The Influence of Cybersecurity Protection Behavior: Employees of Big Four Account Firm Companies
Downloads
This study aims to determine the influence effect of cybersecurity protection behavior from the perspective of employees of Big Four Account Firm Companies. The method used in this research is a quantitative method. The subjects in this study were employees of the Big Four Account Firm with a sample of 150 taken using purposive sampling method. The analysis used in this study was a structural approach to the Equation Model (SEM) by using smart PLS. The results show that Cybersecurity Knowledge has a significant effect towards Self-Efficacy, Cybersecurity Awareness has a significant effect towards Self-Efficacy, and Self-Efficacy has a significant effect towards Cybersecurity Protection Behavior. The managerial implication of this research is important for the organization or management to raise awareness of security culture and can be the reference for other accounting firms.
Abawajy, J. (2014). User preference of cyber security awareness delivery methods. Behavior & Information Technology, 33(3), 237-248. https://doi.org/10.1080/0144929x.2012.708787
Anwar, M., He, W., Ash, I., Yuan, X., Li, L., & Xu, L. (2017). Gender difference and employees' cybersecurity behaviors. Computers in Human Behavior, 69, 437-443. https://doi.org/10.1016/j.chb.2016.12.040
Arachchilage, N. A. G., & Love, S. (2014). Security awareness of computer users: A phishing threat avoidance perspective. Computers in Human Behavior, 38, 304–312. https://doi.org/10.1016/j.chb.2014.05.046
Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R. A., & Boss, R. W. (2009). If someone is watching, i'll do what I'm asked: Mandatoriness, control, and information security. European Journal of Information Systems, 18(2), 151-164. https://doi.org/10.1057/ejis.2009.8
Boehmer, J., LaRose, R., Rifon, N., Alhabash, S., & Cotten, S. (2015). Determinants of online safety behaviour: towards an intervention strategy for college students. Behaviour & Information Technology, 34(10), 1022–1035. https://doi.org/10.1080/0144929x.2015.1028448
Chen, S., Yang, Y., & Dai, L. (2023). The relationship between network fraud and network security awareness: The mediation role of network social self-efficacy. Atlantis Highlights in Computer Sciences, 222-235. https://doi.org/10.2991/978-94-6463-172-2_25
De Kimpe, L., Walrave, M., Verdegem, P., & Ponnet, K. (2021). What we think we know about cybersecurity: An investigation of the relationship between perceived knowledge, internet trust, and protection motivation in a cybercrime context. Behaviour & Information Technology, 41(8), 1796-1808. https://doi.org/10.1080/0144929x.2021.1905066
De Kok, L. C., Oosting, D., & Spruit, M. (2020). The influence of knowledge and attitude on intention to adopt cybersecure behaviour. Information & Security: An International Journal, 46(3), 251-266. https://doi.org/10.11610/isij.4618
Gerdenitsch, C., Wurhofer, D., & Tscheligi, M. (2023). Working conditions and cybersecurity: Time pressure, autonomy and threat appraisal shaping employees’ security behavior. Cyberpsychology: Journal of Psychosocial Research on Cyberspace, 17(4). https://doi.org/10.5817/cp2023-4-7
Gist, M. E. (1987). Self-efficacy: Implications for organizational behavior and human resource management. The Academy of Management Review, 12(3), 472. https://doi.org/10.2307/258514
Grassegger, T., & Nedbal, D. (2021). The role of employees’ information security awareness on the intention to resist social engineering. Procedia Computer Science, 181, 59-66. https://doi.org/10.1016/j.procs.2021.01.103
Hair, J. F., Risher, J. J., Sarstedt, M., & Ringle, C. M. (2019). When to use and how to report the results of PLS-SEM. European Business Review, 31(1), 2-24. https://doi.org/10.1108/ebr-11-2018-0203
Hair, J. F., Howard, M. C., & Nitzl, C. (2020). Assessing measurement model quality in PLS-SEM using confirmatory composite analysis. Journal of Business Research, 109(1), 101–110. https://doi.org/10.1016/j.jbusres.2019.11.069
Hanus, B., & Wu, Y. “. (2015). Impact of users’ security awareness on desktop security behavior: A protection motivation theory perspective. Information Systems Management, 33(1), 2-16. https://doi.org/10.1080/10580530.2015.1117842
Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organizations. European Journal of Information Systems, 18(2), 106-125. https://doi.org/10.1057/ejis.2009.6
Hossain, M. Z., & Zohora, F. T. (2024). Cybersecurity in accounting: Protecting financial data in the digital age. https://doi.org/10.2139/ssrn.4868132
Hossain, M. S., Belina, H., Hasan, M. M., & Kim, M. M. (2024). The Effects of Auditor-level Cybersecurity Breaches on Auditor-Client Relationships. European Accounting Review, 1–28. https://doi.org/10.1080/09638180.2024.2435389
Ifinedo, P. (2012). Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers & Security, 31(1), 83-95. https://doi.org/10.1016/j.cose.2011.10.007
Kankanhalli, A., Teo, H., Tan, B. C., & Wei, K. (2003). An integrative study of information systems security effectiveness. International Journal of Information Management, 23(2), 139-154. https://doi.org/10.1016/s0268-4012(02)00105-6
Khan, N. F., Ikram, N., Murtaza, H., & Javed, M. (2023). Evaluating protection motivation based cybersecurity awareness training on Kirkpatrick’s Model. Computers & Security, 125, 103049. https://doi.org/10.1016/j.cose.2022.103049
Klein, G., Zwilling, M., & Lesjak, D. (2022). A comparative study in Israel and Slovenia regarding the awareness, knowledge, and behavior regarding cyber security. Research Anthology on Business Aspects of Cybersecurity, 424-439. https://doi.org/10.4018/978-1-6684-3698-1.ch020
Li, H., No, W. G., & Boritz, J. E. (2020). Are external auditors concerned about cyber incidents? Evidence from audit fees. AUDITING: A Journal of Practice & Theory, 39(1), 151-171. https://doi.org/10.2308/ajpt-52593
Li, L., Xu, L., He, W., Chen, Y., & Chen, H. (2016). Cyber security awareness and its impact on employee’s behavior. Lecture Notes in Business Information Processing, 103-111. https://doi.org/10.1007/978-3-319-49944-4_8
Li, L., He, W., Xu, L., Ash, I., Anwar, M., & Yuan, X. (2019). Investigating the impact of cybersecurity policy awareness on employees’ cybersecurity behavior. International Journal of Information Management, 45, 13-24. https://doi.org/10.1016/j.ijinfomgt.2018.10.017
Li, L., Xu, L., & He, W. (2022). The effects of antecedents and mediating factors on cybersecurity protection behavior. Computers in Human Behavior Reports, 5, 100165. https://doi.org/10.1016/j.chbr.2021.100165
Lowry, P. B., & Gaskin, J. (2014). Partial least squares (PLS) structural equation modeling (SEM) for building and testing behavioral causal theory: When to choose it and how to use it. IEEE Transactions on Professional Communication, 57(2), 123-146. https://doi.org/10.1109/tpc.2014.2312452
McCormac, A., Calic, D., Parsons, K., Butavicius, M., Pattinson, M., & Lillie, M. (2018). The effect of resilience and job stress on information security awareness. Information & Computer Security, 26(3), 277-289. https://doi.org/10.1108/ics-03-2018-0032.
Neuman, W. L. (2014). Social research methods: Qualitative and quantitative approaches
Posey, C., Roberts, T. L., & Lowry, P. B. (2015). The impact of organizational commitment on insiders’ motivation to protect organizational information assets. Journal of Management Information Systems, 32(4), 179-214. https://doi.org/10.1080/07421222.2015.1138374
Raineri, E. M., & Fudge, T. (2019). Exploring the Sufficiency of Undergraduate Students’ Cybersecurity Knowledge Within Top Universities’ Entrepreneurship Programs. Journal of Higher Education Theory and Practice, 19(4). https://doi.org/10.33423/jhetp.v19i4.2203
Rosati, P., Gogolin, F., & Lynn, T. (2019). Audit firm assessments of cyber-security risk: Evidence from audit fees and SEC comment letters. The International Journal of Accounting, 54(03), 1950013. https://doi.org/10.1142/s1094406019500136
Sekaran, U. & Bougie, R. (2019). Research Methods For Business: A Skill 8th Edition. New Jersey: Wiley
Shaari, R., Rahman, S. A., & Rajab, A. (2014). Self-efficacy as a determined factor for knowledge sharing awareness. International Journal of Trade, Economics and Finance, 39-42. https://doi.org/10.7763/ijtef.2014.v5.337
Shang, Y., Wu, Z., Du, X., Jiang, Y., Ma, B., & Chi, M. (2022). The psychology of the internet fraud victimization of older adults: A systematic review. Frontiers in Psychology, 13. https://doi.org/10.3389/fpsyg.2022.912242
Shaw, R., Chen, C. C., Harris, A. L., & Huang, H. (2009). The impact of information richness on information security awareness training effectiveness. Computers & Education, 52(1), 92-100. https://doi.org/10.1016/j.compedu.2008.06.011
Shillair, R., Esteve-González, P., Dutton, W. H., Creese, S., Nagyfejeo, E., & Von Solms, B. (2022). Cybersecurity education, awareness raising, and training initiatives: National level evidence-based results, challenges, and promise. Computers & Security, 119, 102756. https://doi.org/10.1016/j.cose.2022.102756
Taherdoost, H. (2024). A critical review on cybersecurity awareness frameworks and training models. Procedia Computer Science, 235, 1649-1663. https://doi.org/10.1016/j.procs.2024.04.156
Torten, R., Reaiche, C., & Boyle, S. (2018). The impact of security awareness on information technology professionals’ behavior. Computers & Security, 79, 68-79. https://doi.org/10.1016/j.cose.2018.08.007
Tsai, H. S., Jiang, M., Alhabash, S., LaRose, R., Rifon, N. J., & Cotten, S. R. (2016). Understanding online safety behaviors: A protection motivation theory perspective. Computers & Security, 59, 138-150. https://doi.org/10.1016/j.cose.2016.02.009
Vinzi, V. E., Trinchera, L., & Amato, S. (2009). PLS path modeling: From foundations to recent developments and open issues for model assessment and improvement. Handbook of Partial Least Squares, 47-82. https://doi.org/10.1007/978-3-540-32827-8_3
Warkentin, M., Johnston, A. C., & Shropshire, J. (2011). The influence of the informal social learning environment on information privacy policy compliance efficacy and intention. European Journal of Information Systems, 20(3), 267–284. https://doi.org/10.1057/ejis.2010.72
Wang, S., & Wang, H. (2019). Knowledge management for cybersecurity in business organizations: A case study. Journal of Computer Information Systems, 1-8. https://doi.org/10.1080/08874417.2019.1571458
Zhang, Y., Zhang, C., & Xu, Y. (2021). Effect of data privacy and security investment on the value of big data firms. Decision Support Systems, 146, 113543. https://doi.org/10.1016/j.dss.2021.113543
Zwilling, M., Klien, G., Lesjak, D., Wiechetek, ?., Cetin, F., & Basim, H. N. (2020). Cyber security awareness, knowledge, and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82-97. https://doi.org/10.1080/08874417.2020.1712269
Copyright (c) 2025 Hasnul Qalby, Gunawan Yudi Hariyanto, Dyan Tri Utomo, Rano Kartono

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.





