Back to Search View Original Cite This Article

Abstract

<title>Abstract</title> <p>Existing cybersecurity instruments largely focus on awareness, compliance, or behavioral intentions, while employees’ organizational cybersecurity perceptions remain insufficiently examined from a PMT-based appraisal perspective. This study aimed to develop and psychometrically validate the Organizational Cybersecurity Perception Scale, a Protection Motivation Theory (PMT)-based instrument contextualized by the NIST Cybersecurity Framework (CSF) 2.0. The scale was designed to assess employees’ cognitive appraisals of organizational cybersecurity threats, protective capacities, self-efficacy, and perceived response costs among individuals actively using institutional digital systems. NIST CSF 2.0 was used as a contextual framework during item development rather than as a latent measurement structure. Psychometric analyses were conducted using two independent samples drawn from different institutional sectors in Türkiye: an exploratory factor analysis sample (EFA; n = 519) and a confirmatory factor analysis sample (CFA; n = 400). EFA revealed a six-factor structure consisting of Perceived Severity, Perceived Vulnerability, Preventive Efficacy, Intervention Capability, Self-Efficacy, and Response Cost. This structure indicated that response efficacy differentiated into prevention-oriented and incident-management-oriented dimensions in the organizational cybersecurity context. The final scale included 27 items. Cronbach’s alpha coefficients ranged from .762 to .862, and the overall scale demonstrated good internal consistency (α = .863). CFA supported the modified six-factor measurement model with acceptable overall fit indices (χ²/df = 1.761, RMSEA = .044, RMR = .040, CFI = .952, IFI = .953). Composite reliability values ranged from .727 to .866, and average variance extracted values provided acceptable evidence for convergent validity. HTMT ratios supported discriminant validity, and common method bias assessments did not indicate a substantial threat to the measurement model. Additional known-groups analyses conducted in two context-specific samples (public sports institutions, n = 188; university employees, n = 113) showed that the scale differentiated theoretically relevant groups according to cybersecurity training, incident awareness, policy/procedure awareness, and cybersecurity unit awareness. Overall, the findings indicate that the PMT-OCPS provides researchers and organizations with a theory-driven instrument for assessing organizational cybersecurity perception and evaluating human-centered cybersecurity readiness</p>

Show More

Keywords

cybersecurity organizational scale awareness from

Related Articles

PORE

About

Connect