Using Theories of Formal Control, Mandatoriness, and Reactance to Explain Working Professionals’ Intent to Comply with New IT Security Policies
Paul Benjamin Lowry, Noelle Teh, Braden Molyneux, Son Ngoc Bui · SSRN Electronic Journal · 2010
Substantial research has shown that employees are both a major IT security threat but also a potential security ally in organizations. Recent behavioral IS security research has looked at ways to increase IT security compliance with employees to mitigate this substantial threat. Research has typically focused on deterrence theory as a means of influencing individuals to comply, though the results of this research have been mixed - showing that oftentimes deterrence approaches backfire into undesired behavior. More recently control theory has been extended using the construct of mandatoriness as a key construct in predicting employee compliance. However, to date, research has not very well addressed why deterrence and control approaches can backfire. Better understanding this phenomenon can better help researchers and practictioners understand how to implement effective IT security policies. Accordingly, we introduce psychological reactance theory as an innovative theory that can explain why controlling approaches to IT security policies can backfire. The theory explains that when an individual’s freedoms are threatened, he or she will respond with reactance by attempting to reestablish the threatened freedoms. We thus combined control theory and reactance theory into a cohesive model, the control-reactance model, to better address the inherent conflict between the andatoriness and threats to freedom. We found that the general perception of mandatoriness was influential in the perceived mandatoriness of a newly introduced policy, which also positively predicted subsequent intent to comply. We also discovered that the threat to freedom was the most salient construct in predicting reactance, which reactance then leads to a decreased intent to comply. Given these sets of results, we conclude that while creating a sense of mandatoriness is important for compliance, if this sense of mandatoriness is over communicated or if the policy is too restrictive of personal freedoms (regardless of how good of an idea it is), new IT policies can backfire on organizations and create negative unintended consequences. From these findings, we propose recommendations for practice, including carefully communicating policy, understanding the importance of freedoms to employees, and establishing an environment of threat awareness.