Redefining threat appraisals of organizational insiders and exploring the moderating role of fear in cyberattack protection motivation

被引:29
作者
Vrhovec, Simon [1 ]
Mihelic, Anze [1 ]
机构
[1] Univ Maribor, Fac Criminal Justice & Secur, Kotnikova 8, Ljubljana 1000, Slovenia
关键词
Fear; Cyber-attack; SEM; Moderation; Interaction; Unconstrained latent model; Double-mean centering; Higher education; Computer security; Cybersecurity; SECURITY POLICY COMPLIANCE; INFORMATION-TECHNOLOGY; PLANNED BEHAVIOR; USER ACCEPTANCE; MODEL; APPEALS; EMPLOYEES; INTENTION; EXTENSION; CYBERSECURITY;
D O I
10.1016/j.cose.2021.102309
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Increasingly sophisticated cyberattacks often systematically target organizational insiders. Their motivation for self-protection has therefore an important role in cybersecurity of orga-nizations. Protection motivation studies in information security literature are largely based on the protection motivation theory (PMT) without proper adaptation to the organizational context. Additionally, only few studies consider the role of fear in protection motivation al-though PMT itself is based on fear appeals. This paper aims to revise PMT to better fit the or-ganizational context of organizational insiders. A survey was conducted among academics ( N = 255) at six Slovenian universities to reexamine threat appraisals of organizational insid-ers, and the mediating and moderating roles of fear of cyberattacks in protection motivation. CB-SEM analysis of survey data supports the distinction between appraisals of threats to the individual and to the organization. It also supports differentiatingbetween perceived threats and fear of cyberattacks. Although we did not find support for the mediating role of fear of cyberattacks, perceived threats may mediate the association between perceived severity and vulnerability, and protection motivation. Only perceived vulnerability of the individual and perceived severity of consequences for the organization affect perceived threats. Perceived threats and measure efficacy influence protection motivation. Fear of cyberattacks damp-ens the positive relationship between self-efficacy and protection motivation. Self-efficacy influences protection motivation only when fear of cyberattacks is low. Interventions aim-ing to increase protection motivation need to focus on raising the perceived vulnerability of individuals, emphasizing the consequences for the organization, and increasing the efficacy of self-protective measures. Interventions aiming to improve self-efficacy may be effective only when there is low fear of cyberattacks and can be avoided when high fear of cyberat-tacks is expected. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:22
相关论文
共 86 条
[1]   THE THEORY OF PLANNED BEHAVIOR [J].
AJZEN, I .
ORGANIZATIONAL BEHAVIOR AND HUMAN DECISION PROCESSES, 1991, 50 (02) :179-211
[2]   Self-enhancement and self-protection: What they are and what they do [J].
Alicke, Mark D. ;
Sedikides, Constantine .
EUROPEAN REVIEW OF SOCIAL PSYCHOLOGY, 2009, 20 :1-48
[3]   Uncovering the predictors of unsafe computing behaviors in online crowdsourcing contexts [J].
Alomar, Noura ;
Alsaleh, Mansour ;
Alarifi, Abdulrahman .
COMPUTERS & SECURITY, 2019, 85 :300-312
[4]  
Ashrafi Noushin, 2016, International Conferences on ICT, Society and Human Beings 2016, Web Communities and Social Media 2016, Big Data Analytics, Data Mining and Computational Intelligence 2016, and Theory and Practice in Modern Computing 2016. Proceedings, P251
[5]   HEALTH BELIEF MODEL AND SICK ROLE BEHAVIOR [J].
BECKER, MH .
HEALTH EDUCATION MONOGRAPHS, 1974, 2 (04) :409-419
[6]   Costly but effective: Comparing the factors that influence employee anti-malware behaviours [J].
Blythe, John M. ;
Coventry, Lynne .
COMPUTERS IN HUMAN BEHAVIOR, 2018, 87 :87-97
[7]   WHAT DO SYSTEMS USERS HAVE TO FEAR? USING FEAR APPEALS TO ENGENDER THREATS AND FEAR THAT MOTIVATE PROTECTIVE SECURITY BEHAVIORS [J].
Boss, Scott R. ;
Galletta, Dennis F. ;
Lowry, Paul Benjamin ;
Moody, Gregory D. ;
Polak, Peter .
MIS QUARTERLY, 2015, 39 (04) :837-U461
[8]   Bridging psychological distance: The impact of immersive media on distant and proximal environmental issues [J].
Breves, Priska ;
Schramm, Holger .
COMPUTERS IN HUMAN BEHAVIOR, 2021, 115
[9]  
Bryman A., 2016, Social research methods, V5
[10]   The Adaptive Roles of Positive and Negative Emotions in Organizational Insiders' Security-Based Precaution Taking [J].
Burns, A. J. ;
Roberts, Tom L. ;
Posey, Clay ;
Lowry, Paul Benjamin .
INFORMATION SYSTEMS RESEARCH, 2019, 30 (04) :1228-1247