Purpose - This study examines how the People, Process, and Technology (PPT) pillars jointly shape cybersecurity vigilance in Indonesian university settings and whether formal process becomes behaviorally consequential through human capability. Design/methodology/approach - A quantitatively dominant mixed-methods design combined survey data from 1,684 respondents with interviews involving nine cybersecurity experts. Covariance-based structural equation modeling was conducted in IBM SPSS AMOS, while expert evidence was used for explanatory triangulation. Finding/Results - People and Technology were significantly associated with vigilance, whereas Process had no significant direct relationship. Process operated indirectly through People (indirect effect = 0.402; Sobel Z = 4.331; p < .001). Digital literacy and perceived regulatory reinforcement strengthened selected PPT-vigilance relationships. Originality/Value - The study reframes PPT as an interdependent organizational governance architecture rather than three competing pillars. It shows that formal process requires human internalization and that technical, behavioral, and regulatory conditions should be managed as an integrated cybersecurity capability.
Copyrights © 2026