Whistleblowers perform an essential service in revealing wrongdoing. Most feel compelled to highlight nefarious organisational activities. If their efforts within the organisation are ignored and they feel driven to “go public”, disclosures can harm the organisation’s cybersecurity and whistleblowers themselves usually pay a high price for their actions. We argue that, rather than vilifying whistleblowers, organisations ‘harness’ their propensity to keep the organisation on the straight and narrow. To achieve this, it is crucial to understand the whistleblower’s journey from being triggered by some unethical organisational activity to the final external whistleblowing act. We reviewed the archival literature to produce a synthesis of whistleblower stages. We carried out a case study and interviewed two whistleblowers to inform derivation of a staged whistleblowing model. This makes it possible to identify pressure points for targeted interventions which can encourage internal whistleblowing and thereby prevent the tangential dismantling of organisational information security.
Competition among software firms has given rise to theft of intellectual property and numerous patent infringement lawsuits. A potential key threat is the unauthorized use of code, ideas, or program components by competitors. If former employees or outsourcing partners steal their employers’ intellectual capital, organizations’ software product development may be compromised as a result. This unauthorized use of previous employers’ intellectual capital is a violation of non-disclosure agreements (NDA) by software developers, but IS research has offered limited explanation of this phenomenon. As a first step in addressing this gap, we present a model explaining NDA violations based on the social learning theory (SLT) of criminology. The new insight derived from SLT focuses on the motivations for violation, rather than on how organizations can deter such violations, which is the dominant theoretical lens in IS security to address information policy violations. We argue that, owing to the inconspicuous nature of NDA violations, deterrence (theory) alone is insufficient to explain such behavior. Our empirical findings show that deterrence mechanisms (e.g., formal sanctions and whistleblowing expectations) significantly but modestly reduce violation intentions, whereas social-learning mechanisms, especially significant others’ influence and perceived benefits, have stronger effects. These findings highlight the need to understand software developer culture and the social influences, which affect developers’ motivations to abide by the NDA.
Based on two field experiments, this paper examines the effect of financial incentives on information security policy compliance. The first experiment, conducted online with paid workers, used password strength as a key measure and found that monetary incentives significantly increased password strength at the beginning of the study, with this higher strength being maintained over a four-week period. The second experiment, a longitudinal study in a private firm, evaluated actual employee behaviors over time. It found that compliance with the use of non-work email increased over a 12-week period with incentives. Compliance with password and phishing policies was already high during the baseline period, so incentives had minimal additional effects. Interestingly, changes in behavior observed during the incentive period were sustained even after the incentives were removed through the use of nudges. Overall, the results suggest that though incentives have the potential to influence compliance with information security policies, their effectiveness is likely to vary based on the complexity of the target behaviors and existing habitual behaviors.
Protection motivation theory (PMT) has been used to explain the intention to take protective action in response to threats in a variety of fields, most extensively health behavior research. However, it has been used to a limited extent in the weather domain. The current study uses PMT as a framework to explain intention to respond protectively to five weather hazards. It also probes deeper into the perceived costs associated with a series of protective actions. An online survey measured perceived threat severity, threat susceptibility, efficacy, and costs associated with hypothetical high-and low-cost protective responses and intention to take the recommended action for lightning, flooding, heat, winter weather, and tornadoes. All PMT variables were significantly correlated with the intention to take protective action except for perceived vulnerability and the intent to take action in the high-cost scenarios. In factor analysis, response costs broke down into two factors that could be described as how hard an action is to accomplish or how inconvenient or disruptive it is. In a structural model to predict protection motivation, disruptive costs improved the model fit, along with perceived threat, response efficacy, and self-efficacy. In addition to supporting the significance of perceived efficacy in explaining protective behavior, this study also validates the importance of including response costs in a way that is distinct from self-efficacy.
In the existing discourse on behavioral information systems security, a diverse array of individual and organizational attributes has been investigated regarding the employees’ information security policy (ISP) behavior. However, ethical leadership, a pivotal paradigm profoundly associated with employees’ security behavior, has been starkly overlooked in this domain. The research unveils and examines the role of ethical leadership in influencing employees’ ISP-related behaviors. To test our hypotheses and validate the research model, we conducted a scenario-based online experiment pre-study followed by cross-sectional survey of working professionals. The findings reveal that ethical leadership significantly influences both ISP in-role and extra-role behavior, directly and indirectly, through three mediators: attitude toward security behavior (ATT), subjective norm about information security (SN), and perceived behavioral control over security behavior (BC). This research contributes to the growing streams of information security and ethical leadership literatures and offers actionable managerial suggestions on cultivating ethical leadership to enhance organizational information security performance.
Cybersecurity awareness refers to basic literacy in the digital age. This study discusses the influencing mechanism of an individual's life satisfaction on cybersecurity awareness, considering the mediating effects of internet dependence and burnout based on the broaden-and-build theory (BBT) of positive emotions as well as compensatory internet use (CIU) theory. We constructed a theoretical framework and tested hypotheses using regression analysis of a sample of 951 subjects based on a longitudinal survey. The empirical results showed that life satisfaction - as a stable cognitive indicator of subjective well-being - was associated with higher cybersecurity awareness, both directly and indirectly through pathways informed by the BBT and CIU theory. This study provides managers with actionable insights for promoting cybersecurity awareness by fostering psychological resources (e.g., life satisfaction) that buffer against security fatigue and burnout.
Purpose This study aims to investigate how cultural factors – specifically power distance (PD) and uncertainty avoidance (UA) – affect employees’ use of neutralization techniques to rationalize deviant information systems (IS) behaviors. The goal is to enhance strategies for managing insider threats and improving security policies. Design/methodology/approach A cross-sectional survey was used to examine how national culture affects neutralization strategies related to IS misuse. A scenario-based survey was used to gather data from 292 employees, stressing four top ranked IS deviant behaviors in Ethiopian organizations. Using SmartPLS 4.0 software, the study validates measurement and structural models using partial least squares structural equation modeling. It then uses bootstrapping procedures to assess hypotheses that predict the use of justifications in situations of IS misuse. Findings The research finds that all four neutralization techniques – appeal to higher loyalty, claim of normalcy, defense of necessity and denial of responsibility – significantly predicted employees’ IS deviant use intention behaviors. PD and UA cultures also significantly influence IS deviant use intention, with neutralization techniques mediating this relationship, validating the model’s predictive relevance. Research limitations/implications The reliance on self-reported data and a cross-sectional design may limit the accuracy and causal inference of the findings. Additionally, the focus on Ethiopian respondents may restrict generalizability, highlighting the need for research in diverse contexts. Future studies could explore longitudinal or experimental designs and examine neutralization techniques and knowledge management to understand IS security. Originality/value This study introduces a novel model illustrating how cultural values, such as PD and UA, influence employees’ use of neutralization techniques to justify deviant behavior in Ethiopian organizations. It emphasizes the mediating role of these techniques and the need for culturally tailored anti-neutralization strategies and effective security awareness programs.
This study investigates the factors contributing to consumer resistance toward used electric vehicles (EVs) through the lens of social amplification of risk theory. Despite the rapid growth in new EV sales, adoption of used EVs remains limited, largely due to consumer concerns around various perceived risks. Using an online survey to collect data from 409 potential used EV buyers in China, we examine how different risk dimensions, such as image risk, technological obsolescence risk, financial risk (low resale value), and performance risk, influence consumers' resistance to used EVs. Additionally, we explore EV knowledge and negative word-of-mouth as antecedents to perceived risk, aligning with social amplification of risk theory to understand how these factors intensify risk perceptions. We used structural equation modeling to analyze the data. The results supported 11 out of 12 hypotheses, confirming that higher EV knowledge and exposure to negative word-of-mouth amplify perceived risks, which in turn significantly increase resistance to used EV adoption. This study offers theoretical and practical implications for addressing consumer hesitance and fostering greater acceptance within the used EV market.
Purpose This study aims to investigate employees’ information systems (IS) security deviant behavior and attempts to forecast intentions to misuse IS, emphasizing pragmatic prevention of behavioral security issues. This study explicitly fills research gaps in the developing economy context such as Ethiopia, where security issues are prevalent and context-specific security strategies and policies are lacking. Design/methodology/approach This study used a hypothetical scenario survey involving 292 employees and used partial least squares structural equation modeling with the SmartPLS 4.0 tool for data analysis. The methodology sought to explore the relationship between various rationality-based theories and security countermeasures on employees IS misuse. The authors developed a comprehensive theoretical model to address security challenges. Findings The findings revealed that neutralization techniques, excluding condemnation of the condemners, significantly predicted IS misuse. In addition, rational choice based deterrence was found to mediate the relationship between countermeasure awareness and IS misuse. Interestingly, deterrence tends to predict intentional IS misuse to a certain extent, with greater security awareness enhancing its effectiveness, which underlines the crucial influence of awareness on curbing IS misuse. Research limitations/implications The results of the study are limited by the geographical focus and cross-sectional nature of the sample and may not be generalizable in all contexts. The study needs to be replicated to examine the model across different geographical and sociocultural contexts. The study’s findings inform implications to practice and theory. Originality/value This study explores IS security deviant behavior in a developing economy where context-specific countermeasures are limited. Integrating neutralization and rational choice deterrence theories, this study suggests a new comprehensive IS misuse prediction model. The study emphasizes the pivotal role of enhanced countermeasure awareness in averting IS violations, offering new theory and practice contributions.
Insider threats to organizations prompt them to implement security policies and procedures, but cultural dimensions shape employees' beliefs and behaviors. Employees may justify deviant security behaviors using various neutralization techniques, which can be culturally determined. We present a research model to examine the moderating role of cultural dimensions - power distance and collectivism - on the relationship between neutralization techniques and deviant security behaviors. Based on a scenario-based survey conducted in Ethiopia, our findings indicate that perceived benefits and neutralization techniques are positively associated with the intention to engage in deviant security behavior, while perceived sanction certainty has a negative effect. Our moderation analysis further reveals that power distance and collectivism moderate the relationship between neutralization techniques and the intention to engage in deviant security behaviors. Specifically, higher levels of espoused power distance diminish the impact of "denial of responsibility" and "defense of necessity", while amplifying the effect of "condemn the condemners" and perceived certainty of sanctions. Similarly, higher levels of espoused collectivism enhance the effect of the "defense of necessity", while reducing the impact of the "claim of normalcy" on the intention to engage in deviant behavior.
Facing constant cyberattacks, organizations should use IT security tools, train employees, and motivate them to comply with security policies. Accordingly, employees’ extra-role security behaviors can benefit organizations as an additional line of defense. Drawing on organizational climate theory, we examined the psychological mechanisms through which organizational security climate could shape extra-role security behaviors. These mechanisms, such as employees' increased organizational security concern and a broader definition of their perceived security-related responsibilities, were found to have a full mediating effect between organizational security climate and extra-role security behaviors. This research contributes to the information security literature by presenting an empirically validated model that provides nuanced insights into the role of organizational climate in shaping extra-role security behaviors.
Gamification has been widely adopted by businesses and educational institutions to drive desired user behaviors and performance. Despite its significance across industry, healthcare, and organizational contexts, its role in fostering psychological recovery experiences (PRE) remains underexplored. Grounded in gamification frameworks and literature on affordances and PRE, this study investigates the mediating role of PRE between gamification affordances and personal initiative. Additionally, we examine the moderating effect of perceived visual anonymity as a situational affordance in the relationship between gamification affordances and PRE. To test our hypotheses, we collected data from 682 graduate students enrolled in an enterprise resource planning (ERP) course (Study 1: 258; Study 2: 424). Our findings reveal that mastery and control experiences mediate the relationship between collaboration and feedback affordances and personal initiative. Furthermore, perceived visual anonymity negatively moderates the relationship between collaboration affordance and mastery and control experiences, while positively moderating the relationship between feedback affordance and control experience. This study highlights the importance of psychological recovery experiences and perceived visual anonymity in fostering personal initiative within gamified online learning environments.