Be Careful What You Wish For: Proposing the IT Policy Control-Reactance Model (ITPCRM) to Predict Professionals’ Intent to Comply with New IT Security Policies Along with Their Resulting Anger
Paul Benjamin Lowry, Noelle Teh, Braden Molyneux, Son Ngoc Bui · SSRN Electronic Journal · 2013
Because employees are major IT security threats in organizations, recent behavioral IS security research has looked at ways to increase IT security compliance. Unfortunately, many of these approaches — especially those based on deterrence theory and other controlling approaches — can backfire. Accordingly, we introduce psychological reactance theory as an innovative theory to explain why controlling approaches to IT security policies can backfire. The theory explains that, when an individual’s freedoms are threatened, he or she will respond by attempting to reestablish the threatened freedoms. For nomological validity and explanatory power, we combined control theory, mandatoriness, and reactance theory into a comprehensive model — IT Policy Control-Reactance Model (ITPCRM) — to explain and predict, for the first time, the inherent conflicts between increased control and mandatoriness that may increase IT security policy compliance yet threaten personal freedom in a manner that causes reactance as subsequent negative results. Testing ITPCRM with 320 working professionals demonstrated that that while creating mandatoriness helps intent to comply with a new IT security policy, if this sense of mandatoriness is delivered through high levels of control or controlling language, it also creates reactance, anger, and decreased intent to comply with a new IT security policy. From these findings, we propose recommendations for practice, including carefully communicating policy, understanding the importance of freedoms for employees, and establishing an environment of threat awareness.