Demographic Patterns in Cybersecurity Culture: Insights from a Global Organisation Supporting Safety-Critical and Critical Infrastructure Sectors

📅 2026-06-12
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study investigates how demographic factors influence cybersecurity culture (CSC) within critical infrastructure organizations. Drawing on 6,502 valid survey responses from a global sample of 21,148 employees, the research employs Kruskal-Wallis tests with Dunn’s post hoc analysis to systematically assess associations between nine CSC dimensions and variables such as employment type, age, recruitment pathway, and managerial role. For the first time in safety-critical global organizations, it reveals that full-time, internally recruited, older employees and line managers consistently score significantly higher across multiple CSC dimensions compared to part-time, externally recruited, and younger counterparts. Building on these findings, the study proposes a scalable strategy that leverages high-scoring groups as cultural carriers while targeting low-scoring groups for focused interventions, thereby offering empirical grounding and actionable pathways for differentiated enhancement of organizational cybersecurity culture.
📝 Abstract
This study investigates demographic differences in cybersecurity culture in a large global organisation supporting safety critical and critical infrastructure sectors to target CSC improvement. A global survey was administered to all internal and external employees of a total of 21148 employees, with 6502 responses. The questionnaire evaluates nine CSC dimensions such as Password Management, Governance, Email Use. Anonymous survey responses were analysed using Kruskal-Wallis tests and Dunns post hoc comparisons to identify differences across demographic variables including employment, recruitment paths, managerial role, gender, age, tenure, and work base. CSC was broadly consistent across the organisation, with statistically significant but small to moderate demographic effects. CSC variations were observed across employment, age, recruitment paths, and line managerial role. In general, fulltime, internal, permanent, older employees, Merge and Acquisition recruits, and line managers consistently scored higher across multiple CSC dimensions. Parttime, younger, external employees, and those with 6 to 20 years of tenure in general scored lower. These patterns highlight higher-scoring groups that may act as CSC carriers and lower-scoring groups that may benefit from tailored improvement measures, enabling organisational learning. Our study offers a practical, scalable way to assess CSC, generating meaningful insights despite industrial constraints. It enables organisations to benchmark maturity, identify gaps, and prioritise targeted improvements using workforce diversity as a guide.
Problem

Research questions and friction points this paper is trying to address.

Cybersecurity Culture
Demographic Differences
Critical Infrastructure
Organizational Security
Workforce Diversity
Innovation

Methods, ideas, or system contributions that make the work stand out.

cybersecurity culture
demographic analysis
Kruskal-Wallis test
organizational benchmarking
tailored interventions
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
T
Tita Alissa Bach
Group Research and Development, DNV, Veritasveien 1, Høvik, Norway
A
Amandine Kaiser
Group Research and Development, DNV, Veritasveien 1, Høvik, Norway