Information Security Culture and Organizational Cyber Resilience: The Mediating Role of Security Practices
DOI:
https://doi.org/10.63056/tljet.2.2.2026.272Keywords:
information security culture, organizational cyber resilience, security practices, cybersecurity, incident response, security controls, information systems securityAbstract
Organizations are now more reliant on interconnected information systems, making cybersecurity an integral part of organizational continuity and operational stability. While technical controls are a key aspect of traditional cybersecurity, organizational values, employee conduct, security policies, management dedication to security and regular application of security protocols are equally crucial. Information security culture can set shared expectations of what it means to act in a secure manner, how to deal with risks, whether or not to comply with policies, and whether or not to report incidents, and security practice can take these cultural expectations and turn them into concrete technical and organizational controls. This study focused on the relationship between information security culture and organizational cyber resilience, as well as a mediation effect of information security practices. A simulated cyber security research design that is controlled and a security-audit research design in an isolated virtual organizational network was used. Information security culture was materialized in the form of information security requirements of the organization, such as security policies, support of management, authentication requirements, access-control procedures, standards for patch-management, standards for backup, procedures for reporting of information security incidents, and mechanisms of compliance. Technical audits were performed on access privileges, network segmentation, endpoint protection, patching, logging, vulnerability management, backup procedures, incident response, authentication and security practices. A series of controlled cybersecurity scenarios were placed in the isolated environment and system logs were gathered to assess the time taken for detection, time for response, time for containment, time for recovery, availability of services, affected systems, ability to contain the threat and recovery of data. Organizations were assessed objectively with regard to their cyber resilience using these indicators. The following, mediation analysis utilizing bootstrapping, was then conducted to investigate the effect of whether security practices mediated the effect of information security culture on cyber resilience. The study offered a socio-technical approach to cybersecurity, making links between organization culture and seen behaviours on security and measurable security outcomes.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Muhammad Arslan, Muhammad Akbar

This work is licensed under a Creative Commons Attribution 4.0 International License.

