TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Cybersecurity meets HR : A decade of trends, challenges, and best practices

, *

* Corresponding author · click or hover a name for details

pp. 1547–1558Vol. 28Issue 5-AAugust 2025DOI: 10.47974/JDMSC-2153 Crossmark XML
Published Online:
30 Aug 2025
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-2153
Pages:
1547–1558

Abstract

This systematic literature review (SLR) examines the convergence of cybersecurity and human resource management (HRM), aiming to understand the dynamic landscape, uncover key trends, address challenges, and highlight best practices. The ever-increasing reliance on digital technologies has necessitated robust cybersecurity measures, making it imperative for HRM to adapt and integrate these practices into organizational strategies. The review synthesizes findings from numerous studies published over the past decade, emphasizing HR’s pivotal role in cultivating a cybersecurity-conscious culture, examining how cybersecurity affects employee behavior and organizational performance, and outlining strategies for managing cybersecurity risks. The insights are invaluable for HR professionals, cybersecurity specialists, and organizational leaders, underscoring the essential function of HR in protecting digital assets and ensuring the organization’s resilience in a highly interconnected world.

Keywords

Subject Classifications

Primary 93A30Secondary 49K15

References

[1] S. Khandelwal and A. Chaudhary, “COVID-19 pandemic & cyber security issues: Sentiment analysis and topic modeling approach,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 25, no. 4, pp. 987–997 (May 2022).
[2] M.J. Page, J.E. McKenzie, P.M. Bossuyt, I. Boutron, T.Hoffmann, C.D. Mulrow, L. Shamseer, and D. Moher , “Mapping of reporting guidance for systematic reviews and meta-analyses generated a comprehensive item bank for future reporting guidelines”, Journal of clinical epidemiology, 118, pp. 60-68 (2020), https://doi.org/10.1016/j.jclinepi.2019.11.010,
[3] E. Stovold, D. Beecher, R. Foxlee, and A. Noel-Storr, “Study flow diagrams in Cochrane systematic review updates: An adapted PRISMA flow diagram,” Systematic Reviews, vol. 3, p. 54 (2014).
[4] S. Chaudhary, “Driving behaviour change with cybersecurity awareness,” Computers & Security, Article ID 103858 (2024).
[5] S. Saeed, “Digital Workplaces and Information Security Behavior of Business Employees: An Empirical Study of Saudi Arabia,” Sustainability, vol. 15, no. 7, p. 6019 (2023).
[6] K. D. Strang, “Cybercrime Risk Found in Employee Behavior Big Data Using Semi-Supervised Machine Learning with Personality Theories,” Big Data and Cognitive Computing, vol. 8, no. 4, p. 37 (2024).
[7] S. Nepal, J. Hernandez, R. Lewis, A. Chaudhry, B. Houck, E. Knudsen, R. Rojas, B. Tankus, H. Prafullchandra, and M. Czerwinski, “Burnout in Cybersecurity Incident Responders: Exploring the Factors that Light the Fire,” Proceedings of the ACM on Human-Computer Interaction, vol. 8, no. CSCW1, pp. 1–35 (2024).
[8] R. Spithoven and A. Drenth, “Who will take the bait? Using an embedded, experimental study to chart organization-specific phishing risk profiles and the effect of a voluntary microlearning among employees of a Dutch municipality,” Journal of Cybersecurity, vol. 10, no. 1 (2024).
[9] T. Daengsi, P. Pornpongtechavanich, and P. Wuttidittachotti, “Cybersecurity Awareness Enhancement: A Study of the Effects of Age and Gender of Thai Employees Associated with Phishing Attacks,” Education and Information Technologies, vol. 27, no. 6, pp. 7975–7995 (2022).
[10] M. T. Whitty, N. Moustafa, and M. Grobler, “Cybersecurity when working from home during COVID-19: considering the human factors,” Journal of Cybersecurity, vol. 10, no. 1, Article ID tyae001 (2024).
[11] N. Beu, A. Jayatilaka, M. Zahedi, M. A. Babar, L. Hartley, W. Lewinsmith, and I. Baetu, “Falling for phishing attempts: An investigation of individual differences that are associated with behavior in a naturalistic phishing simulation,” Computers & Security, vol. 131, Article ID 103313 (2023).
[12] M. Waqas, A. Hania, F. Yahya, and I. Malik, “Enhancing Cybersecurity: The Crucial Role of Self-Regulation, Information Processing, and Financial Knowledge in Combating Phishing Attacks,” SAGE Open, vol. 13, no. 4, Article ID 21582440231217720 (2023).
[13] C. Gerdenitsch, D. Wurhofer, and M. Tscheligi, “Working conditions and cybersecurity: Time pressure, autonomy and threat appraisal shaping employees’ security behavior,” Cyberpsychology: Journal of Psychosocial Research on Cyberspace, vol. 17, no. 4 (2023).
[14] E. Tariq, I. Akour, N. Al-Shanableh, E. Alquqa, N. Alzboun, S. Al-Hawary, and M. Alshurideh, “How cybersecurity influences fraud prevention: An empirical study on Jordanian commercial banks,” International Journal of Data and Network Science, vol. 8, no. 1, pp. 69–76 (2024).
[15] D. Baltuttis and T. Teubner, “Effects of Visual Risk Indicators on Phishing Detection Behavior: An Eye-Tracking Experiment,” Computers & Security, Article ID 103940 (2024).
[16] A. Sumner, X. Yuan, M. Anwar, and M. McBride, “Examining factors impacting the effectiveness of anti-phishing trainings,” Journal of Computer Information Systems, vol. 62, no. 5, pp. 975–997 (2022).
[17] M. Canham, C. Posey, D. Strickland, and M. Constantino, “Phishing for long tails: Examining organizational repeat clickers and protective stewards,” SAGE Open, vol. 11, no. 1, Article ID 2158244021990656 (2021).
[18] D. Buil-Gil and E. Barrett, “The dynamics of business, cybersecurity and cyber-victimization: Foregrounding the internal guardian in prevention,” in The New Technology of Financial Crime, Abingdon, UK: Routledge, pp. 5–34 (2022).
[19] A. S. Williams, M. S. Maharaj, and A. I. Ojo, “Employee behavioural factors and information security standard compliance in Nigeria banks,” International Journal of Computing and Digital Systems, vol. 8, no. 4, pp. 387–396 (2019).
[20] E. C. Donald, M. A. Bumpus, and X. Zhang, “A case study in selection and deployment of a multi-factor authentication solution,” Issues in Information Systems, vol. 22, no. 3 (2021).
[21] D. Heering, “Ensuring cybersecurity in shipping: Reference to Estonian shipowners,” TransNav: International Journal on Marine Navigation and Safety of Sea Transportation, vol. 14, no. 2 (2020).
[22] H. Park, Y. Yoo, and H. Lee, “7s Model for technology protection of organizations,” Sustainability, vol. 13, no. 13, p. 7020 (2021).
[23] M. Canham, C. Posey, and M. Constantino, “Phish derby: Shoring the human shield through gamified phishing attacks,” in Frontiers in Education, vol. 6, p. 807277, Frontiers Media SA (Jan. 2022).
[24] A. Leering, L. van de Wijngaert, and S. Nikou, “More honour’d in the breach: predicting non-compliant behaviour through individual, situational and habitual factors,” Behaviour & Information Technology, vol. 41, no. 3, pp. 519–534 (2022).
[25] A. Mihailović, J. Cerović Smolović, I. Radević, N. Rašović, and N. Martinović, “COVID-19 and beyond: employee perceptions of the efficiency of teleworking and its cybersecurity implications,” Sustainability, vol. 13, no. 12, p. 6750 (2021).

Views: 169Downloads: 11Citations: 2