Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours

Traditionally, employees have been viewed as an enemy to information security (IS) within organisations, rather than as an organisational asset that can be harnessed to help protect company information. Existing research is largely fragmented with a distinct lack of theorybased approaches for the de...

Full description

Bibliographic Details
Main Author: Blythe, John Matthew
Other Authors: Coventry, Lynne
Published: Northumbria University 2015
Subjects:
Online Access:https://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.713851
id ndltd-bl.uk-oai-ethos.bl.uk-713851
record_format oai_dc
spelling ndltd-bl.uk-oai-ethos.bl.uk-7138512018-09-05T03:29:44ZInformation security in the workplace : a mixed-methods approach to understanding and improving security behavioursBlythe, John MatthewCoventry, Lynne2015Traditionally, employees have been viewed as an enemy to information security (IS) within organisations, rather than as an organisational asset that can be harnessed to help protect company information. Existing research is largely fragmented with a distinct lack of theorybased approaches for the design and evaluation of behaviour change interventions. Furthermore, research has largely focussed on employees' compliance with IS policies and less so, the multitude of individual behaviours covered in them. This thesis presents a mixed-method approach to changing employees' security behaviour using theory to inform the design of an intervention. The thesis identified influencers and barriers to specific security behaviours and developed an extended-Protection Motivation Theory model. The model includes information sensitivity appraisal as an important influencer for which a new scale (WISA) was developed and validated. The model was tested on three specific anti-malware behaviours: usage of antimalware software, installing software updates and avoiding suspicious links within emails. The testing allowed the identification of the most influential factors for each behaviour and demonstrated how these factors differ between behaviours. A nuance that is lost when adopting the IS policy compliance approach and was also confirmed by the qualitative findings. The findings from the models informed the design of the behaviour change intervention. Components of the model were utilised in an intervention to promote email security behaviour. The intervention comprised of a motivational component, together with a volitional component based on implementation intentions to help translate good 'intentions' into good 'security actions'. The study found significant improvements in objective performance on email legitimacy tasks that were more sustainable with the addition of implementation intentions. Response efficacy was an identified barrier, demonstrated to influence anti-malware behaviours and was malleable to significant change during the intervention. The theoretical and practical implications of these results are discussed together with suggestions for future research.658.4C800 PsychologyNorthumbria Universityhttps://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.713851http://nrl.northumbria.ac.uk/30328/Electronic Thesis or Dissertation
collection NDLTD
sources NDLTD
topic 658.4
C800 Psychology
spellingShingle 658.4
C800 Psychology
Blythe, John Matthew
Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
description Traditionally, employees have been viewed as an enemy to information security (IS) within organisations, rather than as an organisational asset that can be harnessed to help protect company information. Existing research is largely fragmented with a distinct lack of theorybased approaches for the design and evaluation of behaviour change interventions. Furthermore, research has largely focussed on employees' compliance with IS policies and less so, the multitude of individual behaviours covered in them. This thesis presents a mixed-method approach to changing employees' security behaviour using theory to inform the design of an intervention. The thesis identified influencers and barriers to specific security behaviours and developed an extended-Protection Motivation Theory model. The model includes information sensitivity appraisal as an important influencer for which a new scale (WISA) was developed and validated. The model was tested on three specific anti-malware behaviours: usage of antimalware software, installing software updates and avoiding suspicious links within emails. The testing allowed the identification of the most influential factors for each behaviour and demonstrated how these factors differ between behaviours. A nuance that is lost when adopting the IS policy compliance approach and was also confirmed by the qualitative findings. The findings from the models informed the design of the behaviour change intervention. Components of the model were utilised in an intervention to promote email security behaviour. The intervention comprised of a motivational component, together with a volitional component based on implementation intentions to help translate good 'intentions' into good 'security actions'. The study found significant improvements in objective performance on email legitimacy tasks that were more sustainable with the addition of implementation intentions. Response efficacy was an identified barrier, demonstrated to influence anti-malware behaviours and was malleable to significant change during the intervention. The theoretical and practical implications of these results are discussed together with suggestions for future research.
author2 Coventry, Lynne
author_facet Coventry, Lynne
Blythe, John Matthew
author Blythe, John Matthew
author_sort Blythe, John Matthew
title Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
title_short Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
title_full Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
title_fullStr Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
title_full_unstemmed Information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
title_sort information security in the workplace : a mixed-methods approach to understanding and improving security behaviours
publisher Northumbria University
publishDate 2015
url https://ethos.bl.uk/OrderDetails.do?uin=uk.bl.ethos.713851
work_keys_str_mv AT blythejohnmatthew informationsecurityintheworkplaceamixedmethodsapproachtounderstandingandimprovingsecuritybehaviours
_version_ 1718730215873576960