we suggest that information security awareness programs should be designed to emphasize these outcome beliefs; security practitioners should design their information security awareness programs so employees’ beliefs about intrinsic cost and benefit, safety, and vulnerability are reinforced. Further, our results indicate that an employee’s perception that compliance impedes job related functions can be lessened by information security awareness. Thus, ensuring information security awareness can directly and indirectly alter employees’ belief sets about compliance with the information security policy. This implies that creating a security-aware culture within the organization will improve information security