The following content is pulled in part from my research proposal for my PhD in cyberpsychology. I would enjoy any feedback and thoughts.
Cybersecurity has developed from a less known concern into a well-recognized risk to organizations worldwide. A 2021 study found that the “human factor” relates to 39% of cyber risk, and that “human error” is responsible for 95% of successful cyber-attacks, most of which is insider threat (Alsharif, et al., 2021). While much of the cyber industry focuses on improved tooling and systems configuration to mitigate risks, the true threat to organizational security is staff; and leading that threat is the organization’s leadership. Cybercrime Magazine estimates worldwide costs of cybercrime to reach $10.5 Trillion by 2025. (Cybercrime, 2020) And yet, according to Forbes.com, “76% of CEOs admit to bypassing security protocols to get something done faster, sacrificing security for speed.” (Forbes, 2020). Some motivations for organizational leadership to not follow policy could include a sense of entitlement, a willingness to accept risk for perceived advantage, or a misunderstanding of the risk. It is paramount to understand individual behavioral motivations to disregard cyber risk and associated mitigating cyber policies.
Although previous research has provided adequate structures for user acceptance behavior analysis, there remains both a uniqueness to cyber security user acceptance and how internal psychological forces impact an organization’s management and executive leadership’s willingness to accept and follow security policy. A review of current and past studies and literature reveal a scarcity of research identifying how an individual’s own relationship with technology can impact his or her acceptance of the technology in relation to change imposed by cyber security policy. There remains an opportunity to study internal factors as opposed to external influence on how user-perceive affinity with technology impacts their acceptance of security change, specifically an organization’s leadership members.
Understanding the motivations and influences begins with examining models of user acceptance of technology. The Technology Acceptance Model (TAM; Davis, 1989) establishes a foundation of two factors that influence user acceptance: perceived usefulness (PU) and perceived ease-of-use (PEOU). These factors drive a user’s behavioral intention to adopt an associated technology. (Davis, F. D., 1989). This influential model is an expansion of Ajzen and Fishbein’s theory of reasoned action (TRA), which clarifies the connection between a user’s attitudes and resultant behaviors. (Fishbein, M., 1967). Additional researchers have developed expansions and updates on this model over the years. Notably, Viswanath Venkatesh and Fred D. Davis developed a ‘TAM2’ model to provide additional cognitive instrumental processes to the TAM model. (e.g., Subjective Norm, Voluntariness, Image, Job Relevance, Output Quality, and Result Demonstrability). (Venkatesh, V.; Davis, F. D., 2000). These additions provide a tested foundation for measuring potential influences on user acceptance of technology.
Additional difficulties unique to cybersecurity change negatively impacted user acceptance. In an article by Michael Daniel of the Harvard Business Review, “The rules of cyberspace are different from the physical world’s. Cybersecurity law, policy, and practice are not yet fully developed”. (Daniel, M., 2017). Introducing new security-centric requirements adds complexity and difficulty to user and technology relations, as dictated by organizational policy and procedural change. An entire field examines how humans interact with computers and information security, called Human-Computer Interaction (security) or HCISec, to improve the ease-of-use of security elements of applications. (Norman, Kent L). This field focuses on how technology design principles impact the user experience and potentially affect user acceptance. (Yee, K., 2003). And finally, in an article by Maria-Elena Osiceanu, the psychological implications of technophobia and technophilia, are introduced. (Osiceanu, Maria-Elena). Internal psychological ambivalence, attraction, or rejection of technology can have a significant impact on security change acceptance; a factor not addressed fully in past or current literature.
Bibliography
Alsharif, M., et al. (2021). “Impact of Human Vulnerabilities on Cybersecurity”, Computer Systems Science & Engineering, vol.40, no.3. doi:10.32604/csse.2022.019938
Cybercrime (2020). “Cybercrime To Cost The World $10.5 Trillion Annually By 2025” Accessed June 28, 2022. https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/
Forbes.com (2020). “Cybersecurity’s Greatest Insider Threat Is In The C-Suite” Accessed June 28, 2022. https://www.forbes.com/sites/louiscolumbus/2020/05/29/cybersecuritys-greatest-insider-threat-is-in-the-c-suite/?sh=516e7d717626
Davis, F. D. (1989), “Perceived usefulness, perceived ease of use, and user acceptance of information technology”, MIS Quarterly, 13 (3): 319–340, doi:10.2307/249008, JSTOR 249008, S2CID 12476939
Fishbein, M. (1967). A behavior theory approach to the relations between beliefs about an object and the attitude toward the object. In M. Fishbein (Ed.), Readings in attitude theory and measurement (pp. 389-400). New York: John Wiley & Sons.
Venkatesh, V.; Davis, F. D. (2000), “A theoretical extension of the technology acceptance model: Four longitudinal field studies”, Management Science, 46 (2): 186–204, doi:10.1287/mnsc.46.2.186.11926, S2CID 32642600
Daniel, M. (2017), “Why Is Cybersecurity So Hard?” Accessed July 2, 2022. https://hbr.org/2017/05/why-is-cybersecurity-so-hard.
Norman, Kent L. Cyberpsychology: An Introduction to Human-Computer Interaction. Cambridge University Press, 2017.
Yee, Ka-ping. (2003). User Interaction Design for Secure Systems. 10.1007/3-540-36159-6_24.
Osiceanu, Maria-Elena. “Psychological Implications of Modern Technologies: ‘Technofobia’ versus ‘Technophilia.’” Procedia – Social and Behavioral Sciences, The 6th International Conference Edu World 2014 “Education Facing Contemporary World Issues”, 7th – 9th November 2014, 180 (May 5, 2015): 1137–44. https://doi.org/10.1016/j.sbspro.2015.02.229.