References
Aiken, L. S., & West, S. G. (1991). Multiple regression: Testing and interpreting interactions. SAGE Publications. Ajzen, I. (1991). The theory of planned behavior. Organizational Behavior and Human Decision Processes, 50(2), 179–211. Alhassan, I., Sammon, D., & Daly, M. (2021). Data governance activities: An analysis of the literature. Journal of Decision Systems, 25(S1), 64–75. Alikornwo, P. M., & Echendu, S. I. (2026). Digital office practices and information management effectiveness in tertiary institutions in Rivers State, Nigeria. BW Academic Journal: American Journal of Entrepreneurship, Economics and Management, 11(2), 48-57. Alikornwo, P. M., & Orisah-Godfrey, L. A. (2026). Digital office strategy and administrative service delivery in higher education institutions in Rivers State, Nigeria. BW Academic Journal: Innovative Journal of Accounting, Marketing and Management Research, 13(2), 48-62. Amadi, C., Nwachukwu, P., & Okafor, E. (2023). Information security governance in Nigerian universities: Challenges and prospects. African Journal of Information Systems, 15(2), 44– 61. Andress, J. (2019). The basics of information security: Understanding the fundamentals of InfoSec in theory and practice (2nd ed.). Syngress. Baron, R. M., & Kenny, D. A. (1986). The moderator-mediator variable distinction in social psychological research. Journal of Personality and Social Psychology, 51(6), 1173–1182. Becker, G. S. (1968). Crime and punishment: An economic approach. Journal of Political Economy, 76(2), 169–217. Boss, S. R., Kirsch, L. J., Angermeier, I., Shingler, R. A., & Boss, R. W. (2019). If someone is watching, I’ll do what I’m asked: Mandatoriness, control, and information security. European Journal of Information Systems, 18(2), 151–164. Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2020). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. Creswell, J. W., & Creswell, J. D. (2022). Research design: Qualitative, quantitative, and mixed methods approaches (5th ed.). SAGE Publications. Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M., & Baskerville, R. (2020). Future directions for behavioral information security research. Computers and Security, 32(1), 90–101. D’Arcy, J., Hovav, A., & Galletta, D. (2019). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79–98. Federal Republic of Nigeria. (2015). Cybercrimes (prohibition, prevention, etc.) act. Federal Government of Nigeria. Herath, T., & Rao, H. R. (2019). Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness. Decision Support Systems, 47(2), 154–165. Ifinedo, P. (2022). Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers and Security, 31(1), 83–95. E-ISSN 2545-529x Ihejirika, K., Okafor, R., & Eze, C. (2022). Data monitoring and information security in public universities in southern Nigeria. Nigerian Journal of Information Management, 6(1), 33– 49. International Organisation for Standardisation. (2022). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection. ISO. Maddux, J. E., & Rogers, R. W. (1983). Protection motivation and self-efficacy: A revised theory of fear appeals and attitude change. Journal of Experimental Social Psychology, 19(5), 469–479. National Information Technology Development Agency. (2019). Nigeria data protection regulation. Federal Republic of Nigeria. Nduka, O., Ogele, B., & Briggs, A. (2022). Regulatory frameworks and information security compliance in Nigerian public institutions. Journal of Public Administration and Governance, 12(3), 88–104. Nunnally, J. C. (1978). Psychometric theory (2nd ed.). McGraw-Hill. Nwachukwu, P., Amadi, C., & Ordu, S. (2023). Data governance maturity in Rivers State public tertiary institutions. Rivers State Journal of Administration and Management, 4(1), 55–72. Nwinyokpugi, P. N. & Oba-Davies, E. I. (2023). Public sector efficiency: The electronic administration denominator. Journal of Office and Information Management, 7(1), 1–14. Obara, C. E. & Onyebuenyi, C. (2023). Refining organizational performance in deposit money banks using knowledge gap analysis. Journal of Office and Information Management , 7(1), 44–62. Obi, F., Ezenwoke, O., & Chukwuemeka, N. (2023). Information security management in developing countries: A Nigerian perspective. International Journal of Information Security and Privacy, 17(1), 1–18. Okenwa, G., Nwosu, A., & Adaeze, M. (2022). Vulnerabilities and information security risks in Nigerian public universities. Journal of Cybersecurity in Africa, 3(2), 21–38. Orisah-Godfrey, L. A., & Alikornwo, P. M. (2026). Information governance strategy: Assessing the administrative accountability referents in public sector institutions in Rivers State. BW Academic Journal: International Journal of Accounting, Auditing & Management, 13(1), 76-88. Orisah-Godfrey, L. A., & Gbafah, B. L. (2026). Information security strategy and administrative risk management in tertiary institutions in Rivers State, Nigeria. BW Academic Journal: Journal of Management, Marketing, and Accounting Innovations, 10(1), 28-44. Pahnila, S., Siponen, M., & Mahmood, A. (2019). Employees’ behavior towards IS security policy compliance. Proceedings of the 40th Hawaii International Conference on System Sciences, 1–10. Ponemon Institute. (2023). Cost of a data breach report 2023. IBM Security. Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91(1), 93–114. Saunders, M., Lewis, P., & Thornhill, A. (2019). Research methods for business students (8th ed.). Pearson Education. Siponen, M., & Vance, A. (2020). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502. Siponen, M., Mahmood, M. A., & Pahnila, S. (2019). Employees’ adherence to information security policies: An exploratory field study. Information and Management, 51(2), 217– 224. E-ISSN 2545-529x Straub, D. W. (1990). Effective IS security: An empirical study. Information Systems Research, 1(3), 255–276. Straub, D. W., & Welke, R. J. (2018). Coping with systems risk: Security planning models for management decision making. MIS Quarterly, 22(4), 441–469. Trim, P., & Lee, Y. (2021). The global cyber security model: Counteracting cyber attacks through a resilient partnership arrangement. Journal of Information Security, 12(3), 200–215. Von Solms, R., & Van Niekerk, J. (2019). From information security to cyber security. Computers and Security, 38, 97–102. Warkentin, M., Siponen, M., & Straub, D. (2021). An enhanced fear appeal rhetorical framework: Leveraging threats to the human asset through sanctioning rhetoric. MIS Quarterly, 45(3), 1–28. Workman, M., Bommer, W. H., & Straub, D. (2020). Security lapses and the omission of information security measures: A threat control model and empirical test. Computers in Human Behavior, 24(6), 2799–2816. Yamane, T. (1967). Statistics: An introductory analysis (2nd ed.). Harper and Row. Zeb-Obipi, I. (2022). Predictive analytics and organizational competence. 79th Inaugural Lecture of Rivers State University, Port Harcourt, Rivers State, Nigeria, July 27, 2022.