Abstract
Small and medium enterprises (SMEs) constitute the overwhelming majority of Australian businesses, yet they remain disproportionately exposed to cyber threats because of constrained budgets, limited specialist staff and a heavy reliance on individual employees. This thesis examines how information security culture forms within Australian SMEs and how it shapes protective behaviour and uptake of the Australian Cyber Security Centre Essential Eight. Drawing on protection motivation theory and established security-culture frameworks, a conceptual model was tested using survey data from 312 SME owners and staff, supplemented by 14 semi-structured interviews. Partial least squares structural equation modelling showed that leadership commitment, security training and protection motivation together explained 48 per cent of the variance in security culture, which in turn strongly predicted security behaviour and, more weakly, Essential Eight uptake. The findings position visible leadership tone and contextually relevant training as the most actionable levers for strengthening cyber resilience across the Australian SME sector.
Introduction
Small and medium enterprises dominate the Australian economy. The Australian Bureau of Statistics (2023) records that small businesses alone account for roughly 97 per cent of all actively trading businesses, and SMEs together employ a substantial share of the private-sector workforce. This structural weight is not matched by security maturity. The Australian Cyber Security Centre (2023a) received over 94,000 cybercrime reports in 2022-23, equivalent to one report every six minutes, and estimated the average self-reported loss for a small business at approximately 46,000 dollars, rising to about 97,000 dollars for medium businesses. For firms operating on thin margins, a single ransomware or business email compromise event can be existential.
The distinctive feature of the SME threat surface is the human factor. Where large organisations can employ dedicated security teams, most SMEs distribute security responsibility across owners and generalist staff who juggle it alongside their primary duties. The Australian Small Business and Family Enterprise Ombudsman (2023) has repeatedly noted that time, cost and skills constraints leave many small firms without formal policies or training. Regulatory expectations are nonetheless rising: the Notifiable Data Breaches scheme administered under the Privacy Act 1988 (Cth) obliges covered entities to report eligible breaches to the Office of the Australian Information Commissioner (2023), and the Security of Critical Infrastructure Act 2018 (Cth) extends obligations along supply chains that increasingly include smaller vendors. The Essential Eight mitigation strategies published by the Australian Cyber Security Centre (2023b) have become the de facto baseline against which Australian organisations benchmark their controls.
Despite this, most empirical research on information security culture has been conducted in large enterprises, and comparatively little integrates organisational culture with individual protection motivation in the resource-constrained SME setting. This thesis addresses that gap through three research questions:
- Which organisational and individual factors most strongly shape information security culture in Australian SMEs?
- To what extent does security culture mediate the relationship between those factors and employee security behaviour?
- How does security culture relate to the uptake of the Essential Eight mitigation strategies?
This extract presents the condensed literature review, the methodology and the principal findings, followed by their implications for Australian practice.
Literature Review
Information security culture
Information security culture describes the shared assumptions, values and behaviours that determine how security is enacted day to day, rather than merely written into policy. Da Veiga and Eloff (2010) provided an influential framework and assessment instrument, arguing that culture mediates between formal controls and actual employee conduct. Hu et al. (2012) sharpened the managerial implication, demonstrating that top management participation shapes organisational culture, which in turn drives compliance more powerfully than sanctions alone. In an SME, where the owner often embodies the organisation, this leadership mechanism is likely to be even more pronounced than in the large firms these studies examined.
Protection motivation theory
At the individual level, protection motivation theory (Rogers, 1975) explains protective behaviour as the product of threat appraisal, comprising perceived severity and perceived vulnerability, and coping appraisal, comprising response efficacy and self-efficacy. Applied to information security, Boss et al. (2015) showed that fear appeals motivate protective action only when paired with credible efficacy beliefs, so that warning staff about threats is insufficient unless they also believe the recommended response will work and that they can perform it. Ifinedo (2012) integrated protection motivation with the theory of planned behaviour and found that self-efficacy and response efficacy were consistent predictors of policy compliance intention.
Awareness, behaviour and the SME setting
Awareness sits between culture and behaviour. Bulgurcu et al. (2010) established that information security awareness raises the perceived benefit of compliance and reduces the perceived cost, strengthening compliance intention. Yet awareness initiatives are precisely what SMEs struggle to resource. Renaud and Ophoff (2021) found that smaller firms often lack the situational awareness needed to prioritise controls, and that owner attitudes are decisive in whether precautions are implemented at all. Synthesising these strands, this thesis proposes that leadership commitment, security training and protection motivation act as antecedents of security culture, which mediates their influence on both security behaviour and Essential Eight uptake. Figure 1 presents the conceptual model and the hypothesised paths.
Methodology
Research design
An explanatory mixed-methods design was adopted. A cross-sectional survey tested the conceptual model quantitatively, and semi-structured interviews were used afterwards to interpret and contextualise the statistical results. This sequencing suited research questions that ask both how strongly the constructs relate and why the relationships take the form they do.
Sample and data collection
The sampling frame comprised Australian SMEs, defined following the Australian Bureau of Statistics convention as businesses employing fewer than 200 people. Invitations were distributed through industry associations and professional networks across New South Wales, Victoria, Queensland and Western Australia. Of 361 responses received, 312 were retained after removing incomplete and inattentive cases, spanning professional services, retail, construction, health and allied services, and hospitality. Constructs were measured with multi-item scales adapted from the validated instruments reviewed above, each rated on a five-point Likert scale. A subset of 14 owners and managers then took part in interviews of 40 to 55 minutes, recorded with consent and transcribed for analysis.
Analysis and ethics
The measurement and structural models were estimated using partial least squares structural equation modelling, which is well suited to prediction-oriented models and modest sample sizes (Hair et al., 2022). Reliability and convergent validity were assessed before the structural paths were interpreted. Interview transcripts were examined thematically to explain the quantitative patterns. The study received approval from the university Human Research Ethics Committee and was conducted in accordance with the National Statement on Ethical Conduct in Human Research (National Health and Medical Research Council, 2018); participation was voluntary, responses were de-identified, and data were stored on encrypted university systems.
Results
Measurement model
The measurement model demonstrated satisfactory reliability and convergent validity. As shown in Table 1, all constructs recorded Cronbach’s alpha and composite reliability above the 0.70 threshold, and average variance extracted (AVE) above 0.50, indicating that each latent variable explained the majority of its indicators’ variance.
Table 1: Construct descriptive statistics, reliability and convergent validity (n = 312)
| Construct | Items | Mean | SD | Cronbach’s α | CR | AVE |
|---|---|---|---|---|---|---|
| Leadership commitment (LC) | 4 | 3.62 | 0.88 | 0.86 | 0.87 | 0.63 |
| Security training (ST) | 4 | 3.18 | 0.95 | 0.83 | 0.84 | 0.58 |
| Protection motivation (PM) | 5 | 3.74 | 0.79 | 0.88 | 0.89 | 0.62 |
| Security culture (SC) | 6 | 3.45 | 0.83 | 0.91 | 0.92 | 0.65 |
| Security behaviour (SB) | 5 | 3.51 | 0.86 | 0.87 | 0.88 | 0.60 |
| Essential Eight uptake (E8) | 5 | 2.94 | 1.02 | 0.85 | 0.86 | 0.56 |
To illustrate the calculation, composite reliability and AVE for leadership commitment were derived from its four standardised item loadings of 0.78, 0.81, 0.79 and 0.80, using CR = (Σλ)² / [(Σλ)² + Σ(1 – λ²)]:
- Σλ = 0.78 + 0.81 + 0.79 + 0.80 = 3.18, so (Σλ)² = 10.11
- Σλ² = 0.61 + 0.66 + 0.62 + 0.64 = 2.53, so Σ(1 – λ²) = 4 – 2.53 = 1.47
- CR = 10.11 / (10.11 + 1.47) = 10.11 / 11.58 = 0.87
- AVE = Σλ² / 4 = 2.53 / 4 = 0.63
These worked values reproduce the leadership commitment row of Table 1, confirming the internal consistency of the reported statistics. The lowest construct mean was Essential Eight uptake (M = 2.94, SD = 1.02), signalling that self-assessed control maturity lagged the more favourable attitudinal constructs.
Structural model
All five hypothesised paths were positive and statistically significant, as reported in Table 2. Leadership commitment was the strongest antecedent of security culture, followed by security training and protection motivation; together they accounted for 48 per cent of the variance in security culture. Security culture in turn was a strong predictor of security behaviour and a moderate predictor of Essential Eight uptake.
Table 2: Structural model path coefficients and hypothesis tests
| Path | β | SE | t | p | Result |
|---|---|---|---|---|---|
| LC → SC (H1) | 0.34 | 0.06 | 5.67 | < 0.001 | Supported |
| ST → SC (H2) | 0.28 | 0.06 | 4.67 | < 0.001 | Supported |
| PM → SC (H3) | 0.22 | 0.07 | 3.14 | 0.002 | Supported |
| SC → SB (H4) | 0.52 | 0.05 | 10.40 | < 0.001 | Supported |
| SC → E8 (H5) | 0.41 | 0.06 | 6.83 | < 0.001 | Supported |
The coefficient of determination confirmed the differing predictive strength of the outcomes. Security culture explained 27 per cent of the variance in security behaviour (R² = 0.52² = 0.27) but only 17 per cent of the variance in Essential Eight uptake (R² = 0.41² = 0.17). The gap indicates that culture translates more readily into everyday behaviour than into the technical control implementation the Essential Eight requires.
Qualitative themes
Interviews explained these patterns. Three themes were prominent. First, owner tone set the ceiling: staff calibrated their own vigilance to how seriously the owner visibly treated security, echoing the dominance of leadership commitment in the model. Second, resourcing throttled implementation: participants understood the Essential Eight in principle but described patching, application control and multi-factor rollout as competing with billable work for scarce time, consistent with the low uptake mean. Third, relevance drove training value: generic modules were dismissed, whereas short, scenario-based sessions using recognisable Australian examples, such as invoice fraud targeting a trades business, were credited with changing habits.
Discussion
The results carry a clear message for Australian SMEs: culture, not technology, is the proximate lever, and leadership is the lever behind the lever. The primacy of leadership commitment extends Hu et al. (2012) into the small-firm context, where the owner’s visible conduct substitutes for the formal governance structures larger organisations rely upon. Because security culture mediated the antecedents rather than the antecedents acting directly on behaviour, interventions that ignore culture and simply mandate controls are unlikely to endure.
The weaker path from culture to Essential Eight uptake is the most policy-relevant finding. A supportive culture raises the intention to secure the business, but intention collides with the resourcing constraints documented by the Australian Small Business and Family Enterprise Ombudsman (2023). Implementing application control, disciplined patching of applications and operating systems, restriction of administrative privileges, multi-factor authentication and regular backups (Australian Cyber Security Centre, 2023b) demands time and technical capability that many SMEs lack. Culture is necessary but not sufficient; without subsidised support, managed services or simplified tooling, favourable attitudes stall before implementation.
The training results reinforce protection motivation theory. Training influenced behaviour indirectly, through culture, and interviews showed that this influence depended on relevance and efficacy rather than exposure. This is consistent with Boss et al. (2015) and Ifinedo (2012): raising perceived threat without also building response efficacy and self-efficacy produces anxiety rather than action. For SMEs, that argues for concise, locally framed training tied to plausible Australian attack scenarios rather than compliance-driven generic content.
Regulatory context sharpens the stakes. The Notifiable Data Breaches obligations overseen by the Office of the Australian Information Commissioner (2023), together with supply-chain expectations flowing from the Security of Critical Infrastructure Act 2018 (Cth), mean that weak SME security is increasingly a liability for the larger organisations that contract with them. Strengthening SME security culture therefore delivers benefits well beyond the individual firm.
Several limitations qualify these conclusions. The cross-sectional design precludes causal claims, and the reliance on self-report invites common-method and social-desirability bias, most plausibly inflating the self-assessed Essential Eight measure. The sample, although diverse, was drawn from four states and may under-represent micro-businesses and remote operators. Longitudinal and behavioural-trace data would strengthen future tests of the model.
Conclusion
This thesis examined how information security culture forms in Australian SMEs and how it shapes protective behaviour and Essential Eight uptake. Using survey data from 312 owners and staff and 14 interviews, it found that leadership commitment, security training and protection motivation jointly build security culture, which strongly predicts everyday security behaviour and, more weakly, the implementation of technical controls. The central contribution is empirical evidence, grounded in the Australian setting, that culture mediates the human and organisational drivers of SME cyber resilience, and that leadership tone is its most powerful antecedent. Practically, the findings recommend that owners model security visibly, that training be short and contextually relevant, and that Essential Eight adoption be actively resourced rather than merely encouraged, since goodwill alone does not close the implementation gap. Given the weight of SMEs in the Australian economy and their growing position in regulated supply chains, building security culture in these firms is a national resilience priority, not merely a private one.
References
Australian Bureau of Statistics. (2023). Counts of Australian businesses, including entries and exits, July 2019 to June 2023. ABS.
Australian Cyber Security Centre. (2023a). ASD cyber threat report 2022-23. Australian Signals Directorate.
Australian Cyber Security Centre. (2023b). Essential Eight maturity model. Australian Signals Directorate.
Australian Small Business and Family Enterprise Ombudsman. (2023). Small business cyber security: Guidance for owners and managers. ASBFEO.
Boss, S. R., Galletta, D. F., Lowry, P. B., Moody, G. D., & Polak, P. (2015). What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quarterly, 39(4), 837-864.
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523-548.
Da Veiga, A., & Eloff, J. H. P. (2010). A framework and assessment instrument for information security culture. Computers & Security, 29(2), 196-207.
Hair, J. F., Hult, G. T. M., Ringle, C. M., & Sarstedt, M. (2022). A primer on partial least squares structural equation modeling (PLS-SEM) (3rd ed.). Sage.
Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615-660.
Ifinedo, P. (2012). Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers & Security, 31(1), 83-95.
National Health and Medical Research Council. (2018). National statement on ethical conduct in human research. Australian Government.
Office of the Australian Information Commissioner. (2023). Notifiable data breaches report: July to December 2022. OAIC.
Renaud, K., & Ophoff, J. (2021). A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs. Organizational Cybersecurity Journal, 1(1), 24-46.
Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91(1), 93-114.