The Effectiveness of Abstract Versus Concrete Fear Appeals in Information Security
Sebastian Walter Schuetz, Paul Benjamin Lowry, Daniel Pienta, Jason Bennett Thatcher · Journal of Management Information Systems · 2020
Sebastian W. Schuetza, Paul Benjamin Lowryb*, Daniel A. Pientac & Jason Bennett Thatcherda Department of Information Systems and Business Analytics, College of Business, Florida International University, Miami, FL, USAb Department of Business Information Technology, Pamplin College of Business, Virginia Tech, Blacksburg, VA, USAc Hankamer School of Business, Baylor University, Waco, TX, USAd Department of Management Information Systems, Temple University, Philadelphia, PA, USASebastian W. Schuetz is an Assistant Professor at Florida International University. He received his Ph.D. in Information systems from the City University of Hong Kong in 2017. His research interests relate to information security management and the societal implications of information technology. His work has appeared, among others, in the Journal of Management Information Systems, Journal of the AIS, Information Systems Journal, and several international conferences.Paul Benjamin Lowry is the Suzanne Parker Thornhill Chair Professor and Eminent Scholar at the Pamplin College of Business at Virginia Tech. He is also the BIT Ph.D. program director. He received his Ph.D. in Management Information Systems from the University of Arizona. His research interests include organizational and behavioral security and privacy; online deviance, online harassment, and computer ethics; human-computer interaction, social media, and gamification; and business analytics, decision sciences, innovation, and supply chains. Dr. Lowry has published over 127 papers in the Journal of Management Information Systems (JMIS), MIS Quarterly, Information Systems Research, Journal of the AIS (JAIS), Information System Journal (ISJ), European Journal of Information Systems, and others. He is a member of the Editorial Board of JMIS, a department editor of Decision Sciences, and senior editor of JAIS and ISJ.Daniel A. Pienta is an Assistant Professor at Baylor University. He received his Ph.D. in Information Systems from Clemson University. His research focuses on behavioral and technical cybersecurity. He has worked as the managing director of a cybersecurity and due diligence consulting firm, specialized in servicing some of the largest commercial lending institutions. He has extensive experience in penetration testing, information system design and development, and user experience. His work has appeared or is forthcoming in Journal of Management Information Systems, Journal of Information Technology, Communications of the AIS, and the proceedings of several international conferences.Jason Bennett Thatcher holds the Milton F. Stauffer Professorship in the Department of Management Information Systems at the Fox School of Business of Temple University. Dr. Thatcher’s research examines the influence of individual beliefs and characteristics on technology use, cybersecurity, and IT human resource management in organizations. His work appears in the Journal of Management Information Systems, MIS Quarterly, Information Systems Research, Journal of Applied Psychology, Organizational Behavior and Human Decision Processes, and Journal of the AIS. He has served as President of the Association for Information Systems and Senior Editor at MIS Quarterly.CONTACT Paul Benjamin Lowry [email protected] Department of Business Information Technology, Pamplin College of Business, Virginia Tech, Pamplin Hall, Suite 1007, 880 West Campus Drive, Blacksburg, VA 24061 USA.ABSTRACTInformation security (ISec) is a pervasive concern of individuals, organizations, and governments. To encourage individuals to engage in and learn about secure behaviors, ISec research has turned to fear appeals, which are short messages that communicate threats and efficacy to elicit protection motivation among recipients. ISec research has reported contradictory findings on what makes fear appeals effective in ISec contexts, and this lack of clarity is problematic, because it may lead to incorrect conclusions. For example, some studies have argued that the mixed findings arise from differences between personal and organizational contexts and that fear appeals do not work well among organizational users. However, this argument has not been empirically tested, and differences in message design provide an equally plausible explanation, which has also not been tested. To reconcile the mixed findings across these studies, we test the effects of context (i.e., personal users vs. organizational users) and degree of message abstractness (i.e., abstract vs. concrete) on fear-appeal outcomes. We draw from construal-level theory to conceptualize the differences between abstract and concrete fear appeals. Across three experiments, we find evidence that concrete fear appeals are more effective than abstract fear appeals for the purpose of stimulating fear-appeal outcomes. Furthermore, by comparing two identical experiments—one conducted with personal users and another conducted with organizational users—we find differences in participants’ responses to fear appeals. However, contrary to our expectations, our findings suggest that organizational users report higher levels of fear and protection motivation than personal users. This finding is not a theoretical contradiction: the theoretical crux of an effective fear appeal is that it must be personally relevant to stimulate fear; correspondingly, we show that concrete fear appeals help stimulate fear and the desired protective response. Moreover, concrete fear appeals increase actual compliance behaviors, not just intentions. Thus, our findings suggest that the mixed findings in the literature may be a product of message abstractness and differences among audiences. This has pivotal implications for how to construct fear appeals in research and practice.