serious damage to the organisation&#x2019;s information systems or infrastructure, for example, an employee misplacing their work device (Homoliak et al. <xref ref-type="bibr" rid="CIT0012">2017</xref>).</p>
</sec>
<sec id="s20004">
<title>Situational crime prevention and social bond theories</title>
<p>Motivation and opportunity are key factors when exploring insider threats. Situational crime prevention theory explains how to decrease motivation and opportunity to reduce criminal activities or delinquent behaviour (Levan &#x0026; Mackey <xref ref-type="bibr" rid="CIT0016">2015</xref>). The SCP theory therefore argues that motivation and opportunity may trigger an individual to commit a misconduct or delinquent behaviour (Padayachee <xref ref-type="bibr" rid="CIT0019">2016</xref>). The SCP theory focus is therefore different from that of other criminological theories because it seeks to reduce lawbreaking motivation and opportunities rather than punish or rehabilitate offenders. According to Clarke (<xref ref-type="bibr" rid="CIT0006">2018</xref>), the SCP theory approaches crime reduction by making it impossible or difficult to commit the misconduct irrespective of the offender&#x2019;s motivation or intent, deterring the offender from committing the offence or by minimising stimuli that aggravate a person&#x2019;s motivation to commit a crime at any given time or event. Furthermore, a growing number of empirical studies and scientific evaluations have demonstrated that the SCP theory is an effective theory in reducing misconduct (Padayachee <xref ref-type="bibr" rid="CIT0019">2016</xref>).</p>
<p>On the other hand, the SBT states that everyone is capable of misbehaviour and that a &#x2018;bonding&#x2019; or social bond to conventional society can prevent most people from getting involved in delinquency (Choi, Martins &#x0026; Bernik <xref ref-type="bibr" rid="CIT0005">2018</xref>). According to Maalem et al. (<xref ref-type="bibr" rid="CIT0017">2020</xref>), when an individual social bond is weak, the likelihood of that person to engage in criminal activities is increased. Furthermore, the SBT can be applied to establish the rationale of individuals engaging in criminal activities. The SBT is based on the premise that even when offenders are considering or leaning towards engaging in criminal activities, their strong social bonds can deter them away from committing the crime (Dupuis <xref ref-type="bibr" rid="CIT0009">2016</xref>). Furthermore, the author alluded that an insider may not engage in criminal activity for fear of losing social surroundings, reputation and involvement in conventional activities. However, if an insider has a weak belief system and maintains an antisocial background, the chances of an insider crime occurring increase exponentially.</p>
</sec>
<sec id="s20005">
<title>Impact of insider threats to organisations</title>
<p>A survey conducted indicated that about 44&#x0025; of all organisations experienced abuse of computer systems in 2008; 42&#x0025; reported loss of laptops both in 2008 and 2009; and 17&#x0025; reported theft of customer data (Richardson <xref ref-type="bibr" rid="CIT0021">2018</xref>). Homoliak et al. (<xref ref-type="bibr" rid="CIT0012">2017</xref>) also conducted a survey which revealed that 25&#x0025; of the respondents felt that 60&#x0025; of the organisation financial losses was caused by insiders; unauthorised access or privileged access by insiders is 15&#x0025;; and internet access and e-mail abuse by insiders are the fourth most widespread incident. Both the surveys indicate that insider threats are real and nearly rising to the level of an external threat (Homoliak et al. <xref ref-type="bibr" rid="CIT0012">2017</xref>).</p>
</sec>
<sec id="s20006">
<title>Cyberthreats in the South African context</title>
<p>A study was conducted to analyse or review the findings of a research study which was undertaken with a goal of evaluating South Africa&#x2019;s cyberthreat landscape (Pieterse <xref ref-type="bibr" rid="CIT0020">2021</xref>). The study reviewed 74 cybersecurity incidents which were confirmed to have occurred between 2010 and 2020 in South Africa, affecting both government and private sectors. A few examples of organisations which were mentioned from the evaluating study include one of the government departments responsible for unemployment insurance payouts, where changes were implemented on their website to cater for temporary relief scheme during the coronavirus disease 2019 (COVID-19) pandemic; these changes unintentionally exposed confidential information of beneficiaries&#x2019; employers. One of the private hospital service providers was a victim of a cyberattack in June 2020 whereby their admissions, business processing systems and e-mail servers were encrypted. Moreover, a data breach of great magnitude occurred in one of South Africa&#x2019;s credit bureau organisations, where one of their employers unintentionally exposed customers&#x2019; personal information to a suspicious fraudster; this unfortunate incident is said to have affected 24 million South Africans and 800 000 business entities.</p>
</sec>
</sec>
<sec id="s0007">
<title>Research method and design</title>
<p>This study was conducted using a survey research approach. The targeted population for the study was professionals (project managers, software developers, business analysts, software test analysts, network specialists, IT architects, executive managers) within a division of a telecommunications company with legitimate access to computer systems, networks, data and information resources. A sample of 100 was randomly drawn using an Excel (Microsoft Corporation, Redmond, Washington, United States) random number generator from a population of 218. This probability sampling method based on simple random sampling techniques was recommended as all the members in the population had an equal opportunity of being selected (Taherdoost <xref ref-type="bibr" rid="CIT0027">2016</xref>). The Cohen statistical power analysis was utilised to determine the sample size of 100 (Drigo et al. <xref ref-type="bibr" rid="CIT0008">2020</xref>). However, only 95 out of the 100 targeted respondents returned fully completed questionnaires.</p>
<p>The participants were asked all the items associated with the variables on the proposed conceptual model. A secure web-based survey was used in this study as an instrument for gathering data to perform statistical analysis on the factors deterring employees from cybersecurity insider threats and ultimately their intention to reduce insider threats in an organisation. Data were collected using a 7-point Likert scale through a closed-ended questionnaire.</p>
<p>Analysis of data collected from the main survey questionnaire was evaluated through a two-stage approach, that is, the measurement model and structural model. The analysis was performed to ensure that there was no discrepancy in the collected data and to test and conduct an estimation of quantitative relationship that exists interdependently between independent variables (Durdyev, Ismail &#x0026; Kandymov <xref ref-type="bibr" rid="CIT0010">2018</xref>).</p>
</sec>
<sec id="s0008">
<title>Presentation of results</title>
<sec id="s20009">
<title>Demographic data</title>
<p>The results indicated that out of 95 respondents, 38.9&#x0025; (<italic>n</italic> = 37) were male respondents and 61.1&#x0025; (<italic>n</italic> = 58) were female respondents. Most of the participants were between 36 and 45 years at 56.8&#x0025; (<italic>n</italic> = 54), followed by 26&#x2013;35 years at 30.5&#x0025; (<italic>n</italic> = 29). One respondent was above 55 years. Younger people (below 30 years) are more familiar with cybersecurity threats, while the older people are more cautious about cybersecurity issues (Fatokun et al. <xref ref-type="bibr" rid="CIT0011">2019</xref>). The study further showed a distribution of participants with various educational levels, including matric (<italic>n</italic> = 2), certificates (<italic>n</italic> = 3), diploma (<italic>n</italic> = 17), bachelor&#x2019;s degrees (<italic>n</italic> = 30), honours (<italic>n</italic> = 19), Master&#x2019;s (<italic>n</italic> = 22) and PhD (<italic>n</italic> = 1). Only one participant did not disclose his or her level of education. According to Bostan and Akaman (<xref ref-type="bibr" rid="CIT0003">2017</xref>), highly educated people are aware of various technologies, and they become early adopters of new technologies. As noted by Bostan and Akman (<xref ref-type="bibr" rid="CIT0003">2017</xref>), people with higher levels of education are more aware of cybersecurity issues. In relation to this study, it can be noted that most of the participants had higher levels of education, implying that they are highly aware of cybersecurity insider threats.</p>
</sec>
<sec id="s20010">
<title>Correlation analysis of the constructs</title>
<p>According to Isaac and Chikweru (<xref ref-type="bibr" rid="CIT0013">2018</xref>), before evaluating the relationship between the model and constructs, the two variables must be measured at the interval or ratio scale, ensuring that there is a linear relationship between the two variables, significant outliers do not exist and the data should be approximately normally distributed. For this study, these checks were conducted to ensure that Pearson correlation is the suitable statistic. To evaluate the constructs&#x2019; relationships, the results were therefore analysed by using the bivariate Pearson correlation. The constructs&#x2019; correlation was tested at 0.01 and 0.05 confidence level. Likewise, cases were also excluded from the analysis to allow only cases with no missing data to be analysed. Therefore, from the total population of 95, five cases were identified to have missing data; as a result, these cases were therefore eliminated from the analysis. <xref ref-type="fig" rid="F0002">Figure 2</xref> shows the correlation analysis results.</p>
<fig id="F0002">
<label>FIGURE 2</label>
<caption><p>The correlation analysis results.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-24-1573-g002.tif"/>
</fig>
<p>The results in <xref ref-type="fig" rid="F0002">Figure 2</xref> show a positive significant correlation among various model constructs. The results imply that there is a strong relationship among the model constructs. However, the results showed no relation between the involvement (IN) construct and the remove excuses (RE) construct. Most importantly, the results show a strong correlation significance between RIM and all the measuring constructs, that is, increase the effort (IE), increase the risk (IR), reduce the rewards (RR), reduce provocations (RP), RE, attachment (AT), commitment (CO), IN and personal norms (PN). A strong correlation significance was also noted between RIT and all the measuring constructs, including the RIT construct.</p>
</sec>
<sec id="s20011">
<title>Measurement model</title>
<p>This study applied structural equation modelling (SEM) to validate or check the measurement model, and the correlations of the independent and dependent variables were also explored using SEM. The measurement model executes the relationship between the measured to the latent variables. The ovals represented the latent variables when drawing the measurement model in AMOS v. 26.0 (IBM Corporation, Armonk, New York, United States), that is, IE, IR, RR, RP, RE, AT, CO, IN, PN, RIM and RIT. The indicators or attributes for each construct are represented by the rectangles. Construct indicators were coded based on the abbreviation of each construct. Arbitrary names with a term &#x2018;e&#x2019; and a numerical value were the error terms. Nonidentification of the model is one of the known common errors of SEM. However, this was minimised by assigning a fixed value of one to at least one construct indicator. <xref ref-type="fig" rid="F0003">Figure 3</xref> characterises the measurement model for this study.</p>
<fig id="F0003">
<label>FIGURE 3</label>
<caption><p>The measurement model.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-24-1573-g003.tif"/>
</fig>
</sec>
<sec id="s20012">
<title>Testing the structural model</title>
<p>The reliability and validity of this study&#x2019;s model was tested using SEM, as it has the capability of simultaneously testing the model and its validity (Drigo et al. <xref ref-type="bibr" rid="CIT0008">2020</xref>). Furthermore, SEM is a confirmatory factor analysis which can be applied to test and estimate the casual or fundamental relationships using both underlying qualitative assumptions and statistical data. Based on the analysis of the structural measurement model results, the new values obtained for all the model fit indices were within the acceptable threshold. Therefore, it can be concluded that the structural model is fit to measure the reduction of cybersecurity insider threats in South African telecommunication organisation. Based on the structural model results, this study&#x2019;s theoretical hypotheses were also evaluated.</p>
</sec>
<sec id="s20013">
<title>Hypothesis testing</title>
<p>After the completion of the construct&#x2019;s validity and reliability tests, the reduction of constructs to their composite scores was performed in order to allow for the correlation and regression analysis, which was crucial to test the strength of the relationship between the constructs, which are the dependent, independent, moderator and mediating variables. Bivariate correlation coefficient analysis was used to test the strength of the relationship that exists between constructs of this study. <xref ref-type="table" rid="T0001">Table 1</xref> illustrates the results of the hypothesis testing as extracted from the statistical data analysis. The table shows motivation and opportunities that influence employees&#x2019; attitudes towards reducing their intention to participate in cybersecurity misbehaviour.</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Hypothesis test results.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Hypotheses</th>
<th valign="top" align="left">Path</th>
<th valign="top" align="left">Hypothesis description</th>
<th valign="top" align="center">Estimate</th>
<th valign="top" align="center"><italic>p</italic></th>
<th valign="top" align="left">Results</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="6"><bold>SCP theory: Attitudes that employees have towards reduction of intention to engage in cybersecurity violations may be influenced by:</bold></td>
</tr>
<tr>
<td align="left">H1</td>
<td align="left">RIM &#x003C;--- IE</td>
<td align="left"><italic>Increasing the effort required to engage in cybersecurity misbehaviour</italic></td>
<td align="center">&#x2212;0.065</td>
<td align="center">0.48</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H2</td>
<td align="left">RIM &#x003C;---IR</td>
<td align="left"><italic>Increasing the risk attached to engaging in cybersecurity misbehaviour.</italic></td>
<td align="center">0.044</td>
<td align="center">0.635</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H3</td>
<td align="left">RIM &#x003C;---RR</td>
<td align="left"><italic>Reducing the rewards associated with engaging in cybersecurity misbehaviour.</italic></td>
<td align="center">0.077</td>
<td align="center">0.387</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H4</td>
<td align="left">RIM &#x003C;---RP</td>
<td align="left"><italic>Reducing provocations for cybersecurity misbehaviour.</italic></td>
<td align="center">0.013</td>
<td align="center">0.805</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H5</td>
<td align="left">RIM &#x003C;---RE</td>
<td align="left"><italic>Removing excuses for cybersecurity misbehaviour.</italic></td>
<td align="center">0.045</td>
<td align="center">0.628</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left" colspan="6"><bold>SB theory: Factors that influence employees&#x2019; attitudes towards reducing the intention to engage in cybersecurity violations:</bold></td>
</tr>
<tr>
<td align="left">H6</td>
<td align="left">RIM &#x003C;---RE</td>
<td align="left"><italic>Attachment to an organisation</italic></td>
<td align="center">0.241</td>
<td align="center">0.369</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H7</td>
<td align="left">RIM &#x003C;---CO</td>
<td align="left"><italic>Commitment to an organisation</italic></td>
<td align="center">&#x2212;0.051</td>
<td align="center">0.904</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H8</td>
<td align="left">RIM &#x003C;---IN</td>
<td align="left"><italic>Involvement in cybersecurity</italic></td>
<td align="center">&#x2212;0.009</td>
<td align="center">0.935</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H9</td>
<td align="left">RIM &#x003C;---PN</td>
<td align="left"><italic>Personal norms</italic></td>
<td align="center">0.696</td>
<td align="center">0.04</td>
<td align="left">Supported</td>
</tr>
<tr>
<td align="left" colspan="6"><bold>Cybersecurity misbehaviour may be reduced by the:</bold></td>
</tr>
<tr>
<td align="left">H10</td>
<td align="left">RIT &#x003C;---RIM</td>
<td align="left"><italic>low strength of an intent to participate in cybersecurity misbehaviour.</italic></td>
<td align="center">0.942</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">***</xref></td>
<td align="left">Supported</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="TFN0001"><label>***</label><p>, <italic>p</italic>-value of 0.05.</p></fn>
<fn><p>RIM, reduction of intention to misbehaviour; RE, remove excuses; IE, increase the effort; IR, increase the risk; RR, reduce the rewards; RP, reduce provocations; PN, personal norms; CO, commitment; IN, involvement; RIT, reduction of insider threats.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The outcome of testing H1 to H8 shows that these hypotheses were proven to not have any significance towards the employees&#x2019; reduction of their intention to engage in misbehaviour. Therefore, H1 to H8 are not supported. On the contrary, the results show that H9 and H10 are supported. This implies that employees who hold personal values and beliefs that are against misbehaviour in an organisation are most likely to reduce their intention to engage in misbehaviour, consequently reducing cybersecurity insider threats.</p>
</sec>
</sec>
<sec id="s0014">
<title>Discussions</title>
<p>The research questions which grounded this study provided the framework for the discussion.</p>
<sec id="s20015">
<title>Key findings</title>
<p>In the context of this study, PN refer to individual positive or negative beliefs, values and views towards engaging in specific behaviour in the domain of cybersecurity (Padayachee <xref ref-type="bibr" rid="CIT0019">2016</xref>). According to Schoenherr and Thomson (<xref ref-type="bibr" rid="CIT0025">2021</xref>), cybersecurity behaviours are determined by individual PN, and their personality traits are likely to be associated with behaviours that both prevent and promote cybersecurity insider threats. Despite a person&#x2019;s natural feeling towards misbehaviour, their strong will to avoid misbehaviour deters them from committing criminal acts. On the contrary, the possibility of an employee being involved in cybersecurity insider threats increases when they have negative views towards complying with organisation cybersecurity policies (Bell, Rodgers &#x0026; Pearce <xref ref-type="bibr" rid="CIT0002">2019</xref>). Furthermore, the authors alluded that individuals who possess commendable PN and values have an attitude which is of a good outcome concerning adhering to cybersecurity policies, consequently reducing insider threats in their respective organisations.</p>
<p>When employees in an organisation decide against the violation of cybersecurity policies, they are likely to comply or follow the prescribed policies and intend to reduce misbehaviour in the domain of cybersecurity, thereby reducing insider threats (Chattopadhyay, Wang &#x0026; Tan <xref ref-type="bibr" rid="CIT0004">2018</xref>). In this study, review of the literature revealed that PN affect individuals&#x2019; attitudes towards engaging in organisational cybersecurity misbehaviour, and this has a significant relationship with their RIM (Rodbert <xref ref-type="bibr" rid="CIT0022">2020</xref>). According to the empirical evidence gathered in this study, PN were found to have a positive relationship with the reduction of intention to misbehave. This means that employees&#x2019; PN influence their reduction of intention to misbehave, thus reducing insider threats in their organisation.</p>
<p>The findings of this study substantiate the main goal of this study, which was to develop and conceptualise a model to reduce cybersecurity insider threats in a South African telecommunication organisation. The model can be utilised as a mitigation strategy to reduce insider threats and attacks. From the suggested research model, the hypothesised relationships were tested. Some hypotheses were accepted, whereas others were rejected. From the accepted hypotheses, a new validated model was obtained; the model only shows those constructs where the hypothesised relationships were supported during the structural modelling. <xref ref-type="fig" rid="F0004">Figure 4</xref> demonstrates the model developed from the findings of this study.</p>
<fig id="F0004">
<label>FIGURE 4</label>
<caption><p>Model on the reduction of cybersecurity insider threats.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-24-1573-g004.tif"/>
</fig>
</sec>
</sec>
<sec id="s0016">
<title>Strengths and limitations</title>
<p>Even though confirmation of the study&#x2019;s results is based on statistical instruments and methods that have been validated by previous research, the approaches will always have some limitations around internal validity and generalisability (Saunders, Lewis &#x0026; Thornhill <xref ref-type="bibr" rid="CIT0024">2019</xref>). This is because of statistical methods allowing for some measure of error, as well as the context in which the study was performed and how the research data was collected, which can cause problems with regard to validity and generalisability (Cohen <xref ref-type="bibr" rid="CIT0007">2019</xref>). Because of the nature of this study, it was expected that there could be some inherent bias with how individuals would answer the survey questionnaire, as it asks probing questions around the cybersecurity behaviours in cyberspace, which they might not be willing to share truthfully (Cohen <xref ref-type="bibr" rid="CIT0007">2019</xref>). Because of the challenges of the COVID-19 pandemic, it was difficult to physically collect data from participants in the organisation; therefore, the study only relied on electronic responses other than the physical questionnaire.</p>
<p>A cross-sectional survey was used in this study, thus justifying the collection of data only once. The single collection of data might be a missed opportunity to understand insider behaviour in the near future as far as cybersecurity is concerned and also the opportunity to predict or understand how the respondents are planning to reduce their intention to engage in cybersecurity misbehaviour in the long run.</p>
</sec>
<sec id="s0017">
<title>Implications or recommendations</title>
<p>Even though the insider threats challenges are on the rise, there has been scant research explaining how organisations can determine whether their cybersecurity measures and insider threats mitigation strategies are suitable or best fit in their operational environment. Along with the technical solutions to insider threats challenges, future research should consider that exploring the motivation and opportunity to engage in insider threats could be more important to the context of insider threat reduction in the domain of cybersecurity than it is currently known and understood.</p>
<p>This study sampled its population from a telecommunication organisation; however, closely related to the augmentation of cybersecurity insider threats reduction measures, as well as the novelty of protecting valuable information resources in South African telecommunications organisations, future researchers should consider increasing their sample population to cover the broader demographics of institutions other than the telecommunications industry, adopting other sampling and survey methods such as physical interviews which may help reach interested respondents who were thought of as previously unreachable. The adoption of a longitudinal timeline as well contextualising the privacy concept before participation should be considered by future researchers.</p>
<p>Lastly, this study can be further extended by exploring cybersecurity insider threats from different perspectives by exploring how organisational values, culture and employees&#x2019; moral grounds discourage individuals from engaging in cybersecurity misbehaviour.</p>
</sec>
<sec id="s0018">
<title>Conclusion</title>
<p>The study aimed at exploring and explaining the factors which deter employees from engaging in cybersecurity insider threats in a South African telecommunication company. The study examined factors of SCP and SB theories, which influence individual reduction of intentions to violate cybersecurity insider threats prevention policies and subsequently reduce insider threats in this context. On the basis of the empirical data derived from this study, a conceptual model has therefore been presented illustrating how to reduce insider threats in organisations.</p>
<p>A secure web survey was used to gather data from IT professionals who access company information resources, business applications, systems, networks and computing devices in the cyberspace. The survey was developed based on an extensive literature survey on cybersecurity insider threats. Situational crime prevention theory and SBT were used as theoretical lenses for this study. The analysis of the problem and context, the literature survey and the theoretical lenses informed the development of the research questions and research objectives and hypotheses. Based on the empirical evidence gathered in this study, the findings of the study confirmed some of the hypothesised relationships in the research model. Personal norms were found to have a positive influence on individual RIM, thus showing that individual norms and beliefs influence their RIM, which in turn reduces insider threats in their organisation.</p>
<p>Lastly, this study suggests that management should give close and thoughtful attention to factors that encourage their employees to engage in cybersecurity misbehaviour. As an efficient and effective approach to mitigate the risk of cybersecurity insider threats, identification and classification of these factors should be followed by proper planning with a goal of reducing their negative effect on employees&#x2019; behaviour.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<p>Dr L.M. Makhubele (DTech, Department of Informatics) was the research supervisor and Dr S.P. Mamorobela the cosupervisor (DTech, Department of Informatics). They guided the researcher C.B. Silaule in designing the research questions, methodology, literature review, data collection, data analysis and discussion of findings.</p>
<sec id="s20019" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20020">
<title>Authors&#x2019; contributions</title>
<p>C.B.S. was the research leader and involved in designing the research questions, methodology used, literature review, data collection, codification and analysis and writing of the manuscript. L.M.M. was the research supervisor and S.P.M. the cosupervisor. They guided the researcher C.B.S. in designing the research questions, methodology, literature review, data collection, data analysis and discussion of findings.</p>
</sec>
<sec id="s20021">
<title>Ethical considerations</title>
<p>Ethical clearance to conduct this study was obtained from the Tshwane University of Technology Information and Communication Technology Faculty Committee for Research Ethics, before the survey was conducted (ref. no. FCRE/ICT/2020/09/005(1)). Ethical clearance was approved unconditionally on 27 October 2020. The ethical guidelines, as outlined in the approval protocol by the Ethics Committee, were followed throughout the data collection process.</p>
</sec>
<sec id="s20022">
<title>Funding information</title>
<p>This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</p>
</sec>
<sec id="s20023">
<title>Data availability</title>
<p>No names will be provided in questionnaires and when reporting, the researcher will refer to participants as respondents. Feedback to participants will be given by providing a copy of the finished thesis to each section that was involved; moreover, another copy will be handed to the office of the Head of Department, which can be accessed by all employees within the Department. The copy of the thesis will also be made available electronically at Tshwane University of Technology library.</p>
</sec>
<sec id="s20024">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of any affiliated agency of the authors.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Happa</surname>, <given-names>J</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Insider-threat detection using Gaussian</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>77</volume>, <fpage>838</fpage>&#x2013;<lpage>859</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2018.03.006">https://doi.org/10.1016/j.cose.2018.03.006</ext-link></comment></mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bell</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Rogers</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Pearce</surname>, <given-names>M</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The insider threat : Behavioral indicators and factors influencing likelihood of intervention</article-title>&#x2019;, <source><italic>International Journal of Critical Infrastructure Protection</italic></source> <volume>24</volume>, <fpage>166</fpage>&#x2013;<lpage>176</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijcip.2018.12.001">https://doi.org/10.1016/j.ijcip.2018.12.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bostan</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Akman</surname>, <given-names>I</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Impact of education on security practices in ICT</article-title>&#x2019;, <source><italic>MIS Quarterly: Management Information Systems</italic></source> <volume>13</volume>, <fpage>319</fpage>&#x2013;<lpage>339</lpage>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chattopadhyay</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Wang</surname>, <given-names>L</given-names></string-name>. &#x0026; <string-name><surname>Tan</surname>, <given-names>Y.P</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Scenario-based insider threat detection from cyber activities</article-title>&#x2019;, <source><italic>IEEE Transactions on Computational Social Systems</italic></source> <volume>5</volume>(<issue>3</issue>), <fpage>660</fpage>&#x2013;<lpage>675</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/TCSS.2018.2857473">https://doi.org/10.1109/TCSS.2018.2857473</ext-link></comment></mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Choi</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Martins</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Bernik</surname>, <given-names>I</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Information security : Listening to the perspective of organisational insiders</article-title>&#x2019;, <source><italic>Journal of Information Science</italic></source> <volume>44</volume>(<issue>6</issue>), <fpage>752</fpage>&#x2013;<lpage>767</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/0165551517748288">https://doi.org/10.1177/0165551517748288</ext-link></comment></mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Clarke</surname>, <given-names>R.V</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>The theory and practice of situational crime prevention</article-title>&#x2019;, <source><italic>Crime Prevention Studies</italic></source> <volume>1</volume>(<issue>1</issue>), <fpage>1</fpage>&#x2013;<lpage>19</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1093/acrefore/9780190264079.013.327">https://doi.org/10.1093/acrefore/9780190264079.013.327</ext-link></comment></mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cohen</surname>, <given-names>J</given-names></string-name></person-group>., <year>2019</year>, <source><italic>Information systems IBM SPSS workbook</italic></source>, vol. <volume>1</volume>, pp. <fpage>11</fpage>&#x2013;<lpage>14</lpage>, <publisher-name>School of Economic and Business Sciences</publisher-name>, <publisher-loc>Hillsdale, NJ</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Drigo</surname>, <given-names>E</given-names></string-name>., <string-name><surname>Rodriguez</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Embirucu</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Fihlo</surname>, <given-names>S</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Analysis of operational communication through structural equation modeling</article-title>&#x2019;, <source><italic>IEEE Access</italic></source> <volume>8</volume>, <fpage>121705</fpage>&#x2013;<lpage>121723</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/ACCESS.2020.3006421">https://doi.org/10.1109/ACCESS.2020.3006421</ext-link></comment></mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dupuis</surname>, <given-names>M</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Curiosity killed the organization : A psychological comparison between malicious and non-malicious insiders and the insider threat</article-title>&#x2019;, <source><italic>Cybersecurity Crime Prevention Studies</italic></source> <volume>5</volume>, <fpage>35</fpage>&#x2013;<lpage>40</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/2978178.2978185">https://doi.org/10.1145/2978178.2978185</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Durdyev</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Ismail</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Kandymov</surname>, <given-names>N</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Structural equation model of the factors affecting construction labor productivity</article-title>&#x2019;, <source><italic>Journal of Construction Engineering and Management</italic></source> <volume>144</volume>(<issue>4</issue>), <fpage>18</fpage>&#x2013;<lpage>21</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1061/(ASCE)CO.1943-7862.0001452">https://doi.org/10.1061/(ASCE)CO.1943-7862.0001452</ext-link></comment></mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fatokun</surname>, <given-names>F</given-names></string-name>., <string-name><surname>Hamid</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Norman</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Fatakun</surname>, <given-names>J</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The impact of age, gender, and educational level on the cybersecurity behaviors of tertiary institution students: An empirical investigation on Malaysian Universities</article-title>&#x2019;, <source><italic>Journal of Physics: Conference Series</italic></source> <volume>1339</volume>, <fpage>19</fpage>&#x2013;<lpage>21</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1088/1742-6596/1339/1/012098">https://doi.org/10.1088/1742-6596/1339/1/012098</ext-link></comment></mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Homoliak</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Toffalini</surname>, <given-names>F</given-names></string-name>., <string-name><surname>Guarnizo</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Elovici</surname>, <given-names>Y</given-names></string-name>. &#x0026; <string-name><surname>Ocha</surname>, <given-names>M</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Insight into insiders and IT: A survey of insider threat taxonomies, analysis, modeling, and countermeasures</article-title>&#x2019;, <source><italic>Journal for Applied Mathematics and Computer Science</italic></source> <volume>52</volume>(<issue>2</issue>), <fpage>1</fpage>&#x2013;<lpage>40</lpage>.</mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Isaac</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Chikweru</surname> <given-names>E</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Test for significance of pearson&#x2019;s correlation coefficient (r)</article-title>&#x2019;, <source><italic>International Journal of Innovative Mathematics, Statistics &#x0026; Energy Policies</italic></source> <volume>1</volume>, <fpage>11</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kemper</surname>, <given-names>G</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Improving employees&#x2019; cyber security awareness</article-title>&#x2019;, <source><italic>Computer Fraud &#x0026; Security Bulletin</italic></source> <volume>2017</volume>(<issue>8</issue>), <fpage>11</fpage>&#x2013;<lpage>14</lpage>.</mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lamba</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Singh</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Singh</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Dutta</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Muni</surname>, <given-names>R</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Analyzing and fixing cyber security threats for supply chain management</article-title>&#x2019;, <source><italic>SSRN Electronic Journal</italic></source> <volume>4</volume>(<issue>5</issue>), <fpage>5678</fpage>&#x2013;<lpage>5681</lpage>.</mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Levan</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Mackey</surname>, <given-names>A</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Prevention of crime and delinquency</article-title>&#x2019;, <source><italic>International Encyclopedia of the Social &#x0026; Behavioral Sciences</italic></source> <volume>18</volume>, <fpage>877</fpage>&#x2013;<lpage>882</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/B978-0-08-097086-8.45012-9">https://doi.org/10.1016/B978-0-08-097086-8.45012-9</ext-link></comment></mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Maalem</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Caulkins</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Mohapatra</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Kumar</surname>, <given-names>M</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Review and insight on the behavioral aspects of cybersecurity</article-title>&#x2019;, <source><italic>Journal of Cybersecurity</italic></source> <volume>3</volume>, <fpage>1</fpage>&#x2013;<lpage>18</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/s42400-020-00050-w">https://doi.org/10.1186/s42400-020-00050-w</ext-link></comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nurse</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Buckley</surname>, <given-names>O</given-names></string-name>., <string-name><surname>Legg</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Goldsmith</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Creese</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Wright</surname>, <given-names>G</given-names></string-name>. <etal>et al</etal></person-group>., <year>2014</year>, &#x2018;<article-title>Understanding insider threat: A framework for characterising attacks</article-title>&#x2019;, <source><italic>IEEE Security and Privacy Workshops</italic></source> <volume>10</volume>, <fpage>224</fpage>&#x2013;<lpage>228</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/SPW.2014.38">https://doi.org/10.1109/SPW.2014.38</ext-link></comment></mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Padayachee</surname>, <given-names>K</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>An assessment of opportunity-reducing techniques in information security : An insider threat perspective</article-title>&#x2019;, <source><italic>Decision Support Systems</italic></source> <volume>92</volume>, <fpage>47</fpage>&#x2013;<lpage>56</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.dss.2016.09.012">https://doi.org/10.1016/j.dss.2016.09.012</ext-link></comment></mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pieterse</surname>, <given-names>H</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>The cyber threat landscape in South Africa: A 10-year review</article-title>&#x2019;, <source><italic>The African Journal of Information and Communication</italic></source> <volume>28</volume>, <fpage>1</fpage>&#x2013;<lpage>21</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.23962/10539/32213">https://doi.org/10.23962/10539/32213</ext-link></comment></mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Richardson</surname>, <given-names>R</given-names></string-name></person-group>., <year>2018</year>, <source><italic>CSI computer crime and security survey</italic></source>, vol. <volume>1</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>30</lpage>, <publisher-name>Computer Security Institute</publisher-name>, <publisher-loc>San Francisco</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rodbert</surname>, <given-names>M</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Why organisational readiness is vital in the fight against insider threats</article-title>&#x2019;, <source><italic>Network Security</italic></source> <volume>2020</volume>(<issue>8</issue>), <fpage>7</fpage>&#x2013;<lpage>9</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S1353-4858(20)30092-1">https://doi.org/10.1016/S1353-4858(20)30092-1</ext-link></comment></mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Safa</surname>, <given-names>N</given-names></string-name>., <string-name><surname>Maple</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Watson</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Von Solms</surname>, <given-names>R</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Motivation and opportunity based model to reduce information security insider threats in organisations</article-title>&#x2019;, <source><italic>Total SS Private Sector</italic></source> <volume>12</volume>, <fpage>1</fpage>&#x2013;<lpage>61</lpage>.</mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Saunders</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Lewis</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Thornhill</surname>, <given-names>A</given-names></string-name></person-group>., <year>2019</year>, <source><italic>Research methods for business students</italic></source>, <edition>5th</edition> edn., vol. <volume>5</volume>, pp. <fpage>14</fpage>&#x2013;<lpage>134</lpage>, <publisher-name>Pearson Education Limited</publisher-name>, <publisher-loc>Cape Town</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Schoenherr</surname>, <given-names>J.R</given-names></string-name>. &#x0026; <string-name><surname>Thomson</surname>, <given-names>R</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>The cybersecurity (CSEC) questionnaire : Individual differences in unintentional insider threat behaviours</article-title>&#x2019;, <source><italic>Journal of Information Security and Applications</italic></source> <volume>4</volume>, <fpage>8</fpage>&#x2013;<lpage>28</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/CyberSA52016.2021.9478213">https://doi.org/10.1109/CyberSA52016.2021.9478213</ext-link></comment></mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Sid</surname>, <given-names>L</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>A novel model for cybersecurity economics and analysis</article-title>&#x2019;, <conf-name>17th IEEE International Conference on Computer and Information Technology</conf-name>, <conf-loc>Helsinki, Finland</conf-loc>, <conf-date>Aug 22&#x2013;23, 2017</conf-date>, vol. <volume>17</volume>, pp. <fpage>274</fpage>&#x2013;<lpage>279</lpage>.</mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Taherdoost</surname>, <given-names>H</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Sampling methods in research methodology; How to choose a sampling technique for research</article-title>&#x2019;, <source><italic>International Journal of Academic Research in Management (IJARM)</italic></source> <volume>5</volume>(<issue>2</issue>), <fpage>18</fpage>&#x2013;<lpage>27</lpage>.</mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Von Solms</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Van Niekerk</surname>, <given-names>J</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>From information security to cyber security</article-title>&#x2019;, <source><italic>Computers and Security</italic></source> <volume>38</volume>, <fpage>97</fpage>&#x2013;<lpage>102</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2013.04.004">https://doi.org/10.1016/j.cose.2013.04.004</ext-link></comment></mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Silaule, C.B., Makhubele, L.M. &#x0026; Mamorobela, S.P., 2022, &#x2018;A model to reduce insider cybersecurity threats in a South African telecommunications company&#x2019;, <italic>South African Journal of Information Management</italic> 24(1), a1573. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v24i1.1573">https://doi.org/10.4102/sajim.v24i1.1573</ext-link></p></fn>
</fn-group>
</back>
</article>