Digital transformation is considered a source of competitive advantage and improved organisational performance. Within the public sector, leaders anticipate digital transformation to help them improve transparency and accountability, and stakeholders’ participation in public decision-making. At the same time, the accelerated adoption of digital technologies within the sector has also made information an important asset. Thus, the effectiveness of the information security management put in place determines whether an organisation can realise the benefits of successful digital transformation. Adopting a mixed-method approach (13 interviews and an online survey with 128 information security experts), this study identified various antecedents of effective information security management, i.e., leadership skills and attitudes, organisational culture, organisational structure, IT governance, IT alignment, and human resource management practices. Partial Least Structural Equation Modelling technique was adopted to test the proposed theoretical model and hypothesised causal relationships.