Skip to article sections
Purpose

The study aims to investigate the role of employee safety voice in improving a company's information security program.

Design/methodology/approach

This study used an experimental design using visual vignettes, mixing four types of safety voice with the gender of the manager.

Findings

Male employees appear to be more effective at influencing managerial intentions to improve security than female employees. Hostile voice was less likely to have an influence on policy making than other voice types.

Research limitations/implications

This cross-disciplinary study bridges information security research with safety science to investigate the role of employee safety voice in influencing supervisor information security decision making. Beyond testing the limits of safety voice in an untried context (information security), the stimuli used in this study may serve as a primer for researchers interested in a more engaging vignette than the more traditional text-based scenario.

Originality/value

To our knowledge, employee voice toward offering input toward information security policies has not been previously investigated. Little research in social science has made use of the visual vignettes as stimuli as this study has.

In the interest of protecting themselves against revenue loss, civil liabilities and reduced credibility, organizations continually look for effective ways in which to improve their information security. Certainly, the best practices and recommendations offered by experts and peers are among the top sources of security input (Cavusoglu et al., 2015), but important insights could be available from within the organization itself. Its employees, the actual end users themselves, could be valuable toward crafting more effective security policies and procedures. Employees serve at the “street level” of the security program through their interaction with the tools and rules invested in and developed by upper management. They are often the most knowledgeable personnel of the strengths and weaknesses of a security program, and their compliance may ultimately lead to its success or failure (Flowerday and Tuyikeze, 2016). Employee consultation on security matters should be considered a vital part of security program development (Paananen et al., 2020).

This type of grassroots input is commonly referred to in the organizational behavior literature as “employee voice” (LePine and Van Dyne, 2001), and when the input is aimed at improving safety within the workplace, it is classified as a subset known as “safety voice” (Bazzoli and Curcuruto, 2021). We consider issues revolving around organizational information security as being one aspect of workplace safety. As Chan and colleagues (2005) point out, information security shares commonalities with workplace safety initiatives. These include the need for compliance by all parties involved, the goal of potential loss reduction through the prevention of accidents and the use of guidelines that often create inconveniences and lost efficiencies. In order to create an overall safer climate, commitment to secure practices and procedures must include both employees and management (Tejay and Winkfield, 2025; Xue et al., 2021).

This study takes a first step toward understanding where employee safety voice fits into improving an organization's information security program. Specifically, we investigate four types of safety voice that have been identified and tested in the employee voice literature in what appears to be the information security context for the first time. Using an experimental research design, we found that safety voice featuring a future-looking orientation was somewhat more effective at encouraging change than present-oriented safety voice. We also found that the gender of the employee offering security suggestions matters, with male employees being significantly more influential than female employees.

Information security policies are typically thought to be developed and instituted by management in a “top-down” approach, often by mimicking the best practices of competitors or following professional recommendations. In the same vein as the belief that an organization's budget indicates its priorities and goals, a set of security policies developed by management can also define organizational leaders' values (von Solms and von Solms, 2004). However, “bottom-up” policies originating with employees can better reflect actual work processes and the idiosyncrasies of specific organizations and, thus, should not be discouraged (Niemimaa and Niemimaa, 2019). It is also thought that employee participation will lead to better security outcomes, including social acceptance and compliance with new policies (Siponen, 2005). In truth, both approaches are likely to be necessary for developing a holistic security program that is appropriate for each particular work setting.

Employee-led security initiatives are only possible in organizations with a culture of openness and a willingness by management to receive employee input. Management may believe that bottom-up suggestions are reactive in nature, possibly because employees tend to be present for incidents occurring at the perimeter of the organization, and not necessarily for attempts to strike strategic areas (Johnston and Hale, 2009). Supervisory support is crucial for establishing an environment that encourages proactive behavior by employees (Xu et al., 2024).

In order to better understand the psychological factors that support a bottom-up security culture that allows for employee safety voice, the current study is grounded in construal-level theory, otherwise known as CLT (Trope and Liberman, 2010). CLT explains that there are differences in psychological distance between events that occur in the present and speculative possibilities that may occur in the future. By psychological distance, CLT describes one's self as a central reference point from which to craft subjective opinions of events that vary by temporality. Events can be mentally removed from the “here and now”, that is present circumstances, by different distance dimensions – temporal, spatial, social and hypothetical (Trope et al., 2007). For instance, people tend to examine a temporally distant future event by focusing on its benefits and desirability, while temporally closer present events are appraised by their feasibility and their influence on highly-specific others (Nakashima et al., 2017). Simply put, future events are often considered in a nebulous “big picture” fashion and present events involve thinking about the concrete information associated with it. Social distance occurs in a similar fashion, with the decision maker judging whether the source providing the event details as either in-group or out-group. Group membership can be made by attributions related to demographics, interpersonal experience, personality traits or other meaningful points of comparison. Generally, the closer in social distance the source is, the more acceptable the details of the event will be (Trope and Liberman, 2010).

For reasons outlined further in the text, this study focuses mainly on temporal and social distance associated with employees voicing a desire for security changes. The following section distinguishes between the different types of safety voice.

Employee voice is defined by LePine and Van Dyne (2001) as “constructive change-oriented communication intended to improve the situation” (p. 326). As this study focuses on the role that employees play in helping shape organizational security programs, we use a subset of this behavior known as “safety voice.” Employees engage in safety voice when they make proactive suggestions meant to prevent future injury and damages by alerting organizational members who have the capability to enact change (Bazzoli and Curcuruto, 2021). As discussed earlier, safety voice is much more likely to occur when an organization has produced a culture of listening to employee recommendations and a history of taking suggestions seriously. The climate in which the organization operates may also play a role in safety voice (Pandolfo et al., 2025), and in the context of information security, that may mean security incidents within an organization's geography or industry will encourage employees to offer safety voice.

Safety voice itself can be classified as one of four types depending on whether it is meant to reinforce current policies or to challenge the status quo (Bazzoli and Curcuruto, 2021). Promotive voice and preventive voice are both future-oriented, meaning that they center on anticipating and adapting to possible future threats. Promotive voice is devoted to making changes, so suggestions usually are of a constructive tone and express a need to depart from what the organization currently does. It is not uncommon for improvements to organizational safety based on promotive voice to require an ongoing and iterative process, as promotive suggestions appear to possess less urgency and extreme language (Pandolfo et al., 2025). Preventive voice, on the other hand, offers advice on how to sustain current practices while defending against future losses. Bazzoli and Curcurato (2021) categorize preventive safety voice as being future-oriented in that it is based on the belief that organizational accidents and disruptions are not reduced through drastic changes to current processes and procedures; rather, preventive voice seeks to correct human errors through remediation and retraining, improving human performance.

The other two types are prohibitive voice and hostile voice, which are both present-oriented and, rather than predicting the future, are instead highly reactive to current conditions and events. Prohibitive voice deems the status quo as being sufficient for safety purposes, but recommendations deal with the factors that seem to undermine current policies and practices. Whistleblowing is thought to be a form of prohibitive voice (Chen and Trevino, 2022). Hostile voice is comparatively more focused on making changes based on criticism of current policies (Le Poire et al., 1992), often appearing as a form of “Monday-morning quarterbacking” and typically with a more combative tone.

A summary of the four types of employee safety voice is provided in Figure 1. We predict that, because they are future-oriented and less reactive in nature, promotive and preventive safety voice from employees will be more effective in terms of encouraging managers to consider information security suggestions than the present-oriented prohibitive and hostile safety voices.

Using promotive or preventive voice to position a change to information security as distant and abstract is expected to make the proposal more agreeable to decision makers. McCrea and colleagues (2008) found that distant, abstract tasks do not tend to specify deadlines, duties or responsibilities, allowing for the possibility of postponing a previously-agreed upon task indefinitely, where closer, concrete tasks do not provide the decision-maker with the same slack. Hernandez (2012) explained this as being a tendency of distal time perspectives promoting one's idealistic self over the more practical, pragmatic self, thus making covenantal relationships more attractive than they would otherwise be. Further, a higher degree of temporal distance likely means that the proposed changes are viewed more optimistically as abstract construals tend not to capture specific factors associated with the risk involved (Lee et al., 2019). All things being equal, we expect that types of voice that express changes to information security procedures as being psychologically distant will be assessed more favorably than types of voice that press that the changes as being needed urgently.

Following the construal-level theory, future-oriented suggestions voiced by employees should be more compelling to decision-makers due to the factors required to perform the change are still distant and less obligatory. Committing resources toward a future procedural change is not as urgent and can still allow reallocation should the need arise later on. Present-oriented safety voice, especially where information security is concerned, does not afford that luxury. The threats to security are occurring now; they cannot be as easily punted down the road by managers. All things being equal (such as the skills, resources and scalability needed to successfully adopt a security change), we predict that the future-oriented promotive and preventive safety voices will be more likely to inspire change, whether or not the change actually transpires. Therefore, we hypothesize the following:

H1.

Future-oriented safety voice (promotive and preventive) will be associated with higher security change intentions than present-oriented safety voice (prohibitive and hostile).

The second hypothesis explores whether gender differences play a factor in how safety voice is perceived by managers. Research on information security within organizations does not appear to have given much attention to gender roles, particularly with regard to expertise and making recommendations for improvement, though there is reason to believe that the gender of the security proponent may have an impact. As discussed earlier as a dimension identified CLT, gender comparisons could be significant enough to represent a source of psychological distance, with gender similarities providing a form of social closeness that could support a safety message. This may be at the root of gender bias within the workplace (Steinbach et al., 2019). Recent research on the long-standing male dominance of CIO positions indicates that male security leaders benefit from stereotypes that expect them to be more agentic, meaning their recommendations are more assertive and confident, than their female counterparts (Bansal and Axelton, 2024). In fact, a “sticky floor” phenomenon was observed that suggests subordinates discount the expertise of female security leaders, at times preventing them from advancing to an appropriate level of authority. Biases emanating from such stereotypes have obvious consequences for not only women seeking to fill leadership roles within organizations but also, as we discuss below, women merely offering their recommendations for improving the security program in their workplaces.

In addition to the effects of social distance outlined by CLT, expectation states theory (EST) has often been enlisted to help explain the differing effects of workplace voice put forth by males and females. EST proposes that status characteristic differences exist between different subsets of employees. Depending on their demographic differences (e.g. gender, age, race, computer experience, etc.), employees may stand to benefit or suffer from the subconscious perceptions of others, which are often perpetuated by stereotyping (Ridgeway and Bourg, 2004). These status differences may manifest when employees offer recommendations to their managers. For example, McClean and colleagues (2022) have found that female voice is more effective when it utilizes characteristics that are counter to typical female gender stereotypes. When female employees speak assertively and confidently instead of politely and humbly, they were perceived as more competent and were more likely to have their ideas endorsed by management. For men, there was no difference in perception of their competence whether they spoke assertively or adopted a more counter-stereotypical polite and humble tone (McClean et al., 2022).

In other studies exploring gender differences, findings have been mixed. In some studies, female voice is more heard than male voice (in predominantly female environments: Howell et al., 2015; in majority male groups: Farh et al., 2020) and the ideas proposed by female employees are perceived as higher quality than those proposed by their male counterparts (Bain et al., 2021). However, male speakers generally enjoy higher perceived role status than female speakers (McClean et al., 2018). We predict that these perceived status differences could apply to suggestions made about information security improvements.

Prior research has noted that women seem to be more receptive to safety information in the workplace, but whether this applies to recommended improvements to information security made by male employees (or by other females) remains open to conjecture. Within the information systems field, perhaps the most pertinent research to the intersection of voice receptivity and gender differences lies in the technology adoption area, in which females have been identified as being more swayed by social influence than males (Gefen and Straub, 1997; Venkatesh and Morris, 2000).

Several factors discussed earlier in the text lead us to believe that male safety voice will be more influential than female safety voice: the preponderance of previous research indicating that male speakers enjoy higher perceived status than female speakers and findings that male voice is perceived favorably regardless of whether it reinforces or counters gender stereotypes (McClain et al., 2022). Thus, we hypothesize the following:

H2.

Male employees will be more influential with safety voice proposing information security changes than female employees.

Due to the exploratory nature of the two hypotheses, only the main effects related to safety voice orientation and the gender of the recommending employee are predicted in this current study. However, Table 1 describes how both influences may interact toward the intention to change security policies.

To test the hypotheses developed above, we employed an experimental research design featuring two fixed factors, as reported previously (Marett and Marett, 2025). Each participant was randomly assigned to one of the four types of safety voice. Then, participants were presented a comic strip-styled vignette that matched the two characters with the participant's gender identification. Female participants were exposed to one of the following vignettes: female manager and a male employee or a female manager and a female employee. Male participants were exposed to one of the following vignettes: male manager and a male employee or a male manager and a female employee. Figures 2 and 3 provide examples, and Figure A1 in Appendix displays a complete vignette.

Visual vignettes like those used in this study are thought to offer added benefit to the traditional text-based vignette. Both types of vignette allow researchers the opportunity to ask about sensitive topics due to depersonalization and distancing effects, thus reducing social desirability bias (Khanolainen and Semenova, 2020). However, visual vignettes provide a richer, more complex depiction of dialogue and events, leaving behind the one-dimensional characters found in text (Kinicki et al., 1995). Visual vignettes also tend to elicit quicker responses than text due to less required thought and interpretation of the narrative (Hughes and Huby, 2004), reducing the likelihood of delayed responses and decay effects of the treatment embedded within.

The vignettes used stock photos of two employees engaged in a workplace conversation. The dialogue was developed through the use of generative AI software that was provided the definitions for the four types of safety voice and instructed to write a short discussion between a manager and an employee recommending a change to the company's security procedures. For the proposed security improvement, we used the potential adoption of two-factor authentication (2FA) as this has been identified as a security procedure that employees have recognized as being a worthwhile addition while simultaneously considered to be burdensome and unpopular (Marett et al., 2023; Zhan et al., 2024). This paradox of effectiveness and inconvenience made 2FA amenable to the various types of voice we wanted to represent in the vignettes. Each vignette was of equal length (seven panels) across the four types of safety voice and the different male-female pairings.

Aside from the two factors manifested by the vignettes, latent variables were measured using pre-existing scales. Potential moderators identified from existing research included voice behavior (Van Dyne and LePine, 1998), power distance (Dorfman and Howell, 1988), general security concern (Workman et al., 2008) and affective commitment to the organization (Allen and Meyer, 1990). Safety voice was measured using the four-dimension scale drawn from safety science research (Hofmann et al., 2003; Maynes and Podsakoff, 2014; Simard and Marchand, 1995; Tucker and Turner, 2011) and later combined by Bazzoli and colleagues (2020) primarily for manipulation check purposes. A list of the measures and the corresponding items can be found in Table A1 in Appendix.

The dependent variable, intention to initiate security change, was based on scales developed to measure voice influence (Dutton and Ashford, 1993; Oc et al., 2015). We adapted the items to represent future consideration of making changes to the company information security program. Participants were asked, from the perspective of the manager in the vignette, to rate the likelihood they would make the recommended change, the speed with which they would pursue the change, the intent to allocate resources to make the change and the likelihood they would investigate whether others have made the change. As with the aforementioned variables, their responses were captured using a five-point Likert scale ranging from “strongly disagree” to “strongly agree”.

The instrument was designed as follows. Participants were first asked to provide their demographic information, and their response to their gender identification routed them to the appropriate set of vignettes (male or female manager). The vignette itself followed with the appropriate attention and manipulation check items. Participants then provided their assessments of the employee in the vignette, including affective commitment and power distance and their intention to change security if they were themselves the manager in the scenario. Finally, they were asked to provide their own general security concern and their own voice behavior in the workplace.

Before initiating the experiment to a main sample of participants, the materials and procedures involved were put through multiple rounds of pilot testing. The vignettes described before were first appraised by a panel of researchers specializing in information security research. The panel provided feedback on the suggestion to incorporate two-factor authentication, as well as the imagery and dialogue between the two characters used to convey the suggestion. Using an iterative process, the dialogue was modified to better resemble a realistic conversation between an employee and manager. Once the panel was satisfied, the image panels used in the vignette were updated for pilot testing.

A pilot test of the stimuli and study procedures was conducted using a snowball sample of undergraduate students and their parents. This produced a sample of 197 participants, 110 female and 87 male. Manipulation checks of the four types of voice were tested using one-way ANOVA of the safety voice measures, conforming with standards prescribed for information security research (Marett, 2015). The results of the checks indicated that the participants in the promotive voice group felt the dialogue was significantly more promotive than the other types of voice (F = 3.53; p < 0.01), the prohibitive group rated their dialogue as significantly more prohibitive (F = 6.60; p < 0.001) and the hostile group deemed their dialogue as significantly more hostile (F = 2.82; p < 0.05). The preventive group felt that their dialogue was more preventive but not to a significant degree. Thus, the dialogue for that treatment was adjusted before proceeding to the main data collection. A realism check indicated that the situation portrayed in the vignette was representative of something that could occur in a workplace. On a scale ranging from 1 (not realistic) to 5 (very realistic), the pilot sample judged it with a mean of 4.13. The median time to complete the experiment was 6.9 min.

The measures for the latent variables were also assessed for convergent and discriminant validity. Confirmatory factor analysis revealed that one item for general security concern and two items for organizational commitment loaded onto inappropriate constructs, and a reliability analysis subsequently recommended that their associated variables would improve in internal consistency if removed from the analysis. All three items were deemed to be problematic and were dropped from the instrument.

We conducted a second pilot test of the study materials with a sample of business professionals. Two hundred ten full-time employees and managers (105 male and 105 female) were recruited through an online survey panel service. This time, all four types of safety voice passed the manipulation checks, meaning that the revised vignette scripts were more fitting for the type of voice intended to be represented. The revised scales appeared to be psychometrically sound, showing appropriate levels of reliability, convergent and discriminant validity. Finally, the business professionals rated the vignette as being realistic (a mean 4.12 out of 5.0), very similarly to the prior pilot test.

Data for the main study was collected through the use of the online survey panel service Prolific. The sample consisted of business professionals working throughout the United States, ultimately resulting in 140 valid responses from males and 140 from females. Sixty percent of the participants identified as full-time employees working forty or more hours a week, and 12% described themselves as seasonal or temporary employees. The remaining 28% reported themselves as business owners or managers. Participants ranged from 19 to 60 years of age, with a mean age of 37.4 years. All participants reported using a computer and the internet at work. Participants were randomly assigned to one of the four voice treatments, and they were only exposed to the single vignette they were assigned to. As with the pilot test, the manipulation checks provided evidence that the treatments were portraying the appropriate types of voice, and a realism check again suggested that the scenario was true to life across treatments. There were a few problematic responses to be dealt with before data analysis, including five respondents who did not pass the attention check question (e.g. “Mark Disagree for this item”) and two respondents who were judged to hold jobs far below the requisite level of managerial responsibility, so those responses were removed. The median response time to complete the instrument was 7.3 min, so we also removed any responses that were submitted in under 90 s.

A confirmatory factor analysis once again indicated appropriate convergent validity among the variables. Table 2 displays the descriptive statistics and intercorrelations for the latent variables measured following the experiment. All of the variables had sufficient internal reliability and the average variance explained for each variable suggested adequate discriminant validity. A single moderator candidate, power distance, did not significantly correlate with the dependent variable, so it was decided not to represent it as a covariate in the subsequent data analysis. The other three variables, on the other hand, did correlate significantly with security change intentions, so they were all retained as covariates.

To test the hypotheses, we used a two-way ANCOVA mixing the independent variables, type of safety voice and gender, with affective commitment, general security concern and voice behavior as the covariates. An initial Levene's test indicated no heterogeneity in variance between the treatment groups. Table 3 reports the means for security change intention for each of the eight groups. The main effects of independent variables were tested first. The ANCOVA found no significant main effect for the type of safety voice (F(3,276) = 1.87, p = 0.13), though a post hoc Bonferroni test removing the covariates suggested that hostile voice was significantly less influential than promotive voice (p = 0.01) and preventive voice (p = 0.02). Nevertheless, Hypothesis 1 was not fully supported.

However, Hypothesis 2 was supported, as males were found to be more influential toward encouraging security changes than females (F(1,276) = 10.79, p = 0.001). Overall, the ANCOVA model explains 27% of the variance in security change intentions. Table 4 displays the effect sizes for the independent variables and the covariates.

To follow up on the initial findings described above, we conducted a post hoc comparison examining the type of safety voice offered by a same gender or opposite gender employee, again with the participant serving in the role of the manager receiving the input. Table A2 in Appendix reports the descriptive statistics for behavioral intention to change security across the four types of safety voice, the two genders of the employee offering the safety voice and the two genders for the manager being asked to consider the suggestions. The most influential setting found was promotive voice being offered from a male employee to a female manager (M = 4.55, SD = 0.4). The least influential setting involved hostile voice being offered by a female employee to a male manager (M = 3.62, SD = 0.9), followed closely by hostile voice from a female employee to a female manager (M = 3.86, SD = 0.6). There was no significant three-way interaction between voice type, employee gender and manager gender, but the statistical power for that comparison was insufficient for a valid ANOVA, so this result should be taken with caution.

This study aligns with calls for research that explore individual differences found in IT workers who respond to security issues in the workplace on a regular basis (Singh et al., 2023). Indeed, cybersecurity is a stressful job that requires constant monitoring, testing and re-education for workers to be effective. This is where safety voice comes into play; the input of front-line users can be a valuable resource that can help extend the radar of cyber-professionals. As this study shows, the manner in which the recommendations are voiced could result in different outcomes, depending on the recipient. However, this study should be considered preliminary at most. Follow-up work examining the actual decision-making of security managers is critical to applicability of this research.

Our study found preliminary evidence that female managers are more influenced by and receptive to safety voice. Previous work on voice behavior and manager avoidance behavior suggests that males often have a larger “perceptual distance” gap between their own perceived effectiveness and the perceptions of their subordinates (Yang and Li, 2018). This gap can manifest itself in agentic decision-making and can create a less collaborative environment compared to female managers. Meta-analyses back up this notion, as women have been found to be more encouraging and supportive of subordinates than men (Eagly and Carly, 2003).

While our findings could indicate that female managers are more receptive to voice behaviors due to more supportive and collaborative leadership styles, it is also possible that male speakers were more influential due to the topic of discussion. The IT and cybersecurity industry is predominantly male, with estimates of 4 males for every single female obtaining computer science degrees (Cimpian et al., 2020). Female participants of this study may have been more influenced by the male speaker vignettes because they don't frequently interact with female members of the IT industry. The lower numbers of female IT workers could have negatively impacted manager's abilities to view female voices as “expert” voices on security topics. This is an issue that demands further investigation. Alternatively, it is also possible that this study's findings provide additional evidence of male voices being perceived more favorably as demonstrating leadership. As McClean and colleagues (2018) noted, male employees who speak up in the workplace are more likely to be perceived as leaders than their female counterparts and, as a result, their recommendations are seen as more legitimate than women's similar voice behavior.

Our study also indicated that hostile voice is the least influential of the four safety voice types. This aligns with previous research indicating that voice types that elicit positive emotional responses are more effective than voice types that are perceived as a threat or attack (Chen and Trevino, 2022). Hostile voice is the only safety voice behavior that directly criticizes the organization for failing to make a policy change and could be perceived as a direct attack on the manager's judgment. This study examined the effectiveness of voice behaviors in private, one-on-one conversations with managers. We would expect hostile voice to be even less effective when delivered in public settings like meetings, as supported by previous research indicating that all voice types delivered in public settings are perceived as threatening to managers (Isaakyan et al., 2021). Finally, there could also be some gender differences when accepting the type of security change being recommended, with women possibly being more open to behavioral changes to security while men being more likely to pursue technical changes (McGill and Thompson, 2021).

Although this study did not find evidence for a main effect between the four different types of safety voice behavior, it did make an exploratory contribution to the emerging body of literature related to gender differences in voice behaviors. This study found that male managers were not as easily influenced as female managers, which could have other unintended consequences for subsequent voice behaviors within the workplace. Previous research indicates that there are gender differences in engaging in voice behavior (Yan et al., 2022; Eibl et al., 2020; Sherf et al., 2017). Self-efficacy predicts voice behaviors, and past research indicates that female employees typically have lower voice self-efficacy levels (Yan et al., 2022). Past research indicates that voice instrumentality, the belief that speaking up makes a difference, has a direct influence on voice behavior (Tangirala and Ramanujam, 2012; Morrison, 2014; Sherf et al., 2017). When voice rejection occurs, it lowers perceived voice self-efficacy and reduces subsequent voice behaviors (Zhu et al., 2025). If our study findings indicate that male managers are more likely to reject voice suggestions, it could have an impact of unintentionally silencing subsequent female voice behavior in the workplace. For an issue like security threats this is particularly worrisome as the potential damages of allowing threats to remain unaddressed could be catastrophic to the organization.

Although this study should be best considered to be an initial investigation into safety voice and information security, our findings indicate some early implications of this research. First, it appears that the predictions about present- and future- orientation put forth by CLT seems to largely hold true in the context of security recommendations, despite the results failing to find statistical significance. Promotive and preventive safety voice did trend toward being more effective than prohibitive and hostile voice types. We see results like these aiding in our understanding of preventing insider threats within the organization. Safety voice is a type of bottom-up, employee-driven input that is thought to be beneficial toward user acceptance of security policies (Posey et al., 2015), and employees using promotive and preventive voice to encourage personal responsibility could help establish a more secure culture within the organization. In fact, the influence of organizational culture on the acceptance of safety voice would be worthwhile factor to test in future iterations of this research.

The results also illuminate how temporal distance might serve as not just a barrier to changing security policies, but perhaps as motivation to ignore or even resist change, highlighting an area of overlap between organizational safety and information security improvements. As discussed earlier, a distal perspective can allow a person to envision being better able to follow one's ideals as opposed to being confronted by more practical concerns blocking those ideals from being achieved (Hernandez, 2012). Present-oriented safety voice that frames changes to security policies and standards in practicalities could mean those recommendations are viewed more as obstacles than as priorities. Avoidance behaviors and outright resistance could occur if the outcomes of future-oriented recommendations are not readily apparent, which lines up with the concept of temporal discounting. Communication that focuses mainly on distant consequences rather than on future actionable changes can lose their persuasive value (Chapman and Elstein, 1995; Kim and Nan, 2019), perhaps eventually leading to manager obstinance. For employee recommendations for security policies, this should mean relying more on the promotive voice for framing the message.

Second, there is the disappointing result that male safety voice seems to be more effective than that proffered by female employees. As mentioned before, this result parallels earlier work that suggests a stereotypical difference in influence between the two genders. This result is especially sobering given that vignettes were used to reduce socially desirable responses from study participants. If the results here reflect true attitudes and perceptions of anonymous study participants who are free to report their true feelings about the source of employee input, then it appears that there are significant challenges for organizations that seek to create a safe environment in which all voice behavior is recognized equally. Differences in acknowledgement of voice behavior also poses an additional challenge for those seeking to increase female participation in STEM careers like information security. Indeed, gender differences in voice acceptance help undermine organizational efforts to support women through mentoring and implicit bias training aimed at promoting gender equity (Dworkin et al., 2018). It is also entirely possible that other individual differences, whether innate or socially constructed, could inhibit the acceptance of safety voice. One's gender could also intersect with the age, race, country of origin or disability status of the speaker to reduce security effectiveness despite her best intentions.

Finally, we see these results as potentially adding more fuel to the “spiral of silence” that researchers have observed when examining employee voice toward information security initiatives (Petrič and Orehek, 2025). In this, employees become discouraged from offering their recommendations and advice when it becomes apparent when their opinion is not held by the majority of their peers. Even more worrisome, even IS employees with promotive attitudes could find themselves adapting to the majority opinion and then becoming dishonestly opposed to their own former recommendations. Female employees might be particularly vulnerable to a possible spiral of silence if their early attempts to voice security concerns are ignored or are poorly received based solely on her gender. Following from EST, if a person continually finds her contributions being dismissed because of her gender, those negative expectations will eventually become internalized and the employee's performance will begin to reflect those expectations (Deaux and Major, 1987). We fully expect that being dismissed because of one's gender, added to a lack of priority for information security, is likely to produce this spiral of silence. In many organizations, information security is still considered to be a necessary opportunity cost that never satisfactorily returns on its investment; that is, until a breach or disruption unexpectedly occurs (Shao et al., 2020). But barring that, we should not be surprised when recommended investments of money, time and effort to improve information security fail to achieve majority support.

There are many directions future studies on information security and employee input could take based on this study's findings. Among the potential directions that this line of research could take, we view the communication setting used for offering safety voice as one of the logical next steps for research. For instance, employees may have a preferred media choice for communicating their security suggestions, much as they do for other communication that they suspect will not be well-received (Sussman and Sproull, 1999; George et al., 2013). Likewise, the choice to voice suggestions in a group setting as opposed to individually, which the vignettes in this study depicted, offers both the opportunity to receive attention from others for the amenable input but also a voluntary risk should the input be challenged in front of others (Noort et al., 2019). Information security changes are not always welcomed by others, and future research should account for the possible hesitancy by decision makers. Risk-reducing tactics chosen by employees, such as identifying an intermediary to serve as a conduit or another like-minded individual to help champion the suggestion, could also be examined in information security research (Milliken and Lam, 2009).

This study examined the role of safety voice when offering information security recommendations within an organization. Four types of safety voice were tested in an experimental setting, and different permutations of males and females were represented in the vignettes. Though exploratory, we found initial results that will hopefully encourage more investigation into the intersection of safety voice and organizational security. Construal level theory, at least in this early phase of research, seems to predict the level of influence rendered by the types of safety voice. Likewise, the results parallel work in organizational behavior on gender differences and voice, and future research is needed to isolate stereotypes and feelings of self-efficacy when speaking up about security issues. Where information security is concerned, uncovering obstacles and barriers that discourage all employees from offering input should be a top priority for researchers.

An earlier version of this paper was presented at the 58th Hawaii International Conference on System Sciences (HICSS-58): Marett and Marett (2025). The role of safety voice in improving organizational information security. Proceedings of the 58th Hawaii International Conference on System Sciences, Waikoloa, HI, USA. This version has been substantially extended with additional theoretical development and discussion.

The supplementary material for this article can be found online.

Allen
,
N.J.
and
Meyer
,
J.P.
(
1990
), “
The measurement and antecedents of affective, continuance and normative commitment to the organization
”,
Journal of Occupational Psychology
, Vol. 
63
No. 
1
, pp. 
1
-
18
, doi: .
Bain
,
K.
,
Kreps
,
T.A.
,
Meikle
,
N.L.
and
Tenney
,
E.R.
(
2021
), “
Amplifying voice in organizations
”,
Academy of Management Journal
, Vol. 
64
No. 
4
, pp. 
1288
-
1312
, doi: .
Bansal
,
G.
and
Axelton
,
Z.
(
2024
), “
Impact of cybersecurity disclosures on stakeholder intentions
”,
Journal of Computer Information Systems
, Vol. 
64
No. 
1
, pp.
78
-
91
, doi: .
Bazzoli
,
A.
and
Curcuruto
,
M.
(
2021
), “
Safety leadership and safety voices: exploring the mediation role of proactive motivations
”,
Journal of Risk Research
, Vol. 
24
No. 
11
, pp. 
1368
-
1387
, doi: .
Bazzoli
,
A.
,
Curcuruto
,
M.
,
Morgan
,
J.I.
,
Brondino
,
M.
and
Pasini
,
M.
(
2020
), “
Speaking up about workplace safety: an experimental study on safety leadership
”,
Sustainability
, Vol. 
12
No. 
18
, p.
7458
, doi: .
Cavusoglu
,
H.
,
Cavusoglu
,
H.
,
Son
,
J.Y.
and
Benbasat
,
I.
(
2015
), “
Institutional pressures in security management: direct and indirect influences on organizational investment in information security control resources
”,
Information and Management
, Vol. 
52
No. 
4
, pp. 
385
-
400
, doi: .
Chan
,
M.
,
Woon
,
I.
and
Kankanhalli
,
A.
(
2005
), “
Perceptions of information security in the workplace: linking information security climate to compliant behavior
”,
Journal of Information Privacy and Security
, Vol. 
1
No. 
3
, pp. 
18
-
41
, doi: .
Chapman
,
G.B.
and
Elstein
,
A.S.
(
1995
), “
Valuing the future: temporal discounting of health and money
”,
Medical Decision Making
, Vol. 
15
No. 
4
, pp. 
373
-
386
, doi: .
Chen
,
A.
and
Trevino
,
L.K.
(
2022
), “
Promotive and prohibitive ethical voice: coworker emotions and support for the voice
”,
Journal of Applied Psychology
, Vol. 
107
No. 
11
, pp. 
1973
-
1994
, doi: .
Cimpian
,
J.R.
,
Kim
,
T.H.
and
McDermott
,
Z.T.
(
2020
), “
Understanding persistent gender gaps in STEM
”,
Science
, Vol. 
368
No. 
6497
, pp. 
1317
-
1319
, doi: .
Deaux
,
K.
and
Major
,
B.
(
1987
), “
Putting gender into context: an interactive model of gender-related behaviour
”,
Psychological Review
, Vol. 
94
No. 
3
, pp. 
369
-
389
, doi: .
Dorfman
,
P.W.
and
Howell
,
J.P.
(
1988
), “Dimensions of national culture and effective leadership patterns: hofstede revisited”, in
Farmer
,
R.N.
and
McGoun
,
E.G.
(Eds),
Advances in International Comparative Management
, Vol. 
3
, pp. 
127
-
150
.
Dutton
,
J.E.
and
Ashford
,
S.J.
(
1993
), “
Selling issues to top management
”,
Academy of Management Review
, Vol. 
18
No. 
3
, pp. 
397
-
428
, doi: .
Dworkin
,
T.
,
Schipani
,
C.
,
Milliken
,
F.
and
Kneeland
,
M.
(
2018
), “
Assessing the progress of women in corporate America: the more things change, the more they stay the same
”,
American Business Law Journal
, Vol. 
55
No. 
4
, pp. 
721
-
762
, doi: .
Eagly
,
A.H.
and
Carli
,
L.L.
(
2003
), “
The female leadership advantage: an evaluation of the evidence
”,
The Leadership Quarterly
, Vol. 
14
No. 
6
, pp. 
807
-
834
, doi: .
Eibl
,
B.
,
Lang
,
F.R.
and
Niessen
,
C.
(
2020
), “
Employee voice at work: the role of employees' gender, self-efficacy beliefs, and leadership
”,
European Journal of Work and Organizational Psychology
, Vol. 
29
No. 
4
, pp. 
570
-
585
, doi: .
Farh
,
C.
,
Oh
,
J.
,
Hollenbeck
,
J.
,
Yu
,
A.
,
Lee
,
S.
and
King
,
D.
(
2020
), “
Token female voice enactment in traditionally male-dominated teams: facilitating conditions and consequences for performance
”,
Academy of Management Journal
, Vol. 
63
No. 
3
, pp. 
832
-
856
, doi: .
Flowerday
,
S.V.
and
Tuyikeze
,
T.
(
2016
), “
Information security policy development and implementation: the what, how and who
”,
Computers and Security
, Vol. 
61
, pp. 
169
-
183
, doi: .
Gefen
,
D.
and
Straub
,
D.
(
1997
), “
Gender differences in the perception and use of e-mail: an extension to the technology acceptance model
”,
MIS Quarterly
, Vol. 
21
No. 
4
, pp. 
389
-
400
, doi: .
George
,
J.
,
Carlson
,
J.
and
Valacich
,
J.
(
2013
), “
Media selection as a strategic component of communication
”,
MIS Quarterly
, Vol. 
37
No. 
4
, pp. 
1233
-
1251
, doi: .
Hernandez
,
M.
(
2012
), “
Toward an understanding of the psychology of stewardship
”,
Academy of Management Review
, Vol. 
37
No. 
2
, pp. 
172
-
193
, doi: .
Hofmann
,
D.A.
,
Morgeson
,
F.P.
and
Gerras
,
S.J.
(
2003
), “
Climate as a moderator of the relationship between leader-member exchange and content specific citizenship: safety climate as an exemplar
”,
Journal of Applied Psychology
, Vol. 
88
No. 
1
, pp. 
170
-
178
, doi: .
Howell
,
T.M.
,
Harrison
,
D.A.
,
Burris
,
E.R.
and
Detert
,
J.R.
(
2015
), “
Who gets credit for input? Demographic and structural status cues in voice recognition
”,
Journal of Applied Psychology
, Vol. 
100
No. 
6
, pp. 
1765
-
1784
, doi: .
Hughes
,
R.
and
Huby
,
M.
(
2004
), “
The construction and interpretation of vignettes in social research
”,
Social Work and Social Sciences Review
, Vol. 
11
No. 
1
, pp. 
36
-
51
, doi: .
Isaakyan
,
S.
,
Sherf
,
E.N.
,
Tangirala
,
S.
and
Guentler
,
H.
(
2021
), “
Keeping it between us: managerial endorsement of public versus private voice
”,
Journal of Applied Psychology
, Vol. 
106
No. 
7
, pp. 
1049
-
1066
, doi: .
Johnston
,
A.
and
Hale
,
R.
(
2009
), “
Improved security through information security governance
”,
Communications of the ACM
, Vol. 
52
No. 
1
, pp. 
126
-
129
, doi: .
Khanolainen
,
D.
and
Semenova
,
E.
(
2020
), “
School bullying through graphic vignettes: developing a new arts-based method to study a sensitive topic
”,
International Journal of Qualitative Methods
, Vol. 
19
, 1609406920922765, doi: .
Kim
,
J.
and
Nan
,
X.
(
2019
), “
Temporal framing effects differ for narrative versus non-narrative messages: the case of promoting HPV vaccination
”,
Communication Research
, Vol. 
46
No. 
3
, pp. 
401
-
417
, doi: .
Kinicki
,
A.J.
,
Hom
,
P.W.
,
Trost
,
M.R.
and
Wade
,
K.J.
(
1995
), “
Effects of category prototypes on performance-rating accuracy
”,
Journal of Applied Psychology
, Vol. 
80
No. 
3
, pp. 
354
-
370
, doi: .
Le Poire
,
B.A.
,
Burgoon
,
J.K.
and
Parrott
,
R.
(
1992
), “
Status and privacy restoring communication in the workplace
”,
Journal of Applied Communication Research
, Vol. 
20
No. 
4
, pp. 
419
-
436
, doi: .
Lee
,
J.S.
,
Keil
,
M.
and
Shalev
,
E.
(
2019
), “
Seeing the trees or the forest? The effect of IT project managers' mental construal on IT project risk management activities
”,
Information Systems Research
, Vol. 
30
No. 
3
, pp. 
1051
-
1072
, doi: .
LePine
,
J.A.
and
Van Dyne
,
L.
(
2001
), “
Voice and cooperative behavior as contrasting forms of contextual performance: evidence of differential relationships with big five personality characteristics and cognitive ability
”,
Journal of Applied Psychology
, Vol. 
86
No. 
2
, pp. 
326
-
336
, doi: .
Marett
,
K.
(
2015
), “
Checking the manipulation checks in information security research
”,
Information and Computer Security
, Vol. 
23
No. 
1
, pp. 
20
-
30
, doi: .
Marett
,
K.
and
Marett
,
E.G.
(
2025
), “
The role of safety voice in improving organizational information security
”,
Proceedings of the 58th Hawaii International Conference on System Sciences
,
Waikoloa, HI
.
Marett
,
K.
,
Xiao
,
S.
and
Kim
,
S.
(
2023
), “
Security compliance and work-issued mobile devices: out of sight, out of mind?
”,
Information Systems and e-Business Management
, Vol. 
21
No. 
4
, pp. 
913
-
945
, doi: .
Maynes
,
T.D.
and
Podsakoff
,
P.M.
(
2014
), “
Speaking more broadly: an examination of the nature, antecedents, and consequences of an expanded set of employee voice behaviors
”,
Journal of Applied Psychology
, Vol. 
99
No. 
1
, pp. 
87
-
112
, doi: .
McClean
,
E.J.
,
Martin
,
S.R.
,
Emich
,
K.J.
and
Woodruff
,
C.T.
(
2018
), “
The social consequences of voice: an examination of voice type and gender on status and subsequent leader emergence
”,
Academy of Management Journal
, Vol. 
61
No. 
5
, pp. 
1869
-
1891
, doi: .
McClean
,
E.J.
,
Kim
,
S.
and
Martinez
,
T.
(
2022
), “
Which ideas for change are endorsed? How agentic and communal voice affects endorsement differently for men and for women
”,
Academy of Management Journal
, Vol. 
65
No. 
2
, pp. 
634
-
655
, doi: .
McCrea
,
S.M.
,
Liberman
,
N.
,
Trope
,
Y.
and
Sherman
,
S.J.
(
2008
), “
Construal level and procrastination
”,
Psychological Science
, Vol. 
19
No. 
12
, pp. 
1308
-
1314
, doi: .
McGill
,
T.
and
Thompson
,
N.
(
2021
), “
Exploring potential gender differences in information security and privacy
”,
Information and Computer Security
, Vol. 
29
No. 
5
, pp. 
850
-
865
, doi: .
Milliken
,
F.J.
and
Lam
,
N.
(
2009
), “Making the decision to speak up or to remain silent: implications for organizational learning”, in
Greenberg
,
J.
and
Edwards
,
M.S.
(Eds),
Voice and Silence in Organizations
,
Emerald Group Publishing
,
England
, pp. 
225
-
244
.
Morrison
,
E.W.
(
2014
), “
Employee voice and silence
”,
Annual Review of Organizational Psychology and Behavior
, Vol. 
1
No. 
1
, pp. 
173
-
197
, doi: .
Nakashima
,
N.A.
,
Daniels
,
D.P.
and
Laurin
,
K.
(
2017
), “
It's about time: divergent evaluations of restrictive policies in the near and distant future
”,
Organizational Behavior and Human Decision Processes
, Vol. 
142
, pp. 
12
-
27
, doi: .
Niemimaa
,
M.
and
Niemimaa
,
E.
(
2019
), “
Abductive innovations in information security policy development: an ethnographic study
”,
European Journal of Information Systems
, Vol. 
28
No. 
5
, pp. 
566
-
589
, doi: .
Noort
,
M.C.
,
Reader
,
T.W.
and
Gillespie
,
A.
(
2019
), “
Speaking up to prevent harm: a systematic review of the safety voice literature
”,
Safety Science
, Vol. 
117
, pp. 
375
-
387
, doi: .
Oc
,
B.
,
Bashshur
,
M.R.
and
Moore
,
C.
(
2015
), “
Speaking truth to power: the effect of candid feedback on how individuals with power allocate resources
”,
Journal of Applied Psychology
, Vol. 
100
No. 
2
, pp. 
450
-
463
, doi: .
Paananen
,
H.
,
Lapke
,
M.
and
Siponen
,
M.
(
2020
), “
State of the art in information security policy development
”,
Computers and Security
, Vol. 
88
, pp. 
1
-
14
, doi: .
Pandolfo
,
A.M.
,
Reader
,
T.W.
and
Gillespie
,
A.
(
2025
), “
Safety listening in organizations: an integrated conceptual review
”,
Organizational Psychology Review
, Vol. 
15
No. 
1
, pp.
93
-
124
, doi: .
Petrič
,
G.
and
Orehek
,
Š.
(
2025
), “
Expressing opinions about information security in an organization: the spiral of silence theory perspective
”,
Information and Computer Security
, Vol. 
33
No. 
2
, pp.
223
-
241
.
Posey
,
C.
,
Roberts
,
T.L.
and
Lowry
,
P.B.
(
2015
), “
The impact of organizational commitment on insiders' motivation to protect organizational information assets
”,
Journal of Management Information Systems
, Vol. 
32
No. 
4
, pp. 
179
-
214
, doi: .
Ridgeway
,
C.L.
and
Bourg
,
C.
(
2004
), “Gender as status: an expectation states theory approach”, in
Eagly
,
A.H.
,
Beall
,
A.E.
and
Sternberg
,
R.J.
(Eds),
The Psychology of Gender
,
The Guilford Press
, pp. 
217
-
241
.
Shao
,
X.
,
Siponen
,
M.
and
Liu
,
F.
(
2020
), “
Shall we follow? Impact of reputation concern on information security managers' investment decisions
”,
Computers and Security
, Vol. 
97
, 101961, doi: .
Sherf
,
E.N.
,
Tangirala
,
S.
and
Weber
,
K.C.
(
2017
), “
It is not my place! Psychological standing and men's voice and participation in gender-parity initiatives
”,
Organizational Science
, Vol. 
28
No. 
2
, pp. 
193
-
210
, doi: .
Simard
,
M.
and
Marchand
,
A.
(
1995
), “
A multilevel analysis of organisational factors related to the taking of safety initiatives by work groups
”,
Safety Science
, Vol. 
21
No. 
2
, pp. 
113
-
129
, doi: .
Singh
,
T.
,
Johnston
,
A.C.
,
D'Arcy
,
J.
and
Harms
,
P.D.
(
2023
), “
Stress in the cybersecurity profession: a systematic review of related literature and opportunities for future research
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
3
No. 
2
, pp. 
100
-
126
, doi: .
Siponen
,
M.
(
2005
), “
Analysis of modern IS security development approaches: towards the next generation of social and adaptable ISS methods
”,
Information and Organization
, Vol. 
15
No. 
4
, pp. 
339
-
375
, doi: .
Steinbach
,
A.L.
,
Gamache
,
D.L.
and
Johnson
,
R.E.
(
2019
), “
Don't get it misconstrued: executive construal-level shifts and flexibility in the upper echelons
”,
Academy of Management Review
, Vol. 
44
No. 
4
, pp. 
871
-
895
, doi: .
Sussman
,
S.
and
Sproull
,
L.
(
1999
), “
Straight talk: delivering bad news through electronic communication
”,
Information Systems Research
, Vol. 
10
No. 
2
, pp. 
150
-
166
, doi: .
Tangirala
,
S.
and
Ramanujam
,
R.
(
2012
), “
Ask and you shall hear (but not always): examining the relationship between manager consultation and employee voice
”,
Personnel Psychology
, Vol. 
65
No. 
2
, pp. 
251
-
282
, doi: .
Tejay
,
G.P.
and
Winkfield
,
M.
(
2025
), “
Does leadership approach matter? Examining behavioral influences of leaders on employees' information security compliance
”,
Information Systems Frontiers
, Vol. 
28
No. 
2
, pp. 
1
-
21
, doi: .
Trope
,
Y.
and
Liberman
,
N.
(
2010
), “
Construal-level theory of psychological distance
”,
Psychological Review
, Vol. 
117
No. 
2
, pp. 
440
-
463
, doi: .
Trope
,
Y.
,
Liberman
,
N.
and
Wakslak
,
C.
(
2007
), “
Construal levels and psychological distance: effects on representation, prediction, evaluation, and behavior
”,
Journal of Consumer Psychology
, Vol. 
17
No. 
2
, pp.
83
-
95
.
Tucker
,
S.
and
Turner
,
N.
(
2011
), “
Young worker safety behaviors: development and validation of measures
”,
Accident Analysis and Prevention
, Vol. 
43
No. 
1
, pp. 
165
-
175
, doi: .
Van Dyne
,
L.
and
LePine
,
J.A.
(
1998
), “
Helping and voice extra-role behaviors: evidence of construct and predictive validity
”,
Academy of Management Journal
, Vol. 
41
No. 
1
, pp. 
108
-
119
, doi: .
Venkatesh
,
V.
and
Morris
,
M.
(
2000
), “
Why don't men ever stop to ask for directions? Gender, social influence, and their role in technology acceptance and usage behavior
”,
MIS Quarterly
, Vol. 
24
No. 
1
, pp. 
115
-
139
, doi: .
von Solms
,
R.
and
von Solms
,
B.
(
2004
), “
From policies to culture
”,
Computer and Security
, Vol. 
23
No. 
4
, pp. 
275
-
279
, doi: .
Workman
,
M.
,
Bommer
,
W.H.
and
Straub
,
D.
(
2008
), “
Security lapses and the omission of information security measures: a threat control model and empirical test
”,
Computers in Human Behavior
, Vol. 
24
No. 
6
, pp. 
2799
-
2816
, doi: .
Xu
,
F.
,
Hsu
,
C.
,
Wang
,
T.
and
Lowry
,
P.B.
(
2024
), “
The antecedents of employees’ proactive information security behaviour: the perspective of proactive motivation
”,
Information Systems Journal
, Vol. 
34
No. 
4
, pp.
1144
-
1174
, doi: .
Xue
,
B.
,
Xu
,
F.
,
Luo
,
X.
and
Warkentin
,
M.
(
2021
), “
Ethical leadership and employee information security policy (ISP) violation: exploring dual-mediation paths
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
1
No. 
1
, pp. 
5
-
23
, doi: .
Yan
,
T.T.
,
Tangirala
,
S.
,
Vadera
,
A.K.
and
Ekkirala
,
S.
(
2022
), “
How employees learn to speak up from their leaders: gender congruity effects in the development of voice efficacy
”,
Journal of Applied Psychology
, Vol. 
107
No. 
4
, pp. 
650
-
667
.
Yang
,
I.
and
Li
,
L.M.
(
2018
), “
‘It is not fair that you do not know we have problems’: perceptual distance and the consequences of male leaders' conflict avoidance behaviours
”,
European Management Journal
, Vol. 
36
No. 
1
, pp. 
105
-
116
, doi: .
Zhan
,
X.
,
Durcikova
,
A.
and
Galletta
,
D.
(
2024
), “
The paradox of choice: digital Akrasia in the deployment of multi-factor authentication
”,
Proceedings of the 57th Hawaii International Conference on System Sciences
,
Honolulu, HI
.
Zhu
,
Y.
,
Long
,
L.
,
Zhang
,
Y.
and
Wang
,
H.
(
2025
), “
Remember to say ‘thanks’ when rejecting others: the moderating role of leader gratitude expression in the relationship between leader voice rejection and employees’ subsequent upward voice
”,
Asia Pacific Journal of Management
, Vol. 
42
No. 
2
, pp.
531
-
558
.
LePine
,
J.A.
and
Van Dyne
,
L.
(
1998
), “
Predicting voice behavior in work groups
”,
Journal of Applied Psychology
, Vol. 
83
No. 
6
, pp. 
853
-
868
, doi: .
Schreurs
,
B.
,
Hamstra
,
M.R.
and
Davidson
,
T.
(
2020
), “
What's in a word? Using construal-level theory to predict voice endorsement
”,
European Journal of Work and Organizational Psychology
, Vol. 
29
No. 
1
, pp. 
93
-
105
, doi: .
Published in Organizational Cybersecurity Journal: Practice, Process and People. Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) license. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this license may be seen at Link to the terms of the CC BY 4.0 licence.

Supplementary data

Data & Figures

Figure 1
A diagram categorizing types of employee safety voice into four quadrants based on recommendation focus and temporal orientation.A diagram categorizing types of employee safety voice into four quadrants. The diagram is divided into two axes: the vertical axis labeled 'Recommendation Focus' with categories 'Challenging' and 'Defensive', and the horizontal axis labeled 'Temporal Orientation' with categories 'Present' and 'Future'. The four quadrants are labeled as follows: Hostile (Challenging, Present) describes a change needed with an argumentative tone. Promotive (Challenging, Future) indicates constructive change needed. Prohibitive (Defensive, Present) suggests that the status quo is sufficient and calls attention to counterproductive factors. Preventive (Defensive, Future) aims to sustain current practices and avoid future losses.

Summary of safety voice types. Source: Adapted from Bazzoli and Curcurato (2021) 

Figure 1
A diagram categorizing types of employee safety voice into four quadrants based on recommendation focus and temporal orientation.A diagram categorizing types of employee safety voice into four quadrants. The diagram is divided into two axes: the vertical axis labeled 'Recommendation Focus' with categories 'Challenging' and 'Defensive', and the horizontal axis labeled 'Temporal Orientation' with categories 'Present' and 'Future'. The four quadrants are labeled as follows: Hostile (Challenging, Present) describes a change needed with an argumentative tone. Promotive (Challenging, Future) indicates constructive change needed. Prohibitive (Defensive, Present) suggests that the status quo is sufficient and calls attention to counterproductive factors. Preventive (Defensive, Future) aims to sustain current practices and avoid future losses.

Summary of safety voice types. Source: Adapted from Bazzoli and Curcurato (2021) 

Close Figure 1
Figure 2
A cartoon of a man and a woman discussing two-factor authentication in an office setting.A cartoon image shows a man and a woman in an office setting. The man, wearing a suit, is sitting at a desk and speaking to the woman, who is standing and holding a folder. A speech bubble from the man says, 'Good morning, Emily. What's on your mind?' Another speech bubble from the woman says, 'I suggest that we remind all employees to adopt two-factor authentication when logging onto their workplace devices.' The background shows an office environment with blurred figures and office furniture.

Sample panel from preventive voice vignette presented to male participants

Figure 2
A cartoon of a man and a woman discussing two-factor authentication in an office setting.A cartoon image shows a man and a woman in an office setting. The man, wearing a suit, is sitting at a desk and speaking to the woman, who is standing and holding a folder. A speech bubble from the man says, 'Good morning, Emily. What's on your mind?' Another speech bubble from the woman says, 'I suggest that we remind all employees to adopt two-factor authentication when logging onto their workplace devices.' The background shows an office environment with blurred figures and office furniture.

Sample panel from preventive voice vignette presented to male participants

Close Figure 2
Figure 3
A cartoon of two people discussing security issues in an office setting.A cartoon of two people sitting at a table in an office. One person, presumably a manager, is speaking to the other, who appears to be an employee. The manager says, 'Good morning, Emily. What's on your mind?' The employee responds, 'Our security is a joke!' and 'It's ridiculous that we haven't implemented two-factor authentication yet!' The setting includes a wooden table, chairs, and a bookshelf with various items in the background.

Sample panel from hostile voice vignette presented to female participants

Figure 3
A cartoon of two people discussing security issues in an office setting.A cartoon of two people sitting at a table in an office. One person, presumably a manager, is speaking to the other, who appears to be an employee. The manager says, 'Good morning, Emily. What's on your mind?' The employee responds, 'Our security is a joke!' and 'It's ridiculous that we haven't implemented two-factor authentication yet!' The setting includes a wooden table, chairs, and a bookshelf with various items in the background.

Sample panel from hostile voice vignette presented to female participants

Close Figure 3
Table 1

Relationship of independent variables with intention to change security policies

Safety voiceFuture-orientedPresent-oriented
Recommender gender
Male EmployeeHigh Influence: Safety voice is strategic; male source amplifies credibilityModerate: Male source boosts influence, but present-voice is interpreted as immediately reactive
Female EmployeeModerate: Future-framing is agreeable, but female source is suppressed compared to male peersLow Influence: Safety voice is immediately committal; female voice is discounted
Table 2

Descriptive statistics and validities for study constructs

M (SD)Cron αCR12345
1) Change intent4.15 (0.6)0.610.730.83    
2) Org commit3.72 (0.8)0.890.930.31**0.92   
3) Power dist1.68 (0.5)0.710.88−0.110.020.82  
4) Security con4.40 (0.7)0.870.880.35**0.19**−0.090.92 
5) Voice behavior4.03 (0.7)0.870.940.32**0.15*−0.24**0.40**0.86

Note(s): Correlation matrix with square roots of AVE provided in italic in the diagonal. ** = p < 0.01, * = p < 0.05

Table 3

Descriptive statistics for the treatment groups

Voice typeSpeaker
Male (n = 140)Female (n = 140)Total
FuturePromotive (n = 71)4.39 (0.5)4.21 (0.6)4.30 (0.6)
Preventive (n = 70)4.36 (0.6)4.20 (0.7)4.28 (0.6)
PresentProhibit (n = 73)4.12 (0.5)4.01 (0.5)4.06 (0.5)
Hostile (n = 66)4.15 (0.7)3.74 (0.8)3.94 (0.7)
 Total4.25 (0.6)4.04 (0.7) 

Note(s): Means (and standard deviations) for security change intentions

Table 4

Results of the ANCOVA

MSFpλ2
Model3.309.78<0.0010.27
Voice type0.631.870.130.02
Gender3.6410.790.0010.04
Voice type * gender0.130.390.760.00
Affective commitment5.1315.20<0.0010.05
Security concern5.4015.99<0.0010.05
Voice behavior3.299.770.0020.03

Note(s): MS = mean square value; λ2 = effect size

Supplements

Supplementary data

References

Allen
,
N.J.
and
Meyer
,
J.P.
(
1990
), “
The measurement and antecedents of affective, continuance and normative commitment to the organization
”,
Journal of Occupational Psychology
, Vol. 
63
No. 
1
, pp. 
1
-
18
, doi: .
Bain
,
K.
,
Kreps
,
T.A.
,
Meikle
,
N.L.
and
Tenney
,
E.R.
(
2021
), “
Amplifying voice in organizations
”,
Academy of Management Journal
, Vol. 
64
No. 
4
, pp. 
1288
-
1312
, doi: .
Bansal
,
G.
and
Axelton
,
Z.
(
2024
), “
Impact of cybersecurity disclosures on stakeholder intentions
”,
Journal of Computer Information Systems
, Vol. 
64
No. 
1
, pp.
78
-
91
, doi: .
Bazzoli
,
A.
and
Curcuruto
,
M.
(
2021
), “
Safety leadership and safety voices: exploring the mediation role of proactive motivations
”,
Journal of Risk Research
, Vol. 
24
No. 
11
, pp. 
1368
-
1387
, doi: .
Bazzoli
,
A.
,
Curcuruto
,
M.
,
Morgan
,
J.I.
,
Brondino
,
M.
and
Pasini
,
M.
(
2020
), “
Speaking up about workplace safety: an experimental study on safety leadership
”,
Sustainability
, Vol. 
12
No. 
18
, p.
7458
, doi: .
Cavusoglu
,
H.
,
Cavusoglu
,
H.
,
Son
,
J.Y.
and
Benbasat
,
I.
(
2015
), “
Institutional pressures in security management: direct and indirect influences on organizational investment in information security control resources
”,
Information and Management
, Vol. 
52
No. 
4
, pp. 
385
-
400
, doi: .
Chan
,
M.
,
Woon
,
I.
and
Kankanhalli
,
A.
(
2005
), “
Perceptions of information security in the workplace: linking information security climate to compliant behavior
”,
Journal of Information Privacy and Security
, Vol. 
1
No. 
3
, pp. 
18
-
41
, doi: .
Chapman
,
G.B.
and
Elstein
,
A.S.
(
1995
), “
Valuing the future: temporal discounting of health and money
”,
Medical Decision Making
, Vol. 
15
No. 
4
, pp. 
373
-
386
, doi: .
Chen
,
A.
and
Trevino
,
L.K.
(
2022
), “
Promotive and prohibitive ethical voice: coworker emotions and support for the voice
”,
Journal of Applied Psychology
, Vol. 
107
No. 
11
, pp. 
1973
-
1994
, doi: .
Cimpian
,
J.R.
,
Kim
,
T.H.
and
McDermott
,
Z.T.
(
2020
), “
Understanding persistent gender gaps in STEM
”,
Science
, Vol. 
368
No. 
6497
, pp. 
1317
-
1319
, doi: .
Deaux
,
K.
and
Major
,
B.
(
1987
), “
Putting gender into context: an interactive model of gender-related behaviour
”,
Psychological Review
, Vol. 
94
No. 
3
, pp. 
369
-
389
, doi: .
Dorfman
,
P.W.
and
Howell
,
J.P.
(
1988
), “Dimensions of national culture and effective leadership patterns: hofstede revisited”, in
Farmer
,
R.N.
and
McGoun
,
E.G.
(Eds),
Advances in International Comparative Management
, Vol. 
3
, pp. 
127
-
150
.
Dutton
,
J.E.
and
Ashford
,
S.J.
(
1993
), “
Selling issues to top management
”,
Academy of Management Review
, Vol. 
18
No. 
3
, pp. 
397
-
428
, doi: .
Dworkin
,
T.
,
Schipani
,
C.
,
Milliken
,
F.
and
Kneeland
,
M.
(
2018
), “
Assessing the progress of women in corporate America: the more things change, the more they stay the same
”,
American Business Law Journal
, Vol. 
55
No. 
4
, pp. 
721
-
762
, doi: .
Eagly
,
A.H.
and
Carli
,
L.L.
(
2003
), “
The female leadership advantage: an evaluation of the evidence
”,
The Leadership Quarterly
, Vol. 
14
No. 
6
, pp. 
807
-
834
, doi: .
Eibl
,
B.
,
Lang
,
F.R.
and
Niessen
,
C.
(
2020
), “
Employee voice at work: the role of employees' gender, self-efficacy beliefs, and leadership
”,
European Journal of Work and Organizational Psychology
, Vol. 
29
No. 
4
, pp. 
570
-
585
, doi: .
Farh
,
C.
,
Oh
,
J.
,
Hollenbeck
,
J.
,
Yu
,
A.
,
Lee
,
S.
and
King
,
D.
(
2020
), “
Token female voice enactment in traditionally male-dominated teams: facilitating conditions and consequences for performance
”,
Academy of Management Journal
, Vol. 
63
No. 
3
, pp. 
832
-
856
, doi: .
Flowerday
,
S.V.
and
Tuyikeze
,
T.
(
2016
), “
Information security policy development and implementation: the what, how and who
”,
Computers and Security
, Vol. 
61
, pp. 
169
-
183
, doi: .
Gefen
,
D.
and
Straub
,
D.
(
1997
), “
Gender differences in the perception and use of e-mail: an extension to the technology acceptance model
”,
MIS Quarterly
, Vol. 
21
No. 
4
, pp. 
389
-
400
, doi: .
George
,
J.
,
Carlson
,
J.
and
Valacich
,
J.
(
2013
), “
Media selection as a strategic component of communication
”,
MIS Quarterly
, Vol. 
37
No. 
4
, pp. 
1233
-
1251
, doi: .
Hernandez
,
M.
(
2012
), “
Toward an understanding of the psychology of stewardship
”,
Academy of Management Review
, Vol. 
37
No. 
2
, pp. 
172
-
193
, doi: .
Hofmann
,
D.A.
,
Morgeson
,
F.P.
and
Gerras
,
S.J.
(
2003
), “
Climate as a moderator of the relationship between leader-member exchange and content specific citizenship: safety climate as an exemplar
”,
Journal of Applied Psychology
, Vol. 
88
No. 
1
, pp. 
170
-
178
, doi: .
Howell
,
T.M.
,
Harrison
,
D.A.
,
Burris
,
E.R.
and
Detert
,
J.R.
(
2015
), “
Who gets credit for input? Demographic and structural status cues in voice recognition
”,
Journal of Applied Psychology
, Vol. 
100
No. 
6
, pp. 
1765
-
1784
, doi: .
Hughes
,
R.
and
Huby
,
M.
(
2004
), “
The construction and interpretation of vignettes in social research
”,
Social Work and Social Sciences Review
, Vol. 
11
No. 
1
, pp. 
36
-
51
, doi: .
Isaakyan
,
S.
,
Sherf
,
E.N.
,
Tangirala
,
S.
and
Guentler
,
H.
(
2021
), “
Keeping it between us: managerial endorsement of public versus private voice
”,
Journal of Applied Psychology
, Vol. 
106
No. 
7
, pp. 
1049
-
1066
, doi: .
Johnston
,
A.
and
Hale
,
R.
(
2009
), “
Improved security through information security governance
”,
Communications of the ACM
, Vol. 
52
No. 
1
, pp. 
126
-
129
, doi: .
Khanolainen
,
D.
and
Semenova
,
E.
(
2020
), “
School bullying through graphic vignettes: developing a new arts-based method to study a sensitive topic
”,
International Journal of Qualitative Methods
, Vol. 
19
, 1609406920922765, doi: .
Kim
,
J.
and
Nan
,
X.
(
2019
), “
Temporal framing effects differ for narrative versus non-narrative messages: the case of promoting HPV vaccination
”,
Communication Research
, Vol. 
46
No. 
3
, pp. 
401
-
417
, doi: .
Kinicki
,
A.J.
,
Hom
,
P.W.
,
Trost
,
M.R.
and
Wade
,
K.J.
(
1995
), “
Effects of category prototypes on performance-rating accuracy
”,
Journal of Applied Psychology
, Vol. 
80
No. 
3
, pp. 
354
-
370
, doi: .
Le Poire
,
B.A.
,
Burgoon
,
J.K.
and
Parrott
,
R.
(
1992
), “
Status and privacy restoring communication in the workplace
”,
Journal of Applied Communication Research
, Vol. 
20
No. 
4
, pp. 
419
-
436
, doi: .
Lee
,
J.S.
,
Keil
,
M.
and
Shalev
,
E.
(
2019
), “
Seeing the trees or the forest? The effect of IT project managers' mental construal on IT project risk management activities
”,
Information Systems Research
, Vol. 
30
No. 
3
, pp. 
1051
-
1072
, doi: .
LePine
,
J.A.
and
Van Dyne
,
L.
(
2001
), “
Voice and cooperative behavior as contrasting forms of contextual performance: evidence of differential relationships with big five personality characteristics and cognitive ability
”,
Journal of Applied Psychology
, Vol. 
86
No. 
2
, pp. 
326
-
336
, doi: .
Marett
,
K.
(
2015
), “
Checking the manipulation checks in information security research
”,
Information and Computer Security
, Vol. 
23
No. 
1
, pp. 
20
-
30
, doi: .
Marett
,
K.
and
Marett
,
E.G.
(
2025
), “
The role of safety voice in improving organizational information security
”,
Proceedings of the 58th Hawaii International Conference on System Sciences
,
Waikoloa, HI
.
Marett
,
K.
,
Xiao
,
S.
and
Kim
,
S.
(
2023
), “
Security compliance and work-issued mobile devices: out of sight, out of mind?
”,
Information Systems and e-Business Management
, Vol. 
21
No. 
4
, pp. 
913
-
945
, doi: .
Maynes
,
T.D.
and
Podsakoff
,
P.M.
(
2014
), “
Speaking more broadly: an examination of the nature, antecedents, and consequences of an expanded set of employee voice behaviors
”,
Journal of Applied Psychology
, Vol. 
99
No. 
1
, pp. 
87
-
112
, doi: .
McClean
,
E.J.
,
Martin
,
S.R.
,
Emich
,
K.J.
and
Woodruff
,
C.T.
(
2018
), “
The social consequences of voice: an examination of voice type and gender on status and subsequent leader emergence
”,
Academy of Management Journal
, Vol. 
61
No. 
5
, pp. 
1869
-
1891
, doi: .
McClean
,
E.J.
,
Kim
,
S.
and
Martinez
,
T.
(
2022
), “
Which ideas for change are endorsed? How agentic and communal voice affects endorsement differently for men and for women
”,
Academy of Management Journal
, Vol. 
65
No. 
2
, pp. 
634
-
655
, doi: .
McCrea
,
S.M.
,
Liberman
,
N.
,
Trope
,
Y.
and
Sherman
,
S.J.
(
2008
), “
Construal level and procrastination
”,
Psychological Science
, Vol. 
19
No. 
12
, pp. 
1308
-
1314
, doi: .
McGill
,
T.
and
Thompson
,
N.
(
2021
), “
Exploring potential gender differences in information security and privacy
”,
Information and Computer Security
, Vol. 
29
No. 
5
, pp. 
850
-
865
, doi: .
Milliken
,
F.J.
and
Lam
,
N.
(
2009
), “Making the decision to speak up or to remain silent: implications for organizational learning”, in
Greenberg
,
J.
and
Edwards
,
M.S.
(Eds),
Voice and Silence in Organizations
,
Emerald Group Publishing
,
England
, pp. 
225
-
244
.
Morrison
,
E.W.
(
2014
), “
Employee voice and silence
”,
Annual Review of Organizational Psychology and Behavior
, Vol. 
1
No. 
1
, pp. 
173
-
197
, doi: .
Nakashima
,
N.A.
,
Daniels
,
D.P.
and
Laurin
,
K.
(
2017
), “
It's about time: divergent evaluations of restrictive policies in the near and distant future
”,
Organizational Behavior and Human Decision Processes
, Vol. 
142
, pp. 
12
-
27
, doi: .
Niemimaa
,
M.
and
Niemimaa
,
E.
(
2019
), “
Abductive innovations in information security policy development: an ethnographic study
”,
European Journal of Information Systems
, Vol. 
28
No. 
5
, pp. 
566
-
589
, doi: .
Noort
,
M.C.
,
Reader
,
T.W.
and
Gillespie
,
A.
(
2019
), “
Speaking up to prevent harm: a systematic review of the safety voice literature
”,
Safety Science
, Vol. 
117
, pp. 
375
-
387
, doi: .
Oc
,
B.
,
Bashshur
,
M.R.
and
Moore
,
C.
(
2015
), “
Speaking truth to power: the effect of candid feedback on how individuals with power allocate resources
”,
Journal of Applied Psychology
, Vol. 
100
No. 
2
, pp. 
450
-
463
, doi: .
Paananen
,
H.
,
Lapke
,
M.
and
Siponen
,
M.
(
2020
), “
State of the art in information security policy development
”,
Computers and Security
, Vol. 
88
, pp. 
1
-
14
, doi: .
Pandolfo
,
A.M.
,
Reader
,
T.W.
and
Gillespie
,
A.
(
2025
), “
Safety listening in organizations: an integrated conceptual review
”,
Organizational Psychology Review
, Vol. 
15
No. 
1
, pp.
93
-
124
, doi: .
Petrič
,
G.
and
Orehek
,
Š.
(
2025
), “
Expressing opinions about information security in an organization: the spiral of silence theory perspective
”,
Information and Computer Security
, Vol. 
33
No. 
2
, pp.
223
-
241
.
Posey
,
C.
,
Roberts
,
T.L.
and
Lowry
,
P.B.
(
2015
), “
The impact of organizational commitment on insiders' motivation to protect organizational information assets
”,
Journal of Management Information Systems
, Vol. 
32
No. 
4
, pp. 
179
-
214
, doi: .
Ridgeway
,
C.L.
and
Bourg
,
C.
(
2004
), “Gender as status: an expectation states theory approach”, in
Eagly
,
A.H.
,
Beall
,
A.E.
and
Sternberg
,
R.J.
(Eds),
The Psychology of Gender
,
The Guilford Press
, pp. 
217
-
241
.
Shao
,
X.
,
Siponen
,
M.
and
Liu
,
F.
(
2020
), “
Shall we follow? Impact of reputation concern on information security managers' investment decisions
”,
Computers and Security
, Vol. 
97
, 101961, doi: .
Sherf
,
E.N.
,
Tangirala
,
S.
and
Weber
,
K.C.
(
2017
), “
It is not my place! Psychological standing and men's voice and participation in gender-parity initiatives
”,
Organizational Science
, Vol. 
28
No. 
2
, pp. 
193
-
210
, doi: .
Simard
,
M.
and
Marchand
,
A.
(
1995
), “
A multilevel analysis of organisational factors related to the taking of safety initiatives by work groups
”,
Safety Science
, Vol. 
21
No. 
2
, pp. 
113
-
129
, doi: .
Singh
,
T.
,
Johnston
,
A.C.
,
D'Arcy
,
J.
and
Harms
,
P.D.
(
2023
), “
Stress in the cybersecurity profession: a systematic review of related literature and opportunities for future research
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
3
No. 
2
, pp. 
100
-
126
, doi: .
Siponen
,
M.
(
2005
), “
Analysis of modern IS security development approaches: towards the next generation of social and adaptable ISS methods
”,
Information and Organization
, Vol. 
15
No. 
4
, pp. 
339
-
375
, doi: .
Steinbach
,
A.L.
,
Gamache
,
D.L.
and
Johnson
,
R.E.
(
2019
), “
Don't get it misconstrued: executive construal-level shifts and flexibility in the upper echelons
”,
Academy of Management Review
, Vol. 
44
No. 
4
, pp. 
871
-
895
, doi: .
Sussman
,
S.
and
Sproull
,
L.
(
1999
), “
Straight talk: delivering bad news through electronic communication
”,
Information Systems Research
, Vol. 
10
No. 
2
, pp. 
150
-
166
, doi: .
Tangirala
,
S.
and
Ramanujam
,
R.
(
2012
), “
Ask and you shall hear (but not always): examining the relationship between manager consultation and employee voice
”,
Personnel Psychology
, Vol. 
65
No. 
2
, pp. 
251
-
282
, doi: .
Tejay
,
G.P.
and
Winkfield
,
M.
(
2025
), “
Does leadership approach matter? Examining behavioral influences of leaders on employees' information security compliance
”,
Information Systems Frontiers
, Vol. 
28
No. 
2
, pp. 
1
-
21
, doi: .
Trope
,
Y.
and
Liberman
,
N.
(
2010
), “
Construal-level theory of psychological distance
”,
Psychological Review
, Vol. 
117
No. 
2
, pp. 
440
-
463
, doi: .
Trope
,
Y.
,
Liberman
,
N.
and
Wakslak
,
C.
(
2007
), “
Construal levels and psychological distance: effects on representation, prediction, evaluation, and behavior
”,
Journal of Consumer Psychology
, Vol. 
17
No. 
2
, pp.
83
-
95
.
Tucker
,
S.
and
Turner
,
N.
(
2011
), “
Young worker safety behaviors: development and validation of measures
”,
Accident Analysis and Prevention
, Vol. 
43
No. 
1
, pp. 
165
-
175
, doi: .
Van Dyne
,
L.
and
LePine
,
J.A.
(
1998
), “
Helping and voice extra-role behaviors: evidence of construct and predictive validity
”,
Academy of Management Journal
, Vol. 
41
No. 
1
, pp. 
108
-
119
, doi: .
Venkatesh
,
V.
and
Morris
,
M.
(
2000
), “
Why don't men ever stop to ask for directions? Gender, social influence, and their role in technology acceptance and usage behavior
”,
MIS Quarterly
, Vol. 
24
No. 
1
, pp. 
115
-
139
, doi: .
von Solms
,
R.
and
von Solms
,
B.
(
2004
), “
From policies to culture
”,
Computer and Security
, Vol. 
23
No. 
4
, pp. 
275
-
279
, doi: .
Workman
,
M.
,
Bommer
,
W.H.
and
Straub
,
D.
(
2008
), “
Security lapses and the omission of information security measures: a threat control model and empirical test
”,
Computers in Human Behavior
, Vol. 
24
No. 
6
, pp. 
2799
-
2816
, doi: .
Xu
,
F.
,
Hsu
,
C.
,
Wang
,
T.
and
Lowry
,
P.B.
(
2024
), “
The antecedents of employees’ proactive information security behaviour: the perspective of proactive motivation
”,
Information Systems Journal
, Vol. 
34
No. 
4
, pp.
1144
-
1174
, doi: .
Xue
,
B.
,
Xu
,
F.
,
Luo
,
X.
and
Warkentin
,
M.
(
2021
), “
Ethical leadership and employee information security policy (ISP) violation: exploring dual-mediation paths
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
1
No. 
1
, pp. 
5
-
23
, doi: .
Yan
,
T.T.
,
Tangirala
,
S.
,
Vadera
,
A.K.
and
Ekkirala
,
S.
(
2022
), “
How employees learn to speak up from their leaders: gender congruity effects in the development of voice efficacy
”,
Journal of Applied Psychology
, Vol. 
107
No. 
4
, pp. 
650
-
667
.
Yang
,
I.
and
Li
,
L.M.
(
2018
), “
‘It is not fair that you do not know we have problems’: perceptual distance and the consequences of male leaders' conflict avoidance behaviours
”,
European Management Journal
, Vol. 
36
No. 
1
, pp. 
105
-
116
, doi: .
Zhan
,
X.
,
Durcikova
,
A.
and
Galletta
,
D.
(
2024
), “
The paradox of choice: digital Akrasia in the deployment of multi-factor authentication
”,
Proceedings of the 57th Hawaii International Conference on System Sciences
,
Honolulu, HI
.
Zhu
,
Y.
,
Long
,
L.
,
Zhang
,
Y.
and
Wang
,
H.
(
2025
), “
Remember to say ‘thanks’ when rejecting others: the moderating role of leader gratitude expression in the relationship between leader voice rejection and employees’ subsequent upward voice
”,
Asia Pacific Journal of Management
, Vol. 
42
No. 
2
, pp.
531
-
558
.
LePine
,
J.A.
and
Van Dyne
,
L.
(
1998
), “
Predicting voice behavior in work groups
”,
Journal of Applied Psychology
, Vol. 
83
No. 
6
, pp. 
853
-
868
, doi: .
Schreurs
,
B.
,
Hamstra
,
M.R.
and
Davidson
,
T.
(
2020
), “
What's in a word? Using construal-level theory to predict voice endorsement
”,
European Journal of Work and Organizational Psychology
, Vol. 
29
No. 
1
, pp. 
93
-
105
, doi: .

Languages

or Create an Account

Close subscription notice
Close access options