The Research · Studies

The evidence, for and against

8 studies · Download CSV

No. 012025 Phishing reporting in organizations: What motivates employees to take action? Burda et al., Information & Computer Security

The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.

No. 022020 Defining organisational information security culture—Perspectives from academia and industry Veiga et al., Computers & Security, 92, 101713

Combines a scoping review with a 512-respondent industry survey to define information security culture, identifying 5 external and 20 internal influencing factors. Academic definitions were much broader than industry's, and strong cultures were linked to mutual trust and integrity.

No. 032019 Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset Zimmermann & Renaud, International Journal of Human-Computer Studies, 131, 169-187

A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.

No. 042018 Exploring susceptibility to phishing in the workplace Williams et al., International Journal of Human-Computer Studies

Across a simulation sent to about 62,000 employees, emails carrying authority cues raised the likelihood of clicking a suspicious link. Focus groups pointed to workplace factors, such as routine email habits and work pressures, that shape whether employees fall for spear phishing.

No. 052018 Is the responsibilization of the cyber security risk reasonable and judicious? Renaud et al., Computers & Security, 78

Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.

No. 062014 Learning from “Shadow Security:” Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security Kirlappos et al., Workshop on Usable Security (USEC 2014)

Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.

No. 072009 Protection motivation and deterrence: a framework for security policy compliance in organisations Herath & Rao, European Journal of Information Systems, 18(2)

Threat severity, response efficacy, self-efficacy and response costs shaped attitudes to security policy. Organisational commitment and social influence significantly drove compliance intentions, and available resources boosted self-efficacy. Employees underestimated how likely breaches were.

No. 081999 Psychological Safety and Learning Behavior in Work Teams Edmondson, Administrative Science Quarterly, 44(2)

Introduces team psychological safety: a shared belief that it is safe to take interpersonal risks. Psychological safety, not team efficacy, was associated with learning behavior such as seeking feedback and discussing errors, and learning behavior mediated the link to team performance.