Human Factors Shaping Cybersecurity Behavior in Work from Home Environment in Ugandan Universities
Authors
Department of Computer Science, Mbarara University of Science and Technology (Uganda)
Department of Computing, Kampala International University (Uganda)
Department of Computer Science, Mbarara University of Science and Technology (Uganda)
Article Information
DOI: 10.51584/IJRIAS.2026.110100125
Subject Category: cyber secuirity
Volume/Issue: 11/1 | Page No: 1487-1500
Publication Timeline
Submitted: 2026-01-25
Accepted: 2026-01-20
Published: 2026-02-19
Abstract
The shift to remote and hybrid work in Ugandan universities exposed new cybersecurity risks shaped by human motivation, cognitive load, and system usability challenges. As academic operations increasingly depended on digital platforms, understanding how individuals formed and enacted protective intentions within home-based work environments became critical.
This study examined how human and contextual factors—including threat perception, coping appraisal, usability difficulty, cognitive load, and digital fatigue—influenced cybersecurity behaviour among staff working remotely in Ugandan universities. Guided by the Protection Motivation Theory (PMT) and supported by constructs from the Theory of Planned Behaviour (TPB), the research adopted a sequential explanatory mixed-methods design. The quantitative phase identified key motivational and contextual predictors, while the qualitative phase explored how fatigue, usability barriers, and environmental conditions shaped protective motivation. Integration was achieved through narrative comparison and joint display analysis.
Quantitative findings revealed that coping confidence and usability difficulty were the most influential determinants of secure behaviour, whereas fatigue and cognitive load significantly undermined protective intentions. Qualitative narratives reinforced these patterns, highlighting themes of threat awareness, usability frustration, motivational fatigue, and uneven institutional support.
The study concluded that cybersecurity behaviour in remote academic environments was driven by motivational and contextual dynamics rather than technical controls alone. Strengthening coping efficacy, reducing usability burdens, and addressing digital fatigue were identified as essential strategies for developing adaptive, human-centred cybersecurity interventions in higher education.
Keywords
Cybersecurity behavior, human factors, usability, digital fatigue, Theory of Planned Behavior, work from home
Downloads
References
1. Abuiteiwi, A., & Escobar, S. (2025). Evaluating the human factor in cybersecurity threats (a Systematic Literature Review) (SSRN Scholarly Paper No. 5576064). Social Science Research Network. https://doi.org/10.2139/ssrn.5576064 [Google Scholar] [Crossref]
2. Afolalu, O., & Tsoeu, M. S. (2025). Cybersecurity in Higher Education Institutions: A Systematic Review of Emerging Trends, Challenges and Solutions. Future Internet, 17(12), 575. [Google Scholar] [Crossref]
3. Al-Badayneh, D., AL-BADAYNEH, D., & HASHISH, R. (2025). Human Factors of Cybersecurity. Journal of Posthumanism, 5. https://doi.org/10.63332/joph.v5i4.1242 [Google Scholar] [Crossref]
4. Al-Nuaimi, M. (2022). Human and contextual factors influencing cyber-security in organizations, and implications for higher education institutions: A systematic review. Global Knowledge, Memory and Communication, 73. https://doi.org/10.1108/GKMC-12-2021-0209 [Google Scholar] [Crossref]
5. Aloyce Semlambo, A. (2025). Behavioral, Organizational and Cultural Determinants of ICT Security Incident Reporting in Tanzanian Public Higher Learning Institutions. EAST AFRICAN JOURNAL OF EDUCATION AND SOCIAL SCIENCES, 6(4), 79–87. https://doi.org/10.46606/eajess2025v06i04.0457 [Google Scholar] [Crossref]
6. Al-Shanfari, I., Mohamed, W., Tabook, N., Ismail, R., & Ismail, A. (2022). Determinants of Information Security Awareness and Behaviour Strategies in Public Sector Organizations among Employees. International Journal of Advanced Computer Science and Applications, 13, 479–490. https://doi.org/10.14569/IJACSA.2022.0130855 [Google Scholar] [Crossref]
7. Armas, R., & Taherdoost, H. (2025). Building a cybersecurity culture in higher education: Proposing a cybersecurity awareness paradigm. Information, 16(5), 336. [Google Scholar] [Crossref]
8. Battisti, E., Alfiero, S., & Leonidou, E. (2022). Remote working and digital transformation during the COVID-19 pandemic: Economic–financial impacts and psychological drivers for employees. Journal of Business Research, 150, 38–50. [Google Scholar] [Crossref]
9. Colabianchi, S., Costantino, F., Nonino, F., & Palombi, G. (2025). Transforming threats into opportunities: The role of human factors in enhancing cybersecurity. Journal of Innovation & Knowledge, 10(3), 100695. https://doi.org/10.1016/j.jik.2025.100695 [Google Scholar] [Crossref]
10. Eltahir, M. E., & Ahmed, O. S. (2023). Cybersecurity Awareness in African Higher Education Institutions: A Case Study of Sudan. Information Sciences Letters, 12(1), 171–183. https://doi.org/10.18576/isl/120113 [Google Scholar] [Crossref]
11. Ghazi, K. M. A., Ahmed El-Said, O., Ahmad Rather, R., & Elbayoumi Salem, I. (2025). Extrinsic and intrinsic motives to boost employee cybersecurity behavior and organisational cyber-resilience in hotels: Mediation and moderation analysis. Journal of Hospitality and Tourism Technology, 17(1), 250–273. https://doi.org/10.1108/JHTT-05-2024-0310 [Google Scholar] [Crossref]
12. Grobler, M., Gaire, R., & Nepal, S. (2021). User, Usage and Usability: Redefining Human Centric Cyber Security. Frontiers in Big Data, 4, 583723. https://doi.org/10.3389/fdata.2021.583723 [Google Scholar] [Crossref]
13. Kävrestad, J., Rambusch, J., & Nohlberg, M. (2024). Design principles for cognitively accessible cybersecurity training. Computers & Security, 137, 103630. https://doi.org/10.1016/j.cose.2023.103630 [Google Scholar] [Crossref]
14. Mattioli, R., Malatras, A., Hunter, E. N., Biasibetti Penso, M. G., Bertram, D., & Neubert, I. (2023). Identifying emerging cyber security threats and challenges for 2030. European Union Agency for Cybersecurity (ENISA), Athens-Heraklion, Greece, 64. [Google Scholar] [Crossref]
15. Mbonimpa, T., Richard, N., Innocent, M. J., & Priscilla, M. (2024). Investigating Security Awareness and Incident Reporting levels at Mbarara University of Science and Technology. Indonesian Journal of Innovation and Applied Sciences (IJIAS), 4(3), 208–216. https://doi.org/10.47540/ijias.v4i3.1482 [Google Scholar] [Crossref]
16. Mirembe, D. P., Kibukamusoke, M., Mutebi, R., & Namagembe, B. (2025). Remote Working Trends and Their Impact on Employee Performance and Organizational Productivity in Uganda. Science, Technology & Public Policy, 9(1), 47–62. https://doi.org/10.11648/j.stpp.20250901.15 [Google Scholar] [Crossref]
17. Mizrak, F., Demirel, H. G., Yaşar, O., & Karakaya, T. (2025). Digital detox: Exploring the impact of cybersecurity fatigue on employee productivity and mental health. Discover Mental Health, 5(1), 25. https://doi.org/10.1007/s44192-025-00149-x [Google Scholar] [Crossref]
18. N. Kabanda, M. (2025). Information Security Awareness in Sub-Saharan African Schools: The Role of Educational Leadership in Turbulent Times. In M. Mohiuddin, E. Hosseini, M. Julfikar Ali, & M. Osman Gani (Eds.), Business, Management and Economics (Vol. 30). IntechOpen. https://doi.org/10.5772/intechopen.114332 [Google Scholar] [Crossref]
19. Okanda, P., & Abass, A. (2025). AN EVALUATION OF CYBER INCIDENT MANAGEMENT SYSTEMS IN HIGHER EDUCATION INSTITUTIONS (HEIS) IN KENYA. Journal of Digital Security and Forensics, 2(2), 11–37. https://doi.org/10.29121/digisecforensics.v2.i2.2025.50 [Google Scholar] [Crossref]
20. Oroni, C. Z., & Xianping, F. (2025). Evaluating the influence of cybersecurity policies and cybersecurity behavior on institutional security performance in remote learning: The moderating role of technological readiness. Sustainable Futures, 10, 101554. https://doi.org/10.1016/j.sftr.2025.101554 [Google Scholar] [Crossref]
21. Panc, D. (2023). An analysis of the European Union multifaceted approach to addressing the evolving cybersecurity challenges. Conferința Internațională Educație Și Creativitate Pentru o Societate Bazată Pe Cunoaștere-DREPT, 17(XVII), 112–116. [Google Scholar] [Crossref]
22. Ramamurthy, V., Bogalin, V., Zvavahera, P., & Aquino, E. (2025). Evaluating cybersecurity awareness and practices among employees at a private university in Papua New Guinea. IBSUniversity Journal, 1–19. [Google Scholar] [Crossref]
23. Singh, K., Chatterjee, S., Mariani, M., & Wamba, S. F. (2025). Cybersecurity resilience and innovation ecosystems for sustainable business excellence: Examining the dramatic changes in the macroeconomic business environment. Technovation, 143, 103219. https://doi.org/10.1016/j.technovation.2025.103219 [Google Scholar] [Crossref]
24. Sutton, A., & Tompson, L. (2025). Towards a cybersecurity culture-behaviour framework: A rapid evidence review. Computers & Security, 148, 104110. https://doi.org/10.1016/j.cose.2024.104110 [Google Scholar] [Crossref]
25. Taherdoost, H. (2022). Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview. Electronics, 11(14), 2181. [Google Scholar] [Crossref]
26. William Vortia. (2025). Modelling cybersecurity awareness, perceived threats and secure online behavioral intentions among Ghanaian university students: A PLS-SEM Approach. Magna Scientia Advanced Research and Reviews, 14(2), 096–111. https://doi.org/10.30574/msarr.2025.14.2.0094 [Google Scholar] [Crossref]
27. Ye, Q. (2025). Digital leadership enhances organizational resilience by fostering job crafting: The moderating role of organizational culture. Scientific Reports, 15, 24640. https://doi.org/10.1038/s41598-025-09144-2 [Google Scholar] [Crossref]