Information Systems Protection Motivation with Ethical Appraisals

Dailin Zheng, Zhiping D. Walter · Journal of Computer Information Systems · 2025

Employee noncompliance with information systems security policies (ISSPs) is a major cause of organizational data breaches. Protection motivation theory (PMT) has been widely used to model ISSP compliance intention. However, the explanatory power of PMT-based models is lower in workplace settings than in personal settings. We propose that this is due to not modeling the moral hazard caused by cost-consequence misalignment, that is, it is the employee who bears compliance cost, but it is the organization that bears the consequences of noncompliance. We modified PMT with moral intensity appraisal to account for additional cognitive appraisals salient when moral hazard arises. Our model accounts for an additional ten percentage variance in compliance intention compared with PMT. Results highlight the role of employee proximity to the organization in ISSP compliance. We propose concrete measures that have the potential to minimize the cost-consequence misalignment and moral hazard in compliance and thereby decreasing noncompliance.

Read the paper · More papers on PaperTik