Sanctions are a primary lever of cybersecurity governance. Traditional information systems deterrence models have assumed symmetrical effects – that reducing violations proportionally increases compliance. This study aims to challenge that assumption by theorizing deterrence as an asymmetric phenomenon rather than a binary mechanism.
We conducted a meta-analysis of 51 studies (N = 20,768) to examine the differential impact of sanctions across two behavioral trajectories: compliance intentions and violation intentions. We further investigate sanction celerity as a moderator of deterrence effects.
Results reveal a fundamental asymmetry in deterrence. While sanctions act as robust normative reinforcement mechanisms that significantly strengthen compliance, they exert no significant impact on the reduction of violation intentions. Moreover, sanction celerity is a critical moderator that amplifies the deterrent weight of both detection certainty and sanction severity, preventing temporal signal decay.
Managers should shift from volume-based punishment to agility-based governance. To foster compliance, sanctions should act as normative signals that reinforce organizational values, whereas to curb violations, managers must address situational strains (e.g. high workloads) that drive rule-breaking.
By demonstrating that compliance and violation are distinct domains, this study shows that the psychological mechanisms driving rule-following differ from those governing rule-breaking. The findings also underscore that celerity is a prerequisite for efficacy; without timely enforcement, sanctions lose their psychological salience and fail to influence decision-making.
1. Introduction
In organizational cybersecurity, sanctions function as core governance mechanisms intended to deter deliberate policy violations by signaling that non-compliance will incur negative consequences (Straub, 1990). While this logic assumes functional symmetry, that a sanction regime will proportionally promote compliance and suppress violations, organizational practice often indicates a stark divergence, undermining this theoretical ideal.
Discussions with cybersecurity managers revealed a significant disparity in how sanctions are applied. Sanctions are often more readily applied when employees fail to comply with proactive security requirements, such as mandatory training, than for actual violations, like using personal cloud storage. The former is easier to detect, document, and defend, allowing relatively swift administrative responses (i.e. high celerity), whereas the latter often involves ambiguous intent and evidentiary uncertainty, leading to delayed or bypassed enforcement (i.e. low celerity). Consequently, compliance failures are governed through prompt and consistent sanctioning, while violations frequently go unpunished. This creates a deterrence-behavior decoupling: while the organization sends a clear and consistent signal regarding compliance, the signal regarding violations remains muffled and inconsistent. Over time, employees learn these enforcement patterns, leading to an asymmetric calibration of the deterrent force, where the pressure to follow administrative rules does not translate into a restraint from deviant acts. This asymmetry motivates a systematic investigation into how sanctions differentially impact compliance and violation, a gap this study aims to address.
A substantial body of sanctions-based deterrence research in cybersecurity examines how individuals evaluate potential sanction consequences before deciding whether to engage in or refrain from policy violations. However, extant findings exhibit considerable empirical heterogeneity. For instance, while several studies report strong negative effects of sanction likelihood on violation (Johnston et al., 2016; Choi, 2019), others find no significant impact (Brown, 2017; Jaeger et al., 2021), or even report contradictory effects within the same sample (Li et al., 2021). Studies focusing on compliance more consistently report strong positive associations with sanction likelihood (Foth, 2016; Malimage et al., 2020), although negligible effects have also been observed (Moody et al., 2018). These asymmetries point to a fragmented understanding of how sanctions influence behavior, likely because compliance-seeking and violation-avoiding behaviors are governed by distinct enforcement signals and behavioral logics. Moreover, because organizational responses to violations are often delayed or contested, the celerity (timing) of sanctions becomes critical in determining whether deterrent signals remain psychologically salient for insiders (Malimage et al., 2020). This mirrors real-world uncertainty surrounding enforcement and highlights the need for a systematic inquiry into how sanction effects diverge across different behavioral domains.
Meta-analysis provides a robust approach for synthesising existing research and uncovering overarching patterns across studies (Field and Gillett, 2010). This is particularly valuable in domains such as sanctions-based deterrence, where empirical findings are often inconsistent or contradictory. By aggregating evidence across studies, meta-analysis allows researchers to evaluate the overall strength and direction of sanction effects while accounting for variations in sample size, study design, and measurement. Although prior meta-analyses on sanctions (Trang and Brendel, 2019; Liu et al., 2019; D'Arcy and Herath, 2011; Abed and Weistroffer, 2016) have yielded valuable insights, they implicitly assume deterrence symmetry by treating compliance and violation as opposing responses to the same sanctions signals. As a result, they do not examine whether sanctions operate differently across these behavioral domains. This distinction is critical, as compliance and violation may be driven by distinct psychological and contextual mechanisms. While Kuo et al. (2020) include both compliance and risky behavior, their meta-analysis does not theorize or test moderators that explain why sanction effects vary across these domains.
To address these limitations, we conduct a meta-analysis that explicitly examines deterrence asymmetry. By comparing the effects of sanctions on compliance versus violation intentions and testing theoretically grounded moderators that may account for these divergent trajectories, we extend our preliminary work (Prabhu et al., 2026). Our primary objective is to evaluate whether the foundational assumption of symmetry in sanction-based deterrence holds under the complexities of organizational cybersecurity. Accordingly, the research question guiding this study is: How do sanctions differentially affect non-malicious insiders' cybersecurity compliance and violation intentions?
The next section develops the theoretical foundations of sanctions and deterrence. Section 3 details the meta-analytic methodology, followed by Section 4, which reports the procedure and core findings. Section 5 interprets these findings by discussing their theoretical implications, limitations, and avenues for future research. Finally, Section 6 concludes the paper.
2. Theoretical overview
Sanctions are primarily grounded in deterrence theory (DT) (Gibbs, 1968), a framework derived from rational choice theory (Becker, 1968). DT posits that individuals are rational actors who seek to maximize rewards and minimize punishments. The underlying assumption is that employees will be less likely to engage in deviant behaviors if they believe a violation will result in certain, prompt, and serious repercussions (Straub, 1990; Gibbs, 1968). As such, organizations employ sanctions as a formal behavioral control mechanism to prevent internal security breaches, mandate policy compliance, and reinforce a culture of accountability (Prabhu and Dell, 2025; Malimage et al., 2020).
2.1 Deterrence: core constructs
DT identifies three primary dimensions that determine the deterrent weight of a sanction regime: certainty (the perceived likelihood of detecting behavior), severity (the perceived harshness of the consequences), and celerity (the perceived quickness with which punishment is administered) (Straub, 1990; Gibbs, 1968).
Importantly, deterrence operates primarily on perceptions rather than objective enforcement metrics (Vance et al., 2020; Straub, 1987). These perceptions are not static; they are shaped by the individual's experiences, the clarity of organizational communication, and broader cultural norms regarding what is tolerated. In organizational cybersecurity, these sanctions can range from mandatory training and formal warnings to suspension or termination.
Sanction Certainty: Within information systems (IS) research, sanction certainty is a multi-faceted construct, conceptualized as both the “certainty of getting caught” (p. 445) and “certainty of punishment” (p. 446) (Straub and Welke, 1998). Despite this dual nature, empirical research has often privileged one dimension over the other with little explicit theoretical justification. This selective focus is problematic: studies emphasizing detection certainty often focus on surveillance and monitoring technicalities, whereas those focusing on punishment certainty highlight the consistency of enforcement regardless of detection frequency. The empirical landscape reflects this conceptual split, as summarized in Table 1.
Sanction certainty conceptualization
| Original conceptualization | Mapped construct (Current study) | Supporting studies |
|---|---|---|
| Certainty of getting caught | Detection Certainty | Herath and Rao (2009b), Li et al. (2010), Hovav and D'Arcy (2012), Aurigemma and Mattson (2017), Johnston et al. (2016), Foth (2016), Kuo et al. (2017), Moody et al. (2018), Rajab and Eydgahi (2019), Safa et al. (2019), Choi (2019), Chen et al. (2020), Hooper and Blunt (2020), Ameen et al. (2020), Wang and Xu (2021), Al-Shanfari et al. (2022), Jaeger et al. (2021), Malimage et al. (2020), Herath and Rao (2009a), D'Arcy et al. (2009) |
| Certainty of punishment | Sanction Certainty | Peace et al. (2003), Dugo (2007), Liao et al. (2009), Son (2011), Cheng et al. (2013), Brown (2017), Kuo et al. (2017), Xu and Hu (2018), Li et al. (2021), Sarkar et al. (2020), Johnston et al. (2015) |
| Original conceptualization | Mapped construct (Current study) | Supporting studies |
|---|---|---|
| Certainty of getting caught | Detection Certainty | |
| Certainty of punishment | Sanction Certainty |
Regarding detection certainty, findings remain divided. While several studies report significant deterrent effects on cybersecurity intentions (Kuo et al., 2017; Wang and Xu, 2021; Ameen et al., 2020), others find no significant effects (Moody et al., 2018; Rajab and Eydgahi, 2019; Hooper and Blunt, 2020). Notably, Li et al. (2010) observed mixed results within a single study, where detection certainty influenced intentions in only one of three experimental conditions, suggesting that detection alone may be insufficient to deter behavior across all contexts.
Research on punishment certainty is similarly fragmented. While strong support for its deterrent effect exists (Kuo et al., 2017; Sarkar et al., 2020; Ifinedo and Idemudia, 2017), a substantial body of research reports no deterrent effect (Brown, 2017; Cheng et al., 2013; Johnston et al., 2015). These inconsistencies underscore the critical need for theoretical clarity regarding how these two sub-dimensions interact to form a singular “certainty” signal.
Sanction Severity: Research on sanction severity, the perceived harshness of the penalty, presents some of the most contradictory findings in the field. While some studies suggest that heightened penalties deter IS misuse (Hovav and D'Arcy, 2012; Aurigemma and Mattson, 2014), other studies challenge this severity-deterrence link (Rajab and Eydgahi, 2019; Moody et al., 2018).
A significant theoretical complication is the “backfire effect”. Herath and Rao (2009b, 2009a) found a negative relationship between severity and compliance, suggesting that overly punitive environments can induce workplace stress and hostility, ultimately proving counterproductive to security goals. Similarly, Aurigemma and Mattson (2014) noted that experiencing sanctions actually increased future infractions, a phenomenon that contradicts the basic tenets of rational choice theory. These conflicting results suggest that the effectiveness of severity is likely contingent upon psychological moderators or the perceived legitimacy of the rules.
Sanction Celerity: Rooted in early criminological frameworks (Gibbs, 1968), sanction celerity involves an end-to-end process of “prompt detection” and “prompt apprehension”. Despite its foundational status in DT, celerity was introduced into IS research much later than certainty and severity, often reduced to a narrow measure of administrative speed. This neglect has resulted in a limited understanding of how the timing of sanctions impacts their psychological salience.
Recent studies suggest that celerity may not only have a direct effect on compliance intentions (Malimage et al., 2020; Chen et al., 2020) but may also serve as a crucial moderator, amplifying the deterrent effects of certainty and severity (Arunothong, 2014). As noted by Chen et al. (2020), the swiftness of a sanction reinforces accountability by tightening the link between violation and the consequence, thereby amplifying the perceived impact of certainty and severity. This makes celerity a pivotal, yet underexplored, variable in understanding how deterrent signals are processed by employees.
To ensure conceptual consistency across a fragmented empirical landscape, the definition used in this study was derived by synthesizing foundational criminological principles with their specific operationalization in IS research. By tracing these constructs back to their theoretical origins and accounting for their evolution in digital environments, Table 2 establishes a standardized definition for the meta-analytic pooling of results.
Construct definitions
| Construct | Origin of definition | Our definition |
|---|---|---|
| Detection certainty | “certainty of getting caught” (Straub and Welke, 1998) (p. 445) “enforcement agents explicitly or implicitly make their presence felt.” (Straub, 1987) (p. 279) | The perceived likelihood that deviant actions will be identified by organizational monitoring |
| Sanction certainty | “certainty of punishment” (Straub and Welke, 1998) (p. 446) “punishment is more certain” (Straub, 1987) (p. 279) | The perceived likelihood that a detected deviant action will result in the administration of a penalty |
| Sanction severity | “severity of punishment” (Straub and Welke, 1998) (p. 446) | The perceived magnitude or harshness of the penalty administered |
| Sanction celerity | prompt and effective detection and apprehension (Gibbs, 1968) (p. 518) | The perceived swiftness or temporal proximity between the deviation and the resulting sanction |
| Construct | Origin of definition | Our definition |
|---|---|---|
| Detection certainty | “certainty of getting caught” ( | The perceived likelihood that deviant actions will be identified by organizational monitoring |
| Sanction certainty | “certainty of punishment” ( | The perceived likelihood that a detected deviant action will result in the administration of a penalty |
| Sanction severity | “severity of punishment” ( | The perceived magnitude or harshness of the penalty administered |
| Sanction celerity | prompt and effective detection and apprehension ( | The perceived swiftness or temporal proximity between the deviation and the resulting sanction |
Note(s): * referred to as Disincentives Certainty by Straub (1987)
Together, these deterrence dimensions underscore the multifaceted nature of sanction-based control in organizational cybersecurity. While celerity has traditionally received less empirical attention, its interaction with certainty and severity may be the mechanism that transforms a “muffled” organizational signal into a potent deterrent. The complexity of these interrelationships and the potential for them to manifest differently across behavioral types highlight the need for a comprehensive meta-analytic review. By examining each dimension independently and investigating celerity as a potential moderator, this study aims to clarify how timing and consistency of sanctions shape the divergent trajectories of compliance and violation in organizational contexts.
2.2 Behavior: compliance versus deliberate violation
Originally conceptualized to explain deviant behavior, DT emphasizes sanctions as a formal mechanism to discourage rule-breaking (Straub, 1987). Within the IS literature, however, the application of DT has expanded to explain compliant behaviors aimed at proactive risk mitigation (Gundu, 2019). While the literature often treats the deterrence of violations and the motivation to comply as functionally equivalent, they represent conceptually distinct behavioral domains with unique psychological drivers. This aligns with emerging perspectives that compliance and deliberate violation are not opposite ends of a behavioral continuum, but rather distinct concepts (Liang and Xue, 2009; Prabhu and Dell, 2025).
For this meta-analysis, compliance is defined as “employees' intentional engagement in prescribed IS policies and practices, reflecting efforts to adhere to organizational expectations and reduce security risk”. In contrast, violation is defined as “employees' intentional engagement in prohibited or non-compliant security behaviors that contravene organizational policies, including acts of misuse, circumvention, or disregard of security controls”. Consistent with prior organizational cybersecurity research, this study focuses on intentional but non-malicious insider behaviors, where violations reflect policy circumvention or disregard for convenience, efficiency, or task completion rather than an intent to cause harm.
Drawing on regulatory focus theory (Higgins, 1997), we argue that these two domains operate under different psychological orientations. Violation avoidance is primarily rooted in a “prevention focus”, characterized by detection and punishment (Straub, 1987; Safa et al., 2019). However, sustained, proactive compliance often requires a “promotion focus”, where security is more than a mere obligation and includes intrinsic drivers such as personal values, security awareness, and organizational commitment (Prabhu et al., 2025). This suggests that while sanctions are effective “brakes” for stopping proscribed behavior, they may be less effective “engines” for driving value-aligned compliance. To clarify these distinctions, Table 3 synthesizes the fundamental distinctions between these two behavioral domains.
Distinctions between compliance and violation
| Feature | Compliance (policy adherence) | Violation (policy breach) |
|---|---|---|
| Behavioral nature | Adherence: Execution of a mandated protocol. This includes commission (e.g. attending training, using MFA) and omission (e.g. refraining from prohibited websites) | Transgression: Breaking a rule (e.g. using unlicensed applications) or bypassing control (e.g. sharing passwords) |
| Motivation | Value-aligned | Risk-benefit driven, situational opportunity |
| Psychological focus | Promotional focus: Achieving a state of security alignment | Prevention focus: Avoiding a state of risk, detection, and subsequent punishment |
| Primary intent | Constructive: Driven by the desire to fulfill obligations, protect the organization, or maintain professional norms | Instrumental/Deviant: Driven by the desire to bypass obstacles, gain convenience, or achieve personal ends |
| Enforcement signal | Administrative: Typically, high visibility and easy to audit (high celerity) | Investigative: Often technical or hidden; harder to detect and prove (low celerity) |
| Examples in IS literature | Using encrypted drives, changing passwords regularly, performing software updates, attending required training, etc. | Unauthorized data downloading, use of shadow IT, visiting prohibited websites, etc. |
| Feature | Compliance (policy adherence) | Violation (policy breach) |
|---|---|---|
| Behavioral nature | Adherence: Execution of a mandated protocol. This includes commission (e.g. attending training, using MFA) and omission (e.g. refraining from prohibited websites) | Transgression: Breaking a rule (e.g. using unlicensed applications) or bypassing control (e.g. sharing passwords) |
| Motivation | Value-aligned | Risk-benefit driven, situational opportunity |
| Psychological focus | Promotional focus: Achieving a state of security alignment | Prevention focus: Avoiding a state of risk, detection, and subsequent punishment |
| Primary intent | Constructive: Driven by the desire to fulfill obligations, protect the organization, or maintain professional norms | Instrumental/Deviant: Driven by the desire to bypass obstacles, gain convenience, or achieve personal ends |
| Enforcement signal | Administrative: Typically, high visibility and easy to audit (high celerity) | Investigative: Often technical or hidden; harder to detect and prove (low celerity) |
| Examples in IS literature | Using encrypted drives, changing passwords regularly, performing software updates, attending required training, etc. | Unauthorized data downloading, use of shadow IT, visiting prohibited websites, etc. |
Traditional deterrence models operate on an implicit assumption of behavioral symmetry: the belief that a single deterrent signal will increase compliance and suppress violations with equal force. However, this binary view masks critical nuances in intent, context, and psychological processing. We challenge this assumption by highlighting three fundamental theoretical divergences that justify a granular analysis:
Motivational Heterogeneity: Compliance and violation are driven by non-reciprocal antecedents. Compliance is typically a conscious, proactive choice to align with organizational standards; an act of organizational citizenship or duty (doing the job “the right way”) (Moody et al., 2018), whereas violations are often instrumental workarounds (doing the job “the easy/fast way”) (Prabhu and Dell, 2025). Because violations range from malicious intent to benign errors or shadow IT workarounds performed to achieve work goals, removing the incentive for a violation does not inherently generate the motivation for proactive compliance.
Cognitive Decoupling via Neutralization: Neutralization allows individuals to decouple specific behaviors from their moral identity (Moody et al., 2018; Prabhu, 2025). By reclassifying the breach as a functional necessity, an employee can violate policy while maintaining a high subjective compliance identity (Vance et al., 2020). This insulation from deterrent-induced shame or guilt blurs the boundaries between behavioral domains, allowing violations to persist despite a commitment to the organization.
Regulatory Asymmetry: Compliance and violation respond to distinct psychological regulatory systems. While sanctions enforce a baseline of prevention-oriented avoidance, they fail to address the promotion-oriented motivations (e.g. efficiency, goal attainment) that drive violations. Because these systems operate through independent psychological pathways, a change in one does not necessitate a corresponding inverse change in the other.
Consequently, viewing compliance and violation as strict opposites oversimplifies the complexities of cybersecurity behavior. A granular analysis is therefore required to clarify how sanctions function as signals that are interpreted differently depending on whether the desired outcome is the promotion of pro-social behavior or the prevention of proscribed behavior.
2.3 Prior meta-analyses of sanctions in cybersecurity
The evolution of meta-analytic research in cybersecurity deterrence reflects a shift from narrative synthesis to complex quantitative methods. D'Arcy and Herath (2011) provided an early narrative review of DT in IS research, noting the persistent inconsistency of sanction effects and the literature's lopsided focus on deterring negative behaviors rather than promoting positive ones. While they proposed methodological and contextual contingencies as explanations for this “empirical noise”, their study lacked a formal quantitative synthesis.
Abed and Weistroffer (2016) addressed this gap by performing a meta-analysis on core deterrence constructs (i.e. certainty, severity, and celerity), using correlation coefficients as effect sizes. Their findings indicated only small effects ranging from 0.13 to 0.21, leading them to suggest that DT should be integrated with other socio-psychological frameworks to improve its explanatory power. Their study did not include informal deterrence constructs.
Trang and Brendel (2019) extended this work by testing a wide array of contextual moderators (e.g. malicious versus non-malicious behavior, power-distance, and uncertainty avoidance) and methodological moderators (e.g. behavioral versus scenario-based measures and generic versus specific measures). While they confirmed the overall weakness of deterrence effects, they identified significant predictive power in high power-distance and malicious contexts. However, like earlier studies, this analysis remained focused on the three primary constructs without exploring behavioral bifurcation.
While Kuo et al. (2020) made significant strides by synthesizing both compliance and risk behaviors, their analysis excluded moderator analysis, leaving the high degree of heterogeneity unexplained. Our preliminary study (Prabhu et al., 2026) addressed this by updating the landscape and introducing the concept of deterrence asymmetry. This provided the first systematic meta-analytic evidence of how celerity and behavioral logic converge to shape sanction effectiveness. The present meta-analysis extends this foundation by moving beyond initial observations and elevating the role of sanction celerity from a simple direct predictor to a primary moderator of the certainty-severity relationship with compliance and violation intentions. This offers a more nuanced perspective on the temporal conditions under which sanctions promote compliance and deter violations within organizational settings.
2.4 Research model
To synthesize existing empirical evidence on the influence of sanctions in cybersecurity, we conduct a meta-analysis. The primary research model, Figure 1, illustrates our dual-pathway framework. Grounded in DT, the model proposes a framework to test the behavioral symmetry assumption prevalent in IS research. This primary model examines the direct influence of the four deterrent dimensions, detection certainty, sanction certainty, sanction severity, and sanction celerity, on two distinct behavioral trajectories: compliance and violation.
A diagram representing a primary research model that illustrates a dual-pathway framework for the influence of sanctions in cybersecurity. The model includes two main pathways: Compliance Intention and Violation Intention. Four key deterrent dimensions are shown: Detection Certainty, Sanction Certainty, Sanction Severity, and Sanction Celerity. Arrows indicate the directional influence of these dimensions on both compliance and violation intentions. Specific hypotheses (H1a, H1b, H2a, H2b, H3a, H3b, H4a, H4b, H1c, H1d, H2c, H2d, H3c, H3d) are labeled along these arrows, showing the proposed relationships and interactions between the dimensions and the intentions.Primary research model
A diagram representing a primary research model that illustrates a dual-pathway framework for the influence of sanctions in cybersecurity. The model includes two main pathways: Compliance Intention and Violation Intention. Four key deterrent dimensions are shown: Detection Certainty, Sanction Certainty, Sanction Severity, and Sanction Celerity. Arrows indicate the directional influence of these dimensions on both compliance and violation intentions. Specific hypotheses (H1a, H1b, H2a, H2b, H3a, H3b, H4a, H4b, H1c, H1d, H2c, H2d, H3c, H3d) are labeled along these arrows, showing the proposed relationships and interactions between the dimensions and the intentions.Primary research model
Compliance path: We hypothesize that these dimensions positively influence cybersecurity compliance (H1a, H2a, H3a, H4a). In this context, sanctions serve as a promotion signal, reinforcing the necessity of adhering to organizational standards.
Violation path: We hypothesize that these dimensions negatively influence violation intentions (H1b, H2b, H3b, H4b). Here, sanctions function as a prevention signal, designed to increase the perceived cost of deviant acts.
A significant contribution of this study is the investigation of sanction celerity as a moderator. While traditional DT focuses on the direct effect of speed, we propose that celerity acts as a temporal catalyst. Specifically, we explore whether the swiftness of a sanction strengthens the psychological link between behavior and consequence, thereby moderating the relationship between certainty-severity and behavioral intentions.
As prior research has not systematically examined celerity in this capacity, this secondary model is exploratory. We test whether high celerity amplifies the deterrent effect, making the signals less muffled, or if its influence varies across the compliance and violation domains.
Finally, to account for empirical heterogeneity identified in Section 2, we perform post-hoc analyses on three contextual moderators: (1) Sample size: to test for small-study or publication bias, (2) Geographic region: to account for cultural differences in response to formal authority (e.g. power distance), and (3) Sample type: to determine if student and professional employees react differently to the threats of sanctions. Given the exploratory nature of these boundary conditions, we do not propose formal hypotheses, but rather use these analyses to refine the theoretical boundary conditions of the deterrence asymmetry.
3. Materials and method
This study employs a meta-analytic approach to synthesize empirical evidence on the relationship between sanction components and cybersecurity behavioral intentions. Unlike narrative reviews, meta-analysis offers a statistically rigorous approach to aggregating findings across independent studies, providing more precise and generalizable effect size estimates by accounting for sampling error and between-studies variance (Field and Gillett, 2010). This approach is particularly appropriate given the mixed and sometimes contradictory findings identified in prior deterrence-based cybersecurity research (Section 2), as it enables systematic moderator testing to explain heterogeneity in sanction effects.
Our model tests the behavioral symmetry assumption underlying DT by differentiating between two dependent variables: compliance intentions and violation intention (Figure 1). Consistent with prior meta-analyses in IS deterrence research (Abed and Weistroffer, 2016; Trang and Brendel, 2019; Kuo et al., 2020), correlation coefficients (r) are used as the primary effect size metric. Extending prior work, this study (1) conducts subgroup analyses to statistically compare sanction effects across compliance and violation domains, thereby testing behavioral symmetry, and (2) incorporates moderator analyses to examine how contextual factors, particularly sanction celerity, shape these behavioral outcomes.
3.1 Data collection procedure
To construct a comprehensive and representative corpus of empirical studies, we adopted a multi-stage systematic search strategy. First, we conducted a backward search by identifying and cross-referencing all primary studies included in established information security reviews (e.g. D'Arcy and Herath (2011)) and deterrence-based meta-analyses (Abed and Weistroffer, 2016; Trang and Brendel, 2019; Kuo et al., 2020). This step ensured coverage of foundational empirical work grounded in DT.
Second, to capture more recent developments in the cybersecurity domain, we conducted a forward search on the Scopus database. We applied the validated search strings developed by Kuo et al. (2020) to identify studies published between 2020 and 2026. This search identified 17 additional publications not included in prior meta-analyses.
The final dataset comprised 34 unique articles, incorporating 51 studies and a total sample size of N = 20,768, spanning both compliance and violation domains.
3.2 Coding of variables
Data extraction followed a standardized protocol to ensure consistency. For each study, five categories of information were coded: (1) study metadata: authors, publication year, geographic location, (2) methodological characteristics: sample size, participant type (students vs. employed), and data collection method (scenario-based vs. survey), (3) behavioral domain: compliance vs. violation, (4) deterrence constructs: detection certainty, sanction certainty, sanction severity, and sanction celerity, and (5) statistical data: zero-order correlations or statistics convertible to correlations.
When correlations were not explicitly reported, they were computed from available inferential statistics (e.g. t-tests, sample sizes) using established conversion procedures (Borenstein et al., 2009). To address the unit-of-analysis concerns and preserve statistical independence, we adopted a conservative approach: only one effect size per construct-outcome pair was retained per independent sample, even when multiple effect sizes were available, to avoid over-representing any single study.
Reflecting our theoretical framework of deterrence asymmetry, behavioral outcomes were classified through a rigorous process of keyword matching and manual context review. Outcomes framed as “compliance,” “adherence,” “protective behavior,” or “security behavior” were coded as compliance. Those describing “violation,” “misuse,” “abuse,” “deviance,” or “risky behavior” were classified as violations.
3.3 Data analysis
We conducted random-effects meta-analyses using the DerSimonian–Laird method as implemented in the metafor package in R (Viechtbauer, 2010). Correlation coefficients were transformed to Fisher's Z before analysis and back-transformed for interpretation. Effect sizes were weighted by inverse variance (1/(n-3)) to account for sampling errors. Between-studies heterogeneity was assessed using I2, τ2, and Q-statistics.
Studies were included if they reported valid zero-order correlations or statistics convertible to correlations. To ensure statistical stability, each deterrence construct-outcome pairing was required to be represented by at least three independent studies (k ≥ 3) to be included in the analysis. For this reason, we chose to test behavioral intention as opposed to actual behavior. Consistent with prior meta-analytic practice, only one effect size per construct-outcome pair per independent sample was retained. Effect sizes were classified by behavioral intention outcome: compliance intentions and violation intentions.
To examine the moderating role of sanction celerity, we identified studies reporting celerity alongside other deterrence constructs. Moderation was assessed using construct-specific meta-regression models, with centered celerity values entered as continuous predictors. The significance of moderation effects was evaluated using QM statistics, comparing models with and without the moderator term. All moderation models employed restricted maximum likelihood estimation (REML), while the DerSimonian-Laird estimator was used for the primary effects models.
Publication bias was assessed using Egger's regression test and Begg's rank correlation test, where applicable (k ≥ 3). The trim-and-fill procedure was also applied to estimate the potential influence of missing studies, with results interpreted cautiously given known limitations of the model in heterogeneous samples. To ensure statistical stability, each deterrence construct-outcome pairing was required to be represented by at least three independent studies (k ≥ 3). An exception was made for sanction celerity-violation (k = 2), which was retained given the theoretical importance of this relationship and the substantial combined sample size (N = 414).
Post-hoc moderator analyses were conducted using mixed-effects meta-regression to examine demographic and methodological factors. Categorical moderators included geographic region (Asia, Europe, North America, Other), sample type (Students, Employees, Healthcare, Mixed/Other), sample size categories (Small <200, Medium 200–499, Large ≥500), and context specificity (Healthcare-specific, Academic, Organizational, General).
3.4 Meta-analysis models
Primary Effects Model: θi = μ + ui + ei, where θi is the Fisher's Z-transformed effect size for study i, μ is the overall mean effect, ui ∼ N(0, τ2) represents between-study heterogeneity, and ei ∼ N(0, vi) reflects within-study sampling error, with variance vi = 1/(ni-3).
Celerity as a Moderator: θi = β0 + β1(Celerityi - C̄) + ui + ei, where (Celerityi - C̄) represents the centered celerity value for study i, and β1 quantifies the moderating effect of sanction celerity on the relationship between other deterrence constructs and behavioral intention outcomes.
Post-Hoc Analysis – Potential Moderators: θi = β0 + β1X1i + β2X2i + … + βkXki + ui + ei, where Xki represents categorical moderator variables (geographic region, sample type, sample size) as dummy-coded predictors, and βk represents the regression coefficients for each moderator level.
4. Results
4.1 Primary effects
Seven of the eight primary effects models yielded statistically significant pooled effects, providing strong support for most of the proposed hypotheses. The findings are presented separately for compliance and violation outcomes in Tables 4(a) and (b), respectively.
Primary Research Model Results
| # | Construct | k | N | r | 95% CI | p | I2 | Outcome |
|---|---|---|---|---|---|---|---|---|
| (a) Compliance outcomes | ||||||||
| H1a | Detection Certainty | 17 | 5,080 | 0.201 | [0.104, 0.295] | <0.001 | 91.1% | S |
| H2a | Sanction Certainty | 7 | 1,953 | 0.216 | [0.122, 0.307] | <0.001 | 74.7% | S |
| H3a | Sanction Severity | 22 | 6,546 | 0.191 | [0.111, 0.268] | <0.001 | 90.7% | S |
| H4a | Sanction Celerity | 4 | 1,347 | 0.211 | [0.069, 0.344] | 0.004 | 85.3% | S |
| (b) Violation outcomes | ||||||||
| H1b | Detection Certainty | 6 | 1,756 | −0.293 | [−0.502, −0.051] | 0.018 | 96.4% | S |
| H2b | Sanction Certainty | 6 | 1,089 | −0.290 | [−0.557, 0.032] | 0.077 | 96.6% | NS |
| H3b | Sanction Severity | 11 | 2,583 | −0.281 | [−0.413, −0.136] | <0.001 | 93.3% | S |
| H4b | Sanction Celerity | 2 | 414 | −0.137 | [−0.231, −0.041] | 0.005 | 0.0% | S |
| # | Construct | k | N | r | 95% CI | p | I2 | Outcome |
|---|---|---|---|---|---|---|---|---|
| (a) Compliance outcomes | ||||||||
| H1a | Detection Certainty | 17 | 5,080 | 0.201 | [0.104, 0.295] | <0.001 | 91.1% | S |
| H2a | Sanction Certainty | 7 | 1,953 | 0.216 | [0.122, 0.307] | <0.001 | 74.7% | S |
| H3a | Sanction Severity | 22 | 6,546 | 0.191 | [0.111, 0.268] | <0.001 | 90.7% | S |
| H4a | Sanction Celerity | 4 | 1,347 | 0.211 | [0.069, 0.344] | 0.004 | 85.3% | S |
| (b) Violation outcomes | ||||||||
| H1b | Detection Certainty | 6 | 1,756 | −0.293 | [−0.502, −0.051] | 0.018 | 96.4% | S |
| H2b | Sanction Certainty | 6 | 1,089 | −0.290 | [−0.557, 0.032] | 0.077 | 96.6% | NS |
| H3b | Sanction Severity | 11 | 2,583 | −0.281 | [−0.413, −0.136] | <0.001 | 93.3% | S |
| H4b | Sanction Celerity | 2 | 414 | −0.137 | [−0.231, −0.041] | 0.005 | 0.0% | S |
Note(s): k = number of effect sizes; N = cumulative sample size; r = pooled correlation; I2 = heterogeneity; S = supported, NS = not supported
As shown in Table 4(a), all deterrence constructs were significantly and positively associated with compliance intentions, with pooled correlations ranging from r = 0.191 to 0.216. These findings provide support for H1a (detection certainty positively influence cybersecurity compliance intentions), H2a (sanction certainty positively influence cybersecurity compliance intentions), H3a (sanction severity positively influence cybersecurity compliance intentions), and H4a (sanction celerity positively influence cybersecurity compliance intentions).
For violation intentions (Table 4(b)), detection certainty (r = −0.293, p = 0.018), sanction severity (r = −0.281, p < 0.001), and sanction celerity (r = −0.137, p = 0.005) demonstrated significant negative associations, supporting H1b (detection certainty negatively influence cybersecurity violation intentions), H3b (detection severity negatively influence cybersecurity violation intentions), and H4b (sanction celerity negatively influence cybersecurity violation intentions). However, sanction certainty (H2b) did not reach statistical significance for violation outcomes (r = −0.290, p = 0.077), hence H2b was not supported.
Across models, heterogeneity was substantial (I2 >70%), indicating considerable between-study variability and underscoring the importance of subsequent moderator analyses.
4.2 Celerity as a moderator
We further examined sanction celerity as a moderator of deterrence effects. The results of these analyses are presented in Table 5.
Celerity moderation effects
| # | Predictor | k | β | 95% CI | p | r Low celerity | r High celerity | Δ | Outcome |
|---|---|---|---|---|---|---|---|---|---|
| H1c | Detection Certainty → CBI | 3 | 1.454 | [0.955, 1.953] | <0.001 | 0.116 | 0.510 | 0.394 | S |
| H2c | Sanction Certainty → CBI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H3c | Sanction Severity → CBI | 4 | 1.095 | [0.042, 2.153] | 0.042 | 0.036 | 0.356 | 0.320 | S |
| H1d | Detection Certainty → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H2d | Sanction Certainty → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H3d | Sanction Severity → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| # | Predictor | k | β | 95% CI | p | r Low celerity | r High celerity | Δ | Outcome |
|---|---|---|---|---|---|---|---|---|---|
| H1c | Detection Certainty → CBI | 3 | 1.454 | [0.955, 1.953] | <0.001 | 0.116 | 0.510 | 0.394 | S |
| H2c | Sanction Certainty → CBI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H3c | Sanction Severity → CBI | 4 | 1.095 | [0.042, 2.153] | 0.042 | 0.036 | 0.356 | 0.320 | S |
| H1d | Detection Certainty → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H2d | Sanction Certainty → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
| H3d | Sanction Severity → VI | 1 | n/e | n/e | n/e | n/e | n/e | n/e | n/e |
Note(s): CBI = compliance intention; VI = violation intention; k = number of effect sizes; β = moderation coefficient; Δ = effect difference between low and high celerity conditions; S = supported; NS = not supported; n/e = not estimated (k < 3)
Two significant moderation effects were observed, providing partial support for the moderating role of celerity. The relationship between detection certainty and compliance intention (H1c) was significantly moderated by celerity (β = 1.454, p < 0.001), with the estimated effects increasing from r = 0.116 under low celerity to r = 0.510 under high celerity. Similarly, celerity significantly moderated the relationship between sanction severity and compliance intention (H3c) (β = 1.095, p = 0.042), with effects increasing from r = 0.036 at low celerity to r = 0.356 at high celerity.
Celerity moderation effects are observable in studies examining compliance intentions, specifically for detection certainty and sanction severity, reflecting greater empirical attention to temporal sanction dynamics in compliance-focused research. In contrast, violation-focused studies rarely reported on celerity. Consequently, moderation effects for sanction certainty-compliance (H2c), and all violation-intention paths (H1d, H2d, H3d) could not be estimated due to an insufficient number of studies (k < 3) reporting both celerity and the relevant deterrence construct within the same sample. This limitation reflects a broader methodological trend in the deterrence literature: certainty and severity are often examined in isolation, while celerity is often omitted or aggregated into composite constructs, rather than being modeled in designs that permit robust interaction testing.
4.3 Post-Hoc analysis: potential moderators
We further examined a set of demographic and methodological variables as potential moderators. Statistically significant moderation effects are summarized in Table 6.
Other potential moderator effects
| Analysis | Moderator | QM | p | Interpretation |
|---|---|---|---|---|
| Sanction Severity → Violation Intention | Sample Size | 6.18 | 0.045 | Small sample bias |
| Detection Certainty → Compliance Intention | Geographic Region | 7.84 | 0.049 | Cultural differences |
| Analysis | Moderator | QM | p | Interpretation |
|---|---|---|---|---|
| Sanction Severity → Violation Intention | Sample Size | 6.18 | 0.045 | Small sample bias |
| Detection Certainty → Compliance Intention | Geographic Region | 7.84 | 0.049 | Cultural differences |
Note(s): QM = omnibus test of moderator coefficients; p = significance level
Sample size significantly moderated the relationship between sanction severity and violation intentions (QM = 6.18, p = 0.045). An inverse pattern emerged, whereby small-sample studies (n < 200, k = 4) reported the strongest effects (r = −0.491), medium-sample studies (n = 200–499, k = 5) showed more moderate effects (r = −0.201), and large-sample studies (n ≥ 500, k = 2) reported the weakest effects (r = −0.076). This pattern suggests the possibility of small-sample bias, where effect sizes tend to be inflated in studies with limited sample sizes, a phenomenon frequently observed in prior meta-analytic research.
Geographic region significantly moderated the relationship between detection certainty and compliance intentions (QM = 7.84, p = 0.049). Substantial cross-regional variation was observed: studies conducted in Asian contexts reported negative effects (r = −0.109, k = 4), while European (r = 0.209, k = 4) and North American studies (r = 0.261, k = 7) reported strong positive effects. Studies from other regions also showed strong positive effects (r = 0.263, k = 2). This pronounced variation suggests that the effectiveness of detection-based deterrence may be context-dependent, potentially reflecting differences in cultural norms, institutional trust, or perceptions of surveillance, though further research is required to directly test these mechanisms.
Sample type did not reach statistical significance as a moderator (QM = 4.96, p = 0.084), but notable differences were observed. Employee samples yielded significantly larger effects (r = 0.224, k = 11) compared to student samples (r = 0.031, k = 4), representing a 19-point correlation difference. Mixed/Other samples demonstrated the strongest effects (r = 0.403, k = 2). This pattern was also observed for sanction severity and violation relationships, where employee samples showed stronger deterrent effects (r = −0.301, k = 8) than student samples (r = −0.213, k = 3), though this difference was not statistically significant (QM = 0.51, p = 0.476).
5. Discussion
This meta-analysis examined the impact of sanctions on employees' cybersecurity compliance and violation intentions, while also exploring factors that may moderate these relationships.
5.1 Deterrence effects on compliance and violation
5.1.1 Primary model
DT's core predictions received strong support in the context of compliance intentions, with all four deterrence constructs showing significant positive associations with compliance (H1a-H4a supported). This consistent pattern suggests that sanctions, regardless of the deterrence dimension, are effective in promoting proactive cybersecurity intentions.
In contrast, support for deterrence effects on violation intentions was more selective. Detection certainty (H1b), sanction severity (H3b), and sanction celerity (H4b) each showed significant negative associations with violation, confirming their role in deterring violations. However, sanction certainty did not reach statistical significance (H2b not supported), suggesting that the perceived likelihood of punishment may be more effective in motivating compliance than in discouraging violations.
Prior literature implicitly assumes that increases in sanction certainty will elevate compliance and suppress violations. The present findings demonstrate that this symmetry assumption is untenable. The differential findings observed provide empirical support for conceptualizing compliance and violation as distinct behavioral domains within DT. The contrast between H2a and H2b, where sanction certainty significantly predicted compliance but not violation, suggests that this construct may operate through different psychological mechanisms depending on the context. Specifically, sanction certainty may enhance perceived accountability and expectations for proactive compliance but may be insufficient to deter intentional violations. This asymmetry challenges the assumptions of traditional deterrence models, which often treat deterrence effects as symmetrical across behavioral outcomes.
We also compared our findings to those of Kuo et al. (2020). While Kuo et al. reported no significant effect of celerity on compliance, our analysis found a significant positive effect. suggesting that more recent evidence offers a more nuanced understanding of celerity's role in deterrence processes. However, the empirical base for celerity remains limited, with only a small number of studies (Hu et al., 2011; Johnston et al., 2015; Hu and Xu, 2018; Rajab and Eydgahi, 2019; Malimage et al., 2020; Chen et al., 2020) concentrated in recent years, indicating that findings on this construct are still emerging rather than well established. Additionally, where Kuo et al. found sanction certainty to be a significant predictor of both compliance and violation, we observed its significance only for compliance. Overall, our results indicate an asymmetric effect of sanction certainty, while Kuo et al.’s results reflected an asymmetric effect of celerity.
5.1.2 Celerity moderation evidence
The celerity moderation analyses offer the first meta-analytic evidence of interactive deterrence effects in the cybersecurity domain. Detection certainty-compliance (H1c) moderation was strongly supported, indicating that the effectiveness of detection certainty increases substantially when sanctions are applied swiftly (effect difference = 0.394). Similarly, sanction severity-compliance (H3c) moderation was supported, with results showing that the deterrent effect of sanction severity is significantly amplified by its rapid implementation (effect difference = 0.320). These sizable moderation effects suggest that celerity functions as a multiplicative, rather than merely additive factor, intensifying the impact of other deterrence constructs rather than exerting an independent influence. This finding advances traditional DT by identifying sanction celerity as a critical boundary condition that shapes the potency of other deterrence dimensions.
Moreover, the partial support for the moderating impact of sanction celerity, despite data limitations, underscores the theoretical significance of sanction celerity as a boundary condition that shapes the efficacy of other deterrence dimensions. This finding advances DT by emphasizing the interdependence of deterrence constructs and supports a more integrative model where swiftness enhances the salience and perceived credibility of sanctions.
Taken together, these findings call for a refined theoretical approach to deterrence; one that accounts for behavioral distinctions and interactive effects among deterrence components. Future theory development should incorporate these complexities to more accurately reflect how employees perceive and respond to sanctions.
5.1.3 Post-Hoc Analysis – other moderators
Out of 15 moderator tests conducted across demographic and methodological variables, only two moderators reached statistical significance: (1) sample size moderating the relationship between sanction severity and violation intentions, and (2) geographic region moderating the relationship between detection certainty and compliance intentions. These findings reinforce the robustness of the primary effects while highlighting important boundary conditions.
The high levels of heterogeneity observed across analyses (I2 = 74.7%–96.6%) indicate substantial systematic variation beyond what can be attributed to sampling error. While most tested moderators failed to account for this variance, one significant finding emerged: sample size significantly moderated the relationship between sanction severity and violation. This reveals important methodological insights – specifically, the inverse relationship between study size and effect magnitude. Small-sample studies reported markedly stronger effects compared to large-sample studies, suggesting the presence of small-study effects and potential publication bias. This aligns with broader meta-analytic literature, which warns of inflated effect sizes in underpowered studies.
Extreme differences across geographic regions show the divergence between East and West, suggesting that surveillance- and monitoring-based deterrence strategies may be less effective, or even counterproductive, in certain cultural contexts. Such findings underscore the need for future research to systematically examine cultural dimensions as influencers of the perception and efficacy of deterrence mechanisms.
5.2 Theoretical propositions
Our meta-analysis provides empirical evidence of a fundamental deterrence asymmetry, distinguishing compliance-seeking and violation-avoiding intentions. While the overall positive effects across key deterrence dimensions align with core predictions of DT, our moderation results point to the need for theoretical refinement. Specifically, we theorize that deterrence dimensions do not function as independent, additive predictors; rather, they operate synergistically, with sanction celerity acting as the processual anchor that prevents signal decay.
Table 7 presents formal propositions that extend DT by articulating asymmetric, temporal, and contextual mechanisms shaping sanction effectiveness in organizational cybersecurity.
Theoretical propositions for Sanction efficacy
| Proposition (Px) | Source of meta-analytic evidence | Theoretical explanation |
|---|---|---|
| P1: Asymmetric Deterrence | Sanction Certainty p < 0.01 (compliance) vs. p > 0.05 (Violation) | Sanctions function primarily as promotive social cues that reinforce compliance rather than preventive threats that suppress violations |
| P2: Celerity-Dependent Deterrence | Celerity x Certainty/Severity moderation | Temporal delay (low celerity) leads to signal decay, weakening the perceived behavior-consequence linkage, thereby neutralizing the deterrent weight of certainty and severity |
| P3: Context-Contingent Deterrence | Geographic region as a significant moderator | Deterrence efficacy is context-dependent, operating through a trust-control paradox shaped by cultural norms and institutional trust |
| Proposition (Px) | Source of meta-analytic evidence | Theoretical explanation |
|---|---|---|
| P1: Asymmetric Deterrence | Sanction Certainty p < 0.01 (compliance) vs. p > 0.05 (Violation) | Sanctions function primarily as promotive social cues that reinforce compliance rather than preventive threats that suppress violations |
| P2: Celerity-Dependent Deterrence | Celerity x Certainty/Severity moderation | Temporal delay (low celerity) leads to signal decay, weakening the perceived behavior-consequence linkage, thereby neutralizing the deterrent weight of certainty and severity |
| P3: Context-Contingent Deterrence | Geographic region as a significant moderator | Deterrence efficacy is context-dependent, operating through a trust-control paradox shaped by cultural norms and institutional trust |
5.2.1 Proposition 1: asymmetric deterrence
The meta-analytic results present a critical challenge to the traditional “Symmetry Assumption” inherent in IS security research. Historically, compliance and violation have been treated as opposite ends of a single behavioral spectrum, i.e. if a sanctioning cue increases the “cost” of a violation, it should decrease violation intentions and increase compliance intentions. Our findings, however, reveal a fundamental decoupling of these outcomes.
The promotive nature of compliance: We find that sanction certainty is a robust driver for compliance but remains ineffective against violations. We theorize that in cybersecurity, high certainty functions less as a “threat” and more as a normative reinforcement mechanism. When an organization ensures the consistent follow-through, it signals that cybersecurity is a core organizational value rather than a peripheral requirement. This signal fosters a sense of accountability and professional role identity, transforming deterrence from a punishment tool into a source of behavioral clarity.
The reactive nature of violations: In contrast, the non-significant relationship between certainty and violation intentions suggests that deterrent signals are frequently “blocked” by situational pressures. Drawing on general strain theory (Agnew and White, 1992) and neutralisation theory (Sykes and Matza, 1957), we argue that violations are often reactive responses to organizational strains, such as high workloads, unrealistic deadlines, or technical hurdles. Under these pressures, employees employ cognitive shields (e.g. “this task is more important than the policy” or “this rule is just a hindrance”) to silence the moral weight of the sanction, rendering the punishment irrelevant at the moment of the decision-making.
Theoretical contribution: We propose a Dual-Process view of deterrence, that the cognitive filters employees use to evaluate compliance are fundamentally different from those used during violations. The compliance filter is normative and value-based, responding to the clarity and certainty of organizational rules, while the violation filter is situational, largely immune to certainty cues when immediate work demands take precedence. By recognizing this asymmetry, researchers and managers can move toward nuanced governance models that address the specific environmental strains causing violations while leveraging certainty to reinforce a culture of compliance.
5.2.2 Proposition 2: celerity-dependent deterrence
While traditional DT often treats certainty, severity, and celerity as independent levers, our meta-analysis results reveal a more complex, interdependent relationship. Specifically, the finding that celerity moderates the impact of both detection certainty and sanction severity suggests that the temporal efficiency of the organizational response is a prerequisite for deterrent efficacy.
Celerity as the “processual anchor”: To maintain credibility, organizations must demonstrate a tight temporal link between transgression and consequence. When celerity is high, the sanction functions as an automated outcome, reinforcing the perceived inevitability of the rule. However, as the time gap increases, the deterrent signal suffers from temporal signal decay, diluting the psychological connection between the behavior and the outcome, rendering even the most severe penalties ineffective.
The multiplier effect: Celerity provides the interpretive weight necessary for certainty and severity to function. A severe penalty loses its psychological “sting” if it is perceived as distal or uncertain in timing. Speed validates the “realness” of the monitoring process; without it, surveillance is dismissed as a hollow threat. Drawing on temporal construal theory (Liberman and Trope, 1998), we argue that individuals naturally discount future consequences. Celerity is the mechanism that overcomes discount by bringing distal severity into the psychological “now”, making the consequences salient during the moment of decision-making.
Theoretical contribution: This finding shifts the focus of cybersecurity from policy design to organizational agility. We theorize that the timing of the organizational process is as critical as the rules themselves. Without celerity, certainty, and severity are merely symbolic gestures that fail to influence employees' real-time behavior. Consequently, the deterrent weight of a sanction is not an inherent property of the punishment itself, but a function of the timeliness with which the organization can close the loop between detection and discipline.
5.2.3 Proposition 3: context-contingent deterrence
The meta-analytic evidence identifying geographic region as a significant moderator suggests that the practice of sanctioning is highly sensitive to the social environment. These results align with the Trust-Control paradox.
The Trust-Control paradox: In certain cultural contexts, high-certainty detection mechanisms (e.g. intensive surveillance) may be interpreted by employees as a signal of organizational distrust rather than a security necessity. When deterrence is perceived as an overreach, it can trigger psychological reactance (Brehm, 1966). In such environments, employees may intentionally bypass policies not for personal gain, but to reclaim a sense of autonomy and control. Thus, in high-trust cultures, a tight deterrence regime may produce the counter-intuitive result of increasing defiance.
Theoretical Contribution: The findings advocate for a situational deterrence framework, suggesting that the efficacy of a sanction is not universal but is calibrated by cultural boundaries. We argue against blind governance, where increasing sanctions may inadvertently increase the very violation intentions the organization seeks to suppress.
5.3 Practical implications
The findings of this meta-analysis suggest that one-size-fits-all deterrence strategies are unlikely to be effective. Instead, CISOs and security managers should adopt a bifurcated governance approach that treats compliance and violation behaviors as distinct managerial challenges requiring different control mechanisms.
Our findings indicate that organizations should shift focus from the severity of sanctions to the timeliness and consistency of enforcement. To maintain the psychological salience of security policies, managers must focus on closing the loop between detection and response, thereby reducing delays that can lead to signal decay and weaken normative reinforcements. In practice, this may involve automating the identification and follow-up of minor non-compliant behaviors (e.g. missed training) to ensure timely and visible feedback.
Managers should also be cautious of blind governance, whereby deterrence mechanisms are applied uniformly without regard to underlying organizational conditions. While reinforcing cybersecurity as a core professional value can support compliance, suppressing violations often requires addressing organizational strains (e.g. unrealistic deadlines, excessive workload pressures) that drive employees to engage in risky workarounds.
Ultimately, sanctions should be viewed as “brakes” for serious transgressions and as consistent social signals for promoting compliance. By acknowledging the asymmetric drivers of compliance and violation behaviors, organizations can design governance models that not only deter deviance but also cultivate a sustained culture of proactive cybersecurity adherence.
5.4 Limitations
While this meta-analysis provides valuable insights into the role of sanctions in shaping cybersecurity intentions, several limitations should be acknowledged. First, this study focuses on cybersecurity intention rather than actual behavior, reflecting the predominant reliance on intention-based measures in existing literature. As a result, the extent to which these findings generalize to actual security behavior remains an open question, underscoring the need for more field-based and behavioral research. Additionally, because intentions were measured using self-reported responses across the included studies, the findings may be susceptible to social desirability bias, whereby participants report stronger security intentions than they would exhibit in practice. Although assessing this potential bias was beyond the scope of the present meta-analysis, future research should incorporate behavioral measures or field-based designs to better evaluate the relationship between reported intentions and actual cybersecurity behavior.
Second, analyses involving sanction celerity were based on a small number of studies (typically k = 2–4 per analysis), highlighting the limited empirical attention this construct has received despite its conceptual importance in DT. Consequently, findings related to celerity, particularly its moderating effects, should be interpreted cautiously and viewed as exploratory.
Third, the meta-analysis revealed substantial heterogeneity across most effect size estimates (I2 ranging from 74.7% to 96.6%), much of which remained unexplained by the demographic and methodological moderators examined. This suggests that additional unmeasured study-level characteristics, such as organizational context or enforcement visibility, may contribute to variability in deterrence effects.
Finally, the assessment of publication bias was constrained in several analyses due to the small number of available studies, particularly those involving celerity, which further limits the conclusiveness of bias-related inferences.
5.5 Future research
Several avenues remain for future research. First, given the limited number of studies examining actual cybersecurity behaviors, future research should investigate how sanctions influence behavior in practice, not just intentions. This is important because intentions do not always translate to behavior, and understanding real-world behavioral outcomes is essential for designing effective deterrence strategies.
Second, the observed moderation effects of celerity underscore its theoretical and practical importance. We encourage researchers to adopt multi-construct, longitudinal designs that explore how deterrence components interact over time, including celerity. Such designs would enable more rigorous testing of interaction effects and potential synergies among deterrence components.
Third, our results revealed geographic variation, especially between Asian and Western samples. This suggests that deterrence effects may be shaped by cultural values, organizational norms, and regulatory environments. Future studies should examine these moderators, especially in underrepresented regions, to improve generalizability.
Fourth, evidence of sample size effects indicates a need for more pre-registered, adequately powered studies. Doing so would help reduce publication bias and enhance the reliability and credibility of reported effect sizes.
Finally, the asymmetric effect of sanction certainty on compliance versus violation calls for theory-driven investigations into psychological mechanisms underlying these differences. Drawing from organizational psychology, behavioral economics, and criminology could inform fresh insights and support the development of more nuanced and effective deterrence frameworks tailored to cybersecurity settings.
6. Conclusion
This meta-analysis synthesized empirical evidence from 51 studies and 20,768 participants to evaluate the efficacy of sanction-based deterrence in organizational cybersecurity. By distinguishing between compliance-seeking and violation-avoiding intentions, this study provides a comprehensive quantitative framework that challenges the long-standing “symmetry assumption” in IS research.
The findings reveal a fundamental decoupling of behavioral trajectories: sanction certainty acts as a robust normative reinforcement mechanism for compliance, yet it remains largely ineffective in deterring violations. This suggests that the cognitive processes guiding employees to comply differ from those engaged when circumventing rules. This study also provides the first meta-analytic evidence of the celerity catalyst, demonstrating that sanction celerity is not merely a peripheral construct but a processual anchor that amplifies the effects of certainty and severity, transforming policies into effective behavioral signals. For practitioners, these findings advocate a shift from volume-based punishment to agility-based governance: organizational response must be swift as well as certain and severe, as delayed enforcement suffers from temporal discounting and weakens deterrent signals.
While this synthesis clarifies core deterrence mechanisms, it also highlights the Trust-Control paradox in global workforces. Future research should adopt situational deterrence frameworks and examine how emerging technologies (e.g. AI-driven monitoring) shape the effectiveness and legitimacy of these deterrent signals. As cybersecurity threats continue to evolve, deterrence models must account for the complexity of human behavior and the asymmetric dynamics between compliance and violation.
Ethics statement
This study used only publicly available sources and did not involve primary data collection or human participants.
References
Note: * indicates studies included in the meta-analysis

