MARATTO

article · African Journal Of Applied Research

Human-Centric Cyber Attacks on IoT Infrastructure: Implications for Independent Power Producers (IPPs)

Abstract

Purpose: This study examines how user attitude, individual trust, and power struggles influence cyber-attack incidents within Independent Power Producers (IPPs), with a focus on determining the impact of training as a mediating factor between user attitude, trust, and cyber-attack occurrences in the operational environments of the IPPs. Design/Methodology/Approach: A quantitative research approach was employed using a structured questionnaire administered purposively to employees of selected Independent Power Producers (IPPs) who are directly involved in the day-to-day operations of power generation systems. Data were analysed using Partial Least Squares Structural Equation Modelling (PLS-SEM) to assess both the measurement and structural models and to test the proposed hypotheses. Research Limitation: This study focused exclusively on selected Independent Power Producers within the power generation sector, which may limit the generalizability of the findings to other critical infrastructure sectors or geographical contexts. Findings: The findings reveal a statistically significant positive relationship between user attitude and cyber-attack incidents (β = 0.474, p < 0.000), indicating that certain user behavioural tendencies increase vulnerability to cyber threats. User attitude also showed a statistically significant negative relationship with training impact (β = -0.422, p < 0.000). The results further indicate a statistically significant positive relationship between training impact and cyber-attack incidents (β = 0.144, p = 0.041). Trust of individuals exhibited a statistically significant positive relationship with cyber-attack incidents (β = 0.100, p = 0.020) and with training impact (β = 0.353, p < 0.000). In contrast, power struggles demonstrated a statistically significant negative relationship with cyber-attack incidents (β = -0.787, p < 0.000). The mediation analysis revealed that training impact does not significantly mediate the relationships between user attitude, individual trust, and cyber-attack incidents. Practical Implication: The findings highlight the importance of organisations strengthening cybersecurity awareness programs, improving employee behavioural monitoring mechanisms, and incorporating trust management and organisational dynamics into cybersecurity training initiatives. Social Implication: Regulatory frameworks should emphasise continuous cybersecurity education, employee accountability, and organisational governance mechanisms to reduce cyber vulnerabilities within critical national infrastructure environments. Originality/Value: Integrating user attitude, trust of individuals, power struggles, and training impact into a single analytical framework, which extends existing knowledge on human-centred cybersecurity risks and provides empirical evidence from the power generation sector.

Research topics

  • Information and Cyber Security
  • Smart Grid Security and Resilience
  • Cybersecurity and Cyber Warfare Studies

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.26437/17sjev91

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.