Rethinking the Impact of Informal Organizational Rules on Organizational Cybersecurity

M. M. Kasim · 2023

Information and communication technologies (ICTs) have brought unprecedented benefits to humanity. However, despite that, they have come along with many cybersecurity challenges that organizations must worry about. Organizations not only have to consider technical cybersecurity measures but also social measures that transcend the best cybersecurity protocols. Formal rules are one of the measures that organizations adopt to protect their systems against internal and external threats. However, organizations need to pay more attention to the negative impact on organizational cybersecurity. This leads to the formulation of informal rules that could be dangerous to organizational cybersecurity. This chapter reviews the literature related to formal and informal rules. The aim is to understand how formal and informal organizational rules promote or compromise organizational cybersecurity. The result of the review established that inasmuch as formal rules can promote cybersecurity, certain circumstances can compromise it. And inasmuch as informal rules are known to compromise organizational cybersecurity, they could be used to promote compliant behavior related to cybersecurity.

Read the paper · More papers on PaperTik