
- Perception of the burden of compliance: Employees who perceive the action required to guard corporate information as time-consuming or hard to do (with extra steps to make), don’t perform the action or do so only occasionally.
- Policy knowledge: Some employees don’t know or understand what is wrong with a certain behavior or what to do to be secure, so they act insecurely without realizing it.
- Judgment: Often times, employees face work situations that have ambiguous security implications. These tend to be situations where policies do not (and cannot) exist, requiring them to make a judgment call on whether something is risky. The most obvious example is links or attachments in email. Most of these are benign and need to be opened; it takes judgment to spot the suspicious ones that might be a phishing email.
- Risk perception: If employees don’t believe an action is risky, they are more likely to perform it even if they know it’s against policy.
- Emotional commitment: This is the belief that behaving securely is just “the right thing to do”, regardless of policy or consequences to the actor for doing the wrong thing.
- Self-interest in security: Fear of sanctions from non-adherence or the promise of reward from adherence affect employees’ secure behavior.
