The Experts below are selected from a list of 261 Experts worldwide ranked by ideXlab platform

Paul Benjamin Lowry - One of the best experts on this subject based on the ideXlab platform.

  • a review and theoretical explanation of the cyberthreat intelligence cti capability that needs to be fostered in information Security practitioners and how this can be accomplished
    Computers & Security, 2020
    Co-Authors: Bongsik Shin, Paul Benjamin Lowry
    Abstract:

    Abstract Given the global increase in crippling cyberattacks, organizations are increasingly turning to cyberthreat intelligence (CTI). CTI represents actionable threat information that is relevant to a specific organization and that thus demands its close attention. CTI efforts aim to help organizations “know their enemies better” for proactive, preventive, and timely threat detection and remediation—complementing conventional risk-management paradigms designed to improve ‘general readiness’ against known or unknown threats. Organizational Security (OrgSec) and behavioral Security research has lagged behind CTI's growing potential to address current cyberSecurity challenges. Instead, CTI has largely been the purview of computer science from an algorithmic perspective. However, OrgSec and behavioral researchers can contribute a further combined knowledge of design for the organization, human factors, and Organizational governance to foster CTI. In this theory-building and review manuscript, we propose the CTI capability model (CTI-CM) to prescribe the key capabilities necessary for a CTI practitioner to engage effectively in CTI activities. The CTI-CM defines a practitioner's CTI capability in terms of three highly interrelated but conceptually distinctive dimensions: analytical component capability, contextual response capability, and experiential practice capability. We further explain how these capabilities can be fostered, and the key implications for leading Security practice in organizations.

  • using design science based gamification to improve Organizational Security training and compliance
    Journal of Management Information Systems, 2020
    Co-Authors: Mario Silic, Paul Benjamin Lowry
    Abstract:

    We conducted a design-science research project to improve an organization’s compound problems of (1) unsuccessful employee phishing prevention and (2) poorly received internal Security training. To...

  • using design science based gamification to improve Organizational Security training and compliance
    Social Science Research Network, 2020
    Co-Authors: Mario Silic, Paul Benjamin Lowry
    Abstract:

    We conducted a design-science research project to improve an organization’s compound problems of (1) unsuccessful employee phishing prevention and (2) poorly received internal Security training. To do so, we created a gamified Security training system focusing on two factors: (1) enhancing intrinsic motivation through gamification and (2) improving Security learning and efficacy. Our key theoretical contribution is proposing a recontextualized kernel theory from the hedonic-motivation system adoption model that can be used to assess employee Security constructs along with their intrinsic motivations and coping for learning and compliance. A six-month field study with 420 participants shows that fulfilling users’ motivations and coping needs through gamified Security training can result in statistically significant positive behavioral changes. We also provide a novel empirical demonstration of the conceptual importance of “appropriate challenge” in this context. We vet our work using the principles of proof-of-concept and proof-of-value, and we conclude with a research agenda that leads toward final proof-in-use.

  • a tale of two deterrents considering the role of absolute and restrictive deterrence to inspire new directions in behavioral and Organizational Security research
    Journal of the Association for Information Systems, 2018
    Co-Authors: Robert Willison, Paul Benjamin Lowry, Raymond Paternoster
    Abstract:

    This research-perspective article reviews and contributes to the literature that explains how to deter internal computer abuse (ICA), which is criminal computer behavior committed by Organizational insiders. ICA accounts for a large portion of insider trading, fraud, embezzlement, the selling of trade secrets, customer privacy violations, and other criminal behaviors, all of which are highly damaging to organizations. Although ICA represents a momentous threat for organizations, and despite numerous calls to examine this behavior, the academic response has been lukewarm. However, a few Security researchers have examined ICA’s influence in an Organizational context and the potential means of deterring it. However, the results of the studies have been mixed, leading to a debate on the applicability of deterrence theory (DT) to ICA. We argue that more compelling opportunities will arise in DT research if Security researchers more deeply study its assumptions and more carefully recontextualize it. The purpose of this article is to advance a deterrence research agenda that is grounded in the pivotal criminological deterrence literature. Drawing on the distinction between absolute and restrictive deterrence and aligning them with rational choice theory (RCT), this paper shows how deterrence can be used to mitigate the participation in and frequency of ICA. We thus propose that future research on the deterrent effects of ICA should be anchored in a more general RCT, rather than in examinations of deterrence as an isolated construct. We then explain how adopting RCT with DT opens up new avenues of research. Consequently, we propose three areas for future research, which cover not only the implications for the study of ICA deterrence, but also the potential motivations for this type of offence and the skills required to undertake them.

  • examining the relationship of Organizational insiders psychological capital with information Security threat and coping appraisals
    Social Science Research Network, 2017
    Co-Authors: Alan J Burns, Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Practitioners and researchers alike recognize the positive influence insiders’ behavior can have on information systems (IS) Security. This awareness has resulted in a research stream focused on the performance of protective behaviors. We contribute to this research stream by extending an oft-cited theory in the information Security literature — protection motivation theory (PMT) — to include the relationship of insiders’ psychological capital (PsyCap) with the mechanisms of PMT. PsyCap is a construct of role-breadth psychological capacities and resources embodying important workrelated motivational resources. Therefore, given the varied facets central to PMT, determining the relationship of PsyCap with each distinct PMT mechanism is an important contribution. Furthermore, prior research has established that individuals can develop their PsyCap. Consequently, considering the relationship of role-breadth PsyCap with the PMT mechanisms provides an important and malleable, motivational antecedent that complements PMT and is absent from most assessments of the contemporary PMT model. We find support for PsyCap’s relationship with the mechanisms of PMT and suggest opportunities to develop PsyCap in conjunction with other Organizational Security efforts. We present our findings, discuss their implications for research and practice, and highlight several opportunities for future research.

Clay Posey - One of the best experts on this subject based on the ideXlab platform.

  • Organizational information Security as a complex adaptive system: insights from three agent-based models
    Information Systems Frontiers, 2017
    Co-Authors: A. J. Burns, Clay Posey, James F. Courtney, Tom L. Roberts, Prabhashi Nanayakkara
    Abstract:

    The management of information Security can be conceptualized as a complex adaptive system because the actions of both insiders and outsiders co-evolve with the Organizational environment, thereby leading to the emergence of overall Security of informational assets within an organization. Thus, the interactions among individuals and their environments at the micro-level form the overall Security posture at the macro-level. Additionally, in this complex environment, Security threats evolve constantly, leaving organizations little choice but to evolve alongside those threats or risk losing everything. In order to protect Organizational information systems and associated informational assets, managers are forced to adapt to Security threats by training employees and by keeping systems and Security procedures updated. This research explains how Organizational information Security can perhaps best be managed as a complex adaptive system (CAS) and models the complexity of IS Security risks and Organizational responses using agent-based modeling (ABM). We present agent-based models that illustrate simple probabilistic phishing problems as well as models that simulate the Organizational Security outcomes of complex theoretical Security approaches based on general deterrence theory (GDT) and protection motivation theory (PMT).

  • examining the relationship of Organizational insiders psychological capital with information Security threat and coping appraisals
    Social Science Research Network, 2017
    Co-Authors: Alan J Burns, Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Practitioners and researchers alike recognize the positive influence insiders’ behavior can have on information systems (IS) Security. This awareness has resulted in a research stream focused on the performance of protective behaviors. We contribute to this research stream by extending an oft-cited theory in the information Security literature — protection motivation theory (PMT) — to include the relationship of insiders’ psychological capital (PsyCap) with the mechanisms of PMT. PsyCap is a construct of role-breadth psychological capacities and resources embodying important workrelated motivational resources. Therefore, given the varied facets central to PMT, determining the relationship of PsyCap with each distinct PMT mechanism is an important contribution. Furthermore, prior research has established that individuals can develop their PsyCap. Consequently, considering the relationship of role-breadth PsyCap with the PMT mechanisms provides an important and malleable, motivational antecedent that complements PMT and is absent from most assessments of the contemporary PMT model. We find support for PsyCap’s relationship with the mechanisms of PMT and suggest opportunities to develop PsyCap in conjunction with other Organizational Security efforts. We present our findings, discuss their implications for research and practice, and highlight several opportunities for future research.

  • examining the relationship of Organizational insiders psychological capital with information Security threat and coping appraisals
    Computers in Human Behavior, 2017
    Co-Authors: Alan J Burns, Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Practitioners and researchers alike recognize the positive influence insiders' behavior can have on information systems (IS) Security. This awareness has resulted in a research stream focused on the performance of protective behaviors. We contribute to this research stream by extending an oft-cited theory in the information Security literatureprotection motivation theory (PMT)to include the relationship of insiders' psychological capital (PsyCap) with the mechanisms of PMT.PsyCap is a construct of role-breadth psychological capacities and resources embodying important work-related motivational resources. Therefore, given the varied facets central to PMT, determining the relationship of PsyCap with each distinct PMT mechanism is an important contribution. Furthermore, prior research has established that individuals can develop their PsyCap. Consequently, considering the relationship of role-breadth PsyCap with the PMT mechanisms provides an important and malleable, motivational antecedent that complements PMT and is absent from most assessments of the contemporary PMT model. We find support for PsyCap's relationship with the mechanisms of PMT and suggest opportunities to develop PsyCap in conjunction with other Organizational Security efforts. We present our findings, discuss their implications for research and practice, and highlight several opportunities for future research. Extended PMT model is proposed that includes the relationship of insiders' PsyCap.PsyCap uniquely relates to each threat and coping appraisal mechanism of PMT.Via the facets of PMT, PsyCap indirectly relates to protection motivation and PMBs.Higher levels of PsyCap are related to more PMBs and higher protection motivation.Opportunities exist to build insiders' PsyCap and improve information Security.

  • the impact of Organizational commitment on insiders motivation to protect Organizational information assets
    2015
    Co-Authors: Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Insiders may act to sustain and improve Organizational information Security, yet our knowledge of what motivates them to do so remains limited. For example, most extant research use portions of protection motivation theory (PMT) and have relied on isolated behaviors thus limiting the generalizability of findings to single artifacts rather than the global set of protective Security behaviors. We thus investigate the motivations surrounding this larger behavioral set by assessing maladaptive rewards, response costs, and fear alongside traditional PMT components. We extend PMT by showing that: (1) Security education, training, and awareness (SETA) efforts help form appraisals; (2) PMT’s applicability to Organizational rather than personal contexts depends on insiders’ Organizational commitment levels; and (3) response costs provide the link between PMT’s appraisals. Contributions include detailing how Organizational commitment is the mechanism through which Organizational Security threats become personally relevant to insiders and how SETA efforts influence many PMT-based components.

  • the impact of Organizational commitment on insiders motivation to protect Organizational information assets
    Journal of Management Information Systems, 2015
    Co-Authors: Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    AbstractInsiders may act to sustain and improve Organizational information Security, yet our knowledge of what motivates them to do so remains limited. For example, most extant research relies on mere portions of protection motivation theory (PMT) and has focused on isolated behaviors, thus limiting the generalizability of findings to isolated issues, rather than addressing the global set of protective Security behaviors. Here, we investigate the motivations surrounding this larger behavioral set by assessing maladaptive rewards, response costs, and fear alongside traditional PMT components. We extend PMT by showing that: (1) Security education, training, and awareness (SETA) efforts help form appraisals; (2) PMT’s applicability to Organizational rather than personal contexts depends on insiders’ Organizational commitment levels; and (3) response costs provide the link between PMT’s appraisals. We show in detail how Organizational commitment is the mechanism through which Organizational Security threats b...

Tom L. Roberts - One of the best experts on this subject based on the ideXlab platform.

  • Organizational information Security as a complex adaptive system: insights from three agent-based models
    Information Systems Frontiers, 2017
    Co-Authors: A. J. Burns, Clay Posey, James F. Courtney, Tom L. Roberts, Prabhashi Nanayakkara
    Abstract:

    The management of information Security can be conceptualized as a complex adaptive system because the actions of both insiders and outsiders co-evolve with the Organizational environment, thereby leading to the emergence of overall Security of informational assets within an organization. Thus, the interactions among individuals and their environments at the micro-level form the overall Security posture at the macro-level. Additionally, in this complex environment, Security threats evolve constantly, leaving organizations little choice but to evolve alongside those threats or risk losing everything. In order to protect Organizational information systems and associated informational assets, managers are forced to adapt to Security threats by training employees and by keeping systems and Security procedures updated. This research explains how Organizational information Security can perhaps best be managed as a complex adaptive system (CAS) and models the complexity of IS Security risks and Organizational responses using agent-based modeling (ABM). We present agent-based models that illustrate simple probabilistic phishing problems as well as models that simulate the Organizational Security outcomes of complex theoretical Security approaches based on general deterrence theory (GDT) and protection motivation theory (PMT).

  • examining the relationship of Organizational insiders psychological capital with information Security threat and coping appraisals
    Social Science Research Network, 2017
    Co-Authors: Alan J Burns, Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Practitioners and researchers alike recognize the positive influence insiders’ behavior can have on information systems (IS) Security. This awareness has resulted in a research stream focused on the performance of protective behaviors. We contribute to this research stream by extending an oft-cited theory in the information Security literature — protection motivation theory (PMT) — to include the relationship of insiders’ psychological capital (PsyCap) with the mechanisms of PMT. PsyCap is a construct of role-breadth psychological capacities and resources embodying important workrelated motivational resources. Therefore, given the varied facets central to PMT, determining the relationship of PsyCap with each distinct PMT mechanism is an important contribution. Furthermore, prior research has established that individuals can develop their PsyCap. Consequently, considering the relationship of role-breadth PsyCap with the PMT mechanisms provides an important and malleable, motivational antecedent that complements PMT and is absent from most assessments of the contemporary PMT model. We find support for PsyCap’s relationship with the mechanisms of PMT and suggest opportunities to develop PsyCap in conjunction with other Organizational Security efforts. We present our findings, discuss their implications for research and practice, and highlight several opportunities for future research.

  • examining the relationship of Organizational insiders psychological capital with information Security threat and coping appraisals
    Computers in Human Behavior, 2017
    Co-Authors: Alan J Burns, Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Practitioners and researchers alike recognize the positive influence insiders' behavior can have on information systems (IS) Security. This awareness has resulted in a research stream focused on the performance of protective behaviors. We contribute to this research stream by extending an oft-cited theory in the information Security literatureprotection motivation theory (PMT)to include the relationship of insiders' psychological capital (PsyCap) with the mechanisms of PMT.PsyCap is a construct of role-breadth psychological capacities and resources embodying important work-related motivational resources. Therefore, given the varied facets central to PMT, determining the relationship of PsyCap with each distinct PMT mechanism is an important contribution. Furthermore, prior research has established that individuals can develop their PsyCap. Consequently, considering the relationship of role-breadth PsyCap with the PMT mechanisms provides an important and malleable, motivational antecedent that complements PMT and is absent from most assessments of the contemporary PMT model. We find support for PsyCap's relationship with the mechanisms of PMT and suggest opportunities to develop PsyCap in conjunction with other Organizational Security efforts. We present our findings, discuss their implications for research and practice, and highlight several opportunities for future research. Extended PMT model is proposed that includes the relationship of insiders' PsyCap.PsyCap uniquely relates to each threat and coping appraisal mechanism of PMT.Via the facets of PMT, PsyCap indirectly relates to protection motivation and PMBs.Higher levels of PsyCap are related to more PMBs and higher protection motivation.Opportunities exist to build insiders' PsyCap and improve information Security.

  • the impact of Organizational commitment on insiders motivation to protect Organizational information assets
    2015
    Co-Authors: Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    Insiders may act to sustain and improve Organizational information Security, yet our knowledge of what motivates them to do so remains limited. For example, most extant research use portions of protection motivation theory (PMT) and have relied on isolated behaviors thus limiting the generalizability of findings to single artifacts rather than the global set of protective Security behaviors. We thus investigate the motivations surrounding this larger behavioral set by assessing maladaptive rewards, response costs, and fear alongside traditional PMT components. We extend PMT by showing that: (1) Security education, training, and awareness (SETA) efforts help form appraisals; (2) PMT’s applicability to Organizational rather than personal contexts depends on insiders’ Organizational commitment levels; and (3) response costs provide the link between PMT’s appraisals. Contributions include detailing how Organizational commitment is the mechanism through which Organizational Security threats become personally relevant to insiders and how SETA efforts influence many PMT-based components.

  • the impact of Organizational commitment on insiders motivation to protect Organizational information assets
    Journal of Management Information Systems, 2015
    Co-Authors: Clay Posey, Tom L. Roberts, Paul Benjamin Lowry
    Abstract:

    AbstractInsiders may act to sustain and improve Organizational information Security, yet our knowledge of what motivates them to do so remains limited. For example, most extant research relies on mere portions of protection motivation theory (PMT) and has focused on isolated behaviors, thus limiting the generalizability of findings to isolated issues, rather than addressing the global set of protective Security behaviors. Here, we investigate the motivations surrounding this larger behavioral set by assessing maladaptive rewards, response costs, and fear alongside traditional PMT components. We extend PMT by showing that: (1) Security education, training, and awareness (SETA) efforts help form appraisals; (2) PMT’s applicability to Organizational rather than personal contexts depends on insiders’ Organizational commitment levels; and (3) response costs provide the link between PMT’s appraisals. We show in detail how Organizational commitment is the mechanism through which Organizational Security threats b...

Sean B Maynard - One of the best experts on this subject based on the ideXlab platform.

  • Organizational Security learning from incident response
    International Conference on Information Systems, 2017
    Co-Authors: Jeb Webb, Atif Ahmad, Sean B Maynard, Richard L Baskerville, Graeme Shanks
    Abstract:

    The Security-related experiences of Incident Response Teams provide Enterprise Information Security Management with a unique opportunity to draw lessons and insights. However, research has shown that there is often inadequate informationsharing between the Security and response functions of organizations. In this paper we apply a general theory of Organizational learning to interpret findings from a case study of IR practices at a major Australian financial institution, and then propose a learning process model that can be used to bridge IR and ISM functions in organizations. Findings from focus group research carried out for preliminary evaluation of the model are presented, followed by a discussion of the project’s next steps.

  • Organizational Security culture more than just an end user phenomenon
    Information Security Conference, 2006
    Co-Authors: Anthonie B Ruighaver, Sean B Maynard
    Abstract:

    The concept of Security culture is relatively new. It is often investigated in a simplistic manner focusing on end-users and on the technical aspects of Security. Security, however, is a management problem and as a result the investigation of Security culture should also have a management focus. This paper discusses Security culture based on an organisational culture framework of eight dimensions. We believe that use of this framework in Security culture research will reduce the inherent biases of researchers who tend to focus on only technical aspects of culture from an end users perspective.

Anthonie B Ruighaver - One of the best experts on this subject based on the ideXlab platform.

  • Organizational Security culture more than just an end user phenomenon
    Information Security Conference, 2006
    Co-Authors: Anthonie B Ruighaver, Sean B Maynard
    Abstract:

    The concept of Security culture is relatively new. It is often investigated in a simplistic manner focusing on end-users and on the technical aspects of Security. Security, however, is a management problem and as a result the investigation of Security culture should also have a management focus. This paper discusses Security culture based on an organisational culture framework of eight dimensions. We believe that use of this framework in Security culture research will reduce the inherent biases of researchers who tend to focus on only technical aspects of culture from an end users perspective.