Research / Studies

SupportsQualitative · 2014

Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security

Iacovos Kirlappos, Simon Parkin, M. Angela Sasse · Workshop on Usable Security (USEC 2014), 2014

Key finding

Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.

Why it matters for PsySec

Shows that employees often want to be secure, and that treating non-compliance as learning rather than violation can improve both culture and controls.

Stance: Supports. Evidence consistent with a PsySec claim. Summaries are written by the database editors; read the original for full results and limitations.

Tags

Behaviors this study informs

Cite this study

APA

Kirlappos, I., Parkin, S., & Sasse, M. A. (2014). Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security. Workshop on Usable Security (USEC 2014). https://doi.org/10.14722/usec.2014.23007

BibTeX

@inproceedings{kirlappos_2014_shadow_security,
  title = {Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security},
  author = {Iacovos Kirlappos and Simon Parkin and M. Angela Sasse},
  year = {2014},
  booktitle = {Workshop on Usable Security (USEC 2014)},
  doi = {10.14722/usec.2014.23007},
  url = {https://doi.org/10.14722/usec.2014.23007}
}