The Signalgate incident of March 2025, wherein senior US national security officials inadvertently disclosed sensitive military operational details via the encrypted messaging platform Signal, highlights critical vulnerabilities in organizational security arising from human error, governance gaps, and the misuse of technology. Although smaller in scale when compared to historical breaches involving billions of records, Signalgate illustrates critical systemic issues often overshadowed by a focus on external cyber threats. Employing a case-study approach and systematic review grounded in the NIST Cybersecurity Framework, we analyze the incident to identify patterns of human-centric vulnerabilities and governance challenges common to organizational security failures. Findings emphasize three critical points. (1) Organizational security depends heavily on human behavior, with internal actors often serving as the weakest link despite advanced technical defenses; (2) Leadership tone strongly influences organizational security culture and efficacy, and (3) widespread reliance on technical solutions without sufficient investments in human and organizational factors leads to ineffective practices and wasted resources. From these observations, we propose actionable recommendations for enhancing organizational and national security, including strong leadership engagement, comprehensive adoption of zero-trust architectures, clearer accountability structures, incentivized security behaviors, and rigorous oversight. Particularly during periods of organizational transition, such as mergers or large-scale personnel changes, additional measures become particularly important. Signalgate underscores the need for leaders and policymakers to reorient cybersecurity strategies toward addressing governance, cultural, and behavioral risks.
Despite technological advances aimed at preventing them, cybersecurity breaches have grown more numerous and costly over time. Current training programs and policies, for their part, have been largely ineffective in reducing cyberthreats, as human actions continue to be the weakest link. This article urges organizations to make greater efforts to warn employees about cybersecurity dangers and help employees improve their confidence in their ability to defend against such dangers.(1,2)
A key approach in many organizations to address the myriad of information security threats is encouraging employees to better understand and comply with information security policies (ISPs). Despite a significant body of academic research in this area, a commonly held but questionable assumption in these studies is that noncompliance simply represents the opposite of compliance. Hence, explaining compliance is only half of the story, and there is a pressing need to understand the causes of noncompliance, as well. If organizational leaders understood what leads a normally compliant employee to become noncompliant, future security breaches might be avoided or minimized. In this study, we found that compliant and noncompliant behaviors can be better explained by uncovering actions that focus not only on efficacious coping behaviors, but also those that focus on frustrated users who must sometimes cope with emotions, too. Employees working from a basis of emotion-focused coping are unable to address the threat and, feeling overwhelmed, focus only on controlling their emotions, merely making themselves feel better. Based on our findings, organizations can enhance their security by understanding the “tipping point” where employees’ focus likely changes from problem-solving to emotion appeasement, and instead push them into a more constructive direction.Yan Chen is an associate professor at Florida International University. She received her PhD in management information systems from University of Wisconsin–Milwaukee. Her research focuses on information security management, online fraud, privacy, and social media. She has published more than 30 research papers in refereed academic journals and conference proceedings.Dennis F. Galletta is a LEO awardee, fellow, and former president of the Association for Information Systems and professor at University of Pittsburgh since 1985. He has published 108 articles and four books. He is a senior editor at MIS Quarterly and an editorial board member at the Journal of Management Information Systems, and has been on several other boards.Paul Benjamin Lowry is the Suzanne Parker Thornhill Chair Professor in Business Information Technology at the Pamplin College of Business at Virginia Tech. He has published more than 135 journal articles. His research areas include organizational and behavioral security and privacy; online deviance and harassment, and computer ethics; human–computer interaction, social media, and gamification; and decision sciences, innovation, and supply chains.Xin (Robert) Luo is Endowed Regent’s Professor and full professor of MIS at the University of New Mexico. His research has appeared in leading information systems journals, and he serves as an associate editor for the Journal of the Association for Information Systems, Decision Sciences Journal, Information & Management, Electronic Commerce Research, and the Journal of Electronic Commerce Research.Gregory D. Moody is currently Lee Professor of Information Systems at the University of Nevada Las Vegas, and director of the cybersecurity graduate program. His interests include information systems security and privacy, e-business, and human–computer interaction. He is currently a senior editor for the Information Systems Journal and Transactions on Human-Computer Interaction.Robert Willison is a professor of management at Xi’an Jiaotong–Liverpool University. He received his PhD in information systems from the London School of Economics. His research focuses on insider computer abuse, information security policy compliance/noncompliance, software piracy, and cyber-loafing. His research has appeared in refereed academic journals such as MIS Quarterly, Journal of the Association for Information Systems, Information Systems Journal, and others.
Criminal organizational insider computer abuse (ICA) research has focused on factors that influence either ICA intentions, or actual behavior during the ICA process. However, we argue that this research has not correctly conceptualized the decision-making processes involved in ICA. Thus, our first aim is to demonstrate this opportunity by leveraging the rational choice perspective (RCP) from criminology. The RCP advances an "event" stage, in which choices are made leading up to and during the criminal act. However, the RCP also acknowledges a preceding "initial involvement" stage, which encompasses those factors that lead an individual to consider participation in crime. RCP explains that if, during the initial involvement stage, an individual becomes motivated and decides that future criminal behavior is the most suitable course of action, then he or she will have reached a state of "readiness." It is only after an individual has become readied, and at a later time, does the individual make event decisions in the perpetration of a specific crime. Consequently, extant ICA research has overlooked consideration of why-prior to the crime-an individual initially considers engaging in such criminal activity in the first instance. Notably, this consideration should not to be conflated with intentions. We argue that there needs to be a clear distinction between those motivational factors that would lead to the consideration of such engagement at the initial involvement stage, and those factors that would lead an individual at the event stage to perpetrate a crime. We thus propose a revised version of the extended security action cycle (ESAC), which reflects these criminal decision-making stages. Moreover, we provide a means through which to identify and understand the relationship among those factors that may motivate an individual during the initial involvement stage by drawing on the life course perspective (LCP). With a focus on time, context, and process, the LCP offers a framework in which four key principles are inscribed. Through examples drawn from the LCP and white-collar crime literature, we illustrate how these principles can provide a basis for conceptualizing factors that motivate ICA and open up new avenues for future research/theory development.
This research-perspective article reviews and contributes to the literature that explains how to deter internal computer abuse (ICA), which is criminal computer behavior committed by organizational insiders. ICA accounts for a large portion of insider trading, fraud, embezzlement, the selling of trade secrets, customer privacy violations, and other criminal behaviors, all of which are highly damaging to organizations. Although ICA represents a momentous threat for organizations, and despite numerous calls to examine this behavior, the academic response has thus far been lukewarm. However, a few security researchers have examined ICA's influence in an organizational context and addressed potential means of deterring it. However, the results of these studies have been mixed, leading to a debate on the applicability of deterrence theory (DT) to ICA. We argue that more compelling opportunities will arise in DT research if security researchers more deeply study its assumptions and more carefully recontextualize it. The purpose of this article is to advance a deterrence research agenda that is grounded in the pivotal criminological deterrence literature. Drawing on the distinction between absolute and restrictive deterrence and aligning them with rational choice theory (RCT), this paper shows how deterrence can be used to mitigate the participation in and frequency of ICA. We thus propose that future research on the deterrent effects of ICA should be anchored in a more general RCT, rather than in examinations of deterrence as an isolated construct. We then explain how adopting RCT with DT opens up new avenues of research. Consequently, we propose three areas for future research, which cover not only the implications for the study of ICA deterrence, but also the potential motivations for these types of offenses and the skills required to undertake them.
In this essay, we outline some important concerns in the hope of improving the effectiveness of security and privacy research. We discuss the need to re-examine our understanding of information technology and information system (IS) artefacts and to expand the range of the latter to include those artificial phenomena that are crucial to information security and privacy research. We then briefly discuss some prevalent limitations in theory, methodology, and contributions that generally weaken security/privacy studies and jeopardise their chances of publication in a top IS journal. More importantly, we suggest remedies for these weaknesses, identifying specific improvements that can be made and offering a couple of illustrations of such improvements. In particular, we address the notion of loose re-contextualisation, using deterrence theory research as an example. We also provide an illustration of how the focus on intentions may have resulted in an underuse of powerful theories in security and privacy research, because such theories explain more than just intentions. We then outline three promising opportunities for IS research that should be particularly compelling to security and privacy researchers: online platforms, the Internet of things, and big data. All of these carry innate information security and privacy risks and vulnerabilities that can be addressed only by researching each link of the systems chain, that is, technologies–policies–processes–people–society–economy–legislature. We conclude by suggesting several specific opportunities for new research in these areas.
Although employee computer abuse is a costly and significant problem for firms, the existing academic literature regarding this issue is limited. To address this gap, we apply a multi‐theoretical model to explain employees' intentions to abuse computers. To understand the motives for such behaviour, we investigate the role of two forms of organizational justice – distributive and procedural – both of which provide explanations of how perceptions of unfairness are created in the organizational context. By applying deterrence theory, we also examine the extent to which formal sanctions influence and moderate the intentions to abuse computers. Finally, we examine how the potential motives for abuse may be moderated by techniques of neutralization, which allow offenders to justify their actions and absolve themselves of any associated feelings of guilt and shame. Utilizing the scenario‐based factorial survey method for our experimental design, we empirically evaluated the association between these antecedents and the behavioural intention to violate Information systems (IS) security policies in an environment where the measurement of actual behaviour would be impossible. Our findings suggest that individual employees may form intentions to commit computer abuse if they perceive the presence of procedural injustice and that techniques of neutralization and certainty of sanctions moderate this influence. The implications of these findings for research and practice are presented. © 2016 John Wiley & Sons Ltd
Knowledge has been identified as one of the most critical resources for achieving innovation and competitive advantage. Knowledge management systems (KMS) are, therefore, being adopted by companies to enhance knowledge management (KM) processes and innovation. Because most of new products projects are not "clean-sheet" efforts, rather incremental redesigns of existing products, R&D people often retrieve and reuse existing knowledge to solve recurring problems in the prototyping of new products. Thus, knowledge sourcing and reuse are particularly important in this product development process. In the present research we investigated the antecedents of knowledge sourcing and knowledge reuse from an electronic repository. Predictions were tested in the context of the virtual vehicle prototyping process with data from 121 respondents of a large European Automotive supplier of R&D. Results provide support that knowledge accuracy, knowledge format, and knowledge completeness are strong predictors of knowledge reuse. While system integration, flexibility, and response time are considered strong determinants of knowledge sourcing in KMS. The study develops and tests a new model for measuring KMS success in the context of virtual product prototyping. Copyright © 2016 John Wiley & Sons, Ltd.
Organizations and security practitioners expend considerable effort monitoring and preventing the potential external exploits of hackers and malware. However, they must also acknowledge the equally real threat posed by criminal internal computer abuse (ICA) by organizational insiders (e.g., data theft, insider trading, data poaching, access breaches, piracy of intellectual property, sabotage). Numerous industry reports cite ICA as one of the biggest threats that organizations face (Ernst and Young 2014; PwC 2015), and while IS security researchers are increasingly studying this form of behavior, they are faced with several research stumbling blocks. Gaining access to organizations is problematic for most management researchers; however, this is particularly challenging for organizational security researchers. Organizations are extremely sensitive about their security data, especially terms of how any weaknesses this area may produce adverse publicity, reputational damage, or further exploits. Consequently, IS Security researchers are often viewed as threats their own right and rarely afforded such organizational access. Moreover, it is not a feasible option for IS security researchers to interview individuals who have been prosecuted and incarcerated for their ICA, because most are never caught or punished. Given concerns over reputational and market damage, when security breaches occur, organizations will often deal with the matter in house to the exclusion of law enforcement agencies and subsequent prosecutions. Admittedly, some individuals are prosecuted for ICA and do receive custodial sentences, but gaining legal permission to talk to such individuals and to receive ethical approval for such a study is a huge hurdle. Few legal teams allow such access.Given these data-collection barriers, it is not surprising to learn that the study of ICA has mostly been overlooked by security researchers favor of subject areas with fewer hurdles and challenges. Indeed, the vast majority of IS sec studies examine intentions to comply with organizational information security policies. Although, insights into intentions can be helpful, what organizational security research needs for greater breakthroughs is insights into actual “black hat” security behaviors that are criminal and devastating to organizations - particularly ICA (Mahmood et al. 2010). Despite calls for further research into ICA (Crossler et al. 2013; Lowry et al. 2015; Posey et al. 2013; Willison and Warkentin 2013), the obstacles associated with this task present something of an impasse when attempting to study this form of behavior. Therefore, conjunction with these calls, which have suggested what to study, there is an equal need to ask how ICA can be studied. We assert that addressing this conundrum requires a degree of innovation and a willingness to consider new qualitative approaches the face of a seemingly intractable data-collection barrier. Consequently, we propose a possible solution to this issue by considering how secondary data can be innovatively used for qualitative ICA research. Specifically, our paper reviews the commercially and publically available sources of security breaches that can potentially be used for such an effort, and demonstrate some of the valuable information these sources that have yet to be leveraged. This is followed by a consideration of how such data could be applied. For instance, a couple of preliminary ICA case studies have been developed through secondary sources - including court records, official reports and newspaper articles (Willison 2002; Baskerville et al. 2014). But this technique is rarely performed, and is an exciting approach that we can further explain and support, including with details on how to improve on what has been done. Support for this approach comes mostly from the ethnographic tradition (Geertz 1973; Hammersley and Atkinson 1995), which archival material has proved an invaluable source of data. Indeed, some instances, specific accounts of people particular localities have been based solely on secondary documents (Denning 1980; Silverman and Gulliver 1992; Vincent 1984; Woods 1994). Another more traditional qualitative use of secondary data that we also address involves qualitatively coding empirical data (e.g., breach incidents) and then analyzing these codings with various empirical methods. But again, this is rarely done with organizational security data. Notably, we have discovered several public sources of breach data that can be used for qualitative analysis, and are virtually overlooked by the IS security community. After discussing the different approaches which secondary data can be applied, qualitative approaches to coding, and the benefits they offer over existing empirical approaches, we provide some concluding thoughts on future research opportunities secondary qualitative use of organizational-level security data. Rather than regard these qualitative approaches to secondary organizational security data as the poor cousins to traditional highly positivistic empirical approaches (e.g., surveys and experiments), we view the application and use of secondary sources as their equal, if not a potentially superior source. Again, unlike other IS areas of study, such as systems development, which the associated behavior and practices can be studied the organizational context, the nature of ICA makes it virtually impossible to examine this behavior situ. Therefore, arguably the best way our understanding of such behavior can improve is through insights garnered through these secondary sources. Given the aforementioned difficulties associated with empirical ICA research, we believe the use of these sources is a promising step forward understanding this form of criminal behavior.
Recent academic investigations of computer security policy violations have largely focused on nonmalicious noncompliance due to poor training, low employee motivation, weak affective commitment, or individual oversight. Established theoretical foundations applied to this domain have related to protection motivation, deterrence, planned behavior, self-efficacy, individual adoption factors, organizational commitment, and other individual cognitive factors. But another class of violation demands greater research emphasis: the intentional commission of computer security policy violation, or insider computer abuse. Whether motivated by greed, disgruntlement, or other psychological processes, this act has the greatest potential for loss and damage to the employer. We argue the focus must include not only the act and its immediate antecedents of intention (to commit computer abuse) and deterrence (of the crime), but also phenomena which temporally precede these areas. Specifically, we assert the need to consider the thought processes of the potential offender and how these are influenced by the organizational context, prior to deterrence. We believe the interplay between thought processes and this context may significantly impact the efficacy of IS security controls, specifically deterrence safeguards. Through this focus, we extend the Straub and Welke (1998) security action cycle framework and propose three areas worthy of empirical investigation--techniques of neutralization (rationalization), expressive/instrumental criminal motivations, and disgruntlement as a result of perceptions of organizational injustice--and propose questions for future research in these areas.
Software piracy is a major economic concern for organizations. Previous research indicates that neutralization, a form of rationalization, can help explain software piracy intentions. However, a knowledge gap exists in our understanding of which neutralization techniques most influence software piracy intention. To address this gap, we developed a model that explains the effects of neutralization techniques on software piracy intention. We included different types of deterrents (formal sanctions, shame, and moral belief) in our model because individuals may use neutralization techniques to mitigate feelings of guilt and shame, which, subsequently, reduce the deterrent effect. Our empirical results (for 183 people surveyed) showed that appeal to higher loyalties and condemn the condemners strongly predict software piracy intentions. In addition, informal deterrents such as shame and moral beliefs are strong predictors. These findings suggest that anti-piracy efforts should involve educational intervention aimed at addressing these two neutralization techniques rather than relying on formal sanctions.
Insider computer abuse, the problem of intentional computer-related crimes by employees, is a costly problem for firms (Warkentin and Willison, 2009). To counter this threat, IT practitioners and IS researchers assess potential antecedents of and motivations for computer abuse intentions among employees. The theory of organizational justice, the techniques of neutralization, and the role of deterrence are offered as lenses for evaluating the formation of employee disgruntlement leading to computer abuse behaviors. We have evaluated the impacts of these perceived organizational injustice and neutralization on the formation of employee intention to commit computer abuse activities in violation of security policies and procedures, with additional influences of deterrence. Utilizing the factorial survey method, we have empirically evaluated the association between these antecedents.
Software piracy continues to be a major economic concern for organizations. Given the widespread nature of the problem, software piracy has received attention from IS scholars. Previous research indicates that neutralization - a form of rationalization - can help to explain software piracy intentions. However, a knowledge gap exists in our understanding about which techniques of neutralization contributes most to software piracy intentions. To address this gap, we advance a model that explains the effects of neutralization techniques on software piracy intentions. For greater explanatory power, we also include formal sanctions, shame, and moral beliefs in our model. Empirical results (n=183) show that neutralization techniques "appeal to higher loyalties" and "condemnation of the condemners" strongly predict software piracy intentions. In addition, shame and moral beliefs are also strong predictors. These findings suggest that anti-piracy efforts should involve educational interventions aimed at addressing these two neutralization techniques, rather than relying on formal sanctions.
Modern global economic and political conditions, technological infrastructure, and socio-cultural developments all contribute to an increasingly turbulent and dynamic environment for organizations, which maintain information systems (IS) for use in business, government, and other domains. As our institutions (economic, political, military, legal, social) become increasingly global and inter-connected; as we rely more on automated control systems to provide us with energy and services; and as we establish internet-based mechanisms for coordinating this global interaction, we introduce greater vulnerability to our systems and processes. This increased dependence on cyberspace also inflates our vulnerability – isolation is no longer an option. Perhaps no aspect of this phenomenon is as alarming and challenging as the need to understand and address the various risks to the security of the IS on which we depend.
Information security has become increasingly important for organizations, given their dependence on ICT. Not surprisingly, therefore, the external threats posed by hackers and viruses have received extensive coverage in the mass media. Yet numerous security surveys also point to the 'insider' threat of employee computer crime. In 2006, for example, the Global Security Survey by Deloitte reports that 28% of respondent organizations encountered considerable internal computer fraud. This figure may not appear high, but the impact of crime perpetrated by insiders can be profound. Donn Parker argues that 'cyber-criminals' should be considered in terms of their criminal attributes, which include skills, knowledge, resources, access and motives (SKRAM). It is as a consequence of such attributes, acquired within the organization, that employers can pose a major threat. Hence, employees use skills gained through their legitimate work duties for illegitimate gain. A knowledge of security vulnerabilities can be exploited, utilising resources and access are provided by companies. It may even be the case that the motive is created by the organization in the form of employee disgruntlement. These criminal attributes aid offenders in the pursuit of their criminal acts, which in the extreme can bring down an organization. In the main, companies have addressed the insider threat through a workforce, which is made aware of its information security responsibilities and acts accordingly. Thus, security policies and complementary education and awareness programmes are now commonplace for organizations. That said, little progress has been made in understanding the insider threat from an offender's perspective. As organizations attempt to grapple with the behavior of dishonest employees, criminology potentially offers a body of knowledge for addressing this problem. It is suggested that Situational Crime Prevention (SCP), a relative newcomer to criminology, can help enhance initiatives aimed at addressing the insider threat. In this article, we discuss how recent criminological developments that focus on the criminal act, represent a departure from traditional criminology, which examines the causes of criminality. As part of these recent developments we discuss SCP. After defining this approach, we illustrate how it can inform and enhance information security practices. In recent years, a number of criminologists have criticised their discipline for assuming that the task of explaining the causes of criminality is the same as explaining the criminal act. Simply to explain how people develop a criminal disposition is only half the equation. What is also required is an explanation of how crimes are perpetrated. Criminological approaches, which focus on the criminal act, would appear to offer more to information security practitioners than their dispositional counterparts. Accordingly, the SCP approach can offer additional tools for practitioners in their fight against insider computer crime.
Within the IS security field, employee computer crime has received increased attention. Indeed, a number of researchers have focused their attention on the behaviour of the 'insider', both prior to and during the perpetration. Despite this, there is currently an absence of academic IS insight into the problem of workplace disgruntlement and how this may motivate employee computer crime. To address this deficiency, this paper draws on a body of knowledge called 'organisational justice', which examines how perceptions of fairness are formed. Under this umbrella term are four constructs which relate to different organisational phenomena and influence employees' fairness perceptions. It is believed that these constructs, entitled distributive, procedural, interactional and informational justice, and the theories which underpin them, can not only assist in understanding, but also in mitigating disgruntlement. To illustrate this, a case of employee computer sabotage is analysed, highlighting which forms of organisational justice occurred, and how they could have been addressed. The discussion section notes how mitigating disgruntlement provides a new area for safeguard implementation, with the final part of the paper discussing the conclusions and potential for future research.
International information security management guidelines play a key role in managing and certifying organizational IS. We analyzed BS7799, BS ISO/IEC17799: 2000, GASPP/GAISP, and the SSE-CMM to determine and compare how these guidelines are validated, and how widely they can be applied. First, we found that BS7799, BS ISO/IEC17799: 2000, GASPP/GAISP and the SSE-CMM were generic or universal in scope; consequently they do not pay enough attention to the differences between organizations and the fact that their security requirements are different. Second, we noted that these guidelines were validated by appeal to common practice and authority and that this was not a sound basis for important international information security guidelines. To address these shortcomings, we believe that information security management guidelines should be seen as a library of material on information security management for practitioners.
It is well known that software piracy is widespread. While the existing research on this subject has applied a number of theories in order to understand and prevent such an act, this text presents an alternative perspective by advancing two criminological theories. More specifically, a novel theoretical model is advanced, drawing on these theories entitled Techniques of Neutralization and Differential Association Theory. The former helps to explain how individuals are able to rationalize their criminal behaviour in a manner which absolves them of pressures from social norms and internal controls such as feelings of guilt and shame. The latter explains how criminality is developed through a learning process taking place in personal groups. While empirical research is needed to test the model further, it is argued that these theories offer both an alternative perspective on the intention to commit software piracy, but also potentially open up new avenues for preventing this crime.