The Roles of Positive and Negative Exemplars in Information Security Strategy
Richard G. Taylor, Sammie L. Robinson · Academy of Information and Management Sciences journal · 2014
INTRODUCTION On September 11, 2001 two planes crashed into the World Trade Center in New York City. Most of us can recall where we were on that morning. For many of us, hearing the date, or remembering 9/11 evokes strong emotions, causing us to automatically feel fear, sadness, hate ... or an overwhelming sense of patriotism. However, by contrast, another date, August 2, 1988 probably doesn't have the same effect. What thoughts come to mind when you think of the name Barack Obama? Again, does the name evoke strong emotions, both positive and negative, depending on your political views? For many African-Americans his name evokes a sense of accomplishment and a belief that anything is possible. Each of these can be considered exemplary; a representative example of what typifies a person, group, event or instance (Zhou, 2008). Exemplary people and events have such an impact that when encountered, they trigger or activate an automatic affective response. This paper will examine how such exemplars, both positive and negative, play a role in an important organizational context: information security strategy. Evidence gathered since the 1980s suggests that organizations continue to be victims of serious incidents that put their information at risk (Hoffer & Straub 1989; Taylor, 2006; Taylor & Brice, 2012). Occurrences of information security breaches continue to be an issue even though there are continually highly publicized events that amplify the risk potential to organizations (Kasperson et al., 1988). These breaches should serve as wake-up calls for managers. Security breaches by some specific individuals (i.e. Edward Snowden) are well-known by company executives, and understandably, cause them to reflect on the level of information security of within their organizations. These executives become concerned that their organization could be vulnerable to the same type of attacks. However, many of security breaches are perpetrated by individuals who still remain unknown, such as the 2013 event that exposed Target customer information Even though the names of the perpetrators are not known; the representative nature of such events, as exemplars (Zhou, 2008) leads executives to question their vulnerability. These recent high profile incidents support the contention that information security is currently not being adequately addressed, leaving many organizations critically exposed. Clearly, security remains a top concern for IS managers, who acknowledge escalating risks to organizational information resulting in financial losses for their organizations. To address the issue of vulnerability to information security threats, organizations must change their current perspective on information security and adopt a new view. The current view of information security is very technology oriented (Taylor, 2008). As a result organizations spend heavily on technology-based solutions to protect organizational information. These technology solutions include firewalls for perimeter security, anti-virus software to prevent viruses and worms, and intrusion detection systems to discover potential abusers (Cavusoglu, et al., 2005). Properly installed and maintained these hardware and software solutions do create a solid foundation for effective information security. However, these technology-based solutions are primarily intended to prevent outsiders from gaining access to organizational information and are thus inadequate to prevent all security breaches. This can ultimately create a false sense of security for an organization (Frolick 2003, Taylor 2006, Taylor & Brice, 2010). The authors' position is that along with these technology-based solutions, organizations must also adopt a human-based approach to address the information security risks introduced by the social and cultural aspects of the human element (Frolick 2003, Taylor, 2008). Understanding information security as a social issue calls for an investigation of organizational behavior issues that may affect information security. …