The Non-Malicious Risky Behavior in the Enterprise Information System Security
Saiyidi Mat Roni, Hadrian Geri Djajadikerta, Terri Trireksani · 2022
Focus on insider threats to organization information system assets primarily lays an emphasis on malicious security incidences. The practice comes to no surprise as the intentional destructive behavior typically makes headlines. However, non-malicious and often unintentional employee actions are also equally damaging. Therefore, in this chapter, we examine the human and organizational factors that trigger or motivate non-malicious inside actors to engage in risky behaviors. Regression analyses using 2,000 bootstrap samples suggest that the 85 middle managers surveyed are likely to engage in non-malicious risky behaviors when such action is reasonably expected from other co-workers and can improve the quality of their outputs. This is regardless of how the job performance is evaluated and the level of the complexity of the organization information system.