Studies
4 studies · CSV
- Tuning Out Security Warnings: A Longitudinal Examination of Habituation Through fMRI, Eye Tracking, and Field Experiments Vance et al. (2018). MIS Quarterly, 42(2), 355-380 Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.
- Security Fatigue Stanton et al. (2016). IT Professional, 18(5) Although the interviews never asked about fatigue, over half of the 40 participants described it: resignation, loss of control, fatalism, risk minimization and decision avoidance. This fatigue fed their sense that following security advice has little benefit.
- So long, and no thanks for the externalities: the rational rejection of security advice by users Herley (2009). Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09) Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
- The compliance budget: managing security behaviour in organisations Beautement et al. (2008). Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08) Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.