Studies
10 studies · CSV
- Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al. (2023). HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer Science Government security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
- Defining organisational information security culture—Perspectives from academia and industry Veiga et al. (2020). Computers & Security, 92, 101713 Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.
- Is the responsibilization of the cyber security risk reasonable and judicious? Renaud et al. (2018). Computers & Security, 78 Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.
- Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security Kirlappos et al. (2014). Workshop on Usable Security (USEC 2014) Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.
- Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations Siponen & Vance (2010). MIS Quarterly, 34(3), 487-502 Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
- Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao (2009). European Journal of Information Systems, 18(2) Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.
- So long, and no thanks for the externalities: the rational rejection of security advice by users Herley (2009). Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09) Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
- User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach D'Arcy et al. (2009). Information Systems Research, 20(1) User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.
- The compliance budget: managing security behaviour in organisations Beautement et al. (2008). Proceedings of the 2008 New Security Paradigms Workshop (NSPW '08) Employees decide whether to comply by weighing the personal costs and benefits of compliance against perceived benefit to the organization. Proposes the 'Compliance Budget': a finite store of goodwill that security demands draw down and that must be managed.
- Users are not the enemy Adams & Sasse (1999). Communications of the ACM, 42(12) Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.