Supports
Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security
Iacovos Kirlappos, Simon Parkin, M. Angela Sasse · Workshop on Usable Security (USEC 2014), 2014
Key finding
Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.
Why it matters for PsySec
Shows that employees often want to be secure, and that treating non-compliance as learning rather than violation can improve both culture and controls.
Stance: Supports. Evidence consistent with a PsySec claim. Summaries are written by the database editors; read the original for full results and limitations.
Tags
P2. Culture eats compliance for breakfastP3. Feedback, Feedback, Feedback
BeliefBehavior
ComplianceSecurity cultureUsable securityInsider behavior
Behaviors this study informs
- supports
PB-11 · Raises security friction openly - supports
OB-08 · Designs security rules people can actually follow
Cite this study
APA
Kirlappos, I., Parkin, S., & Sasse, M. A. (2014). Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security. Workshop on Usable Security (USEC 2014). https://doi.org/10.14722/usec.2014.23007
BibTeX
@inproceedings{kirlappos_2014_shadow_security,
title = {Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security},
author = {Iacovos Kirlappos and Simon Parkin and M. Angela Sasse},
year = {2014},
booktitle = {Workshop on Usable Security (USEC 2014)},
doi = {10.14722/usec.2014.23007},
url = {https://doi.org/10.14722/usec.2014.23007}
}