Exploring Contrasting Effects of Trust in Organizational Security Practices and Protective Structures on Employees’ Security-Related Precaution Taking
Information AnalyticsÌýÌýÌýÌýGreulich, Malte; Lins, Sebastian; Pienta, Daniel; Thatcher, Jason Bennett; Sunyaev, Ali. Exploring Contrasting Effects of Trust in Organizational Security Practices and Protective Structures on Employees' Security-Related Precaution Taking. Information Systems Research. Dec2024, Vol. 35 Issue 4, p1586-1608.ÌýÌýÌýÌý
Encouraging employees to take security precautions is a vital strategy that organizations can use to reduce their vulnerability to information security (ISec) threats. This study investigates how the bright- and dark-side effects of trust in organizational information security impact employees' intention to take security precautions. Employees who trust organizational security practices are more committed to protecting the organization and are more willing to take security precautions. To foster trust in organizational security practices and security commitment, ISec managers should establish a trusting security climate to ensure that employees can speak freely about the security problems they face in their work and receive support to resolve those problems if needed. This study also alerts managers to the potential adverse consequences of employees' trust in the organization's protective structures. We find that employees' trust in the organization's protective structures can backfire, making employees complacent regarding security. Further analyses indicate that security mindfulness mediates the influence of security complacency and security commitment on precaution taking. This study contributes by exploring and verifying the bright- and dark-side effects of trust in organizational ISec. Employees' precautionary security behaviors are vital to the effective protection of organizations from cybersecurity threats. Despite substantial security training efforts, employees frequently do not take security precautions. This study draws from trust theory and mindfulness theory to investigate how the bright- and dark-side effects of two conceptualizations of trust in organizational information security impact employees' precaution taking. Insights drawn from a survey of 380 organizational employees suggest that employees who trust their organization's security practices are more committed and less complacent in protecting their organization and more likely to take security precautions. In contrast, we find evidence of the dark-side effect of employees' trust in organizational protective structures by showing that such trust can lead to complacency regarding security. Analyses indicate that security mindfulness mediates the influence of security complacency and security commitment on precaution taking. These results highlight the crucial roles of security commitment, security complacency, and security mindfulness in shaping employees' precaution taking. This study contributes to information security research by providing empirical evidence concerning the simultaneous bright- and dark-side effects of employees' trust in organizational information security, thereby creating valuable opportunities for researchers to theorize about the ways in which trusting beliefs shape employees' security behaviors. ÌýÌýÌýÌý
Ìý