When cybersecurity units conduct vulnerability assessments to evaluate the security of organizations, they can have unintended consequences for employees. Although cybersecurity personnel may view tactics such as fake phishing attacks and email scanning as protective measures, employees may view them as threats because being singled out as a security risk can harm their standing in the organization. To understand the implications of vulnerability assessments, we examine how organizations’ use of different tactics to identify user vulnerabilities can lead employees to feel betrayed by the cybersecurity unit, resulting in negative cybersecurity outcomes. Drawing on the theory of betrayal aversion, we develop a model that shows that when employees perceive these tactics as harmful, they can lead to an affective state of cybersecurity betrayal, resulting in a damaged relationship with the cybersecurity unit. In collaboration with an organization’s cybersecurity unit, we evaluated our model using an experimental vignette survey, post hoc interviews, and a crosssectional survey with two samples (i.e., employees in the organization and employees from a panel). We found that when organizations conduct vulnerability assessments to enhance cybersecurity, they often induce an affective state of betrayal and increase employees’ active resistance to cybersecurity (i.e., abandonment, avoidance, and sabotage of cybersecurity policies, technologies, and units). The paper concludes with implications for research and practice that explain the unintended consequences of vulnerability assessment and betrayal.
Cybersecurity groups navigate complex, challenging environments in their mission to protect their organizations. They experience uncertainty from adaptive threats from external attackers and unpredictable stakeholders. Under such volatility, business groups operate best when they are psychologically empowered. Recognizing the potential for empowerment to reduce organizational risk, we sought to learn how cybersecurity groups come to be (dis)empowered and how this (dis)empowerment is sustained. Instead of the conventional view of the empowerment process as designed, we advance an emergent view of the empowerment process. We abductively surface this process from our case analyses of 15 U.S. organizations. We offer three insights: First, organizations with empowered cybersecurity groups enjoy an enhanced level of protection from breaches. Second, we highlight generative rules through which groups become empowered—via their bridging initiatives that co-opt stakeholders into security behaviors and stakeholder responsiveness to bridging, rather than unilaterally applied buffering initiatives. Third, we highlight reinforcing rules through which empowered states persist—via the group’s ability to safeguard organizational information assets, thereby ensuring cybersecurity group viability, continued bridging, and motivated stakeholder responsiveness. For practitioners, our study underscores the interdependence between cybersecurity groups and their stakeholders in securing an organization and posits processes for empowering cybersecurity groups.
This article provides an overview of the findings from the Information Systems (IS) Well-Being Project that was started in the fall of 2020. There were two goals of this project: 1) to understand the physical, mental, social, and financial well-being of IS academics during the COVID-19 pandemic, and 2) to theorize the downstream effects of the pandemic on the health of the IS research ecosystem. This investigation surfaced a troubling phenomenon that we coined “the IS scholarly divide”. This editorial develops the theoretical underpinnings for the scholarly divide and posits the taxonomy of the divide. Finally, we explore the effects and forward some possible remedies.
Despite widespread awareness of risks, significant investments in cybersecurity protection, and substantial economic incentives to avoid security breaches, organizations remain vulnerable to phishing attacks. Phishing research has informed effective practical interventions to address phishing susceptibility that emphasize the importance of broadly applicable IT security knowledge. Yet employees still frequently fall victim to phishing attempts. To help understand why, we conceptualize phishing susceptibility as the failure to differentiate between deceptive and legitimate information processing requests that occur within the context of an employee’s typical job responsibilities. We apply this contextual lens to identify characteristics of knowledge workers’ organizational task and social context that may enhance or diminish performance in detecting deception in phishing email attempts. To test our hypotheses, we conducted a study in which employees of the finance division of a large university encountered simulated email-based phishing attempts as part of their normal work routine. We found evidence supporting our hypotheses that an individual’s susceptibility to phishing attacks is influenced by their position in the knowledge flows of the organization and by the impact of workgroup responsibilities on their cognitive processing. We contend that phishing susceptibility is not merely a matter of IT security knowledge but is also influenced by contextualized, multilevel influences on information processing. As phishing attacks are increasingly targeted to specific organizational settings, it is even more important to incorporate this contextualized information processing view of phishing susceptibility.
This cross-sectional study used secondary data of urban youth to explore parental approaches as predictors of positive youth development among a group of 182 African American youth. This study aimed to examine how parental approaches (maternal and paternal encouragement and monitoring) predict prosocial behaviors (aspirations, self-efficacy, emotional restraint, and social responsibility) among a sample of African American youth residing in public housing. The regression analysis revealed three significant models. Overall, the results suggest that maternal monitoring and encouragement are essential for positive outcomes for African American youth in the context of urban public housing.
Transformative artificially intelligent tools, such as ChatGPT, designed to generate sophisticated text indistinguishable from that produced by a human, are applicable across a wide range of contexts. The technology presents opportunities as well as, often ethical and legal, challenges, and has the potential for both positive and negative impacts for organisations, society, and individuals. Offering multi-disciplinary insight into some of these, this article brings together 43 contributions from experts in fields such as computer science, marketing, information systems, education, policy, hospitality and tourism, management, publishing, and nursing. The contributors acknowledge ChatGPT's capabilities to enhance productivity and suggest that it is likely to offer significant gains in the banking, hospitality and tourism, and information technology industries, and enhance business activities, such as management and marketing. Nevertheless, they also consider its limitations, disruptions to practices, threats to privacy and security, and consequences of biases, misuse, and misinformation. However, opinion is split on whether ChatGPT's use should be restricted or legislated. Drawing on these contributions, the article identifies questions requiring further research across three thematic areas: knowledge, transparency, and ethics; digital transformation of organisations and societies; and teaching, learning, and scholarly research. The avenues for further research include: identifying skills, resources, and capabilities needed to handle generative AI; examining biases of generative AI attributable to training datasets and processes; exploring business and societal contexts best suited for generative AI implementation; determining optimal combinations of human and generative AI for various tasks; identifying ways to assess accuracy of text produced by generative AI; and uncovering the ethical and legal issues in using generative AI across different contexts.
Phishing is an increasing threat that causes billions in losses and damage to productivity, trade secrets, and reputations each year. This work explores how security gamification techniques can improve phishing reporting. We contextualized the cognitive evaluation theory (CET) as a kernel theory and constructed a prototype phishing reporting system. With three experiments in a simulated work setting, we tested gamification elements of validation, attribution, incentives, and public presentation for improvements in experiential (e.g., motivation) and instrumental outcomes (e.g., hits and false positives) in phishing reporting. Our findings suggest public attribution with rewards and punishments best balance the competing necessities of accuracy with widespread reporting. Furthermore, our results demonstrate the unique benefits of security gamification to phishing reporting over and above other phishing mitigation techniques (e.g., training and warnings). However, we also noted that unintended consequences in false alarms might arise from shifts in motivation resulting from public display of incentives. These findings suggest that carefully calibrated external incentives (rather than intrinsic rewards) are most likely to improve the ancillary task of phishing reporting.
Organisations face growing IT security risks with substantial consequences for missteps in business continuity, data loss, reputational harm, and future competitive advantage. To improve precaution-taking among organisation members, leaders frequently turn to susceptibility claims embedded in security education, training, and awareness (SETA) initiatives to motivate change. However, prior studies have produced mixed empirical results concerning the role of susceptibility in motivating precaution-taking. To deepen theorising about using susceptibility claims to change behaviour, we argue that threat characteristics (overt versus furtive attacks) shape individuals’ attitudes of the threat, and these attitudes subsequently anchor how individuals respond to new claims about the threats. We introduce social judgement theory (SJT) to argue that when individuals participate in SETA initiatives, susceptibility claims that are too distant from individuals’ existing attitudes will be ignored, while claims that are more proximal are more likely to be accepted and result in behaviour change. Using a longitudinal field experiment, we found that susceptibility claims motivated precaution taking against phishing (overt attack) but did not against password cracking (furtive attack). These results support SJT predictions and imply latitudes of acceptability and rejection into which susceptibility claims are placed. Implications for researchers, organisation leaders, and SETA developers are discussed.
Initial research on using crowdsourcing as a collaborative method for helping individuals identify phishing messages has shown promising results. However, the vast majority of crowdsourcing research has focussed on crowdsourced system components broadly and understanding individuals' motivation in contributing to crowdsourced systems. Little research has examined the features of crowdsourced systems that influence whether individuals utilise this information, particularly in the context of warnings for phishing emails. Thus, the present study examined four features related to warnings derived from a mock crowdsourced anti‐phishing warning system that 438 participants were provided to aid in their evaluation of a series of email messages: the number of times an email message was reported as being potentially suspicious, the source of the reports, the accuracy rate of the warnings (based on reports) and the disclosure of the accuracy rate. The results showed that crowdsourcing features work together to encourage warning acceptance and reduce anxiety. Accuracy rate demonstrated the most prominent effects on outcomes related to judgement accuracy, adherence to warning recommendations and anxiety with system use. The results are discussed regarding implications for organisations considering the design and implementation of crowdsourced phishing warning systems that facilitate accurate recommendations.
Many technologies today comprise distinct IT components, all operating together in the form of a complex technology configuration (CTC). Given how common it is for users to encounter CTCs today, there is a need for IS research to move beyond treating such IT as monoliths. Researchers must closely evaluate and understand how, why and when attitudes towards one component of a CTC may influence attitudes towards the other components, and how such attitudes influence trusting behavior towards the CTC overall. This paper examines how trust transfers between components of a CTC. Theoretical support is drawn from Trust Transfer Theory, which is extended with Social Exchange Theory (SET). To test hypotheses, a laboratory experiment is conducted featuring a highly realistic CTC. Participants play a game (focal IT) hosted on Facebook (platform IT) in which advertising is embedded (embedded IT), and the unique attitudes towards the separate components in the CTC are explored. We find that participants perceived each component in the CTC separately and the behavior of each component leads to distinct levels of perceived costs and rewards from each component. There is evidence of a transfer of trust from prior known components to the little-known component. Interestingly, trust towards the newest component in the CTC has the greatest influence on trusting behavior which affects the entire CTC. This work offers several theoretical and practical contributions to the study of CTCs and lays the foundation for future work that looks critically into the Blackbox of complex technologies.
As the highest level of cloud computing delivery model, Software-as-a-Service (SaaS) has gained considerable popularity in the industry as a new way of deploying IT solutions, due to its low cost and high elasticity. However, the new business model associated with SaaS highlights the importance for SaaS vendors to understand how to retain customers in a hyper-competitive market. In particular, increasing customer retention and preventing customers from replacing the adopted SaaS applications has become a crucial task for all SaaS vendors. In this study, using a mixed-methods approach, and drawing on the cognitive–affective–conative– action (CACA) framework, we investigate the IS replacement phenomenon in the context of SaaS-delivered applications. Our qualitative study allows us to develop an IS-centric view of customer commitment by differentiating between organizations’ commitment to the SaaS application and to the cloud computing technology in general, while the subsequent quantitative study validates the difference between the two types of commitment and helps understand how they together influence organizations’ intentions to replace a SaaS application. Our results generate important theoretical implications for research on IS replacement and clarifies the concept of customer commitment. We also offer practical guidelines to SaaS vendors on how to retain customers so as to survive/thrive in this competitive market.
Phishing is an increasing organizational threat that causes billions in losses and damage to productivity, trade secrets, and reputation each year. This work explores how organizations can use gamification techniques to improve phishing detection efforts by individuals to create a human firewall. We build on cognitive evaluation theory to begin a new area of inquiry in gamification of IT security. With three experiments in a mock work setting, we test leaderboard components of validation, attribution, incentives, and public presentation for improvements in experiential (e.g., motivation) and instrumental outcomes (e.g., hits and false positives) in phishing reporting. Our findings suggest public attribution with rewards and punishments best balance the competing necessities of accuracy with widespread reporting. Further, our results demonstrate leaderboards’ unique benefits to phishing reporting over and above other phishing mitigation techniques (training and warnings). However, we noted that unintended consequences in false alarms may arise from shifts in motivation resulting from public display of incentives.
WillowTree began as a small digital products company in 2007. By 2020, it had more than 500 full-time team members operating out of offices in four locations, and it had launched hundreds of digital products, including mobile apps, websites, voice assistants, and TV experiences. But also in 2020, WillowTree was facing the most significant challenge in its 12 years of corporate existence—a global pandemic.By analyzing how WillowTree blends project and product management, students will gain insights into how a digital products services company integrates a product mindset within contract-based projects, and get the opportunity to brainstorm how WillowTree can further adapt to provide a unique value proposition during the pandemic and beyond. Excerpt UVA-S-0338 Oct. 2, 2020 WillowTree: Project Driven with a Product Mindset Introduction WillowTree began as a small digital products start-up company based in Charlottesville, Virginia, in 2007. By 2020, WillowTree's more than 500 full-time team members had launched hundreds of digital products, including mobile apps, websites, voice assistants, and TV experiences. As WillowTree's website stated: We are driven by a simple goal: amaze our clients by delivering high quality digital products that solve their business needs, and ensuring our projects run smoothly, strategically and predictably. We not only create great products, we help our clients answer the strategic questions around what to build, and in what order. . . .
Download This Paper Open PDF in Browser Add Paper to My Library Share: Permalink Using these links will ensure access to this page indefinitely Copy URL Copy DOI
How information systems impact task performance has attracted a significant amount of attention from information systems researchers and generated high interest among practitioners. A commonly accepted view is that the potential of information systems must be realized through system use. Nevertheless, existing findings regarding the impact of system use on task performance are not yet conclusive. We attributed this to the various conceptualizations of system use and the unclear mechanisms through which system use influences task performance. Thus, this research attempts to create a better understanding of how system use influences task performance. To this end, we developed an exploitative-explorative system use framework in order to reconcile the various conceptualizations of system use and to depict how both exploitative and explorative system use influences task performance through impacting task innovation, management control, and task productivity. We created an instantiation of the framework using USAGE (exploitative system use) and adaptive system use (ASU, explorative system use). We conducted two empirical studies involving two different populations and using two different technologies. The first study consisted of 212 experienced users of MS Office, whereas the second study employed 372 new users of a video-editing tool. Our findings offer insight into how exploitative system use and explorative system use independently and jointly influence task performance constructs and also have implications for research and practices.
CarMax, based in Richmond, Virginia, is the largest retailer of used cars in the United States. Over the past several years leading up to 2019, CarMax has undergone a major digital transformation, integrating agile, lean, and user experience (UX) design best practices to become a customer-centric, product-driven organization.In this case, CarMax is facing new competitors (e.g., digital native players Carvana and CarsDirect), changing consumer shopping behavior, and technological advancements in electric cars, autonomous vehicles, and ride-sharing platforms. In order to maintain its dominant position in the used-car marketplace, CarMax must continue to evolve from a traditional brick-and-mortar model marked by legacy corporate practices (such as annual roadmaps and budget cycles) to a product-focused, omnichannel experience that delivers significant value to its customers. Excerpt UVA-S-0317 Aug. 26, 2019 CarMax: Driving What's Possible CarMax, a Fortune 200 company, was the largest used-vehicle retailer in the United States in 2019, operating 206 stores in 102 markets nationwide. Started as “just a test” by then–electronic giant Circuit City in 1993, “CarMax revolutionized the auto industry by delivering an honest, transparent, and high-integrity car buying experience” to its customers. For 26 years, CarMax's focus had been on making “car buying more ethical, fair, and stress free by offering a no-haggle experience and an incredible selection of vehicles.” In addition, CarMax had made car selling easy by offering no-obligation appraisals good for seven days, using the slogan “At CarMax, we'll buy your car even if you don't buy ours.” Headquartered in Richmond, Virginia, as of February 2019, CarMax had “nearly 25,000 associates nationwide and for 15 consecutive years [had] been named as one of the Fortune 100 Best Companies to Work For.” The size of the pre-owned market in 2019 was at the highest levels since the recession, with sales of over 40 million vehicles totaling over $ 150 billion. Competition for this market included local dealer franchises that sold used cars, and large traditional players such as CarMax, Penske, AutoNation, and Lithia, plus a host of online dealerships that had recently emerged, such as CarsDirect and Carvana. Despite the intense competition, CarMax's sales had remained strong with impressive financial results (see Exhibit 1). CarMax sold more than one million vehicles (748,961 retail and 447,491 wholesale) in fiscal year 2019, a 7% increase from the previous year, while posting over $ 18 billion in revenue. In addition to selling more cars than any other used car dealer, an industry source reported that CarMax had the highest gross profit margin (over $ 2,100) and the highest gross profit per unit sold (10.7%). By comparison, upstart Carvana made less than $ 1,000 per car and a gross profit of about 5% per unit sold. In addition to competing through their different business models, the entire automotive industry was facing a great deal of disruptive change. During the annual shareholders' meeting on June 25, 2019, when Bill Nash, president and CEO of CarMax, was asked if he was concerned about the potential risks that new technologies (electric and autonomous vehicles in particular) and ride sharing posed to CarMax's business model, Nash responded: . . .
Heikki Topi合作论文数Computer Information Systems Department;Bentley College;403 Smith Technology Center10
Shaila M. Miranda合作论文数University of Oklahoma.2