Using susceptibility claims to motivate behaviour change in IT security. Issue 1 (2nd January 2021)
- Record Type:
- Journal Article
- Title:
- Using susceptibility claims to motivate behaviour change in IT security. Issue 1 (2nd January 2021)
- Main Title:
- Using susceptibility claims to motivate behaviour change in IT security
- Authors:
- Jensen, Matthew L.
Durcikova, Alexandra
Wright, Ryan T - Abstract:
- ABSTRACT: Organisations face growing IT security risks with substantial consequences for missteps in business continuity, data loss, reputational harm, and future competitive advantage. To improve precaution-taking among organisation members, leaders frequently turn to susceptibility claims embedded in security education, training, and awareness (SETA) initiatives to motivate change. However, prior studies have produced mixed empirical results concerning the role of susceptibility in motivating precaution-taking. To deepen theorising about using susceptibility claims to change behaviour, we argue that threat characteristics (overt versus furtive attacks) shape individuals' attitudes of the threat, and these attitudes subsequently anchor how individuals respond to new claims about the threats. We introduce social judgement theory (SJT) to argue that when individuals participate in SETA initiatives, susceptibility claims that are too distant from individuals' existing attitudes will be ignored, while claims that are more proximal are more likely to be accepted and result in behaviour change. Using a longitudinal field experiment, we found that susceptibility claims motivated precaution taking against phishing (overt attack) but did not against password cracking (furtive attack). These results support SJT predictions and imply latitudes of acceptability and rejection into which susceptibility claims are placed. Implications for researchers, organisation leaders, and SETAABSTRACT: Organisations face growing IT security risks with substantial consequences for missteps in business continuity, data loss, reputational harm, and future competitive advantage. To improve precaution-taking among organisation members, leaders frequently turn to susceptibility claims embedded in security education, training, and awareness (SETA) initiatives to motivate change. However, prior studies have produced mixed empirical results concerning the role of susceptibility in motivating precaution-taking. To deepen theorising about using susceptibility claims to change behaviour, we argue that threat characteristics (overt versus furtive attacks) shape individuals' attitudes of the threat, and these attitudes subsequently anchor how individuals respond to new claims about the threats. We introduce social judgement theory (SJT) to argue that when individuals participate in SETA initiatives, susceptibility claims that are too distant from individuals' existing attitudes will be ignored, while claims that are more proximal are more likely to be accepted and result in behaviour change. Using a longitudinal field experiment, we found that susceptibility claims motivated precaution taking against phishing (overt attack) but did not against password cracking (furtive attack). These results support SJT predictions and imply latitudes of acceptability and rejection into which susceptibility claims are placed. Implications for researchers, organisation leaders, and SETA developers are discussed. … (more)
- Is Part Of:
- European journal of information systems. Volume 30:Issue 1(2021)
- Journal:
- European journal of information systems
- Issue:
- Volume 30:Issue 1(2021)
- Issue Display:
- Volume 30, Issue 1 (2021)
- Year:
- 2021
- Volume:
- 30
- Issue:
- 1
- Issue Sort Value:
- 2021-0030-0001-0000
- Page Start:
- 27
- Page End:
- 45
- Publication Date:
- 2021-01-02
- Subjects:
- Dov Te'eni
Anat Hovav
Phishing -- password -- susceptibility -- fear appeal -- field experiment -- social judgement theory -- overt attack -- furtive attack -- latitude of acceptability -- latitude of rejection
Information technology -- Periodicals
Information technology -- Europe -- Periodicals
Management information systems -- Periodicals
Management information systems -- Europe -- Periodicals
658.403805 - Journal URLs:
- http://www.palgrave-journals.com/ejis/index.html ↗
http://www.palgrave.com/home/index.asp ↗ - DOI:
- 10.1080/0960085X.2020.1793696 ↗
- Languages:
- English
- ISSNs:
- 0960-085X
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3829.730400
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 22734.xml