Going Beyond Deterrence: A Middle-Range Theory of Motives and Controls for Insider Computer Abuse
Published Online:10 May 2022https://doi.org/10.1287/isre.2022.1133
References
- (2002) Sabotage in the workplace: The role of organizational injustice. Organ. Behav. Human Decision Processes 89(1):947–965.Crossref, Google Scholar
- (2010) The Psychology of Criminal Conduct (Matthew Bender & Company, New Providence, NJ).Google Scholar
- (2002) The self-importance of moral identity. J. Personality Soc. Psych. 83(6):1423–1440.Crossref, Google Scholar
- (2002) Procrastination, deadlines, and performance: Self-control by precommitment. Psych. Sci. 13(3):219–224.Crossref, Google Scholar
- (2001) The significance of context in information systems and organizational change. Inform. Systems J. 11(1):43–63.Crossref, Google Scholar
- (2005) Motivation and transactional, charismatic, and transformational leadership: A test of antecedents. J. Leadership Organ. Stud. 11(4):26–40.Crossref, Google Scholar
- (2000) Development of a measure of workplace deviance. J. Appl. Psych. 85(3):349–360.Crossref, Google Scholar
- (1988) An Introduction to the Principles of Morals and Legislation (Prometheus Books, New York).Google Scholar
- (2008) When employees strike back: Investigating mediating mechanisms between psychological contract breach and workplace deviance. J. Appl. Psych. 93(5):1104–1117.Crossref, Google Scholar
- (2015) What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviors. MIS Quart. 39(4):837–864.Crossref, Google Scholar
- (2009) If someone is watching, I’ll do what I’m asked: Mandatoriness, control, and information security. Eur. J. Inform. Systems 18(2):151–164.Crossref, Google Scholar
- (1998) Expressive voting and electoral equilibrium. Public Choice 95(1):149–175.Crossref, Google Scholar
- (2017) Understanding consumers’ attitudes toward controversial information technologies: A contextualization approach. Inform. Systems Res. 28(4):760–774.Link, Google Scholar
- (2010) Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quart. 34(4):523–548.Crossref, Google Scholar
- (2017) Examining the relationship of organizational insiders’ psychological capital with information security threat and coping appraisals. Comput. Human Behav. 68(March):190–209.Crossref, Google Scholar
- (2018) Intentions to comply vs. intentions to protect: A VIE theory approach to understanding the influence of insiders’ awareness of organizational SETA efforts. Decision Sci. 49(6):1187–1228.Crossref, Google Scholar
- (2015) The behavioral roots of information systems security: Exploring key factors related to unethical IT use. J. Management Inform. Systems 31(4):49–87.Crossref, Google Scholar
- (2012) Organizations’ information security policy compliance: Stick or carrot approach? J. Management Inform. Systems 29(3):157–188.Crossref, Google Scholar
- (2013) Controlling for common method variance in PLS analysis: The measured latent marker variable approach. Abdi H, Chin WW, Vinzi VE, Russolillo G, Trinchera L, eds. New Perspectives in Partial Least Squares and Related Methods (Springer, New York), 231–239.Crossref, Google Scholar
- (2008) The relationship between psychological contract breach and employee deviance: The moderating role of hostile attributional style. J. Vocational Behav. 73(3):426–433.Crossref, Google Scholar
- (1988) Statistical Power Analysis for the Behavioral Sciences, 2nd ed. (Lawrence Erlbaum Associates, Hillsdale, NJ).Google Scholar
- (2013) Future directions for behavioral information security research. Comput. Security 32(February):90–101.Crossref, Google Scholar
- (2011) A review and analysis of deterrence theory in the IS security literature: Making sense of the disparate findings. Eur. J. Inform. Systems 20(6):643–658.Crossref, Google Scholar
- (2007) Deterring internal information systems misuse. Comm. ACM 50(10):113–117.Crossref, Google Scholar
- (2019) Cognitive‐affective drivers of employees’ daily compliance with information security policies: A multilevel, longitudinal study. Inform. Systems J. 29(1):43–69.Crossref, Google Scholar
- (2014) Understanding employee responses to stressful information security requirements: A coping perspective. J. Management Inform. Systems 31(2):285–318.Crossref, Google Scholar
- (2009) User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Inform. Systems Res. 20(1):79–98.Link, Google Scholar
- (2005) A meta-analysis of the relationship between organizational citizenship behavior and counterproductive work behavior. J. Appl. Psych. 90(6):1241–1255.Crossref, Google Scholar
- (2016) Context is king! Considering particularism in research design and reporting. J. Inform. Tech. 31(3):241–249.Crossref, Google Scholar
- (2021) Circumventing circumvention: An economic analysis of the role of education and enforcement. Management Sci., ePub ahead of print August 11, 2021, https://doi.org/10.1287/mnsc.2021.4027.Google Scholar
- (1964) The function of aggression and the regulation of aggressive drive. Psych. Rev. 71(4):257–272.Crossref, Google Scholar
- (1982) Two structural equation models: LISREL and PLS applied to consumer exit-voice theory. J. Marketing Res. 19(4):440–452.Crossref, Google Scholar
- (1981) Evaluating structural equation models with unobservable variables and measurement error. J. Marketing Res. 18(1):39–50.Crossref, Google Scholar
- (2016) Factors influencing the intention to comply with data protection regulations in hospitals: Based on gender differences in behaviour and deterrence. Eur. J. Inform. Systems 25(2):91–109.Crossref, Google Scholar
- (1988) An updated paradigm for scale development incorporating unidimensionality and its assessment. J. Marketing Res. 25(2):186–192.Crossref, Google Scholar
- (2011) Unable to resist temptation: How self-control depletion promotes unethical behavior. Organ. Behav. Human Decision Processes 115(2):191–203.Crossref, Google Scholar
- (2011) Sanctions, situations, and agency in control theories of crime. Eur. J. Criminology 8(2):128–143.Crossref, Google Scholar
- (2017) Self-control theory and crime. Oxford Research Encyclopedia of Criminology. Retrieved September 6, https://oxfordre.com/criminology/view/10.1093/acrefore/9780190264079.001.0001/acrefore-9780190264079-e-252.Google Scholar
- (1990) A General Theory of Crime (Stanford University Press, Stanford, CA).Crossref, Google Scholar
- (2020) A Tesla employee thwarted an alleged ransomware plot. Wired (August 27), https://www.wired.com/story/tesla-ransomware-insider-hack-attempt/.Google Scholar
- (2006) The nature of theory in information systems. MIS Quart. 30(3):611–642.Crossref, Google Scholar
- (2015) New state of play in information systems research: The push to the edges. MIS Quart. 39(2):271–296.Crossref, Google Scholar
- (2011) Understanding nonmalicious security violations in the workplace: A composite behavior model. J. Management Inform. Systems 28(2):203–236.Crossref, Google Scholar
- (2010) Ego depletion and the strength model of self-control: A meta-analysis. Psych. Bull. 136(4):495–525.Crossref, Google Scholar
- (2017) A Primer on Partial Least Squares Structural Equations Modeling (PLS-SEM), 2nd ed. (SAGE, Thousand Oaks, CA).Google Scholar
- (2017) An integrative model of information security policy compliance with psychological contract: Examining a bilateral perspective. Comput. Security 66(May):52–65.Crossref, Google Scholar
- (1996) The effect of codes of ethics and personal denial of responsibility on computer abuse judgments and intentions. MIS Quart. 20(3):257–278.Crossref, Google Scholar
- (2015) Seeking middle-range theories in information systems research. Proc. Internat. Conf. Inform. Systems, December 13–18 (ICIS, Fort Worth, TX).Google Scholar
- (2019) The process of information systems theorizing as a discursive practice. J. Inform. Tech. 34(3):198–220.Crossref, Google Scholar
- (2010) A comparison of approaches for the analysis of interaction effects between latent variables using partial least squares path modeling. Structural Equation Model. 17(1):82–109.Crossref, Google Scholar
- (2015) A new criterion for assessing discriminant validity in variance-based structural equation modeling. J. Acad. Marketing Sci. 43(1):115–135.Crossref, Google Scholar
- (2014) Common beliefs and reality about PLS: Comments on Rönkkö and Evermann (2013). Organ. Res. Methods 17(2):182–209.Crossref, Google Scholar
- (2009) Protection motivation and deterrence: A framework for security policy compliance in organisations. Eur. J. Inform. Systems 18(2):106–125.Crossref, Google Scholar
- (2017) Causes of Delinquency (Routledge, New York).Crossref, Google Scholar
- (2008) Low self-control, routine activities, and fraud victimization. Criminology 46(1):189–220.Crossref, Google Scholar
- (2014) A framework and guidelines for context-specific theorizing in information systems research. Inform. Systems Res. 25(1):111–136.Link, Google Scholar
- (1999) Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria vs. new alternatives. Structural Equation Model. 6(1):1–55.Crossref, Google Scholar
- (2015) The role of self-control in information security violations: Insights from a cognitive neuroscience perspective. J. Management Inform. Systems 31(4):6–48.Crossref, Google Scholar
- (2011) Does deterrence work in reducing information security policy abuse by employees? Comm. ACM 54(6):54–60.Crossref, Google Scholar
- IBM (2021) Cost of a data breach report 2021, Accessed November 11, 2021, https://www.ibm.com/security/data-breach.Google Scholar
- (2017) Training to mitigate phishing attacks using mindfulness techniques. J. Management Inform. Systems 34(2):597–626.Crossref, Google Scholar
- (2018) Self-control as the fuel for effective self-regulation at work: Antecedents, consequences, and boundary conditions of employee self-control. Elliot AJ, ed. Advances in Motivation Science, vol. 5 (Elsevier, Cambridge, MA), 87–128.Google Scholar
- (2010) Fear appeals and information security behaviors: An empirical study. MIS Quart. 34(3):549–566.Crossref, Google Scholar
- (2015) An enhanced fear appeal rhetorical framework: Leveraging threats to the human asset through sanctioning rhetoric. MIS Quart. 39(1):113–134.Crossref, Google Scholar
- (2016) Dispositional and situational factors: Influences on information security policy violations. Eur. J. Inform. Systems 25(3):231–251.Crossref, Google Scholar
- (2009) In the eye of the impulsive beholder: The interaction between impulsivity and perceived informal social control on offending. Criminal Justice Behav. 36(3):307–321.Crossref, Google Scholar
- (2012) Does survey format influence self-disclosure on sensitive question items? Comput. Human Behav. 28(1):251–256.Crossref, Google Scholar
- (2017) To cyberloaf or not to cyberloaf: The impact of the announcement of formal organizational controls. J. Management Inform. Systems 34(1):141–176.Crossref, Google Scholar
- (2012) The influence of subordinate affect and self-monitoring on multiple dimensions of leader-member exchange. Internat. J. Management Marketing Res. 5(3):83–100.Google Scholar
- (2004) An integrative model of computer abuse based on social control and general deterrence theories. Inform. Management 41(6):707–718.Crossref, Google Scholar
- (2021) The CARE theory of dignity amid personal data digitalization. MIS Quart. 45(1b):343–370.Crossref, Google Scholar
- (1999) Work motivation: The incorporation of self-concept-based processes. Human Relations 52(8):969–998.Crossref, Google Scholar
- (2021) Understanding information security policy violation from a situational action perspective. J. Assoc. Inform. Systems 22(3):5.Google Scholar
- (2018) Self-control, organizational context, and rational choice in internet abuses at work. Inform. Management 55(3):358–367.Crossref, Google Scholar
- (2014) Abusive supervision and retaliation: A self-control framework. Acad. Management J. 57(1):116–139.Crossref, Google Scholar
- (2007) Assimilation of enterprise systems: The effect of institutional pressures and the mediating role of top management. MIS Quart. 31(1):59–87.Crossref, Google Scholar
- (2018) User resistance to the implementation of information systems: A psychological contract breach perspective. J. Assoc. Inform. Systems 19(4):306–332.Google Scholar
- (1981) Goal setting and task performance: 1969–1980. Psych. Bull. 90(1):125–152.Crossref, Google Scholar
- (2014) Partial least squares (PLS) structural equation modeling (SEM) for building and testing behavioral causal theory: When to choose it and how to use it. IEEE Trans. Professional Comm. 57(2):123–146.Crossref, Google Scholar
- (2017a) Why security and privacy research lies at the centre of the information systems (IS) artefact: Proposing a bold research agenda. Eur. J. Inform. Systems 26(6):546–563.Crossref, Google Scholar
- (2017b) Using IT design to prevent cyberbullying. J. Management Inform. Systems 34(3):863–901.Crossref, Google Scholar
- (2016a) “Cargo cult” science in traditional organization and information systems survey research: A case for using nontraditional methods of data collection, including Mechanical Turk and online panels. J. Strategic Inform. Systems 25(3):232–240.Crossref, Google Scholar
- (2013a) The drivers in the use of online whistle-blowing reporting systems. J. Management Inform. Systems 30(1):153–189.Crossref, Google Scholar
- (2015) Leveraging fairness and reactance theories to deter reactive computer abuse following enhanced organisational information security policies: An empirical study of the influence of counterfactual reasoning and organisational trust. Inform. Systems J. 25(3):193–273.Crossref, Google Scholar
- (2013b) Is your banker leaking your personal information? The roles of ethics and individual-level cultural characteristics in predicting organizational computer abuse. J. Bus. Ethics 121(3):385–401.Crossref, Google Scholar
- (2016b) Why do adults engage in cyberbullying on social media? An integration of online disinhibition and deindividuation effects with the social structure and social learning model. Inform. Systems Res. 27(4):962–986.Link, Google Scholar
- (2019) An integrative theory addressing cyberharassment in the light of technology-based opportunism. J. Management Inform. Systems 36(4):1142–1178.Crossref, Google Scholar
- (2020) Why individual employees commit malicious computer abuse: A routine activity theory perspective. J. Assoc. Inform. Systems 21(6):1552–1593.Google Scholar
- (1977) Deterrence as social control: The legal and extralegal production of conformity. Amer. Sociol. Rev. 42(2):292–304.Crossref, Google Scholar
- (2018) The impact of collectivism and psychological ownership on protection motivation: A cross-cultural examination. Comput. Security 75(June):147–166.Crossref, Google Scholar
- (1968) Social Theory and Social Structure (Free Press, New York).Google Scholar
- (2018) 2017 U.S. state of cybercrime highlights. SEI Blog (January 17), https://insights.sei.cmu.edu/insider-threat/2018/01/2017-us-state-of-cybercrime-highlights.html.Google Scholar
- (2018) Toward a unified model of information security policy compliance. MIS Quart. 42(1):285–311.Crossref, Google Scholar
- (1997) When employees feel betrayed: A model of how psychological contract violation develops. Acad. Management Rev. 22(1):226–256.Crossref, Google Scholar
- (2002) Effortful control: Factor structure and relation to externalizing and internalizing behaviors. J. Abnormal Child Psych. 30(5):503–514.Crossref, Google Scholar
- (2009) What levels of moral reasoning and values explain adherence to information security rules? An empirical study. Eur. J. Inform. Systems 18(2):126–139.Crossref, Google Scholar
- (1998) Deterrence and incapacitation. Tonry M, ed. The Handbook of Crime and Punishment (Oxford University Press, New York), 345–368.Google Scholar
- (1993) Enduring individual differences and rational choice theories of crime. Law Soc. Rev. 27(3):467–496.Crossref, Google Scholar
- (2001) Integrating celerity, impulsivity, and extralegal sanction threats into a model of general deterrence: Theory and evidence. Criminology 39(4):865–892.Crossref, Google Scholar
- (1978) Psychometric Theory (McGraw-Hill, New York).Google Scholar
- (2017) The role of business intelligence and communication technologies in organizational agility: A configurational approach. J. Assoc. Inform. Systems 18(9):648–686.Google Scholar
- (1955) Family, Socialization and Interaction Process (Free Press, Glencoe, IL).Google Scholar
- (2005) Psychological contract violation in online marketplaces: Antecedents, consequences, and moderating role. Inform. Systems Res. 16(4):372–399.Link, Google Scholar
- (2007) Specifying formative constructs in information systems research. MIS Quart. 31(4):623–656.Crossref, Google Scholar
- (2011) Elaborating the individual difference component in deterrence theory. Annu. Rev. Law Soc. Sci. 7(1):335–360.Crossref, Google Scholar
- (2003) Common method biases in behavioral research: a critical review of the literature and recommended remedies. J. Appl. Psych. 88(5):879–903.Crossref, Google Scholar
- Ponemon Institute (2018) 2018 cost of a data breach report: Global overview. accessed April 18, 2019, https://www.ibm.com/downloads/cas/861MNWN2.Google Scholar
- (2011) Understanding the mindset of the abusive insider: An examination of insiders’ causal reasoning following internal security changes. Comput. Security 30(6):486–497.Crossref, Google Scholar
- (2015) The impact of organizational commitment on insiders’ motivation to protect organizational information assets. J. Management Inform. Systems 32(4):179–214.Crossref, Google Scholar
- (2013) Insiders’ protection of organizational information assets: Development of a systematics-based taxonomy and theory of diversity for protection-motivated behaviors. MIS Quart. 37(4):1189–1210.Crossref, Google Scholar
- PWC (2014) Managing cyber risks in an interconnected world: Key findings from the Global State of Information Security Survey 2015. Acccessed December 12, 2014, https://www.pwc.com/gx/en/consulting-services/information-security-survey/assets/the-global-state-of-information-security-survey-2015.pdf.Google Scholar
- (2018) The short-lived benefits of abusive supervisory behavior for actors: An investigation of recovery and work engagement. Acad. Management J. 61(5):1951–1975.Crossref, Google Scholar
- (2006) Effects of psychological contract breach on performance of IT employees: The mediating role of affective commitment. J. Occupational Organ. Psych. 79(2):299–306.Crossref, Google Scholar
- (2015) SmartPLS3. SmartPLS GmbH, Bönningstedt, Germany.Google Scholar
- (2021) Theory building is neither an art nor a science: It is a craft. J. Inform. Tech. 36(3):316–328.Crossref, Google Scholar
- (1995) A typology of deviant workplace behaviors: A multidimensional scaling study. Acad. Management J. 38(2):555–572.Crossref, Google Scholar
- (1997) Workplace deviance: Its definition, its manifestations, and its causes. Lewicki RJ, Bies RJ, Sheppard BH, eds. Research on Negotiations in Organizations, vol. 6 (Elsevier, Amsterdam), 3–27.Google Scholar
- (2000) The development of psychological contract breach and violation: A longitudinal study. J. Organ. Behav. 21(5):525–546.Crossref, Google Scholar
- (1998) Monkey see, monkey do: The influence of work groups on the antisocial behavior of employees. Acad. Management J. 41(6):658–672.Crossref, Google Scholar
- (1989) Psychological and implied contracts in organizations. Employee Responsibilities Rights J. 2(2):121–139.Crossref, Google Scholar
- (2004) Psychological contracts in the workplace: Understanding the ties that motivate. Acad. Management Perspect. 18(1):120–127.Crossref, Google Scholar
- (1999) Criminal victimization and low self-control: An extension and test of a general theory of crime. Justice Quart. 16(3):633–654.Crossref, Google Scholar
- (2008) A reappraisal of the overlap of violent offenders and victims. Criminology 46(4):871–906.Crossref, Google Scholar
- (2017) Examining the impact and detection of the urban legend of common method bias. ACM SIGMIS Database 48(1):93–119.Crossref, Google Scholar
- (2010) Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quart. 34(3):487–502.Crossref, Google Scholar
- (2014) Understanding the drivers of unethical programming behavior: The inappropriate reuse of Internet-accessible code. J. Management Inform. Systems 31(3):287–325.Crossref, Google Scholar
- (2019) Post-hoc statistical power calculator for hierarchical multiple regression, version 4.0, Accessed January 16, 2019, https://www.danielsoper.com/statcalc/calculator.aspx?id=17.Google Scholar
- (2017) “Going viral” and “Going country”: The expressive and instrumental activities of street gangs on social media. J. Youth Stud. 20(6):677–696.Crossref, Google Scholar
- (1990) Effective IS security. Inform. Systems Res. 1(3):255–276.Link, Google Scholar
- (1990) Discovering and disciplining computer abuse in organizations: A field study. MIS Quart. 14(1):45–60.Crossref, Google Scholar
- (2004) Integrating expectations, experiences, and psychological contract violations: A longitudinal study of new professionals. J. Occupational Organ. Psych. 77(4):493–514.Crossref, Google Scholar
- (2004) High self-control predicts good adjustment, less pathology, better grades, and interpersonal success. J. Personality 72(2):271–324.Crossref, Google Scholar
- (2005) Extending the chain of relationships among organizational justice, social exchange, and employee reactions: The role of contract violations. Acad. Management J. 48(1):146–157.Crossref, Google Scholar
- (2002) Individual propensities and rational decision-making: Recent findings and promising approaches. Piquero AR, Tibbetts SG, eds. Rational Choice and Criminal Behavior Recent Research and Future Challenges (Routledge, New York), 3–24.Google Scholar
- (2009) Governance-knowledge fit in systems development projects. Inform. Systems Res. 20(2):180–197.Link, Google Scholar
- (2015) Evolutionary competition in platform ecosystems. Inform. Systems Res. 26(2):266–281.Link, Google Scholar
- (2014) “Can’t stop, won’t stop”: Self-control, risky lifestyles, and repeat victimization. J. Quant. Criminol. 30(1):29–56.Crossref, Google Scholar
- (2013) Using accountability to reduce access policy violations in information systems. J. Management Inform. Systems 29(4):263–289.Crossref, Google Scholar
- (2001) The effects of organizational and ethical climates on misconduct at work. J. Bus. Ethics 29(4):325–337.Crossref, Google Scholar
- (1964) Work and Motivation (Wiley, Oxford, UK).Google Scholar
- (2007) Offender and crime characteristics of female serial arsonists in Japan. J. Investigative Psych. Offender Profiling 4(1):29–52.Crossref, Google Scholar
- (2011) Daily customer mistreatment and employee sabotage against customers: Examining emotion and resource perspectives. Acad. Management J. 54(2):312–334.Crossref, Google Scholar
- (2020) Beyond depletion: Daily self‐control motivation as an explanation of self‐control failure at work. J. Organ. Behav. 41(9):931–947.Crossref, Google Scholar
- (2009) Using PLS path modeling for assessing hierarchical construct models: Guidelines and empirical illustration. MIS Quart. 33(1):177–196.Crossref, Google Scholar
- (2018) Disentangling the motivations for organizational insider computer abuse through the rational choice and life course perspectives. ACM SIGMIS Database 49(S1):81–102.Crossref, Google Scholar
- (2013) Beyond deterrence: An expanded view of employee computer abuse. MIS Quart. 37(1):1–20.Crossref, Google Scholar
- (2018a) A tale of two deterrents: Considering the role of absolute and restrictive deterrence in inspiring new directions in behavioral and organizational security. J. Assoc. Inform. Systems 19(12):1187–1216.Google Scholar
- (2018b) Examining employee computer abuse intentions: Insights from justice, deterrence and neutralization perspectives. Inform. Systems J. 28(2):266–293.Crossref, Google Scholar
- (2016) Internet aggression in online communities: A contemporary deterrence perspective. Inform. Systems J. 26(6):641–667.Crossref, Google Scholar
- (2016) Expressive and instrumental offending: Reconciling the paradox of specialisation and versatility. Internat. J. Offender Therapy Comparative Criminology 60(4):397–422.Crossref, Google Scholar
- (1994) Punishment celerity and severity: Testing a specific deterrence model on drunk driving recidivism. J. Criminal Justice 22(4):355–366.Crossref, Google Scholar
- (2007) The impact of psychological contract breach on work‐related outcomes: A meta‐analysis. Personnel Psych. 60(3):647–680.Crossref, Google Scholar

