<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>September</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Nudging Towards Compliance? Assessing the Impact of Nudging Strategies on Information Security Policy Adherence</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Theresa Pfaff</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Goettingen</institution>
          ,
          <addr-line>Goettingen</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Paderborn</institution>
          ,
          <addr-line>Paderborn</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <volume>18</volume>
      <issue>2023</issue>
      <fpage>70</fpage>
      <lpage>76</lpage>
      <abstract>
        <p>Data breaches pose a significant economic risk to companies in their daily business. To mitigate this risk, organizations implement information security policies (ISPs) to guide their employee's behavior. However, employees often fail to comply with these policies. To address this issue and promote desired behavior, the concept of nudging has emerged as a potential strategy. By leveraging insights from the dual-process theory, which recognizes two distinct cognitive systems involved in decision-making, this ongoing research aims to explore the effectiveness of nudging strategies through an online experiment. Specifically, it investigates whether information security policy messages can nudge employees towards adopting more secure behaviors by targeting their intuitive responses (System 1) or invoking critical thinking (System 2). This research seeks to advance our understanding of behavioral interventions in the context of information security and has the potential to provide valuable insights for designing effective strategies to promote ISP compliance.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;ISP Compliance</kwd>
        <kwd>Digital Nudging Strategies</kwd>
        <kwd>Dual-Process Theory</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        One of the most prominent threats to organizational information assets comes from employees
who have regular access to these resources [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. To mitigate the risks posed by insider threats,
organizations adapt their risk management by implementing ISPs as a crucial instrument to
reduce vulnerabilities and guide employee behavior. ISPs are a documented set of rules and
guidelines that outline how an organization protects its sensitive information and manages
information security risks [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. It is a necessary tool as organizations face significant risks from
cyberattacks and data breaches targeting their internal information, resulting in substantial costs
for the affected company [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        Research indicates that individuals often exhibit inappropriate and insecure behavior because
they often prioritize convenience over adhering to information security policies [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Prior studies
have examined various factors influencing employee compliance from a rational standpoint.
Recent studies looked at employee’s behavior by focusing on costs and benefits of compliance
based on rational choice theory [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], threat and coping assessment by utilizing protection
motivation theory [
        <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
        ], and exerting pressure by using general deterrence theory including the
assessment of potential sanctions [
        <xref ref-type="bibr" rid="ref10 ref11 ref9">9, 10, 11</xref>
        ]. While these studies provide valuable insights, they
often focus on factors to explain certain behavior or to understand employees decision-making
processes in a work environment. For example, most studies in this field specifically focus on
employees' attitudes, knowledge, and intentions towards ISP compliance. They, furthermore,
often explore the role of individual factors, such as awareness, perception of risk, and
organizational support, in order to make the black-box of humans’ decision-making-processes
more transparent [
        <xref ref-type="bibr" rid="ref12 ref13">12, 13</xref>
        ]. While research has provided valuable insights into the factors that
contribute to understanding security behavior, the question how to get employees towards the
desired behavior has not been investigated yet. Deterrence measures for example, like
punishment may effectively force employees towards the desired outcome [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Still, they also
provoke a work environment built on fear and dissatisfaction. Surprisingly and to the best of our
knowledge, no study has thought about the concept of nudging in this context i.e., how to
strategically nudge employees towards the desired behavior. A recent study by [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] has shown
that different types of employees react differently in their compliance behavior to certain
deterrents. Therefore, it is reasonable to assume that this could also be the case with different
nudge messages addressing different systems. In this context, nudging refers to the use of certain
design elements in a user interface to influence users' choices while using IS [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>At the same time, most studies only focus on factors affecting employee compliance on both a
rational and deliberated level. Consequently, there is a need to delve deeper into the less-explored
dimensions of employee compliance, also considering non-rational and automated aspects that
may influence their behavior. This research aims to fill this gap by investigating the dual-process
nature of employees' cognitive responses to information security nudge messages. Therefore, this
study seeks to answer the research question (RQ):</p>
      <p>RQ: How can information security policy (ISP) messages nudge employees towards a more
compliant behavior?</p>
      <p>The aim of this research is to investigate whether and how information security policy
messages can effectively nudge employees towards enhanced compliance with ISPs as this is the
desired behavior from an organizational perspective. The study further seeks to uncover the
mechanisms through which these policy messages influence employees' cognitive processes,
specifically their gut reactions (System 1) and/or critical thinking (System 2). By unraveling the
impact of information security policy messages on employees' cognitive processes, the research
aims to contribute to the understanding of behavioral interventions in the context of information
security and provide insights for designing more effective strategies to promote ISP compliance.
The aim of this research in progress paper is to present a status quo of current undertakings and
to provide an outlook on further actions.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Theoretical Background</title>
      <sec id="sec-2-1">
        <title>2.1. Dual-Process Theory</title>
        <p>
          First The dual-process theory posits that human cognition and decision-making involve two
distinct cognitive processes: System 1 and System 2. System 1 thinking is automatic, intuitive, and
fast, driven by heuristics and immediate emotional responses. On the other hand, System 2
thinking is reflective, deliberate, and analytical, involving conscious reasoning and cognitive
effort [
          <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
          ]. In the context of investigating information security policy compliance, the
dualprocess theory provides a suitable theoretical lens for several reasons. In order to understand
employees' compliance behavior, it requires examining both, their automatic, intuitive responses
(System 1) and their reflective, deliberative processes (System 2). By considering the interplay
between these cognitive processes, insights into the factors influencing employees'
decisionmaking can be gained. For example, [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ] found that presenting fact-checking results in a
combined approach targeting both systems, automatic cognition via symbols and deliberate
cognition via text phrases, was twice as effective in detecting fake news compared to settings
where only one system was primarily addressed. Additionally, the theory helps to explain why
employees may exhibit inconsistent compliance behavior. System 1 responses, driven by
heuristics and emotions, can lead to impulsive or careless actions that deviate from established
policies [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. System 2 thinking, on the other hand, allows employees to engage in conscious
reasoning and critically evaluate the implications of their behavior in terms of information
security. The dual-process theory also highlights the potential conflicts and trade-offs between
System 1 and System 2 processes [
          <xref ref-type="bibr" rid="ref20 ref21">20, 21</xref>
          ]. Employees may face cognitive biases, such as cognitive
dissonance or anchoring, that influence their decision-making and adherence to security policies.
Understanding these conflicts can provide valuable insights for designing effective nudging
strategies that target both automatic and reflective cognitive processes.
        </p>
        <p>Overall, the dual-process theory provides a comprehensive framework for examining the
cognitive mechanisms underlying employees' compliance behavior and offers guidance for
designing interventions that effectively promote information security policy compliance.
paragraph in every section does not have first-line indent. Use only styles embedded in the
document.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Digital Nudging towards Desired Behavior</title>
        <p>
          Digital nudging refers to the strategic use of subtle and non-intrusive digital interventions aimed
at guiding individuals' decision-making and influencing their behavior towards desired outcomes
[
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. Rooted in behavioral economics and psychology, digital nudging leverages principles of
choice architecture to shape decisions without resorting to strict regulations or mandates. In the
context of employees' compliance with ISPs, investigating nudging strategies becomes imperative
due to the persistent challenge of motivating employees to adhere to established security
protocols. Traditional approaches, such as training programs and enforcement measures, often
fall short in effectively modifying employees' behavior. By exploring the potential of digital
nudging techniques, organizations can harness the power of choice architecture to nudge
employees towards more secure behaviors.
        </p>
        <p>
          This research endeavors to examine the efficacy of nudging strategies in the realm of ISP
compliance, aiming to provide valuable insights into the design of interventions that align with
employees' decision-making processes, thereby fostering a culture of enhanced information
security while respecting individuals' autonomy and decision-making agency. Nudging strategies
are applied in various contexts, such as public health decisions, consumer behavior, or tax
compliance [
          <xref ref-type="bibr" rid="ref15 ref22 ref23">15, 22, 23</xref>
          ]. While there is an upcoming trend of examining nudging in privacy and
security context, research primarily focuses on privacy settings, password creation or phishing
detection [
          <xref ref-type="bibr" rid="ref24 ref25 ref26">24, 25, 26</xref>
          ]. However, recent literature claims to further extend the design of nudges
to other scenarios in cybersecurity, such as protection of data [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Hypotheses Development and Research Model</title>
      <p>
        The goal of an intervention aiming to influence cognitive functions in System 1 is to provide an
intuitively clear stimulus, according to [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Simple visual signs can be understood fast and with
less cognitive effort [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] making it a suitable nudge strategy, triggering heuristic and immediate
responses. Contrary to this, textual detailed information will more likely trigger System 2 as it
takes more time and effort to process the given information. Understanding text arguments and
connecting them to prior knowledge requires deliberate attention to detail, which is usually part
of System 2 cognition [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. In their study, [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] revealed that a security nudge text-message can
increase users security behavior. Especially messages emphasizing the threat and the
corresponding coping behavior were most effective. Therefore, it is expected:
H1a: Employees' ISP compliance behavior with a System 1 nudge strategy is enhanced when
compared to decision settings in which no nudge is applied.
      </p>
      <p>H1b: Employees' ISP compliance behavior with a System 2 nudge strategy is enhanced when
compared to decision settings in which no nudge is applied.</p>
      <p>
        However, system 1 and system 2 cannot be strictly separated as both systems are considered
rather complements than substitutes [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. An intervention that combines the two theories will
likely have a greater effect than the two single-interventions if they are both, primarily, acting
through one theoretical route. If both single interventions primarily act through one theoretical
route, then an intervention that combines the two strategies and triggers both systems
simultaneously will likely have a better effect than the single-interventions [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. Therefore, it is
stated:
H2: The combination of both nudging strategies is more effective than no nudge or a single
nudge applied.
      </p>
      <p>
        Information security policy compliance is more likely to occur if employees believe their
managers, IT personnel, or peers expect them to comply [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. However, work environments are
dynamic environments with arising situational characteristics such as demanding colleagues and
finding workarounds [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ]. Conversely, if peers, IT personnel, or managers themselves do not
adhere to policies this, then employees might adapt this behavior. Moreover, if these peers put
colleagues into demanding situations this, can result in peer pressure which is defined as
influencing or urging individuals to do something, regardless of whether they personally want to
or not [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. It can be argued that peers not following ISPs will cause other employees to break the
rules and diminish the effect of nudge messages towards ISP compliance, leading to the following
hypotheses:
      </p>
      <p>H3: The perceived peer pressure from colleagues to deviate from the ISP will negatively
impact employees' ISP compliance behavior.</p>
      <p>H4a: The perceived peer pressure from colleagues to deviate from the ISP will weaken the
impact of the System 1 nudge strategy on employees' ISP compliance.</p>
      <p>H4b: The perceived peer pressure from colleagues to deviate from the ISP will weaken the
impact of the System 2 nudge strategy on employees' ISP compliance.</p>
      <p>H5: The perceived peer pressure from colleagues to deviate from the ISP will weaken the
impact of the combined nudge strategy on employees' ISP compliance.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Methodology</title>
      <p>
        To test the proposed model, a four-condition between-subjects design will be applied in an online
experiment where ISP compliance will be measured through an in-basket task. Participants will
be required to respond to incoming mails from fictive colleagues, assessing their compliance
behavior. An in-basket task with emails provides a realistic simulation of employees' work
environment, allowing researchers to assess compliance behavior in authentic scenarios [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ].
Emails, being a common communication mode in organizations, offer a relevant context for
measuring ISP compliance. The design for this email task will follow [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ], [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. For
evaluation, a binary coding scheme will be used, assigning a value of "0" for non-compliance and
"1" for compliance. The design of the ISP nudge messages is based on the approaches of [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ],
[
        <xref ref-type="bibr" rid="ref33">33</xref>
        ] and will appear right before participants start with their task. Perceived peer pressure will
be assessed using a 7-point Likert scale ranging from 1="strongly disagree" to 7="strongly agree".
The specific items, as well as the complete in-basket task, are currently under development and
will be presented in a future research paper. A potential challenge in this study is the power of
the nudge message, which needs to be strong enough to interfere across multiple mails.
Therefore, a pilot study will be carried out first. To conduct data analysis and test the proposed
research model, H1a/b will be evaluated using unpaired t-tests while H2 will be assessed with a
one-way ANOVA. Hypotheses 3 to 5 will be tested using structural equation modelling (SEM) with
the software SmartPLS.
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion</title>
      <p>In conclusion, this study aims to investigate the effectiveness of different nudging strategies in
enhancing employees' ISP compliance behavior. Building upon the dual-process theory, which
suggests that individuals' decision-making can be influenced by both intuitive (System 1) and
reflective (System 2) processes, the study explores the impact of System 1 and System 2 digital
nudge messages on employees' ISP compliance behavior. A potential challenge in this study is the
power of the nudge message, which needs to be strong enough to interfere across multiple mails.
By examining the individual and combined effects of visual and textual nudges, the study seeks to
provide insights into the mechanisms through which these nudges influence employees' cognitive
processes. The findings of this study will contribute to the understanding of behavioral
interventions in the context of information security. Ultimately, the study aims to advance
knowledge in the field and provide practical recommendations for organizations seeking to
improve their employees' adherence to information security policies.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M.</given-names>
            <surname>Warkentin</surname>
          </string-name>
          and
          <string-name>
            <given-names>R.</given-names>
            <surname>Willison</surname>
          </string-name>
          , “
          <article-title>Behavioral and policy issues in information systems security: The insider threat,”</article-title>
          <string-name>
            <given-names>Eur. J.</given-names>
            <surname>Inf</surname>
          </string-name>
          . Syst., vol.
          <volume>18</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>101</fpage>
          -
          <lpage>105</lpage>
          ,
          <year>2009</year>
          , doi: 10.1057/ejis.
          <year>2009</year>
          .
          <volume>12</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>R.</given-names>
            <surname>Willison</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Warkentin</surname>
          </string-name>
          , “
          <article-title>Beyond deterrence: An expanded view of employee computer abuse,” MIS</article-title>
          <string-name>
            <given-names>Q.</given-names>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>37</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          ,
          <year>2013</year>
          , doi: 10.25300/MISQ/
          <year>2013</year>
          /37.1.01.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D.</given-names>
            <surname>Ormond</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Warkentin</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R. E.</given-names>
            <surname>Crossler</surname>
          </string-name>
          , “
          <article-title>Integrating cognition with an affective lens to better understand information security policy compliance,”</article-title>
          <string-name>
            <given-names>J.</given-names>
            <surname>Assoc</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>20</volume>
          , no.
          <issue>12</issue>
          , pp.
          <fpage>1794</fpage>
          -
          <lpage>1843</lpage>
          ,
          <year>2019</year>
          , doi: 10.17705/1jais.
          <fpage>00586</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>H.</given-names>
            <surname>Cavusoglu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Mishra</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Raghunathan</surname>
          </string-name>
          , “
          <article-title>A model for evaluating IT security investments</article-title>
          ,
          <source>” Commun. ACM</source>
          , vol.
          <volume>47</volume>
          , no.
          <issue>7</issue>
          , pp.
          <fpage>87</fpage>
          -
          <lpage>92</lpage>
          ,
          <year>2004</year>
          , doi: 10.1145/1005817.1005828.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>J. D'Arcy and P. B. Lowry</surname>
          </string-name>
          , “
          <article-title>Cognitive-affective drivers of employees' daily compliance with information security policies: A multilevel, longitudinal study</article-title>
          ,
          <source>” Inf. Syst. J.</source>
          , vol.
          <volume>29</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>43</fpage>
          -
          <lpage>69</lpage>
          ,
          <year>2019</year>
          , doi: 10.1111/isj.12173.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>H.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Sarathy</surname>
          </string-name>
          , “
          <article-title>Understanding compliance with internet use policy from the perspective of rational choice theory,”</article-title>
          <string-name>
            <given-names>Decis. Support</given-names>
            <surname>Syst</surname>
          </string-name>
          ., vol.
          <volume>48</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>635</fpage>
          -
          <lpage>645</lpage>
          ,
          <year>2010</year>
          , doi: 10.1016/j.dss.
          <year>2009</year>
          .
          <volume>12</volume>
          .005.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>G. D.</given-names>
            <surname>Moody</surname>
          </string-name>
          , M. Siponen, and
          <string-name>
            <given-names>S.</given-names>
            <surname>Pahnila</surname>
          </string-name>
          , “
          <article-title>Toward a unified model of information security policy compliance,” MIS</article-title>
          <string-name>
            <given-names>Q.</given-names>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>42</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>285</fpage>
          -
          <lpage>311</lpage>
          ,
          <year>2018</year>
          , doi: 10.25300/MISQ/
          <year>2018</year>
          /13853.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Masuch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hengstler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Trang</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Brendel</surname>
          </string-name>
          , “Replication Research of Moody, Siponen, and
          <article-title>Pahnila's Unified Model of Information Security Policy Compliance,”</article-title>
          <source>AIS Trans. Replication Res.</source>
          , vol.
          <volume>6</volume>
          , no.
          <issue>13</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>16</lpage>
          ,
          <year>2020</year>
          , doi: 10.17705/1atrr.
          <fpage>00056</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>J. D'Arcy</surname>
            and
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Herath</surname>
          </string-name>
          , “
          <article-title>A review and analysis of deterrence theory in the IS security literature: Making sense of the disparate findings,”</article-title>
          <string-name>
            <given-names>Eur. J.</given-names>
            <surname>Inf</surname>
          </string-name>
          . Syst., vol.
          <volume>20</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>643</fpage>
          -
          <lpage>658</lpage>
          ,
          <year>2011</year>
          , doi: 10.1057/ejis.
          <year>2011</year>
          .
          <volume>23</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>J. D'Arcy</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Herath</surname>
            , and
            <given-names>M. K.</given-names>
          </string-name>
          <string-name>
            <surname>Shoss</surname>
          </string-name>
          , “
          <article-title>Understanding Employee Responses to Stressful Information Security Requirements: A Coping Perspective,”</article-title>
          <string-name>
            <given-names>J.</given-names>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>31</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>285</fpage>
          -
          <lpage>318</lpage>
          ,
          <year>2014</year>
          , doi: 10.2753/MIS0742-1222310210.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Trang</surname>
          </string-name>
          and
          <string-name>
            <given-names>B.</given-names>
            <surname>Brendel</surname>
          </string-name>
          , “
          <article-title>A Meta-Analysis of Deterrence Theory in Information Security Policy Compliance Research</article-title>
          ,” Inf. Syst. Front., vol.
          <volume>21</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>1265</fpage>
          -
          <lpage>1284</lpage>
          ,
          <year>2019</year>
          , doi: 10.1007/s10796-019-09956-4.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>B.</given-names>
            <surname>Bulgurcu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Cavusoglu</surname>
          </string-name>
          ,
          <string-name>
            <surname>and I. Benbasat</surname>
          </string-name>
          , “
          <article-title>Information Security Policy Compliance: An Empirical Study of Rationality-Based Beliefs</article-title>
          and Information Security Awareness,” MIS
          <string-name>
            <given-names>Q.</given-names>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>34</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>523</fpage>
          -
          <lpage>548</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>L.</given-names>
            <surname>Jaeger</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Eckhardt</surname>
          </string-name>
          , “
          <article-title>When colleagues fail: Examining the role of information security awareness on extra-role security behaviors,” 26th</article-title>
          <string-name>
            <given-names>Eur. Conf. Inf. Syst. Beyond</given-names>
            <surname>Digit</surname>
          </string-name>
          . -
          <source>Facet. Socio-Technical Chang. ECIS</source>
          <year>2018</year>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Hengstler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kuehnel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Masuch</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Nastjuk</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Trang</surname>
          </string-name>
          , “
          <article-title>Should I Really do That? Using Quantile Regression to Examine the Impact of Sanctions on Information Security Policy Compliance Behavior,”</article-title>
          <string-name>
            <surname>Comput. Secur.</surname>
          </string-name>
          , vol.
          <volume>133</volume>
          , p.
          <fpage>103370</fpage>
          ,
          <year>2023</year>
          , doi: 10.1016/j.cose.
          <year>2023</year>
          .
          <volume>103370</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>M.</given-names>
            <surname>Mirbabaie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Marx</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Germies</surname>
          </string-name>
          , “
          <article-title>Conscious Commerce-Digital Nudging</article-title>
          and
          <string-name>
            <surname>Sustainable E-commerce Purchase</surname>
            <given-names>Decisions</given-names>
          </string-name>
          ,” Australas. Conf. Inf. Syst., pp.
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          ,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>K. E.</given-names>
            <surname>Stanovich</surname>
          </string-name>
          and
          <string-name>
            <given-names>R. F.</given-names>
            <surname>West</surname>
          </string-name>
          , “
          <article-title>"Individual differences in reasoning: Implications for the rationality debate?,”</article-title>
          <string-name>
            <given-names>Behav. Brain</given-names>
            <surname>Sci</surname>
          </string-name>
          ., vol.
          <volume>26</volume>
          , no.
          <issue>4</issue>
          , p.
          <fpage>527</fpage>
          ,
          <year>2003</year>
          , doi: 10.1017/S0140525X03210116.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>D.</given-names>
            <surname>Kahneman</surname>
          </string-name>
          , “
          <article-title>A Perspective on Judgment and Choice: Mapping Bounded Rationality,”</article-title>
          <string-name>
            <surname>Am. Psychol.</surname>
          </string-name>
          , vol.
          <volume>58</volume>
          , no.
          <issue>9</issue>
          , pp.
          <fpage>697</fpage>
          -
          <lpage>720</lpage>
          ,
          <year>2003</year>
          , doi: 10.1037/
          <fpage>0003</fpage>
          -
          <lpage>066X</lpage>
          .
          <year>58</year>
          .9.697.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>P. L.</given-names>
            <surname>Moravec</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kim</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Dennis</surname>
          </string-name>
          , “
          <article-title>Appealing to sense and sensibility: System 1 and system 2 interventions for fake news on social media,” Inf</article-title>
          .
          <source>Syst. Res.</source>
          , vol.
          <volume>31</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>987</fpage>
          -
          <lpage>1006</lpage>
          ,
          <year>2020</year>
          , doi: 10.1287/ISRE.
          <year>2020</year>
          .
          <volume>0927</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>J. S. B. T.</given-names>
            <surname>Evans</surname>
          </string-name>
          and
          <string-name>
            <given-names>K. E.</given-names>
            <surname>Stanovich</surname>
          </string-name>
          , “
          <article-title>Dual-Process Theories of Higher Cognition: Advancing the Debate,” Perspect</article-title>
          . Psychol. Sci., vol.
          <volume>8</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>223</fpage>
          -
          <lpage>241</lpage>
          ,
          <year>2013</year>
          , doi: 10.1177/1745691612460685.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>J. S. B. T.</given-names>
            <surname>Evans</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Curtis-Holmes</surname>
          </string-name>
          , “
          <article-title>Rapid responding increases belief bias: Evidence for the dual-process theory of reasoning</article-title>
          ,” Think. Reason., vol.
          <volume>11</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>382</fpage>
          -
          <lpage>389</lpage>
          ,
          <year>2005</year>
          , doi: 10.1080/13546780542000005.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J. S. B. T.</given-names>
            <surname>Evans</surname>
          </string-name>
          , “
          <article-title>Dual-processing accounts of reasoning, judgment</article-title>
          , and social cognition,
          <source>” Annu. Rev. Psychol.</source>
          , vol.
          <volume>59</volume>
          , pp.
          <fpage>255</fpage>
          -
          <lpage>278</lpage>
          ,
          <year>2008</year>
          , doi: 10.1146/annurev.psych.
          <volume>59</volume>
          .103006.093629.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>J.</given-names>
            <surname>Wisdom</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Downs</surname>
          </string-name>
          , and G. Loewenstein, “Promoting Healthy Choices 
          <article-title>: Information versus Convenience Author ( s ): Jessica Wisdom , Julie S . Downs</article-title>
          and George Loewenstein Published by : American Economic Association Stable URL : https://www.jstor.org/stable/25760210 REFERENCES Linked references a,”
          <source>Am. Econ. J. Appl. Econ.</source>
          , vol.
          <volume>2</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>164</fpage>
          -
          <lpage>178</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>A.</given-names>
            <surname>Antinyan</surname>
          </string-name>
          and
          <string-name>
            <given-names>Z.</given-names>
            <surname>Asatryan</surname>
          </string-name>
          , “
          <article-title>Nudging for Tax Compliance: A Meta-Analysis,” SSRN Electron</article-title>
          . J.,
          <source>no. 8500</source>
          ,
          <year>2021</year>
          , doi: 10.2139/ssrn.3680357.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>R. van Bavel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Rodríguez-Priego</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Vila</surname>
          </string-name>
          , and
          <string-name>
            <given-names>P.</given-names>
            <surname>Briggs</surname>
          </string-name>
          , “
          <article-title>Using protection motivation theory in the design of nudges to improve online security behavior,”</article-title>
          <string-name>
            <surname>Int. J. Hum. Comput. Stud.</surname>
          </string-name>
          , vol.
          <volume>123</volume>
          , no.
          <source>September</source>
          <year>2018</year>
          , pp.
          <fpage>29</fpage>
          -
          <lpage>39</lpage>
          ,
          <year>2019</year>
          , doi: 10.1016/j.ijhcs.
          <year>2018</year>
          .
          <volume>11</volume>
          .003.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>V.</given-names>
            <surname>Zimmermann</surname>
          </string-name>
          and
          <string-name>
            <given-names>K.</given-names>
            <surname>Renaud</surname>
          </string-name>
          , “
          <article-title>The nudge puzzle: Matching nudge interventions to cybersecurity decisions,”</article-title>
          <source>ACM Trans. Comput. Interact.</source>
          , vol.
          <volume>28</volume>
          , no.
          <issue>1</issue>
          ,
          <year>2021</year>
          , doi: 10.1145/3429888.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>K.</given-names>
            <surname>Hartwig</surname>
          </string-name>
          and
          <string-name>
            <given-names>C.</given-names>
            <surname>Reuter</surname>
          </string-name>
          , “
          <article-title>Nudge or restraint: How do people assess nudging in cybersecurity - A representative study in germany</article-title>
          ,
          <source>” ACM Int. Conf. Proceeding Ser</source>
          ., pp.
          <fpage>141</fpage>
          -
          <lpage>150</lpage>
          ,
          <year>2021</year>
          , doi: 10.1145/3481357.3481514.
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kirlappos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Parkin</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Sasse</surname>
          </string-name>
          , “
          <article-title>Learning from 'Shadow Security:' Why Understanding Non-Compliant Behaviors Provides the Basis for Effective Security,” USEC'14 Work</article-title>
          . Usable Secur., no.
          <source>February</source>
          ,
          <year>2014</year>
          , doi: 10.14722/usec.
          <year>2014</year>
          .
          <volume>23007</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>D. R.</given-names>
            <surname>Clasen</surname>
          </string-name>
          and
          <string-name>
            <given-names>B. B.</given-names>
            <surname>Brown</surname>
          </string-name>
          , “
          <article-title>The multidimensionality of peer pressure in adolescence,”</article-title>
          <string-name>
            <given-names>J. Youth</given-names>
            <surname>Adolesc</surname>
          </string-name>
          ., vol.
          <volume>14</volume>
          , no.
          <issue>6</issue>
          , pp.
          <fpage>451</fpage>
          -
          <lpage>468</lpage>
          ,
          <year>1985</year>
          , doi: 10.1007/BF02139520.
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>D. S.</given-names>
            <surname>Kiker</surname>
          </string-name>
          and
          <string-name>
            <given-names>S. J.</given-names>
            <surname>Motowidlo</surname>
          </string-name>
          , “
          <article-title>Main and interaction effects of task and contextual performance on supervisory reward decisions</article-title>
          ,
          <source>” J. Appl. Psychol.</source>
          , vol.
          <volume>84</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>602</fpage>
          -
          <lpage>609</lpage>
          ,
          <year>1999</year>
          , doi: 10.1037/
          <fpage>0021</fpage>
          -
          <lpage>9010</lpage>
          .
          <year>84</year>
          .4.602.
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Vance</surname>
          </string-name>
          , “Neutralization:
          <article-title>New Insights into the Problem of Employee Information Systems Security Policy Violations,” MIS</article-title>
          <string-name>
            <given-names>Q.</given-names>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>34</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>487</fpage>
          -
          <lpage>502</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>S.</given-names>
            <surname>Trang</surname>
          </string-name>
          and
          <string-name>
            <surname>I. Nastjuk</surname>
          </string-name>
          , “
          <article-title>Examining the role of stress and information security policy design in information security compliance behaviour: An experimental study of in-task behaviour,” Comput</article-title>
          . Secur., vol.
          <volume>104</volume>
          , p.
          <fpage>102222</fpage>
          ,
          <year>2021</year>
          , doi: 10.1016/j.cose.
          <year>2021</year>
          .
          <volume>102222</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>C.</given-names>
            <surname>Schneider</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Weinmann</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J. Vom</given-names>
            <surname>Brocke</surname>
          </string-name>
          , “
          <article-title>Digital nudging: Guiding online user choices through interface design Designers can create designs that nudge users toward the most desirable option,” Commun</article-title>
          . ACM, vol.
          <volume>61</volume>
          , no.
          <issue>7</issue>
          , pp.
          <fpage>67</fpage>
          -
          <lpage>73</lpage>
          ,
          <year>2018</year>
          , doi: 10.1145/3213765.
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>T.</given-names>
            <surname>Mirsch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Lehrer</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Jung</surname>
          </string-name>
          , “
          <article-title>Making digital nudging applicable: The digital nudge design method</article-title>
          ,
          <source>” Int. Conf. Inf. Syst</source>
          .
          <year>2018</year>
          ,
          <string-name>
            <surname>ICIS</surname>
          </string-name>
          <year>2018</year>
          , no.
          <year>2009</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>16</lpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>