This study investigated the factors influencing hotel employees’ intentions to comply with information security (IS) policies, using protection motivation theory (PMT) as the guiding framework. Specifically, this study aims to examine how perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy and response costs impact compliance intentions while also exploring the moderating role of generational differences.
Data were collected from 298 US-based hotel employees through an online survey. The research model was tested through the application of structural equation modeling.
The results demonstrated that perceived vulnerability, perceived severity, response efficacy and self-efficacy positively influenced employees’ compliance intentions, whereas maladaptive rewards and response costs had significant negative effects. Furthermore, generational differences were found to significantly moderate the relationships between perceived severity, maladaptive rewards, response costs and hotel employees’ intentions to comply with IS security policies.
The findings offer actionable insights for hotel management and IS professionals to develop tailored strategies aimed at enhancing employees’ compliance with IS policies. These strategies address generational-specific motivators and barriers to foster a culture of cybersecurity awareness and adherence.
This study contributes to the cybersecurity literature by applying PMT within the hotel industry context. Its focus on generational differences as moderating factors provides a nuanced understanding of IS compliance, offering valuable implications for both academic research and practical applications.
