<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-26-1853</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v26i1.1853</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A model on workarounds and information security integrity</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-6403-3624</contrib-id>
<name>
<surname>Njenga</surname>
<given-names>Kennedy</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0009-0007-0887-1731</contrib-id>
<name>
<surname>Nyamandi</surname>
<given-names>Ntsakisi F.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-4190-8256</contrib-id>
<name>
<surname>Segooa</surname>
<given-names>Mmatshuene A.</given-names>
</name>
<xref ref-type="aff" rid="AF0002">2</xref>
</contrib>
<aff id="AF0001"><label>1</label>Department of Applied Information Systems, College of Business and Economics, University of Johannesburg, Johannesburg, South Africa</aff>
<aff id="AF0002"><label>2</label>Department of Informatics, Faculty of Information &#x0026; Communication Technology, Tshwane University of Technology, Tshwane, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Kennedy Njenga, <email xlink:href="knjenga@uj.ac.za">knjenga@uj.ac.za</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>30</day><month>08</month><year>2024</year></pub-date>
<pub-date pub-type="collection"><year>2024</year></pub-date>
<volume>26</volume>
<issue>1</issue>
<elocation-id>1853</elocation-id>
<history>
<date date-type="received"><day>18</day><month>03</month><year>2024</year></date>
<date date-type="accepted"><day>09</day><month>07</month><year>2024</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024. The Authors</copyright-statement>
<copyright-year>2024</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution License.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>Workarounds are creative human actions that bypass a known problem in a system or a policy. Workarounds serve as temporary &#x2018;fixes&#x2019; when effective but will often compromise the integrity of information systems in the long term, mainly when they are ineffective.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>Forming part of behavioural studies in information systems security, the study aimed to investigate how workarounds influence the integrity of information security systems across businesses.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>A quantitative approach that followed the positivism paradigm was employed. A survey strategy was used, and data were collected using closed-ended questionnaires targeting employees working in the Gauteng province of South Africa. The survey elicited responses from 207 professional participants. Analysis was done using Statistical Package for Social Sciences (SPSS) v29 software.</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>The study suggests that <italic>Individuality</italic> and <italic>Job characteristics</italic> are crucial predictors of workarounds, with the most notable findings pointing to a significant positive association between <italic>Workaround</italic> and <italic>Information security integrity.</italic> Crucially, highly individualistic employees are more likely to initiate workarounds, and in turn, this influences information security integrity.</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>The work shows that employees with highly individualistic personalities are more likely to initiate workarounds and should be trained and supervised to mitigate this attribute, as this might be detrimental to information security integrity.</p>
</sec>
<sec id="st6">
<title>Contribution</title>
<p>The study contributes theoretically by showing how workaround activities influence information security integrity. This study will assist enterprises in fortifying their information security measures.</p>
</sec>
</abstract>
<kwd-group>
<kwd>workarounds</kwd>
<kwd>information security</kwd>
<kwd>integrity</kwd>
<kwd>behaviour</kwd>
<kwd>non-compliance</kwd>
</kwd-group>
<funding-group>
<funding-statement><bold>Funding information</bold> This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</funding-statement>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>The importance of information security in the context of human behaviour in modern organisations cannot be understated and remains crucial (Aksoy <xref ref-type="bibr" rid="CIT0001">2024</xref>). Understanding the socio-technical aspects of information security in organisations is necessary because human behaviour poses a high risk to the integrity of information security. Humans are often perceived as the weakest link in the information security chain (Daudi <xref ref-type="bibr" rid="CIT0020">2023</xref>), and targeted remedial measures are necessary to raise users&#x2019; awareness of this.</p>
<p>Human behaviour may introduce inherent information security risk particularly when such behaviour is exemplified in workarounds. Workarounds are creative human actions that bypass a known problem in a system or a policy. An employee may engage in workarounds to overcome any emergent challenge or limitation exposed by a system or process, and these workarounds will at times have a significant impact on the <italic>integrity, confidentiality</italic> and <italic>availability</italic> of protected data.</p>
<sec id="s20002">
<title>Study context</title>
<p>In early 2010, in a study by Kyobe (<xref ref-type="bibr" rid="CIT0035">2010</xref>), the authors raised concerns about compliance with information security policies across universities in South Africa. Twenty years later, Murire et al. (<xref ref-type="bibr" rid="CIT0040">2020</xref>) cited a lack of awareness as a major contributor to non-compliance across South African businesses. As recently as this year, Mugwagwa Bhero and Chibaya (<xref ref-type="bibr" rid="CIT0037">2024</xref>) pointed out that some of the strategies that should be implemented to curb cybersecurity threats include a &#x2018;focus on compliance&#x2019;. The Gauteng province hosts two large cities which include, Johannesburg, the largest city and Pretoria, the capital city. Gauteng attracts multinational and national financial institutions and businesses that are targets of serious cybercrimes, with employees playing a big part in contributing to cybersecurity risks. Employee behaviour across these institutions was raised as a concern. Workaround behaviour across businesses in Gauteng, South Africa, that are seen as contributing to non-compliance with information security policies and, therefore, contributing to risk is explained in the next section.</p>
</sec>
<sec id="s20003">
<title>Workarounds and compliance</title>
<p>Workarounds refer to employees&#x2019; ability to seek solutions to problems through bypassing policies when these policies are not perceived to be working. In efforts to circumvent an established information security protocol or procedure and initiate a workaround, an employee may introduce a system weakness known as a vulnerability that can be, at a later stage, exploited by an attacker with nefarious intentions. It is, therefore, necessary to understand what individual, cultural or institutional factors motivate employees to carry out workarounds. This research endears to the following problem:</p>
</sec>
<sec id="s20004">
<title>Problem statement</title>
<p>Adhering to information security policies is central to good information security practices (Siponen <xref ref-type="bibr" rid="CIT0045">2006</xref>). Unfortunately, workarounds seen as a form of non-complaint information security behaviour are becoming common because of perceived benefits (Azad &#x0026; King <xref ref-type="bibr" rid="CIT0005">2008</xref>). Little is known regarding why this is so. This research explores the reasons behind this trend, with a focus on how workarounds threaten the integrity of information systems.</p>
</sec>
<sec id="s20005">
<title>Research objectives</title>
<p>Considering the concern scholars raise regarding the non-compliance behaviour that characterises workarounds, this research undertook to examine the following:</p>
<list list-type="order">
<list-item><p>Carry out a literature review to gain an understanding of what are the factors that drive workarounds in workplaces.</p></list-item>
<list-item><p>Develop a model that explains these factors, propose and test hypotheses derived from this model.</p></list-item>
<list-item><p>Derive insights from the testing of this model that can add value and contribute to the body of knowledge on how organisations can manage workarounds and strengthen compliance of policies.</p></list-item>
</list>
<p>This research is therefore structured as follows: Section one has outlined the context of research and articulated the research problem and research objectives. Section two that follows examines the literature regarding workarounds, and the impact this behaviour has on the integrity of information. Section three explains the research methodology used in this study, and the penultimate sections discusses how data were analysed and the results that followed. The conclusion follows thereafter presenting the research work&#x2019;s contribution and way forward.</p>
</sec>
</sec>
<sec id="s0006">
<title>Literature review</title>
<p>This section provides a literature review of Information Security Integrity. A systematic literature review identified factors drawn from behavioural sciences that specifically focus on workaround behaviour. Based on these factors, six hypotheses were formulated and proposed. These factors were identified using a non-biased and scientific approach. The university under which this study was domiciled has subscribed to the following databases that assisted the researchers in identifying the relevant literature: <italic>ACM Digital Library, ProQuest, Emerald Management, IEE Explore, Scopus</italic> and <italic>ScienceDirect</italic>.</p>
<p>The search works included &#x2018;information integrity&#x2019;, &#x2018;factors influencing integrity,&#x2019; &#x2018;information security behaviour&#x2019;, &#x2018;information security workarounds&#x2019; and &#x2018;risk-in-workarounds&#x2019;. Various literature that presented factors that influence workarounds and how workarounds pose a security risk to information security integrity were included in this study. <xref ref-type="table" rid="T0001">Table 1</xref> summarises the outcome of this systematic literature review process.</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Information security integrity factors (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Constructs</th>
<th valign="top" align="left">Authors</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"><italic>Information security integrity</italic></td>
<td align="left">Liu, Wang and Liang (<xref ref-type="bibr" rid="CIT0038">2020</xref>), Harley and Cooper (<xref ref-type="bibr" rid="CIT0027">2021</xref>), Harley and Cooper (<xref ref-type="bibr" rid="CIT0027">2021</xref>), Colwill (<xref ref-type="bibr" rid="CIT0015">2009</xref>), Wong et al. (<xref ref-type="bibr" rid="CIT0053">2019</xref>).</td>
</tr>
<tr>
<td align="left"><italic>Workarounds</italic></td>
<td align="left">Alter (<xref ref-type="bibr" rid="CIT0003">2014</xref>), Woltjer (<xref ref-type="bibr" rid="CIT0052">2017</xref>), Rooney et al. (<xref ref-type="bibr" rid="CIT0043">2021</xref>), Slabbert, Thomson and Futcher (<xref ref-type="bibr" rid="CIT0046">2021</xref>), Van Offenbeek et al. (<xref ref-type="bibr" rid="CIT0050">2024</xref>)</td>
</tr>
<tr>
<td align="left"><italic>Self-efficacy</italic></td>
<td align="left">Hameed and Arachchilage (<xref ref-type="bibr" rid="CIT0026">2021</xref>), Rhee, Kim and Ryu (<xref ref-type="bibr" rid="CIT0042">2009</xref>), Tamjidyamcholo et al. (<xref ref-type="bibr" rid="CIT0048">2013</xref>).</td>
</tr>
<tr>
<td align="left"><italic>Individuality</italic></td>
<td align="left">Twenge and Campbell (<xref ref-type="bibr" rid="CIT0049">2018</xref>), Locke and Latham (<xref ref-type="bibr" rid="CIT0039">2002</xref>), Kshetri (<xref ref-type="bibr" rid="CIT0034">2017</xref>), Chua, Awaworyi Churchill and Koestner (<xref ref-type="bibr" rid="CIT0014">2020</xref>), Huuskonen and Vakkari (<xref ref-type="bibr" rid="CIT0032">2013</xref>).</td>
</tr>
<tr>
<td align="left"><italic>Information processing capability</italic></td>
<td align="left">Wei, Chen and Rice (<xref ref-type="bibr" rid="CIT0051">2023</xref>), Beerepoot et al. (<xref ref-type="bibr" rid="CIT0006">2019a</xref>), Alshammari (<xref ref-type="bibr" rid="CIT0002">2023</xref>), Beerepoot, Van de Weerd and Reijers (<xref ref-type="bibr" rid="CIT0007">2019b</xref>).</td>
</tr>
<tr>
<td align="left"><italic>Collegiality</italic></td>
<td align="left">Freedman (<xref ref-type="bibr" rid="CIT0023">2012</xref>), Sharpe, Lounsbery and Templin (<xref ref-type="bibr" rid="CIT0044">1997</xref>), Bissett and Saunders (<xref ref-type="bibr" rid="CIT0008">2015</xref>).</td>
</tr>
<tr>
<td align="left"><italic>Job characteristics</italic></td>
<td align="left">D&#x2019;Arcy, Hovav and Galletta (<xref ref-type="bibr" rid="CIT0018">2009</xref>), Alter (<xref ref-type="bibr" rid="CIT0003">2014</xref>), Huang et al. (<xref ref-type="bibr" rid="CIT0030">2016</xref>).</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Please see full reference list of the article for more information.</p></fn>
</table-wrap-foot>
</table-wrap>
<p><xref ref-type="table" rid="T0001">Table 1</xref> offers a comprehensive summary of pertinent literature that provides insights regarding the factors that are most likely to influence workarounds. These factors are discussed in depth in the subsequent sections.</p>
<sec id="s20007">
<title>Information security integrity</title>
<p><italic>Confidentiality, integrity and availability</italic> (CIA) triad forms the fundamental basis for information security that stresses information protection against unauthorised access, alteration or destruction (Liu et al. <xref ref-type="bibr" rid="CIT0038">2020</xref>). Part of maintaining information integrity requires that measures to protect information by reducing breaches through continuous monitoring, secure authentication practices and training to raise user awareness (Da Veiga &#x0026; Martins <xref ref-type="bibr" rid="CIT0021">2015</xref>). Studies point to the advancing of understanding regarding information integrity and the protection of data, but a crucial concern has been the organisations lack a way of standardising this understanding. Many scholars talk of information integrity (Harley &#x0026; Cooper <xref ref-type="bibr" rid="CIT0027">2021</xref>) or of data integrity (Duggineni <xref ref-type="bibr" rid="CIT0022">2023</xref>), which mostly considers similar aspects. It is, therefore, crucial that the integrity of information be better understood. Studies point out that human factors such as behaviour may compromise the integrity of information, particularly those employees working in the organisations (Wong et al. <xref ref-type="bibr" rid="CIT0053">2019</xref>). The next section details some of these human factors specifically focusing on workaround behaviour.</p>
</sec>
<sec id="s20008">
<title>Workarounds</title>
<p>Though mentioned in management, organisational and technology literature, workarounds are under theorised in information security literature. The theory of workarounds postulated by Alter (<xref ref-type="bibr" rid="CIT0003">2014</xref>) explains workarounds in organisational settings, pointing to how these occur and, importantly, assists management efforts in policy compliance (or non-compliance). Woltjer (<xref ref-type="bibr" rid="CIT0052">2017</xref>) has pointed out that workarounds-as-improvisation correlated with information systems expertise, and although those skilled individuals intended to achieve work quality and integrity, the unintended consequence was non-compliance as the trade-off. Indeed, scholars have raised the concern that the trade-offs in workarounds, bypassing established policies and procedures, may constitute an information security risk (Slabbert et al. <xref ref-type="bibr" rid="CIT0046">2021</xref>). Workarounds overwhelm information security practitioners in organisations because they may not know which policies have been violated and how they have been violated when workarounds are initiated. When employees are under pressure because of time or lack of resources and initiate workarounds, this is often detrimental to information security integrity (Van Offenbeek et al. <xref ref-type="bibr" rid="CIT0050">2024</xref>). Workarounds primarily stem from personality traits such as self-efficacy or organisational traits such as culture and collegiality (Rooney et al. <xref ref-type="bibr" rid="CIT0043">2021</xref>), propagating shortcuts to tasks. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H1:</bold> Workarounds will predict information security integrity.</p>
</disp-quote>
</sec>
<sec id="s20009">
<title>Self-efficacy</title>
<p>Self-efficacy theory places a great emphasis on the importance of how individuals perceive their own abilities. In information systems research, studies show that employees with stronger &#x2018;self-confidence for tackling IS security threats are more likely to adopt [information system] IS security innovation&#x2019; (Hameed &#x0026; Arachchilage <xref ref-type="bibr" rid="CIT0026">2021</xref>). While in some parts, this innovation may be of important to the organisation, most times it is not, because the workaround was performed outside of policy and regulation. Self-efficacy most often influences intention and may result in abuse of computer systems tasks (Rhee et al. <xref ref-type="bibr" rid="CIT0042">2009</xref>). Self-efficacy may benefit organisations when employees are confident in themselves to initiate practical remedies against attempted information security breaches, finding solutions but staying within the limits of policy guidelines. According to Tamjidyamcholo et al. (<xref ref-type="bibr" rid="CIT0048">2013</xref>), self-efficacy positively impacts the ability to identify and successfully respond to security threats and compliance. At times, the individual may lack self-regulating mechanisms that override these policies. This is where self-efficacy becomes detrimental. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H2:</bold> Self-efficacy will predict workaround behaviour.</p>
</disp-quote>
</sec>
<sec id="s20010">
<title>Individuality</title>
<p>Individuality places greater emphasis on the independence and rights of individuals than collective entities. The idea of individuality fosters personal freedom and the pursuit of personal goals with minimal intrusion from external forces (Twenge &#x0026; Campbell <xref ref-type="bibr" rid="CIT0049">2018</xref>). Locke and Latham (<xref ref-type="bibr" rid="CIT0039">2002</xref>) state that individual attitudes advance effective goal-setting processes, which enhance employee motivation and job satisfaction by emphasising individual accomplishments rather than group outcomes in performance appraisals. Kshetri (<xref ref-type="bibr" rid="CIT0034">2017</xref>) has studied information security integrity in healthcare and observed that integrity might be hindered by individuality because employees might prioritise self-interests over organisational security protocols in their efforts to work around challenges. According to Chua et al. (<xref ref-type="bibr" rid="CIT0014">2020</xref>), independence and personal well-being can be promoted through individual cultures but also hinder industry-wide information-sharing initiatives while encouraging competition, leading to a decline in overall safety postures. Another problem is that information system sectors are faced with competition based on culture, which makes it difficult for them to share knowledge about cyber-attacks (Chua et al. <xref ref-type="bibr" rid="CIT0014">2020</xref>). In their study, Huuskonen and Vakkari (<xref ref-type="bibr" rid="CIT0032">2013</xref>) examined social workers who undertook workarounds and exhibited individualism by employing small-scale tricks within their Information Technology (IT) department to maintain a continuum of positive trajectory for their clients. Though this saved time, the social workers either ignored policies entirely or merged information, a clear policy violation. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H3:</bold> Individuality will predict workaround behaviour.</p>
</disp-quote>
</sec>
<sec id="s20011">
<title>Information processing capability</title>
<p>An organisation&#x2019;s ability to gather, interpret, transform and disseminate information is referred to as organisational information processing capabilities (IPC) (Chen &#x0026; Nath <xref ref-type="bibr" rid="CIT0012">2018</xref>). Employees may sometimes assume that the current systems or procedures do not fit or accommodate their needs, and they often resort to workarounds to &#x2018;fix&#x2019; these processes. The problem is that organisations usually spot abnormalities or patterns that point to potential security breaches if they have the necessary processing power, but this &#x2018;fixing&#x2019; may affect IPC (Wei et al. <xref ref-type="bibr" rid="CIT0051">2023</xref>).</p>
<p>Information processing capability and information security can be affected by issues like increasing data volume and complexity, information system vulnerabilities, poor infrastructure, human error and data protection law compliance (Beerepoot et al. <xref ref-type="bibr" rid="CIT0006">2019a</xref>). As workarounds may cause breaches of business standards that can give rise to unauthorised entry or loss of data because of system restrictions or inefficiencies, among others, they establish extra risks to information security (Alshammari <xref ref-type="bibr" rid="CIT0002">2023</xref>).</p>
<p>Organisations usually confront difficulties in processing information where processes have been &#x2018;worked around&#x2019;, and this affects the integrity of information security, as proposed by Beerepoot et al. (<xref ref-type="bibr" rid="CIT0007">2019b</xref>). Investing in cutting-edge IT infrastructure and personnel training is necessary to manage the workarounds and foster proper data handling using best practices. Organisations should emphasise compliance with data protection regulations to reduce the risks associated with compromised information integrity. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H4:</bold> Information processing capability will predict workaround behaviour.</p>
</disp-quote>
</sec>
<sec id="s20012">
<title>Collegiality</title>
<p>Freedman (<xref ref-type="bibr" rid="CIT0023">2012</xref>) reviewed the boundaries of collegiality by examining what collegiality means in the context of organisational settings and considered the contradictory and opposing sides of collegiality. Collegial decision-making has been important because of the joint decisions that are to be made regarding resource allocation and support from senior executives or supervisors towards ensuring that organisational goals are met. Supportive leadership and cooperative decision-making are the main drives of collegiality in organisations (Sharpe et al. <xref ref-type="bibr" rid="CIT0044">1997</xref>). Bissett and Saunders (<xref ref-type="bibr" rid="CIT0008">2015</xref>) argue that collegiality results from managers and supervisors taking an active role at work and being dedicated to creating a friendly environment that promotes growth, productivity and employee development. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H5:</bold> Collegiality will predict workaround behaviour.</p>
</disp-quote>
</sec>
<sec id="s20013">
<title>Job characteristics</title>
<p>It is important to understand how job characteristics might influence employee behaviour and workarounds, partly because employees are now faced with an ever-growing reliance on technology and the always-changing information security threat landscape. Task relevance and skill variety, because of the changing technology requirements for tasks, are important job characteristics that have been observed to affect motivation to carry out workarounds (D&#x2019;Arcy et al. <xref ref-type="bibr" rid="CIT0018">2009</xref>).</p>
<p>Employees may turn to solutions outside of their area of expertise when they feel underutilised or lack a variety of skills (Alter <xref ref-type="bibr" rid="CIT0003">2014</xref>), which could lead to unintentional information security vulnerabilities (Woltjer <xref ref-type="bibr" rid="CIT0052">2017</xref>). As proposed by Huang et al. (<xref ref-type="bibr" rid="CIT0031">2016</xref>), organisations should concentrate on neutralising and resolving fundamental job characteristics concerns that would likely lead to workarounds to lessen the negative impact on information security integrity. To this end, the following hypothesis is proposed:</p>
<disp-quote>
<p><bold>H6:</bold> Job Characteristics will predict workaround behaviour.</p>
</disp-quote>
</sec>
</sec>
<sec id="s0014">
<title>Research methodology</title>
<p>As a critical component of the research process, the research methodology not only addresses methodically the research issues on hand (Bryman <xref ref-type="bibr" rid="CIT0009">2016</xref>) but also has to be appropriately selected to explain those issues (Galliers &#x0026; Land <xref ref-type="bibr" rid="CIT0024">1987</xref>). The research methodology entails collecting empirical data using methods such as surveys, interviews and observations (Asenahabi <xref ref-type="bibr" rid="CIT0004">2019</xref>). An important research methodology component is the research ontology and epistemology. Research ontology deals with the nature of reality, while research epistemology directs data gathering and analysis and deals with how knowledge is gathered (Creswell <xref ref-type="bibr" rid="CIT0017">2014</xref>; Hirschheim <xref ref-type="bibr" rid="CIT0028">1985</xref>). Both research ontology and research epistemology are key aspects of well-designed research as these will influence the philosophy, approach, strategy and methods of data collection and analysis. This research takes the positivist approach that recognises research consisting of only data that can scientifically be verified and capable of mathematical-quantitative proof (Goertzen <xref ref-type="bibr" rid="CIT0025">2017</xref>; Hjalmarson &#x0026; Moskal <xref ref-type="bibr" rid="CIT0029">2018</xref>). The validity and reliability of data are objectively derived from facts, placing a strong emphasis on empirical observation and measurement (Bryman &#x0026; Bell <xref ref-type="bibr" rid="CIT0010">2015</xref>).</p>
<sec id="s20015">
<title>Approach</title>
<p>The rationale for selecting a positivist and objective approach was for the researchers to be able to determine the causal relationship between constructs derived from the literature review: <italic>information security integrity</italic> as the dependent variable with <italic>workaround</italic>. The causal relationship between the independent variables, <italic>self-efficacy, individuality, collegiality, information processing capability</italic> and <italic>job characteristics</italic> with <italic>workaround</italic> was also considered. This called for drawing inferences of these relationships using the deductive approach, beginning with hypotheses development and leading towards the testing of these hypotheses. To this end, an online web-based survey was administered to 207 participants, using online platforms such as LinkedIn and Facebook, targeting participants aged between 18 years and 65 years who resided in Gauteng, South Africa. A purposeful, non-probability sampling strategy was used, with the size determined using <xref ref-type="disp-formula" rid="FD1">Equation 1</xref> provided by Raosoft (<xref ref-type="bibr" rid="CIT0041">2004</xref>) as follows:
<disp-formula id="FD1"><alternatives><mml:math display="block" id="M1"><mml:mtable columnalign="left"><mml:mtr><mml:mtd><mml:mi>x</mml:mi><mml:mo>=</mml:mo><mml:mi>Z</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>c</mml:mi><mml:mo>/</mml:mo><mml:mn>100</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn><mml:mi>r</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>100</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mi>N</mml:mi><mml:mi>x</mml:mi><mml:mo>/</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mi>E</mml:mi><mml:mn>2</mml:mn><mml:mo>+</mml:mo><mml:mi>x</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>E</mml:mi><mml:mo>=</mml:mo><mml:mtext>Sqrt</mml:mtext><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mi>x</mml:mi><mml:mo>/</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math><graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-26-1853-e001.tif"/></alternatives><label>[Eqn 1]</label></disp-formula></p>
<p>Raosoft (<xref ref-type="bibr" rid="CIT0041">2004</xref>) designed a web-based, scientific sample size calculator that embeds the above formula, which the researchers applied to determine the optimal sample of 212. The researchers used this recommendation in conjunction with defining the possible number of potential Information Technology professionals in the Gauteng province who met the criteria of the research as 1500 (<italic>N</italic>). Dada et al. (<xref ref-type="bibr" rid="CIT0019">2022</xref>) estimated that at least 3355 Information Technology jobs were published by LinkedIn, suggesting that 46.7&#x0025; (or 1543.4) of these were domiciled in Gauteng. We, therefore, used <italic>N</italic> as 1500 active LinkedIn and Facebook (assuming the same participants used both platforms) IT professionals to be targeted. We applied a 5&#x0025; margin of error, with a 95&#x0025; confidence level, and a low response distribution of 20&#x0025;, resulting in a recommended size of 212. The researchers managed to get 207 participants who completed the web-based survey.</p>
</sec>
<sec id="s20016">
<title>Web-based survey instrument</title>
<p>A study&#x2019;s most important component is gathering data, and there are several ways to do it based on the resources available, the financial implications and the time the researcher must complete (Kothari <xref ref-type="bibr" rid="CIT0033">2004</xref>). With Internet usage proliferating in Gauteng, it would be possible to target these groups of IT professionals using web-based surveys, saving on time and costs and, importantly, uploading data into software for analysis. Web-based surveys have their own benefits, like low costs, quick data gathering and design flexibility (Lawrence Neuman <xref ref-type="bibr" rid="CIT0036">2014</xref>). A Likert scale of five points was used to structure the closed-ended questions on the web-based survey, which was then separated into each of the three sections:</p>
<list list-type="order">
<list-item><p>Research Background and Participant Consent.</p></list-item>
<list-item><p>Section A, Participant demographics.</p></list-item>
<list-item><p>Section B, Information on users&#x2019; security behaviour.</p></list-item>
</list>
<p>Participants who required ethical protection were filtered out using the first two screening questions. A pilot study was carried out using preliminary data from 20 participants to assess the validity of the research instrument and guarantee that bias or impact is minimised.</p>
</sec>
<sec id="s20017">
<title>Data analysis</title>
<p>The collected data were analysed using SPSS (Statistical Package of Social Sciences, version 24). A total number of 207 participant data points was analysed after missing and filtered out data. Participants who did not reply were removed from the study. The initial round of online inquiries aimed to gather demographic information about the participants.</p>
</sec>
<sec id="s20018">
<title>Ethical considerations</title>
<p>Research ethics was a key consideration while developing the data collection instrument, deciding on the approach to use in the research process and, importantly, analysing data. The ethical principles guided the participants&#x2019; rights in providing data and how data were to be used once collected. The research was granted ethical clearance by the University of Johannesburg and issued with the reference number 2023AIS012.</p>
<p>All participants were required to give their informed consent to participate; the consent included the following:</p>
<list list-type="bullet">
<list-item><p>Participants would be required to agree to participate in the survey.</p></list-item>
<list-item><p>Participants were free to stop participating in the survey at any time.</p></list-item>
<list-item><p>Participants were assured of anonymity.</p></list-item>
</list>
</sec>
</sec>
<sec id="s0019">
<title>Results</title>
<p>The descriptive statistics of the study participants are presented, depicting the participant&#x2019;s duration of service and the role the participants play in the various industries across Gauteng, South Africa.</p>
<sec id="s20020">
<title>Profile of participants: Duration of service</title>
<p>Most of the participants in the sample had over 30 years of IT experience in various IT roles. The distribution of the duration of service suggests that there is a significant presence of experienced IT participants, which suggests a mature workforce. This distribution is as follows: those working for less than 10 years were 20.8&#x0025;, those working for more than 10 years to 20 years were 15.5&#x0025;, those working for more than 20 years to 30 years were 28.5&#x0025;, while those working for more than 30 years were 33.3&#x0025;. The results are provided in <xref ref-type="table" rid="T0002">Table 2</xref>.</p>
<table-wrap id="T0002">
<label>TABLE 2</label>
<caption><p>Duration of service (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" colspan="5" align="left">How many years have you been in the industry?<hr/></th>
</tr>
<tr>
<th valign="top" align="left">Valid years</th>
<th valign="top" align="center">Frequency</th>
<th valign="top" align="center">&#x0025;</th>
<th valign="top" align="center">Valid &#x0025;</th>
<th valign="top" align="center">Cumulative &#x0025;</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Other-undefined</td>
<td align="center">4</td>
<td align="center">1.9</td>
<td align="center">1.9</td>
<td align="center">1.9</td>
</tr>
<tr>
<td align="left">11&#x2013;20</td>
<td align="center">32</td>
<td align="center">15.5</td>
<td align="center">15.5</td>
<td align="center">17.4</td>
</tr>
<tr>
<td align="left">21&#x2013;30</td>
<td align="center">59</td>
<td align="center">28.5</td>
<td align="center">28.5</td>
<td align="center">45.9</td>
</tr>
<tr>
<td align="left">Less than 10</td>
<td align="center">43</td>
<td align="center">20.8</td>
<td align="center">20.8</td>
<td align="center">66.7</td>
</tr>
<tr>
<td align="left">More than 30</td>
<td align="center">69</td>
<td align="center">33.3</td>
<td align="center">33.3</td>
<td align="center">100.0</td>
</tr>
<tr>
<td colspan="5"><hr/></td>
</tr>
<tr>
<td align="left"><bold>Total</bold></td>
<td align="center"><bold>207</bold></td>
<td align="center"><bold>100.0</bold></td>
<td align="center"><bold>100.0</bold></td>
<td align="center"><bold>-</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s20021">
<title>Profile of participants: Role and industry</title>
<p>Statistical Package of Social Sciences derived a graphical representation of the role the IT participants played in various industries across Gauteng, South Africa. The shape and size of the various data points for the role in the industry suggest that many of the participants worked in positions that were not generally defined. This is because of the nature of the technological advancements in the field pointing to emerging new roles, particularly in the fields of retail, pharmaceuticals, healthcare and human resources. Most participants with clearly defined roles were technicians who worked in the engineering sector. There were legal practitioners who played a role both in IT and in the legal profession (e.g., forensic experts, eDiscovery specialists, cybersecurity experts and legal IT support) who also participated in the research. These professionals also constituted an averagely higher sample size. The study also sampled a few IT and telecommunication industry chief information officers. The results are provided in <xref ref-type="fig" rid="F0001">Figure 1</xref>.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Population pyramid on industry and role (researcher).</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-26-1853-g001.tif"/>
</fig>
</sec>
<sec id="s20022">
<title>Measurement testing: Common method variance test</title>
<p>Research results may at times be skewed, and this may lead to interpretation errors. One way of addressing this concern is to carry out a common method variance (CMV) test as suggested by Craighead et al. (<xref ref-type="bibr" rid="CIT0016">2011</xref>). To see whether CMV was going to be a concern before further analysis was to be carried out. An exploratory factor analysis (EFA) was carried out to see whether there would be any single factor that would account for a substantial portion (more than 50&#x0025;) of the total variance. Using SPSS EFA generated the total variance explained table shown by <xref ref-type="table" rid="T0003">Table 3</xref>.</p>
<table-wrap id="T0003">
<label>TABLE 3</label>
<caption><p>Total variance (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" colspan="7" align="left">Total variance explained<hr/></th>
</tr>
<tr>
<th valign="top" align="center" rowspan="2">Component</th>
<th valign="top" align="center" colspan="3">Initial eigenvalues<hr/></th>
<th valign="top" align="center" colspan="3">Extraction sums of squared loadings<hr/></th>
</tr>
<tr>
<th valign="top" align="center">Total</th>
<th valign="top" align="center">&#x0025; of variance</th>
<th valign="top" align="center">Cumulative &#x0025;</th>
<th valign="top" align="center">Total</th>
<th valign="top" align="center">&#x0025; of variance</th>
<th valign="top" align="center">Cumulative &#x0025;</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">1</td>
<td align="center">5.54</td>
<td align="center">24.11</td>
<td align="center">24.11</td>
<td align="center">5.54</td>
<td align="center">24.10</td>
<td align="center">24.11</td>
</tr>
<tr>
<td align="left">2</td>
<td align="center">4.02</td>
<td align="center">17.48</td>
<td align="center">41.59</td>
<td align="center">4.02</td>
<td align="center">17.48</td>
<td align="center">41.59</td>
</tr>
<tr>
<td align="left">3</td>
<td align="center">1.49</td>
<td align="center">6.48</td>
<td align="center">48.06</td>
<td align="center">1.49</td>
<td align="center">6.48</td>
<td align="center">48.06</td>
</tr>
<tr>
<td align="left">4</td>
<td align="center">1.37</td>
<td align="center">5.95</td>
<td align="center">54.01</td>
<td align="center">1.37</td>
<td align="center">5.95</td>
<td align="center">54.01</td>
</tr>
<tr>
<td align="left">5</td>
<td align="center">1.20</td>
<td align="center">5.24</td>
<td align="center">59.24</td>
<td align="center">1.20</td>
<td align="center">5.24</td>
<td align="center">59.25</td>
</tr>
<tr>
<td align="left">6</td>
<td align="center">1.13</td>
<td align="center">4.92</td>
<td align="center">64.16</td>
<td align="center">1.13</td>
<td align="center">4.92</td>
<td align="center">64.16</td>
</tr>
<tr>
<td align="left">7</td>
<td align="center">1.03</td>
<td align="center">4.50</td>
<td align="center">68.66</td>
<td align="center">1.03</td>
<td align="center">4.50</td>
<td align="center">68.66</td>
</tr>
<tr>
<td align="left">8</td>
<td align="center">0.74</td>
<td align="center">3.23</td>
<td align="center">71.90</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">9</td>
<td align="center">0.69</td>
<td align="center">2.99</td>
<td align="center">74.89</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">10</td>
<td align="center">0.63</td>
<td align="center">2.76</td>
<td align="center">77.65</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">11</td>
<td align="center">0.61</td>
<td align="center">2.64</td>
<td align="center">80.29</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">12</td>
<td align="center">0.58</td>
<td align="center">2.52</td>
<td align="center">82.81</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">13</td>
<td align="center">0.53</td>
<td align="center">2.29</td>
<td align="center">85.11</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">14</td>
<td align="center">0.50</td>
<td align="center">2.17</td>
<td align="center">87.27</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">15</td>
<td align="center">0.47</td>
<td align="center">2.05</td>
<td align="center">89.33</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">16</td>
<td align="center">0.45</td>
<td align="center">1.98</td>
<td align="center">91.31</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">17</td>
<td align="center">0.40</td>
<td align="center">1.73</td>
<td align="center">93.03</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">18</td>
<td align="center">0.38</td>
<td align="center">1.64</td>
<td align="center">94.67</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">19</td>
<td align="center">0.34</td>
<td align="center">1.50</td>
<td align="center">96.17</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">20</td>
<td align="center">0.31</td>
<td align="center">1.35</td>
<td align="center">97.52</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">21</td>
<td align="center">0.23</td>
<td align="center">0.99</td>
<td align="center">98.51</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">22</td>
<td align="center">0.21</td>
<td align="center">0.92</td>
<td align="center">99.43</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">23</td>
<td align="center">0.13</td>
<td align="center">0.57</td>
<td align="center">100.00</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Extraction method: Principal component analysis.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>Statistical Package of Social Sciences results of the EFA using principal component analysis (PCA) reveal that the first component explained 24.109&#x0025; of the total variance, followed by the second component explaining 17.476&#x0025; resulting in a cumulative 41.586&#x0025; across two components. This falls short of the rule-of-thumb threshold of 50&#x0025; for one component, and that common method bias would not be a concern for this study. The extraction of the 23 other factors indicates that the variance is distributed across multiple factors, suggesting that further data analysis was possible.</p>
</sec>
<sec id="s20023">
<title>Validity, reliable and factor loading</title>
<p>The degree to which a quantitative analysis test accurately measures a concept is known as validity, while reliability considers the consistency of any conclusions made by the researcher (Street &#x0026; Ward <xref ref-type="bibr" rid="CIT0047">2012</xref>). The test of sampling adequacy performed by SPSS using Kaiser&#x2013;Mayer&#x2013;Olkin&#x2019;s (KMO) measure showed that the KMO was 0.828, with the degree of freedom being 253, significant at &#x003C; 0.001, confirming that factor analysis would be a good method to reduce underlying variables in the model. <xref ref-type="table" rid="T0004">Table 4</xref> provides KMO results.</p>
<table-wrap id="T0004">
<label>TABLE 4</label>
<caption><p>Validity, Kaiser&#x2013;Mayer&#x2013;Olkin&#x2019;s and Bartlett&#x2019;s test (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" colspan="3" align="left">KMO and Bartlett&#x2019;s test</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="2">Kaiser-Meyer-Olkin measure of sampling adequacy</td>
<td align="center">0.830</td>
</tr>
<tr>
<td align="left" rowspan="3">Bartlett&#x2019;s test of sphericity</td>
<td align="left">Approx. Chi-square</td>
<td align="center">1819.530</td>
</tr>
<tr>
<td align="left"><italic>df</italic></td>
<td align="center">253.000</td>
</tr>
<tr>
<td align="left">Sig.</td>
<td align="center">&#x003C; 0.001</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Approx, approximately; <italic>df</italic>, degrees of freedom; Sig., significance.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>To determine how well the factor items (10 questionnaire items) were related to each other and to assess the consistency of the responses to these questions, a reliability analysis that applied Cronbach alpha was matched to the 10 related items.</p>
<p>This <xref ref-type="table" rid="T0005">Table 5</xref> shows that items that did not load into their components were removed and not included for further analysis. The Cronbach&#x2019;s alpha values were greater than 0.5 are deemed appropriate in information systems research (Street &#x0026; Ward <xref ref-type="bibr" rid="CIT0047">2012</xref>).</p>
<table-wrap id="T0005">
<label>TABLE 5</label>
<caption><p>Reliability and factor loading (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Factor item</th>
<th valign="top" align="center">10 items (questions) - Factor loading</th>
<th valign="top" align="center">Loading<xref ref-type="table-fn" rid="TFN0001">&#x2020;</xref></th>
<th valign="top" align="center">Cronbach&#x2019;s alpha values</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="5">Self-efficacy</td>
<td align="center">1</td>
<td align="center">0.67</td>
<td align="center" rowspan="5">0.79</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.71</td>
</tr>
<tr>
<td align="center">3</td>
<td align="center">0.65</td>
</tr>
<tr>
<td align="center">4</td>
<td align="center">0.57</td>
</tr>
<tr>
<td align="center">5</td>
<td align="center">0.84</td>
</tr>
<tr>
<td align="left" rowspan="5">Individuality</td>
<td align="center">1</td>
<td align="center">0.58</td>
<td align="center" rowspan="5">0.78</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.75</td>
</tr>
<tr>
<td align="center">3</td>
<td align="center">0.78</td>
</tr>
<tr>
<td align="center">4</td>
<td align="center">0.69</td>
</tr>
<tr>
<td align="center">5</td>
<td align="center">0.69</td>
</tr>
<tr>
<td align="left" rowspan="4">Information processing capability<xref ref-type="table-fn" rid="TFN0002">&#x2021;</xref></td>
<td align="center">1</td>
<td align="center">0.64</td>
<td align="center" rowspan="4">0.83</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.79</td>
</tr>
<tr>
<td align="center">3</td>
<td align="center">0.87</td>
</tr>
<tr>
<td align="center">4</td>
<td align="center">0.77</td>
</tr>
<tr>
<td align="left" rowspan="2">Job characteristics<xref ref-type="table-fn" rid="TFN0003">&#x00A7;</xref></td>
<td align="center">1</td>
<td align="center">0.74</td>
<td align="center" rowspan="2">0.51</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.58</td>
</tr>
<tr>
<td align="left" rowspan="3">Collegiality<sup><xref ref-type="table-fn" rid="TFN0004">&#x00B6;</xref></sup></td>
<td align="center">1</td>
<td align="center">0.53</td>
<td align="center" rowspan="3">0.58</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.51</td>
</tr>
<tr>
<td align="center">3</td>
<td align="center">0.90</td>
</tr>
<tr>
<td align="left" rowspan="2">Workaround behaviour<xref ref-type="table-fn" rid="TFN0005">&#x2020;&#x2020;</xref></td>
<td align="center">1</td>
<td align="center">0.85</td>
<td align="center" rowspan="2">0.86</td>
</tr>
<tr>
<td align="center">2</td>
<td align="center">0.88</td>
</tr>
<tr>
<td align="left" rowspan="2">Information security integrity<xref ref-type="table-fn" rid="TFN0006">&#x2021;&#x2021;</xref></td>
<td align="center">1</td>
<td align="center">0.89</td>
<td align="center" rowspan="2">0.69</td>
</tr>
<tr>
<td align="center">1</td>
<td align="center">0.78</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Extraction method: Principal component analysis. Rotation method: Varimax with kaiser normalisation.</p></fn>
<fn id="TFN0001"><label>&#x2020;</label><p>, Rotation converged in 8 iterations.</p></fn>
<fn id="TFN0002"><label>&#x2021;</label><p>, 1 item did not load to this component.</p></fn>
<fn id="TFN0003"><label>&#x00A7;</label><p>, 3 items did not load to this component.</p></fn>
<fn id="TFN0004"><label>&#x00B6;</label><p>, 2 items did not load to this component</p></fn>
<fn id="TFN0005"><label>&#x2020;&#x2020;</label><p>, 3 items did not load to this component.</p></fn>
<fn id="TFN0006"><label>&#x2021;&#x2021;</label><p>, 3 items did not load to this component.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>A correlation test was carried out to determine whether there was any association between variables. This was a quick check to see whether further analysis in regression was worthwhile. The results are shown in <xref ref-type="table" rid="T0006">Table 6</xref>.</p>
<table-wrap id="T0006">
<label>TABLE 6</label>
<caption><p>Test of correlation (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Job characteristics</th>
<th valign="top" align="center">Self-efficacy</th>
<th valign="top" align="center">Individuality</th>
<th valign="top" align="center">Information processing capability</th>
<th valign="top" align="center">Job characteristics</th>
<th valign="top" align="center">Collegiality</th>
<th valign="top" align="center">Information security integrity</th>
<th valign="top" align="center">Workaround</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="8"><bold>Self-efficacy</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">1.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Individuality</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">0.221<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">1.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">0.001</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Information processing capability</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">0.596<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.069</td>
<td align="center">1.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.324</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Job characteristics</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">&#x2212;0.057</td>
<td align="center">0.447<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">&#x2212;0.124</td>
<td align="center">1.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">0.412</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.075</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Collegiality</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">0.413<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.346<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.314<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.213<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">1.000</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.002</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Information security integrity</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">&#x2212;0.227<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.185<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">&#x2212;0.277<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.184<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">&#x2212;0.080</td>
<td align="center">1.000</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">0.001</td>
<td align="center">0.008</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.008</td>
<td align="center">0.254</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left" colspan="8"><bold>Workaround</bold></td>
</tr>
<tr>
<td align="left">Pearson Correlation</td>
<td align="center">&#x2212;0.222</td>
<td align="center">0.281<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">0.253</td>
<td align="center">0.414<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">&#x2212;0.036</td>
<td align="center">0.340<xref ref-type="table-fn" rid="TFN0007">&#x002A;&#x002A;</xref></td>
<td align="center">1.000</td>
</tr>
<tr>
<td align="left">Sig. (2-tailed)</td>
<td align="center">0.061</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.020</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">0.603</td>
<td align="center">&#x003C; 0.001</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left"><italic>N</italic></td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
<td align="center">206.000</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Sig, significance.</p></fn>
<fn id="TFN0007"><label>&#x002A;&#x002A;</label><p>, Correlation is significant at the 0.01 level (2-tailed).</p></fn>
</table-wrap-foot>
</table-wrap>
<p><xref ref-type="table" rid="T0006">Table 6</xref> shows association, suggesting a further need to conduct a regression to present, examine and explain the model. The results show that the correlations were not high (close to 1 or &#x2013;1), suggesting that multicollinearity would not be a major concern.</p>
</sec>
<sec id="s20024">
<title>Examination of the model</title>
<p>The hypotheses to be included in the model were tested using multiple linear regression analysis. This was done to test and determine whether there was an existing relationship between independent variables and the dependent variable, information security integrity (as well as workaround behaviour). <xref ref-type="table" rid="T0007">Table 7</xref> displays the regression analysis&#x2019;s findings.</p>
<table-wrap id="T0007">
<label>TABLE 7</label>
<caption><p>Liner regression weights: Hypothesis 1 (H1) (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" colspan="6" align="left">Coefficients<xref ref-type="table-fn" rid="TFN0008">&#x2020;</xref><hr/></th>
</tr>
<tr>
<th valign="top" align="left" rowspan="2">Model</th>
<th valign="top" align="center" colspan="2">Unstandardised coefficients<hr/></th>
<th valign="top" align="center">Standardised coefficients<hr/></th>
<th valign="top" align="center" rowspan="2"><italic>t</italic></th>
<th valign="top" align="center" rowspan="2">Sig.</th>
</tr>
<tr>
<th valign="top" align="center">B</th>
<th valign="top" align="center">SE</th>
<th valign="top" align="center">Beta</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">(Constant)</td>
<td align="center">3.22</td>
<td align="center">0.33</td>
<td align="center">-</td>
<td align="center">9.87</td>
<td align="center">&#x003C; 0.001</td>
</tr>
<tr>
<td align="left">Workaround</td>
<td align="center">0.34</td>
<td align="center">0.06</td>
<td align="center">0.34</td>
<td align="center">5.16</td>
<td align="center">&#x003C; 0.001</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>SE, Standard error; Sig, significance.</p></fn>
<fn id="TFN0008"><label>&#x2020;</label><p>, Dependent variable: Information security integrity.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The results liner regression results for H1 indicated that the model significantly predicted the variable <italic>Information Security Integrity</italic>, (<italic>p</italic> &#x003C; 0.001). It was observed that the predictor variable <italic>Workaround</italic> had a significant positive effect on Information Security integrity (&#x03B2; = 0.340, <italic>t</italic> = 5.165, <italic>p</italic> &#x003C; 0.001). A multiple liner regression was done to test whether the other variables would predict workaround. The results are presented by <xref ref-type="table" rid="T0008">Table 8</xref>.</p>
<table-wrap id="T0008">
<label>TABLE 8</label>
<caption><p>Multiple regression weights: Hypothesis 2-6 (H2-6) (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" colspan="6" align="left">Coefficients<xref ref-type="table-fn" rid="TFN0009">&#x2020;</xref><hr/></th>
</tr>
<tr>
<th valign="top" align="left" rowspan="2">Model</th>
<th valign="top" align="center" colspan="2">Unstandardised coefficients<hr/></th>
<th valign="top" align="center">Standardised coefficients<hr/></th>
<th valign="top" align="center" rowspan="2"><italic>t</italic></th>
<th valign="top" align="center" rowspan="2">Sig.</th>
</tr>
<tr>
<th valign="top" align="center">B</th>
<th valign="top" align="center">SE</th>
<th valign="top" align="center">Beta</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">(Constant)</td>
<td align="center">2.26</td>
<td align="center">0.64</td>
<td align="center">-</td>
<td align="center">3.53</td>
<td align="center">&#x003C; 0.001</td>
</tr>
<tr>
<td align="left">Self-efficacy</td>
<td align="center">&#x2212;0.16</td>
<td align="center">0.09</td>
<td align="center">&#x2212;0.15</td>
<td align="center">&#x2212;1.84</td>
<td align="center">0.067</td>
</tr>
<tr>
<td align="left">Individuality</td>
<td align="center">0.32</td>
<td align="center">0.11</td>
<td align="center">0.21</td>
<td align="center">2.87</td>
<td align="center">0.005</td>
</tr>
<tr>
<td align="left">Information processing capability</td>
<td align="center">&#x2212;0.10</td>
<td align="center">0.07</td>
<td align="center">&#x2212;0.11</td>
<td align="center">&#x2212;1.47</td>
<td align="center">0.142</td>
</tr>
<tr>
<td align="left">Job characteristics</td>
<td align="center">0.46</td>
<td align="center">0.10</td>
<td align="center">0.31</td>
<td align="center">4.46</td>
<td align="center">&#x003C; 0.001</td>
</tr>
<tr>
<td align="left">Collegiality</td>
<td align="center">&#x2212;0.09</td>
<td align="center">0.09</td>
<td align="center">&#x2212;0.08</td>
<td align="center">&#x2212;1.09</td>
<td align="center">0.276</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>SE, Standard error; Sig, significance.</p></fn>
<fn id="TFN0009"><label>&#x2020;</label><p>, Dependent variable: Workaround.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The results of the multiple liner regression analysis also show that the model significantly predicted <italic>Workaround.</italic> Several predictors contribute to this, specifically <italic>Job Characteristics</italic> (&#x03B2; = 0.315, <italic>t</italic> = 4.464, <italic>p</italic> &#x003C; 0.001) and <italic>Individuality</italic> (&#x03B2; = 0.208, <italic>t</italic> = 2.867, <italic>p</italic> = 0.005), which show a positive relationship with Workaround. However, it was observed that <italic>Self-efficacy</italic> (&#x03B2; = &#x2013;0.150, <italic>t</italic> = &#x2013;1.845, <italic>p</italic> = 0.067), <italic>Information Processing Capability</italic> (&#x03B2; = &#x2013;0.114, <italic>t</italic> = &#x2013;1.473, <italic>p</italic> = 0.142) and <italic>Collegiality</italic> (&#x03B2; = &#x2013;0.078, <italic>t</italic> = &#x2013;1.091, <italic>p</italic> = 0.276) did not significantly predict workaround.</p>
</sec>
<sec id="s20025">
<title>Summary of hypothesis testing findings</title>
<p>Findings of the six hypotheses that were tested suggest that <italic>self-efficacy, collegiality</italic> and information processing capability are not crucial predictors to workarounds. This can be explained as follows: In the first instance, many organisations are observed to have started training their employees on information security risks that their employees expose their organisations when the employees bypass policies as temporary &#x2018;fixes&#x2019;, but in doing so compromise the integrity of information systems. However, because of the individual characteristics of skilled employees, as well as the nature and characteristics of the work they do, chances of experiencing workarounds from those employees remains high. The testing summary results are illustrated in <xref ref-type="table" rid="T0009">Table 9</xref>.</p>
<table-wrap id="T0009">
<label>TABLE 9</label>
<caption><p>Multiple liner regression weights (researcher).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Hypotheses</th>
<th valign="top" align="left">Factors</th>
<th valign="top" align="center"><italic>p</italic></th>
<th valign="top" align="left">Action</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">HI</td>
<td align="left">Information security integrity &#x2190; Workaround</td>
<td align="center">&#x003C; 0.001</td>
<td align="left">Accepted</td>
</tr>
<tr>
<td align="left">H2</td>
<td align="left">Workaround &#x2190; Self-efficacy</td>
<td align="center">0.067</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H3</td>
<td align="left">Workaround &#x2190; Individuality</td>
<td align="center">0.005</td>
<td align="left">Accepted</td>
</tr>
<tr>
<td align="left">H4</td>
<td align="left">Workaround &#x2190; Information processing capability</td>
<td align="center">0.142</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H5</td>
<td align="left">Workaround &#x2190; Collegiality</td>
<td align="center">0.276</td>
<td align="left">Rejected</td>
</tr>
<tr>
<td align="left">H6</td>
<td align="left">Workaround &#x2190; Job characteristics</td>
<td align="center">&#x003C; 0.001</td>
<td align="left">Accepted</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s0026">
<title>Discussion</title>
<p>Considering that when employees engage in workarounds and bypass policies, the management may be left unaware of what the employees did. These workarounds may lead to new information security vulnerabilities, and management may not be certain how these vulnerabilities arose. This is especially true for employees who exhibit high individualism and the characteristics of their work. The findings that workaround impacts information security integrity are in agreement with Woltjer (<xref ref-type="bibr" rid="CIT0052">2017</xref>), who established that workarounds are improvisational acts that are frequently seen in organisations and are seen as non-compliance behaviour. This study, however, did not delve into pointing out how this non-compliance may influence information security integrity. This study adds to these insights. Indeed, as suggested by many information systems studies (Bulgurcu, Cavusoglu &#x0026; Benbasat <xref ref-type="bibr" rid="CIT0011">2010</xref>; Cheng et al. <xref ref-type="bibr" rid="CIT0013">2013</xref>), policy compliance is a necessary part of information systems governance that monitors procedures to be followed.</p>
<p>Pointing out that individuality may influence workarounds, it follows that highly individualistic personality types are more inclined to bypass formal policies if they think that by doing so, they may likely achieve desired outcomes, following their own methods independent of the organisation. The study findings point to this and show how this can challenge information security integrity. To effectively manage these individuals, organisations should provide the necessary training while advocating cultural changes targeted mostly at highly individualistic employees. Organisations can create policies and procedures that clarify proper conduct regarding policy compliance, perhaps pointing to the information security dangers of workarounds.</p>
<sec id="s20027">
<title>Contribution to practice</title>
<p>Workarounds behaviour significantly affects information security integrity, and it remains crucial for management to be aware that this happens. Practitioners can handle information integrity risks necessitated by workarounds through effectively learning, improving user experience and developing a security-conscious culture. This research has brought this understanding to the fore, pointing out that workarounds create vulnerabilities that are potential entry points for those with nefarious intent to exploit. In practice, the existence of the policies is not enough to deter employees&#x2019; intent on workarounds; however, cultural change and raising awareness would be important starting points. Management may suggest that employees engage in transparency and truthfulness and uphold proper work ethics as they carry out their duties, lessening the need for workarounds.</p>
</sec>
<sec id="s20028">
<title>Contribution to knowledge</title>
<p>While the goal of any research is to address a research issue or problem, this research study points to a crucial concern regarding how workarounds affect information security integrity. Although there is a dearth of work that points to workarounds being a concern, this research adds to the body of knowledge already available in the field of information security but addresses integrity concerns, particularly in the context of the Gauteng province, South Africa. Although the study was carried out in the Gauteng province, which can be a limitation regarding generalisability, the study is grounded in a strong theoretical framework that is applicable across broader contexts. By examining workarounds under this context, the study may assist those interested in the field in understanding how information security vulnerabilities occur. Organisations can, therefore, take the necessary steps, equipped with these insights, to establish training programs.</p>
</sec>
<sec id="s20029">
<title>Limitations and future research</title>
<p>This research study lays a groundwork for future research and decision-making with insights into the dynamic around workarounds. In our study, we found that &#x2018;collegiality&#x2019; did not significantly predict workaround behaviour. This may require further exploration as to why this is so for future research. The research findings provide a standard by which monitoring workaround behaviour can be established. While the work took a quantitative and objective approach, it fell short of new discoveries by asking participants to discuss their lived experiences. Qualitative research would, therefore, provide richer aspects of these lived experiences. Future research should employ qualitative techniques to elicit these insights.</p>
</sec>
</sec>
<sec id="s0030">
<title>Conclusion</title>
<p>To conclude, this research work underscores an often-overlooked cultural dimension to information security integrity, namely the presence of workarounds in organisational settings. The study has shown, through surveying IT practitioners working and residing in the Gauteng province of South Africa, that workarounds are often present in situations where employees are collegial and tend to have high self-efficacy. This study aligns well with the literature that indicates that workarounds are prevalent and often indicate non-compliance to policies. Overall, the work points to a better understanding of the underlying socio-contextual and cultural underpinnings surrounding individuals who bypass policies to overcome intended goals. This work has provided a good foundation for future studies touching on information security and the constant battle to ensure its integrity.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<sec id="s20031" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20032">
<title>Authors&#x2019; contributions</title>
<p>K.N. was the main supervisor for the project and conceptualised the work and curated the data. N.F.N. drafted the initial investigation, write-up and reviewed the work. K.N. sent the work to a third reviewed literature. N.F.N. was involved in the conceptualisation, methodology, investigation and writing the original draft. M.A.S. was involved in the methodology and validation of the study.</p>
</sec>
<sec id="s20033" sec-type="data-availability">
<title>Data availability</title>
<p>The data that support the findings of this study are available on request from the corresponding author, K.N.</p>
</sec>
<sec id="s20034">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and are the product of professional research. It does not necessarily reflect the official policy or position of any affiliated institution, funder, agency or that of the publisher. The authors are responsible for this article&#x2019;s results, findings and content.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aksoy</surname>, <given-names>C</given-names></string-name></person-group>., <year>2024</year>, <article-title>Building a cyber security culture for resilient organizations against cyber attacks</article-title>. <source><italic>&#x0130;&#x015F;letme Ekonomi ve Y&#x00F6;netim Ara&#x015F;t&#x0131;rmalar&#x0131; Dergisi</italic></source> <volume>7</volume>(<issue>1</issue>), <fpage>96</fpage>&#x2013;<lpage>110</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.33416/baybem.1374001">https://doi.org/10.33416/baybem.1374001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alshammari</surname>, <given-names>A</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>A novel security framework to mitigate and avoid unexpected security threats in Saudi Arabia</article-title>&#x2019;, <source><italic>Engineering, Technology &#x0026; Applied Science Research</italic></source> <volume>13</volume>(<issue>4</issue>), <fpage>11445</fpage>&#x2013;<lpage>11450</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.48084/etasr.6091">https://doi.org/10.48084/etasr.6091</ext-link></comment></mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alter</surname>, <given-names>S</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Theory of workarounds</article-title>&#x2019;, <source><italic>Communications of the Association for Information Systems</italic></source> <volume>34</volume>, <fpage>a55</fpage>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Asenahabi</surname>, <given-names>B.M</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Basics of research design: A guide to selecting appropriate research design</article-title>&#x2019;, <source><italic>International Journal of Contemporary Applied Researches</italic></source> <volume>6</volume>(<issue>5</issue>), <fpage>76</fpage>&#x2013;<lpage>89</lpage>.</mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Azad</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>King</surname>, <given-names>N</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>Enacting computer workaround practices within a medication dispensing system</article-title>&#x2019;, <source><italic>European Journal of Information Systems</italic></source> <volume>17</volume>(<issue>3</issue>), <fpage>264</fpage>&#x2013;<lpage>278</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1057/ejis.2008.14">https://doi.org/10.1057/ejis.2008.14</ext-link></comment></mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Beerepoot</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Ouali</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Van de Weerd</surname>, <given-names>I</given-names></string-name>. &#x0026; <string-name><surname>Reijers</surname>, <given-names>H.A</given-names></string-name></person-group>., <year>2019a</year>, &#x2018;<article-title>Working around health information systems: To accept or not to accept?</article-title>&#x2019;, <conf-name>Twenty-Seventh European Conference on Information Systems (ECIS2019)</conf-name>, <conf-loc>Stockholm-Uppsala, Sweden</conf-loc>, <conf-date>June 08, 2014</conf-date>.</mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Beerepoot</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Van de Weerd</surname>, <given-names>I</given-names></string-name>. &#x0026; <string-name><surname>Reijers</surname>, <given-names>H.A</given-names></string-name></person-group>., <year>2019b</year>, &#x2018;<article-title>The potential of workarounds for improving processes</article-title>&#x2019;, <conf-name>Paper presented at the Business Process Management Workshops: BPM 2019 International Workshops</conf-name>, <conf-loc>Vienna, Austria</conf-loc>, <conf-date>September 1&#x2013;6, 2019</conf-date>, <comment>Revised Selected Papers 17</comment>.</mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bissett</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Saunders</surname>, <given-names>S</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Criticality and collegiality: A method for humanizing everyday practice?</article-title>&#x2019;, <source><italic>Journal of Management Education</italic></source> <volume>39</volume>(<issue>5</issue>), <fpage>597</fpage>&#x2013;<lpage>625</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/1052562914557281">https://doi.org/10.1177/1052562914557281</ext-link></comment></mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Bryman</surname>, <given-names>A</given-names></string-name></person-group>., <year>2016</year>, <source><italic>Social research methods</italic></source>, <publisher-name>Oxford University Press</publisher-name>, <publisher-loc>Oxford</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Bryman</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Bell</surname>, <given-names>E</given-names></string-name></person-group>., <year>2015</year>, <source><italic>Business research meth ods</italic></source>, <publisher-name>Oxford University Press</publisher-name>, <publisher-loc>Oxford</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bulgurcu</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Cavusoglu</surname>, <given-names>H</given-names></string-name>. &#x0026; <string-name><surname>Benbasat</surname>, <given-names>I</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness</article-title>&#x2019;, <source><italic>MIS Quarterly</italic></source> <volume>34</volume>(<issue>3</issue>), <fpage>523</fpage>&#x2013;<lpage>548</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2307/25750690">https://doi.org/10.2307/25750690</ext-link></comment></mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname>, <given-names>L</given-names></string-name>. &#x0026; <string-name><surname>Nath</surname>, <given-names>R</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Business analytics maturity of firms: An examination of the relationships between managerial perception of IT, business analytics maturity and success</article-title>&#x2019;, <source><italic>Information Systems Management</italic></source> <volume>35</volume>(<issue>1</issue>), <fpage>62</fpage>&#x2013;<lpage>77</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/10580530.2017.1416948">https://doi.org/10.1080/10580530.2017.1416948</ext-link></comment></mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cheng</surname>, <given-names>L</given-names></string-name>., <string-name><surname>Li</surname>, <given-names>Y</given-names></string-name>., <string-name><surname>Li</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Holm</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Zhai</surname>, <given-names>Q</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>Understanding the violation of IS security policy in organizations: An integrated model based on social control and deterrence theory</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>39</volume>(<issue>Part B</issue>), <fpage>447</fpage>&#x2013;<lpage>459</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2013.09.009">https://doi.org/10.1016/j.cose.2013.09.009</ext-link></comment></mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Chua</surname>, <given-names>S.N</given-names></string-name>., <string-name><surname>Awaworyi Churchill</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Koestner</surname>, <given-names>R</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<chapter-title>Life, liberty and the pursuit of happiness: Examining the role of personal and country-level freedom in well-being</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>S.</given-names> <surname>Awaworyi Churchill</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Farrell</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Appau</surname></string-name> (eds.)</person-group>, <source><italic>Measuring, understanding and improving wellbeing among older people</italic></source>, pp. <fpage>237</fpage>&#x2013;<lpage>263</lpage>, <publisher-name>Palgrave Macmillan</publisher-name>, <publisher-loc>Singapore</publisher-loc>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-981-15-2353-3_11">https://doi.org/10.1007/978-981-15-2353-3_11</ext-link></comment></mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Colwill</surname>, <given-names>C</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Human factors in information security: The insider threat&#x2013;Who can you trust these days?</article-title>&#x2019;, <source><italic>Information Security Technical Report</italic></source> <volume>14</volume>(<issue>4</issue>), <fpage>186</fpage>&#x2013;<lpage>196</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.istr.2010.04.004">https://doi.org/10.1016/j.istr.2010.04.004</ext-link></comment></mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Craighead</surname>, <given-names>C.W</given-names></string-name>., <string-name><surname>Ketchen</surname>, <given-names>D.J</given-names></string-name>., <string-name><surname>Dunn</surname>, <given-names>K.S</given-names></string-name>. &#x0026; <string-name><surname>Hult</surname>, <given-names>G.T.M</given-names></string-name></person-group>., <year>2011</year>, &#x2018;<article-title>Addressing common method variance: Guidelines for survey research on information technology, operations, and supply chain management</article-title>&#x2019;, <source><italic>IEEE Transactions on Engineering Management</italic></source> <volume>58</volume>(<issue>3</issue>), <fpage>578</fpage>&#x2013;<lpage>588</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/TEM.2011.2136437">https://doi.org/10.1109/TEM.2011.2136437</ext-link></comment></mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Creswell</surname>, <given-names>J.W</given-names></string-name></person-group>., <year>2014</year>, <source><italic>Research design qualitative quantitative and mixed methods approaches</italic></source>, <publisher-name>Sage</publisher-name>, <publisher-loc>Los Angeles, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>D&#x2019;Arcy</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Hovav</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Galletta</surname>, <given-names>D</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach</article-title>&#x2019;, <source><italic>Information Systems Research</italic></source> <volume>20</volume>(<issue>1</issue>), <fpage>79</fpage>&#x2013;<lpage>98</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1287/isre.1070.0160">https://doi.org/10.1287/isre.1070.0160</ext-link></comment></mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Dada</surname>, <given-names>O.A</given-names></string-name>., <string-name><surname>Obaido</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Mienye</surname>, <given-names>I.D</given-names></string-name>. &#x0026; <string-name><surname>Aruleba</surname>, <given-names>K</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>The Leading Locations of Information Technology (IT) Jobs in South Africa</article-title>&#x2019;, <conf-name>In International Conference on Sustainability in Software Engineering &#x0026; Business Information Management</conf-name>, pp. <fpage>63</fpage>&#x2013;<lpage>74</lpage>, <conf-loc>Springer International Publishing, Cham</conf-loc>.</mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Daudi</surname>, <given-names>M</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Trust framework on exploitation of humans as the weakest link in cybersecurity</article-title>&#x2019;, <source><italic>Applied Cybersecurity &#x0026; Internet Governance</italic></source> <volume>2</volume>(<issue>1</issue>), <fpage>1</fpage>&#x2013;<lpage>26</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.60097/ACIG/162867">https://doi.org/10.60097/ACIG/162867</ext-link></comment></mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Da Veiga</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Martins</surname>, <given-names>N</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Improving the information security culture through monitoring and implementation actions illustrated through a case study</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>49</volume>, <fpage>162</fpage>&#x2013;<lpage>176</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2014.12.006">https://doi.org/10.1016/j.cose.2014.12.006</ext-link></comment></mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Duggineni</surname>, <given-names>S</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Impact of controls on data integrity and information systems</article-title>&#x2019;, <source><italic>Science and Technology</italic></source> <volume>13</volume>(<issue>2</issue>), <fpage>29</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Freedman</surname>, <given-names>S</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Collegiality matters: How do we work with others?</article-title>&#x2019;, <source><italic>Journal of Academic Librarianship</italic></source> <volume>38</volume>(<issue>2</issue>) <fpage>108</fpage>&#x2013;<lpage>114</lpage>.</mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Galliers</surname>, <given-names>R.D</given-names></string-name>. &#x0026; <string-name><surname>Land</surname>, <given-names>F.F</given-names></string-name></person-group>., <year>1987</year>, &#x2018;<article-title>Choosing appropriate information systems research methodologies</article-title>&#x2019;, <source><italic>Communications of the ACM</italic></source> <volume>30</volume>(<issue>11</issue>), <fpage>901</fpage>&#x2013;<lpage>902</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/32206.315753">https://doi.org/10.1145/32206.315753</ext-link></comment></mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Goertzen</surname>, <given-names>M.J</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Introduction to quantitative research and data</article-title>&#x2019;, <source><italic>Library Technology Reports</italic></source> <volume>53</volume>(<issue>4</issue>), <fpage>12</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hameed</surname>, <given-names>M.A</given-names></string-name>. &#x0026; <string-name><surname>Arachchilage</surname>, <given-names>N.A.G</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>The role of self-efficacy on the adoption of information systems security innovations: A meta-analysis assessment</article-title>&#x2019;, <source><italic>Personal and Ubiquitous Computing</italic></source> <volume>25</volume>(<issue>5</issue>), <fpage>911</fpage>&#x2013;<lpage>925</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s00779-021-01560-1">https://doi.org/10.1007/s00779-021-01560-1</ext-link></comment></mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Harley</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Cooper</surname>, <given-names>R</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Information integrity: Are we there yet?</article-title>&#x2019;, <source><italic>ACM Computing Surveys (CSUR)</italic></source> <volume>54</volume>(<issue>2</issue>), <fpage>1</fpage>&#x2013;<lpage>35</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3436817">https://doi.org/10.1145/3436817</ext-link></comment></mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hirschheim</surname>, <given-names>R</given-names></string-name></person-group>., <year>1985</year>, &#x2018;<article-title>Information systems epistemology: An historical perspective</article-title>&#x2019;, <source><italic>Research Methods in Information Systems</italic></source> <volume>9</volume>, <fpage>13</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hjalmarson</surname>, <given-names>M.A</given-names></string-name>. &#x0026; <string-name><surname>Moskal</surname>, <given-names>B</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Quality considerations in education research: Expanding our understanding of quantitative evidence and arguments</article-title>&#x2019;, <source><italic>Journal of Engineering Education</italic></source> <volume>107</volume>(<issue>2</issue>), <fpage>179</fpage>&#x2013;<lpage>185</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/jee.20202">https://doi.org/10.1002/jee.20202</ext-link></comment></mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Huang</surname>, <given-names>Z</given-names></string-name>., <string-name><surname>DAngelo</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Miyani</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Lie</surname>, <given-names>D</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Talos: Neutralizing vulnerabilities with security workarounds for rapid response</article-title>&#x2019;, <conf-name>Paper presented at the 2016 IEEE Symposium on Security and Privacy (SP)</conf-name>.</mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Huang</surname>, <given-names>Z</given-names></string-name>., <string-name><surname>DAngelo</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Miyani</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Lie</surname>, <given-names>D</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>May. Talos: Neutralizing vulnerabilities with security workarounds for rapid response</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>M.</given-names> <surname>Locasto</surname></string-name> (ed.)</person-group>, <conf-name>2016 IEEE Symposium on Security and Privacy (SP)</conf-name>, pp. <fpage>618</fpage>&#x2013;<lpage>635</lpage>, <conf-loc>IEEE, San Jose, CA</conf-loc></mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huuskonen</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Vakkari</surname>, <given-names>P</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>&#x201C;I did it my way&#x201D;: Social workers as secondary designers of a client information system</article-title>&#x2019;, <source><italic>Information Processing &#x0026; Management</italic></source> <volume>49</volume>(<issue>1</issue>), <fpage>380</fpage>&#x2013;<lpage>391</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ipm.2012.05.003">https://doi.org/10.1016/j.ipm.2012.05.003</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Kothari</surname>, <given-names>C.R</given-names></string-name></person-group>., <year>2004</year>, <source><italic>Research methodology: Methods and techniques</italic></source>, <edition>2nd</edition> edn., <publisher-name>New Age International Publishers</publisher-name>, <publisher-loc>New Delhi</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kshetri</surname>, <given-names>N</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Blockchain&#x2019;s roles in strengthening cybersecurity and protecting privacy</article-title>&#x2019;, <source><italic>Telecommunications Policy</italic></source> <volume>41</volume>(<issue>10</issue>), <fpage>1027</fpage>&#x2013;<lpage>1038</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.telpol.2017.09.003">https://doi.org/10.1016/j.telpol.2017.09.003</ext-link></comment></mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Kyobe</surname>, <given-names>M</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Towards a framework to guide compliance with IS security policies and regulations in a university</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>H.S.</given-names> <surname>Venter</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Coetzee</surname></string-name> &#x0026; <string-name><given-names>M.</given-names> <surname>Loock</surname></string-name> (eds.)</person-group>, <conf-name>2010 Information security for South Africa</conf-name>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <conf-loc>IEEE, Sandton, Johannesburg</conf-loc>.</mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Lawrence Neuman</surname>, <given-names>W</given-names></string-name></person-group>., <year>2014</year>, <source><italic>Social research methods: Qualitative and quantitative approaches</italic></source>, <publisher-name>Pearson</publisher-name>, <publisher-loc>Essex</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mugwagwa</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Bhero</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Chibaya</surname>, <given-names>C</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Cybersecurity strategy: Future proof cybersecurity for small to medium enterprises in South Africa</article-title>&#x2019;, <source><italic>International Journal of Research in Business and Social Science</italic></source> <volume>13</volume>(<issue>4</issue>), <fpage>15</fpage>&#x2013;<lpage>24</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.20525/ijrbs.v13i4.3308">https://doi.org/10.20525/ijrbs.v13i4.3308</ext-link></comment></mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Wang</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Liang</surname>, <given-names>H</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Motivating information security policy compliance: The critical role of supervisor-subordinate guanxi and organizational commitment</article-title>&#x2019;, <source><italic>International Journal of Information Management</italic></source> <volume>54</volume>, <fpage>102152</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijinfomgt.2020.102152">https://doi.org/10.1016/j.ijinfomgt.2020.102152</ext-link></comment></mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Locke</surname>, <given-names>E.A</given-names></string-name>. &#x0026; <string-name><surname>Latham</surname>, <given-names>G.P</given-names></string-name></person-group>., <year>2002</year>, &#x2018;<article-title>Building a practically useful theory of goal setting and task motivation: A 35-year odyssey</article-title>&#x2019;, <source><italic>American Psychologist</italic></source> <volume>57</volume>(<issue>9</issue>), <fpage>705</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1037/0003-066X.57.9.705">https://doi.org/10.1037/0003-066X.57.9.705</ext-link></comment></mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Murire</surname>, <given-names>O.T</given-names></string-name>., <string-name><surname>Flowerday</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Strydom</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Fourie</surname>, <given-names>C.J</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Narrative review: Social media use by employees and the risk to institutional and personal information security compliance in South Africa</article-title>&#x2019;, <source><italic>TD: The Journal for Transdisciplinary Research in Southern Africa</italic></source> <volume>17</volume>(<issue>1</issue>), <fpage>1</fpage>&#x2013;<lpage>10</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/td.v17i1.909">https://doi.org/10.4102/td.v17i1.909</ext-link></comment></mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>Raosoft</collab></person-group>, <year>2004</year>, <source><italic>Raosoft sample size calculator</italic></source>, <comment>viewed 04 July 2024, from <ext-link ext-link-type="uri" xlink:href="http://www.raosoft.com/samplesize.html">http://www.raosoft.com/samplesize.html</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rhee</surname>, <given-names>H.-S</given-names></string-name>., <string-name><surname>Kim</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Ryu</surname>, <given-names>Y.U</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Self-efficacy in information security: Its influence on end users&#x2019; information security practice behavior</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>28</volume>(<issue>8</issue>), <fpage>816</fpage>&#x2013;<lpage>826</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2009.05.008">https://doi.org/10.1016/j.cose.2009.05.008</ext-link></comment></mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Rooney</surname>, <given-names>M.J</given-names></string-name>., <string-name><surname>Levy</surname>, <given-names>Y</given-names></string-name>., <string-name><surname>Li</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Kumar</surname>, <given-names>A</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Towards assessing password workarounds and perceived risk to data breaches for organizational cybersecurity risk management taxonomy</article-title>&#x2019;, <conf-name>Proceedings on Cybersecurity Education, Research and Practice 30th October 2021</conf-name>, <conf-loc>Kennesaw State University, Kennesaw, GA</conf-loc>.</mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sharpe</surname>, <given-names>T</given-names></string-name>., <string-name><surname>Lounsbery</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Templin</surname>, <given-names>T</given-names></string-name></person-group>., <year>1997</year>, &#x2018;<article-title>Cooperation, collegiality, and collaboration: Reinforcing the scholar-practitioner model</article-title>&#x2019;, <source><italic>Quest</italic></source> <volume>49</volume>(<issue>2</issue>), <fpage>214</fpage>&#x2013;<lpage>228</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/00336297.1997.10484236">https://doi.org/10.1080/00336297.1997.10484236</ext-link></comment></mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Siponen</surname>, <given-names>M</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Six design theories for IS security policies and guidelines</article-title>&#x2019;, <source><italic>Journal of the Association for Information systems</italic></source> <volume>7</volume>(<issue>1</issue>), <fpage>19</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.17705/1jais.00095">https://doi.org/10.17705/1jais.00095</ext-link></comment></mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Slabbert</surname>, <given-names>E</given-names></string-name>., <string-name><surname>Thomson</surname>, <given-names>K.-L</given-names></string-name>. &#x0026; <string-name><surname>Futcher</surname>, <given-names>L</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Towards a risk assessment matrix for information security workarounds</article-title>&#x2019;, in <conf-name>International Symposium on Human Aspects of Information Security and Assurance</conf-name>, pp. <fpage>164</fpage>&#x2013;<lpage>178</lpage>, <conf-loc>Springer International Publishing, Cham</conf-loc>.</mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Street</surname>, <given-names>C.T</given-names></string-name>. &#x0026; <string-name><surname>Ward</surname>, <given-names>K.W</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Improving validity and reliability in longitudinal case study timelines</article-title>&#x2019;, <source><italic>European Journal of Information Systems</italic></source> <volume>21</volume>(<issue>2</issue>), <fpage>160</fpage>&#x2013;<lpage>175</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1057/ejis.2011.53">https://doi.org/10.1057/ejis.2011.53</ext-link></comment></mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tamjidyamcholo</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Baba</surname>, <given-names>M.S.B</given-names></string-name>., <string-name><surname>Tamjid</surname>, <given-names>H</given-names></string-name>. &#x0026; <string-name><surname>Gholipour</surname>, <given-names>R</given-names></string-name></person-group>., <year>2013</year>, <article-title>Information security&#x2013;Professional perceptions of knowledge-sharing intention under self-efficacy, trust, reciprocity, and shared-language</article-title>&#x2019;, <source><italic>Computers &#x0026; Education</italic></source> <volume>68</volume>, <fpage>223</fpage>&#x2013;<lpage>232</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.compedu.2013.05.010">https://doi.org/10.1016/j.compedu.2013.05.010</ext-link></comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Twenge</surname>, <given-names>J.M</given-names></string-name>. &#x0026; <string-name><surname>Campbell</surname>, <given-names>W.K</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Cultural individualism is linked to later onset of adult-role responsibilities across time and regions</article-title>&#x2019;, <source><italic>Journal of Cross-Cultural Psychology</italic></source> <volume>49</volume>(<issue>4</issue>), <fpage>673</fpage>&#x2013;<lpage>682</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/0022022118764838">https://doi.org/10.1177/0022022118764838</ext-link></comment></mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Van Offenbeek</surname>, <given-names>M.A</given-names></string-name>., <string-name><surname>Vos</surname>, <given-names>J.F</given-names></string-name>., <string-name><surname>Van den Hooff</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>Boonstra</surname>, <given-names>A</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>When workarounds aggravate misfits in the use of electronic health record systems</article-title>&#x2019;, <source><italic>Information Systems Journal</italic></source> <volume>34</volume>(<issue>2</issue>), <fpage>293</fpage>&#x2013;<lpage>326</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/isj.12478">https://doi.org/10.1111/isj.12478</ext-link></comment></mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wei</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Chen</surname>, <given-names>X</given-names></string-name>. &#x0026; <string-name><surname>Rice</surname>, <given-names>R.E</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>We can work it out: A multilevel examination of relationships among group and individual technology workarounds, and performance</article-title>&#x2019;, <source><italic>Journal of Operations Management</italic></source> <volume>69</volume>(<issue>6</issue>), <fpage>1008</fpage>&#x2013;<lpage>1038</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/joom.1267">https://doi.org/10.1002/joom.1267</ext-link></comment></mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Woltjer</surname>, <given-names>R</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Workarounds and trade-offs in information security&#x2013;An exploratory study</article-title>&#x2019;, <source><italic>Information &#x0026; Computer Security</italic></source> <volume>25</volume>(<issue>4</issue>), <fpage>402</fpage>&#x2013;<lpage>420</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ICS-02-2016-0017">https://doi.org/10.1108/ICS-02-2016-0017</ext-link></comment></mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wong</surname>, <given-names>W.P</given-names></string-name>., <string-name><surname>Tan</surname>, <given-names>H.C</given-names></string-name>., <string-name><surname>Tan</surname>, <given-names>K.H</given-names></string-name>. &#x0026; <string-name><surname>Tseng</surname>, <given-names>M.-L</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Human factors in information leakage: Mitigation strategies for information sharing integrity</article-title>&#x2019;, <source><italic>Industrial Management &#x0026; Data Systems</italic></source> <volume>119</volume>(<issue>6</issue>), <fpage>1242</fpage>&#x2013;<lpage>1267</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/IMDS-12-2018-0546">https://doi.org/10.1108/IMDS-12-2018-0546</ext-link></comment></mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Njenga, K., Nyamandi, N.F. &#x0026; Segooa, M.A., 2024, &#x2018;A model on workarounds and information security integrity&#x2019;, <italic>South African Journal of Information Management</italic> 26(1), a1853. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v26i1.1853">https://doi.org/10.4102/sajim.v26i1.1853</ext-link></p></fn>
</fn-group>
</back>
</article>