Shadow information security practices in organizations: The role of information security transparency, overload, and psychological empowerment
Duy Dang-Pham, Nik Thompson, Atif Ahmad, Sean B. Maynard · Computers & Security · 2025
Employees are both the first line of defense in organizations and a significant source of vulnerability. Behavioral research in information security (InfoSec) has predominantly studied the compliance of employees with organizational directives. Less understood are ‘shadow security practices’ – a related category of behavior where employees adopt InfoSec workarounds, albeit to still comply with organizational security needs. We develop a model of the antecedents of employees’ intentions to engage in shadow security practices and empirically test our model through a sample of 433 office workers. Results of our structural equation modeling analysis reveal that both InfoSec overload and psychological empowerment increase intentions to adopt shadow security measures, whereas perceived transparency of organizational InfoSec (through InfoSec communication) reduces this intention. Furthermore, we find that these constructs are interrelated and that InfoSec overload can be increased by both psychological empowerment and InfoSec transparency . Our study develops the theoretical understanding of the important yet under-researched concept of shadow security and presents practical recommendations to effectively manage organizational InfoSec through these factors.