Purpose

We examine information systems security policy (ISSP) compliance through the lens of ethical decision-making to uncover new insights into employee ISSP compliance and recommend managerial practices that improve ISSP compliance.

Design/methodology/approach

We anchored our theoretical framework to moral intensity theory and developed hypotheses based on deontological ethics, utilitarian ethics and construal level theory. Scenario-based surveys were conducted to test the research model.

Findings

We found that employees would align their compliance motivation with organizational information security interests even at a cost to themselves if negative consequences to the organization from data breaches are well understood and if a pro-compliance social consensus among coworkers is evident. Employees tend to develop a sufficient understanding of the negative consequences of data breaches if they feel psychologically close to the organization and if they perceive that damage from data breaches will occur sooner rather than later.

Practical implications

To improve compliance, we recommend that organizations align employee compliance motivation with organizational security interests through clear communications of potential security breach damages, fostering a pro-compliance culture and reducing the psychological distance employees feel from the organization.

Originality/value

Theoretically, our ethical decision-making perspective on ISSP compliance complements the cost-benefit analysis framework widely adopted in ISSP compliance research. Our research model offers a new framework for analyzing employee ISSP compliance. Managerially, highlighting the effects of psychological distance and social consensus among coworkers contributes to the management of employee ISSP compliance.

Global cybercrime costs from all sources are estimated at $10.5 trillion annually (Khalil, 2025). In the organizational context, although non-malicious human errors due to noncompliance with organizations’ information systems security policies (ISSPs) have been a major root cause of more than 60% of organizational data breaches (Verizon, 2025), damages and costs from organizational data breaches are overwhelmingly borne by the organization and its stakeholders, rather than by the employees themselves, through lost customers and sales, compensation to customers or suppliers, regulatory fines and penalties, damage to brand reputation and goodwill, additional customer acquisition investment, legal and investigation expenses, operational disruptions, and rising insurance premiums, among others (Le and Zamora, 2018; Ponemon, 2017).

Numerous studies have examined employee compliance with organizational ISSPs anchored on social science theories such as theory of planned behavior, theory of reasoned action, protection motivation theory, and deterrence theory (e.g. Hinsz, 2025; Moody et al., 2018; Sharma et al., 2021). A comprehensive meta-analysis of ISSP compliance research classified independent variables into seventeen distinct categories (Cram et al., 2019). Among them, personal norms, values, and ethics (PNVE) and normative beliefs had large effect sizes. The other fifteen categories were related to extrinsic motivation, which included perceived usefulness, perceived ease of use, perceived benefits, threat appraisal, response costs, response efficacy, rewards, and punishment. Their effect sizes varied from very small for rewards to moderate for threat and coping appraisals, and large for organizational support and perceived usefulness.

In the ISSP compliance literature, extrinsic motivations (such as rewards) have been mostly studied using a cost-benefit analysis framework such as deterrence theory, protection motivation theory, and theory of reasoned action (see Cram et al., 2019). Although extrinsic motivational factors have been found to impact compliance in varying degrees (Cram et al., 2019), some can have unintended consequences. For example, punishment and sanctions engender fear, which, in the long term, discourages employees from investing in cybersecurity because it causes workplace anxiety about information security and impedes employee loyalty to the company (Renaud, 2020).

Normative beliefs are a person’s perception of whether important others such as supervisors and coworkers think they should or should not perform a behavior (Ajzen, 1991). Normative beliefs activate extrinsic motivations to comply through social pressure (Bicchieri, 2005).

The established influence of PNVE on ISSP compliance underscores the ethical nature of compliance decisions because there is a tension between personal cost and organizational risk in compliance: It is ultimately the employees, rather than the organization, who exercise free will in deciding whether to bear the personal cost to comply with an ISSP. However, it is the organization, not the employee, that bears the majority of the consequences from data breaches, as discussed earlier. This misalignment between the personal costs of compliance borne by employees and the organizational costs of noncompliance creates an ethical issue–a situation where a person’s decision or action in the organizational context has consequences for others and therefore involves considerations of right and wrong (Jones, 1991). Recognizing this ethical issue activates an employee’s ethical decision-making. However, this phenomenon has not received sufficient attention.

Unlike compliance driven by external rewards or sanctions, PNVE motivates behavior through deeply internalized moral self-regulation in the ethical decision-making process. Moral self-regulation is the process through which internalized norms and values act as an enduring internal moral compass to govern conduct (Bicchieri, 2005; Ryan and Deci, 2000). This is a broad process that includes perceiving and evaluating a moral situation (in personal or societal context) or an ethical situation (in organizational context), monitoring one’s response, and aligning behavior with internal standards (Jones, 1991; Joosten et al., 2014). Although PNVE has been found to promote employee ISSP compliance (e.g. D'Arcy and Lowry, 2019; Li et al., 2014), to the best of our knowledge, little research has examined the moral self-regulation process through which PNVE influences ISSP compliance.

In this paper, we focus on the first component of moral self-regulation in the organizational context, which is the evaluation of an ethical issue, that is, moral evaluation. Specifically, this study seeks to explore the underlying moral evaluation dimensions that shape employees’ compliance behavior. We address the following research questions:

RQ1.

What moral evaluation dimensions are associated with ISSP compliance, and how does each dimension influence compliance behavior? What managerial practices can we recommend based on an understanding of these relationships?

RQ2.

How do different moral evaluation dimensions interact with one another in shaping employees’ ISSP compliance? What managerial practices can we recommend based on an understanding of these relationships?

Recognizing that the influence of these moral evaluation dimensions operates through individuals’ PNVE, by answering the above two research questions we move beyond merely confirming PNVE’s impact on ISSP compliance, which does not easily translate into managerial practices. Rather, we aim to identify actionable organizational strategies that can better align employees’ moral motivations with the organization’s information security objectives. Our research results will provide guidance for management to inspire employees to align their compliance behavior with the organization’s information systems security interests and to comply with ISSPs based on moral evaluation rather than fear calculus.

Employee ISSP compliance refers to the extent to which employees adhere to organizational policies, rules, and procedures designed to protect information systems and organizational data from security threats (Cram et al., 2019). ISSP compliance has become a central topic in information systems research because human behavior is widely acknowledged as one of the most significant sources of security vulnerability. Even well-designed technical systems can be compromised by policy violations, negligence, or intentional misuse (Bulgurcu et al., 2010). ISSP noncompliance refers to the intentional violation of organizational ISSPs without the malicious intent to cause damage (Guo et al., 2011). Although noncompliance and unethical IT use are both ethical issues, they are different in that unethical IT use involves explicit wrongdoing where individuals are fully aware they are making a morally wrong decision to engage in unethical IT use for personal gains (Chatterjee et al., 2015). In contrast, ISSP compliance typically involves following organizational procedures, such as password management or secure email, that may appear bureaucratic or procedural rather than ethical (Crossler et al., 2017; D'Arcy and Lowry, 2019). As such, the moral aspect of compliance is only activated when the moral issue is recognized (Jones, 1991). Consequently, the mechanisms driving unethical IT use differ fundamentally from those that underline ISSP noncompliance, making findings from the former not directly applicable to the latter.

We classify PNVE-related antecedents to ISSP compliance into three categories: social normative influence, organizational ethical context, and internal moral drivers.

2.2.1 Social normative influence

Normative beliefs refer to perceptions such as “my coworkers think I should follow the policy”. These beliefs generate social pressure to conform to expected behaviors (Brooks et al., 2024; Bulgurcu et al., 2010). However, employees may neutralize the fear stemming from social pressure if they are unwilling to comply (Cram et al., 2024). In some cases, social pressure can even backfire, leading to maladaptive behaviors (e.g. aggression) instead of compliance (Stanaland and Gaither, 2021). Thus, social pressure is distinct from PNVE.

2.2.2 Organizational ethical context

Corporate social responsibility initiatives and ethical leadership have been shown to directly impact ISSP compliance intention (Kim and Han, 2019; Wang and Xu, 2021). Ethical leadership indirectly reduces employees’ ISSP violation intentions by shaping the organization’s ethical information security climate (Xue et al., 2021), which strongly influences ISSP compliance (Yazdanmehr et al., 2024).

Related to the above, organizational justice research highlights fairness perceptions as an important antecedent of employees’ compliance with ISSPs. Li et al. (2014) integrated deterrence theory and organizational justice theory to show that perceptions of fairness, which encompasses distributive, procedural, interpersonal, and informational justice, serve as intrinsic motivators for compliance with internet use policies. Their findings revealed that organizational justice not only directly increases compliance intention but also indirectly fosters compliance by strengthening employees’ personal ethics against policy violations. This line of work reframes compliance as a self-regulatory behavior driven by fairness-based moral evaluations rather than by external sanctions alone.

2.2.3 Internal moral drivers

Prior research consistently shows that personal beliefs significantly shape compliance behavior. For example, personal ethics strongly predict intentions to follow internet use policies (Li et al., 2014), while moral beliefs motivate daily compliance and reduce policy violations (D'Arcy and Lowry, 2019). Moral obligation also drives security-related behavioral intentions (Yoon and Kim, 2013), and moral norms lessen resistance to ISSPs (Merhi and Ahluwalia, 2019).

A growing line of research has explored moral intensity, a multidimensional construct proposed by Jones (1991), to capture moral evaluation in ethical decision-making across contexts. In ISSP compliance research, some studies have applied moral intensity but treated it as unidimensional (Crossler et al., 2017; Fleischman et al., 2023). Lankton et al. (2019) unpacked moral intensity into multiple dimensions; however, they aggregated these dimensions into a single moral belief and did not investigate the direct effects of individual dimensions or the interrelationships among them. Outside ISSP compliance, various studies have found that different dimensions of moral intensity have different impact on ethical behaviors including digital piracy (Chatterjee et al., 2015; Kos Koklic et al., 2014), academic misconduct (Chatterjee et al., 2015; Kini et al., 2003), employee software piracy (Zhang et al., 2016), and reporting of bad news (Wang et al., 2015). Yet, despite Jones’s (1991) call for investigating interactions among dimensions, no studies have explicitly examined how moral intensity dimensions influence each other.

Building on the work in both organizational ethical context and internal moral drivers, the present research extends the justice-based view by shifting the focus from general fairness perceptions to the moral evaluation of noncompliance itself. Whereas Li et al. (2014) conceptualized justice as a contextual antecedent that shapes ethical beliefs, this study examines how different moral evaluation dimensions underlying ethical judgment interact to influence compliance decisions. We explore the nuanced relationships among moral intensity dimensions and their combined influence on employees’ voluntary compliance behavior. The goal is to inform the design of organizational interventions that effectively influence employees’ ethical decision-making regarding ISSP compliance.

ISSP violation is typically a freely performed action. Since freely performed actions that have consequences for others are moral (personal context) and ethical (organizational context) issues (Velasquez and Rostankowski, 1985), ISSP compliance is an ethical issue governed by the ethical decision-making process.

An individual’s ethical decision-making is a systemic approach to resolving moral dilemmas by evaluating action choices based on ethical principles, consequences, and societal norms (Hunt and Vitell, 1986). Ethical decision-making can occur whether the potential victims involved in a moral act are persons or non-human entities (Han and Vasquez, 2020). For example, posting distorted harmful reviews can damage a company. When done purposefully, such behavior is influenced by the poster’s ethical evaluation and judgment of this action (Han and Vasquez, 2020).

The ethical decision-making process involves recognizing a moral issue, analyzing the situation, making moral judgments, establishing moral intent, and making a choice that aligns with one’s ethical standards (Rest, 1986). Each stage of this process is affected by characteristics of the moral issue, which was introduced as a multidimensional construct termed moral intensity (Jones, 1991).

In ethical decision-making literature, moral intensity is a well-accepted theory that explains ethical behavior. Moral intensity, proposed by Jones (1991), is a collection of characteristics pertaining to an ethical issue that an individual assesses when faced with the decision of whether to perform an action (Jones, 1991). According to Jones’s (1991) moral intensity theory, moral issues vary in moral intensity along six dimensions: magnitude of consequence, probability of effect, temporal immediacy, social consensus, proximity, and concentration of effect.

Magnitude of consequence refers to the total harm (or benefit) done to victims (or beneficiaries) of the moral act in question (Jones, 1991). Probability of effect evaluates the probability that an act will cause harm (benefit). Temporal immediacy refers to the length of time between the moral act in question and its predicted consequences (Jones, 1991). Social consensus refers to the “degree of social agreement that a proposed act is evil (good)” (Jones, 1991). Proximity refers to an individual’s feeling of social, cultural, psychological, or physical nearness to the victims (beneficiaries) of the moral act in question. Concentration of effect is “an inverse function of the number of people affected by an act of given magnitude” (Jones, 1991). In our context, we study compliance from the perspective of the organization and therefore consider organization as a proxy for all victims who bear the consequences of employee ISSP non-compliance. Consequently, concentration of effect is a constant and therefore is not included in our study.

An individual’s ethical decision-making process involves evaluating and choosing among various alternatives in a manner consistent with their ethical principles and values (Farayola and Olorunfemi, 2024). Normative ethical theories explain this process.

A wide range of ethical issues are important in information systems research, including issues of privacy, combating cybercrime, and digital divide, among others (Mingers and Walsham, 2010). There is general agreement that three normative ethical theories–deontology, utilitarianism, and virtue ethics–are currently the main approaches. Each of these theories explains ethical evaluation based on its own set of principles and criteria. Deontology emphasizes the inherent rightness or wrongness of an action based on moral rules or principles; utilitarianism evaluates the morality of an action based on its outcomes or consequences; virtue ethics focuses on the character traits or virtues of the decision maker (Farayola and Olorunfemi, 2024; Mersinas and Bada, 2024; Xu and Ma, 2016).

Next, we draw on deontological and utilitarian ethics to derive our hypotheses. We do not employ virtue ethics because it emphasizes moral character and personal development (Solomon, 1992), whereas our study focuses on characteristics contingent on the moral issue of ISSP compliance rather than individual virtues.

Deontological ethics emphasizes the duty to follow universal moral principles or rules (Brady and Wheeler, 1996; Xu and Ma, 2016). In this view, morality is judged by adherence to moral duties rather than by consequences (Jones, 1991). Within organizations, employees may rely on prevailing professional or social norms when forming moral judgments about ISSP compliance. Thus, when employees perceive that most coworkers view compliance as morally right, they are more likely to regard compliance as an ethical duty. Such shared moral evaluations strengthen the perception that following ISSPs is the proper and responsible course of action, increasing the likelihood of compliance (Mersinas and Bada, 2024). Therefore, we propose the following hypothesis:

H1.

Pro-compliance social consensus has a positive impact on employee ISSP compliance intention.

It is important to note that while both social consensus and social influence involve perceptions of others’ opinions, they differ conceptually. Social consensus, as a dimension of moral intensity (Jones, 1991), reflects the perceived social agreement about the moral rightness or wrongness of an act. In contrast, social influence refers to the motivational pressure to conform to others’ expectations (Ajzen, 1991). Accordingly, this study treats social consensus as a cognitive element of moral judgment rather than a conformity-based behavioral driver.

Utilitarian ethics focuses on what is considered a good outcome or overall consequence. According to this theory, an action that maximizes societal benefits in ethical decision-making is considered ethical (Yazdani and Murad, 2015). Since the magnitude of consequence dimension of moral intensity reflects an employee’s evaluation of the severity of potential damage from data breaches caused by ISSP violation, drawing on utilitarian ethics, we infer that magnitude of consequence has a positive impact on employee ISSP compliance intention. Similarly, since the probability of effect dimension of moral intensity reflects an employee’s evaluation of the probability of damage due to data breaches caused by ISSP violation, drawing on utilitarian ethics, we infer that probability of effect has a positive impact on employee ISSP compliance intention.

Magnitude of consequence and probability of effect were found to be highly correlated (May and Pauli, 2002; Singhapakdi et al., 1996). Fox (1991) recommends combining highly correlated moral intensity dimensions into a single dimension. Following this recommendation, we combined the magnitude of consequence and probability of effect into a single construct called consequence and propose the following hypothesis:

H2.

Consequence has a positive impact on employee ISSP compliance intention.

According to moral intensity theory (Jones, 1991), the perceived seriousness of consequences associated with an action shapes individuals’ moral evaluations and activates awareness of relevant social norms. When employees perceive that violating ISSPs could cause serious harm such as data breaches or reputational loss, they become more attuned to the moral implications of their actions. This heightened moral awareness leads them to infer that most of their colleagues also regard compliance as the appropriate and responsible behavior (Yazdanmehr and Wang, 2016). Thus, perceived consequence amplifies the perception of a shared moral stance toward compliance, reinforcing pro-compliance social consensus (Bicchieri, 2005). Therefore, we propose the following hypothesis:

H3.

Consequence has a positive impact on pro-compliance social consensus.

The remaining two dimensions of moral intensity (temporal immediacy and proximity) relate to psychological distance, or how close a decision maker feels to the timing and the victims of potential harm. To explain their influence, we draw on construal level theory (CLT), which examines how psychological distance shapes individuals’ mental representations and evaluations of events (Wiesenfeld et al., 2017).

CLT posits that people construe the same event at different levels depending on their psychological distance from it. High-level construals represent events abstractly and broadly, whereas low-level construals involve concrete, contextualized thinking (Vadera et al., 2025). When people feel distant from an event, they rely on high-level construals and are less inclined to act; when they feel close, they form low-level construals that increase perceived relevance and behavioral intention (Trope and Liberman, 2010; Trope et al., 2007). For example, people perceive climate change as less urgent when it feels temporally and spatially distant, leading to weaker behavioral responses (Guillard et al., 2021). Similarly, framing heart disease risk in daily (versus yearly) terms evokes lower psychological distance, increasing risk perception and preventive intentions (Chandran and Menon, 2004).

Psychological distance includes temporal, spatial, social, and hypothetical dimensions (Trope and Liberman, 2010). In our study, temporal immediacy reflects the time gap between an employee’s ISSP violation and potential data breach consequences, whereas proximity captures the perceived social closeness between the employee and their organization.

Prior research indicates that psychological distance influences individuals’ threat perceptions and security-related behavioral intentions (Schuetz et al., 2020; Trope et al., 2007). When employees feel temporally distant from potential breaches, they tend to view resulting harm as less imminent and underestimate its severity (Li et al., 2019; Trope and Liberman, 2003). Likewise, when employees feel socially distant from their organization, they frame potential damages in abstract, impersonal terms, which reduces perceived consequences.

Drawing on CLT, we argue that closer temporal and social distance heightens perceived harm from ISSP violations by inducing low-level construals and greater personal relevance. Accordingly, we propose the following hypotheses:

H4.

Temporal immediacy has a positive impact on perceived consequence.

H5.

Proximity has a positive impact on perceived consequence.

Construal level theory posits that different psychological distance dimensions are correlated; that is, an individual’s evaluation of one psychological distance dimension may affect their evaluation of other psychological distance dimensions (Trope and Liberman, 2010; Stephan et al., 2010). Specifically, when an event is stated in a colloquial (normative) language that indicates close (far) social distance, individuals tend to perceive short (long) enactment time (Stephan et al., 2010). In our context, when an employee perceives close social distance from the organization, they tend to perceive that the damage caused by ISSP violations would occur soon. Therefore, we propose the following hypothesis:

H6.

Proximity has a positive impact on temporal immediacy.

Self-efficacy reflects an employee’s confidence in their ability to successfully comply with ISSPs. According to coping theory, when employees perceive a moral need to follow ISSPs, they are more likely to do so when they have greater confidence in their ability to achieve success and in the effectiveness of their compliance behavior in protecting organizational information systems (Huang and Lin, 2023; Johnston et al., 2015). Therefore, we propose the following hypothesis:

H7.

Self-efficacy has a positive impact on employee ISSP compliance intention.

Figure B1 in Appendix B of the Supplementary shows all hypotheses in a graphical representation.

We conducted a scenario-based survey to test the proposed model and its hypotheses after obtaining human subjects research approval from our state’s Multiple Institutional Review Board on January 27th, 2020 (protocol approval number #18–2754). The data collection process adhered to all applicable ethical standards and guidelines for human subject research as specified by the Multiple Institutional Review Board.

Three scenarios were used. The first scenario involved using public Wi-Fi to access a company database, which was adapted from Guo et al. (2011). The second scenario was about sending out a confidential email without encryption, which was against the company policy. The third scenario was about accessing a company database remotely without using a VPN, which was also against the company policy. The second and the third scenarios were newly developed for this study. The three vignettes were designed to represent plausible and frequently observed ISSP noncompliance behaviors that vary in technical focus, situational context, and motivational cues rather than to systematically cover all three core security objectives of confidentiality, integrity, and availability. Together, the three vignettes reflect diverse compliance-relevant dilemmas involving convenience, resource limitation, and time urgency–situations that are both ecologically valid and frequently documented in prior behavioral security research. All scenarios were written in third person to reduce social desirability bias (D'Arcy et al., 2014). See Appendix A in the Supplementary for scenario details.

The measurement scales were adapted from existing items in the literature. We inserted the employee’s name used in the scenario and the scenario title; the items were otherwise the same as those in the literature. Compliance intention was obtained from D'Arcy et al. (2014) and used a three-item 7-point Likert scale. Measures for four moral intensity dimensions (i.e. magnitude of consequence, probability of effect, temporal immediacy, and social consensus) were taken from Shawver and Miller (2017) and modified to fit the specifics of our ISSP violation scenarios. Among them, magnitude of consequence was measured with two 7-point Likert scale items and one semantic differential scale item; probability of effect was measured with two 7-point Likert scale items and one semantic differential scale item; and temporal immediacy was measured with a three-item 7-point semantic differential scale. Magnitude of consequence and probability of effect were combined into one construct in hypothesis testing. Social consensus was measured as a reflective construct using a three-item 7-point Likert scale, with a higher score indicating a more pro-compliance social consensus.

Proximity of a moral issue is the feeling of nearness (social, cultural, psychological, or physical) for the victims (beneficiaries) of the evil (beneficial) act in question (Jones, 1991). Perceived close ties to the organization affect employee behavior such as green behavior and knowledge-sharing behavior (Ismail and Hilal, 2023; Zhang et al., 2021). Being psychologically distant leads to organizational rule-breaking (Roberts and Wasieleski, 2012). In our context, proximity is reflected in how much the employee identified with the company and considered the company “my company” and how closely they feel culturally or psychologically connected to the company. Employees who feel a strong connection to their company are more likely to fully invest in its success (Pierce et al., 2001). With respect to ISSP compliance, psychological distance significantly impacts an employee’s intention to violate ISSP through negative emotions (Zhen et al., 2022).

We used a four-item 7-point Likert scale to assess proximity following Van Dyne and Pierce (2004). These authors validated the scale across three samples comprising more than 800 employees from diverse job types and organizational levels, none of whom held ownership stakes in their organizations. Their findings demonstrate that the items capture employees’ psychological feelings of possession toward the organization rather than literal or legal ownership. Such feelings of possession reflect employees’ perceived psychological closeness to, and identification with, the organization, which aligns with our conceptualization of proximity in this study. Table B1 in Appendix B in the Supplementary lists the measurement items for the email-encryption scenario.

Given that our study examined the behavioral intentions of individuals, we controlled for the impact of demographic factors, including age, gender, and educational background. We accounted for job experience, since the research focused on employees' behavioral intentions in the workplace. We also controlled for whether the participants held roles related to IT/IS or managerial roles. We further controlled for organizational factors including industry type and firm size.

Data were collected from Amazon Mechanical Turk (MTurk) because its population is considered representative of the US working population (Paolacci et al., 2010). Its large population size also allowed us to perform random sampling (Lowry et al., 2016).

Potential participants first landed on the study’s main page, which detailed procedures and the purpose of the study. They were fully informed of their rights to exit the survey at any time and their responses’ anonymity and confidentiality. They were informed that no personally identifiable information would be collected and only aggregated results would be published solely for research purposes. All participants gave their consent by clicking a clearly labeled button before continuing to the survey questions.

We collected data through multiple batches. Each respondent was allowed to participate in only one batch of data collection. To improve data quality, we disapproved responses that finished in an unreasonably short duration, failed embedded attention-checking questions (e.g. reporting an incorrect answer compared with the facts described in the given hypothetical scenario), or provided abnormal responses (e.g. one-end choices). In addition, we allowed only high-performing survey takers (HIT approval rate ≥95%) to participate in our survey (Lowry et al., 2016). No responses contained missing data because responses were mandatory. Each approved response received $0.75 in compensation. A total of 1,461 responses were received from all batches. We conducted an independent-samples Kruskal–Wallis test on all main items to determine if all batches could be pooled. No significant differences were found in their distributions across all batches; therefore, all batches were pooled for further analyses. After cleaning the data, the final study sample contained 469 responses. The respondents’ demographics are listed in Table B2 in Appendix B in the Supplementary.

Because several control variables in our model were specified as single-indicator or formative constructs, partial least squares structural equation modeling (PLS-SEM) was selected as the primary analytical approach (Sarstedt et al., 2022).

To mitigate common method bias (CMB), several pre-hoc procedural remedies, such as assuring anonymity and emphasizing that there were no right or wrong answers, were implemented to reduce social desirability bias (Podsakoff et al., 2003). For post-hoc statistical assessment, a common method factor (CMF) analysis was conducted using covariance-based structural equation modeling in SPSS AMOS 28. The standardized CMF loading was 0.768, and the chi-square difference between models including and excluding the latent method factor was 136.85, indicating the presence of shared variance. However, the common latent factor captures all shared covariance among indicators and cannot distinguish between method variance and substantively meaningful construct overlap (Podsakoff et al., 2003). Importantly, inclusion of the CMF did not materially alter the magnitude, direction, or statistical significance of the structural path coefficients, suggesting that the substantive relationships in the model remained stable.

Additional PLS-based CMB diagnostics were performed in SmartPLS 4.0 (Sarstedt et al., 2022). All full collinearity VIF values ranged from 1.00 to 1.92, well below the conservative threshold of 3.3, indicating that common method variance is unlikely to bias the structural estimates. Furthermore, the marker variable exhibited small and non-significant correlations with other constructs, and controlling for the marker, the model’s structural path coefficients remained similar in magnitude, direction, and statistical significance. All measurement items were adapted from established scales that have demonstrated reliability and validity across multiple prior studies. Confirmatory factor analysis (presented below) also demonstrated strong convergent and discriminant validity for all reflective constructs. Collectively, the convergence of results across multiple analytical techniques suggests that although some shared variance may exist at the measurement level, it does not materially threaten the validity or robustness of the model’s structural conclusions.

Regarding measurement quality, composite reliability and rho_A values exceeded 0.91 for all reflective constructs. Average Variance Extracted (AVE) values ranged from 0.81 to 0.94, and the square roots of AVE (0.90–0.97) exceeded inter-construct correlations, supporting discriminant validity. Item loadings ranged from 0.84 to 0.97 and were consistently higher than cross-loadings, further confirming convergent and discriminant validity (see Tables 1 and 2).

Table 1

Mean, standard deviation, psychometric properties, construct correlations, square root of AVE

MeanSDrho_AComposite reliabilityAVESCCNSTIPROXSEINT
SC4.691.130.910.940.850.92     
CNS3.961.380.950.960.810.520.90    
TI3.811.440.960.980.930.220.470.96   
PROX3.831.730.980.980.940.260.460.260.97  
SE4.881.100.920.950.860.570.270.100.020.93 
INT4.831.220.950.960.900.710.500.150.120.570.95

Note(s): CNS = consequence; TI = temporal immediacy; SC = social consensus; PROX = proximity; SE = self-efficacy; INT = intention

SD: Standard Deviation

Diagonal and italic: square root of AVE

Source(s): authors' own work
Table 2

Loadings and cross-loadings

SCCNSTIPROXSEINT
SC10.930.460.210.220.550.65
SC20.920.450.160.220.540.66
SC30.920.530.230.290.480.65
CNS10.490.920.360.400.260.47
CNS20.520.920.360.390.320.53
CNS30.410.880.480.480.150.38
CNS40.490.920.420.390.260.48
CNS50.520.910.390.370.290.52
CNS60.350.840.520.480.150.30
TI10.200.450.960.260.110.14
TI20.230.450.960.240.100.16
TI30.200.440.970.240.070.13
PROX10.250.440.250.970.020.12
PROX20.260.420.220.960.020.12
PROX30.260.460.260.970.020.12
PROX40.250.470.270.970.020.12
SE10.500.210.080.000.930.49
SE20.530.220.08−0.020.930.52
SE30.550.310.100.070.920.56
INT10.690.480.160.100.540.95
INT20.660.490.130.130.510.95
INT30.660.450.130.120.560.95

Note(s): CNS = consequence; TI = temporal immediacy; SC = social consensus; PROX = proximity; SE = self-efficacy; INT = intention

italic: loadings

Source(s): authors' own work

For hypothesis testing, we used the partial least squares algorithm to estimate coefficients and ran the bootstrapping re-sampling algorithm with 5,000 re-samples to estimate the t-statistics and p-values.

As shown in Figure 1, our model explains 59.3% of the variance in compliance intention; both consequence (β = 0.277, p < 0.01) and pro-compliance social consensus (β = 0.487, p < 0.01) have a significant and positive impact on employee ISSP compliance intention. Therefore, H1 and H2 are both supported. Consequence has a significant and positive impact on pro-compliance social consensus (β = 0.52, p < 0.01). Therefore, H3 is supported. Both temporal immediacy (β = 0.373, p < 0.01) and proximity (β = 0.367, p < 0.01) have a significant and positive impact on consequence. Therefore, H4 and H5 are both supported. Proximity has a significant and positive impact on temporal immediacy (β = 0.257, p < 0.01). Therefore, H6 is supported. Self-efficacy has a significant and positive impact on employee ISSP compliance intention (β = 0.225, p < 0.01). Therefore, H7 is supported.

Figure 1
A diagram depicting the factors influencing compliance intention.A diagram depicting the factors influencing compliance intention. The diagram shows Proximity leading to Temporal Immediacy and Consequence. Temporal Immediacy influences Consequence, which is further divided into Magnitude of Consequence and Probability of Effect. Consequence influences Social Consensus and compliance intention. Social Consensus and Self-efficacy also influence Compliance Intention. Various factors such as Age, Gender, Education, Job Experience, Firm Size, Industry, Managerial Role, and IT/IS Position are shown to have varying levels of influence on Compliance Intention. The diagram includes path coefficients and statistical significance indicators for the relationships between these factors.

Hypothesis testing results

Figure 1
A diagram depicting the factors influencing compliance intention.A diagram depicting the factors influencing compliance intention. The diagram shows Proximity leading to Temporal Immediacy and Consequence. Temporal Immediacy influences Consequence, which is further divided into Magnitude of Consequence and Probability of Effect. Consequence influences Social Consensus and compliance intention. Social Consensus and Self-efficacy also influence Compliance Intention. Various factors such as Age, Gender, Education, Job Experience, Firm Size, Industry, Managerial Role, and IT/IS Position are shown to have varying levels of influence on Compliance Intention. The diagram includes path coefficients and statistical significance indicators for the relationships between these factors.

Hypothesis testing results

Close modal

We also examined the mediating effect of temporal immediacy on consequence, and the mediating effects of social consensus and consequence on compliance intention using Shrout and Bolger’s tests (Shrout and Bolger, 2002). We used SmartPLS 4.0, with a bootstrapping algorithm and 5,000 re-samples to estimate the standard error, confidence level, and significance level of the mediating path (a × b in Table B3 in Appendix B in the Supplementary). The results of the mediation test are presented in Table B3, which shows that the confidence intervals computed based on empirical distribution and the bias-corrected confidence intervals are very similar in our results, indicating minimal skewing and bias.

The total effect of proximity on consequence (C in Table B3) is positive and significant (β = 0.46, p < 0.01); (2) the indirect impact (a × b in Table B3) is significant but small (β = 0.10, p < 0.01); and (3) when the mediation path is included, the direct effect of proximity on consequence (c’ in Table B3) is large and significant (β = 0.37, p < 0.01). The mediation effect ratio is 20.8%. These results indicate that the primary impact of proximity on consequence is direct.

The total effect of proximity on compliance (C in Table B3) is positive and significant (β = 0.11, p < 0.01); (2) the indirect impact (a × b in Table B3) is significant but small (β = 0.10, p < 0.01); and (3) when the mediation path is included, the direct effect of proximity on compliance (c’ in Table B3) is significant but small and negative (β = −0.11, p < 0.01). The mediation effect ratio is 90.3%. These results indicate that consequence mediates most of the impact of proximity on compliance.

The total effect of consequence on compliance (C in Table B3) is positive and significant (β = 0.53, p < 0.01); (2) the indirect impact (a × b in Table B3) is large and significant (β = 0.25, p < 0.01); and (3) when the mediation path is included, the direct effect of consequence on compliance (c’ in Table B3) is large and significant (β = 0.28, p < 0.01). The mediation effect ratio is 47.7%. These results indicate that social consensus mediates about half of the impact of consequence on compliance, while the other half is a direct effect.

The total effect of temporal immediacy on compliance (C in Table B3) is positive and significant (β = 0.12, p < 0.01); (2) the indirect impact (a × b in Table B3) is significant but small (β = 0.10, p < 0.01); and (3) when the mediation path is included, the direct effect of temporal immediacy on compliance (c’ in Table B3) is small and weakly significant (β = −0.08, p < 0.05). The mediation effect ratio is 87.3%. These results indicate that consequence mediates most of the impact of temporal immediacy on compliance.

To evaluate whether a construct has a substantive impact on the endogenous constructs, we measured the f2 effect size for each exogenous construct by measuring the change in the R2 value when the exogenous construct was excluded from the model (Sarstedt et al., 2022). Specifically, the f2 effect size was calculated as follows:

where Rincluded2 and Rexcluded2 are the R2 values of the endogenous latent variable when a selected exogenous latent variable is included in or excluded from the model (Sarstedt et al., 2022). Our results indicate that social consensus has a medium effect (f2 >0.15); consequence, proximity, and self-efficacy each has a small effect (f2 >0.02); and temporal immediacy has no effect (f2 <0.02).

Employee ISSP compliance has been studied primarily through a cost-benefit analysis framework, whereby an employee evaluates personal consequences when deciding whether to comply with ISSP policies. However, organizational sanctions to discourage noncompliance often fail because they cause workplace anxiety, breed resentment, and are easily nullified through neutralization techniques. We recognized that a neglected phenomenon of ISSP noncompliance is that the real consequences of data breaches are borne mostly by the organization, its customers, and its other stakeholders, not by the employees themselves. This realization led us to examine ISSP compliance from an ethical decision-making perspective. Although the role of PNVE in ISSP compliance is well established, the mechanisms through which PNVE exerts its influence has been scarely investigated. We examined one component of this mechanism, namely moral evaluation, to derive hypotheses that can translate into managerial practices. The resulting model incorporates utilitarian ethics, deontological ethics, and construal level theory into an analytical framework, which represents a theoretical contribution to ISSP compliance research. Our application of CLT to interpret organization-level ISSP compliance is a key contribution because it allowed us to analyze relationships among our model constructs and derive actionable insights concerning how to align employee compliance motivation with organizational information security interests to facilitate compliance, as detailed below.

With respect to our first research question, using ethics theories, we found that employees evaluate both utilitarian ethics based on the overall protection of the organization and deontological ethics based on the righteousness of an action when deciding whether to comply with ISSPs. Our results showed that both the negative organizational consequences of the security breaches and the prevailing opinions of coworkers significantly impact employees’ compliance intentions. This implies compliance is not solely driven by self-interest or cost-benefit reasoning. Rather, employees align their compliance motivation with organizational information security interests if the negative consequences to the organization are understood and if a pro-compliance social consensus is evident. To help employees achieve this alignment, we recommend that management clearly communicate the potential damage that could result from non-compliant behavior, including case studies of past security breaches, potential financial losses, and legal implications, to make the risks tangible to employees. The finding that half of the impact of consequences on compliance is indirect through social consensus highlights the importance of a compliance norm. We recommend that management foster a workplace culture where ISSP adherence is the norm by providing clear codes of conduct, showcasing examples of compliance, using internal communications to highlight at team meetings how most employees are following ISSPs, and recognizing employees who exemplify adherence to ISSPs.

We further found that the negative consequences of ISSP violation significantly impact employees’ perception of pro-compliance social consensus. Hence, we recommend that efforts to facilitate a pro-compliance social norm be tied to efforts to enhance employee understanding of security breach consequences for the organization and all its stakeholders.

We found that deontological ethics (the righteousness of an action) has a stronger impact on compliance intention than utilitarianism, which is consistent with existing empirical results (e.g. Smith et al., 2023). We further found that utilitarianism influences compliance intention primarily through acting on deontological ethics. Therefore, we recommend that management prioritize deontological ethics, that is, emphasize moral and ethical responsibilities, not just consequences, associated with ISSP compliance through ethical training sessions and other communications.

With respect to our second research question, in line with construal level theory, we found that both proximity to the organization suffering the damage and temporal immediacy of damage caused by an ISSP violation significantly impact employee evaluation of the consequences of ISSP violation. In addition, we found that employees tend to believe that negative consequences would occur sooner when they feel more socially proximal to the organization. However, the impact of proximity on consequence is mostly direct, rather than indirect through temporal immediacy. Even if the consequences do not happen for some time, feeling socially close to the organization can help employees see and feel the consequences of data breaches. This means that reducing psychological distance will reduce the underestimation of potential data breach consequences, even when the damage may not occur in the immediate future. We therefore recommend that, in training sessions, management use relatable and real-world scenarios to show how ISSP violations can immediately affect employees, coworkers, and other stakeholders. To bring employees closer to the organization, we recommend that management encourage employee participation in setting departmental and organizational goals regarding information security. We also recommend that, when promoting ISSP compliance, management focus on providing support and resources to help employees adhere to ISSPs, rather than punishing them for noncompliance.

This study has several limitations. First, it relied on self-reported items; although common method bias was not significant, future research could use alternative data sources. Second, the scenario-based survey may not fully reflect real-life employee behavior, potentially biasing ISSP compliance intentions. Third, we measured intention rather than actual behavior. Finally, while proximity was defined as employees’ organizational identification, some items used possessive wording (e.g. “my company”), which could invite literal interpretations. Nonetheless, these items have been used in prior research and responses were consistent with psychological ownership.

Future research could employ cognitive pre-testing to examine the interpretation of proximity items in the context of ISSP compliance and refine wording to better capture psychological connectedness, if needed. Future research could replicate this study and complement it with qualitative methods to mitigate biases inherent in self-reported, scenario-based measures, or re-examine the model using field experiments and actual employee compliance behavior in real workplace ethical dilemmas. Using field experiments, future research could identify antecedents to our model, explore the differential effects of deontological and utilitarian ethics on compliance, and incorporate other ethical theories into our model to uncover more insights. Future research could also develop a comprehensive ISSP compliance model that integrates both extrinsic motivations and social influences that compel employees to comply with ISSPs, together with moral judgment and ethical considerations that shape employees’ intrinsic motivation and help align their personal values with the organization’s information security interests. Future research could explore how organizations might assess PNVE during recruitment and use them as criteria for employee selection to enhance internal ISSP compliance.

Sanctions for noncompliance are often ineffective in promoting compliance. Investigating compliance from an ethics perspective, we established that redirecting employee compliance motivation from a self-interested cost-benefit analysis to alignment with organizational information security interests can be fruitful. This can be achieved through clear communication efforts emphasizing the substantial losses and harm that may be suffered by the organization and its various stakeholders, and by fostering a strong pro-compliance culture. Developing an organizational culture in which employees feel psychologically close to their organization is essential. Improved ISSP compliance will ensure the improved security of information systems.

A short early-development version of this paper was presented at the 58th Hawaii International Conference on System Science (HICSS 2025) (Zheng and Walter, 2025).

The supplementary material for this article can be found online.

Ajzen
,
I.
(
1991
), “
The theory of planned behavior
”,
Organizational Behavior and Human Decision Processes
, Vol. 
50
No. 
2
, pp. 
179
-
211
, doi: .
Bicchieri
,
C.
(
2005
),
The Grammar of Society: The Nature and Dynamics of Social Norms
,
Cambridge University Press
,
New York, NY
.
Brady
,
F.N.
and
Wheeler
,
G.E.
(
1996
), “
An empirical study of ethical predispositions
”,
Journal of Business Ethics
, Vol. 
15
No. 
9
, pp. 
927
-
940
, doi: .
Brooks
,
R.R.
,
Williams
,
K.J.
and
Lee
,
S.Y.
(
2024
), “
Personal and contextual predictors of information security policy compliance: evidence from a low-fidelity simulation
”,
Journal of Business and Psychology
, Vol. 
39
No. 
3
, pp. 
657
-
677
, doi: .
Bulgurcu
,
B.
,
Cavusoglu
,
H.
and
Benbasat
,
I.
(
2010
), “
Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness
”,
MIS Quarterly
, Vol. 
34
No. 
3
, pp. 
523
-
548
, doi: .
Chandran
,
S.
and
Menon
,
G.
(
2004
), “
When a day means more than a year: effects of temporal framing on judgments of health risk
”,
Journal of Consumer Research
, Vol. 
31
No. 
2
, pp. 
375
-
389
, doi: .
Chatterjee
,
S.
,
Sarker
,
S.
and
Valacich
,
J.S.
(
2015
), “
The behavioral roots of information systems security: exploring key factors related to unethical IT use
”,
Journal of Management Information Systems
, Vol. 
31
No. 
4
, pp. 
49
-
87
, doi: .
Cram
,
W.A.
,
D'Arcy
,
J.
and
Proudfoot
,
J.G.
(
2019
), “
Seeing the forest and the trees: a meta-analysis of the antecedents to information security policy compliance
”,
MIS Quarterly
, Vol. 
43
No. 
2
, pp. 
525
-
553
, doi: .
Cram
,
W.A.
,
D’ Arcy
,
J.
and
Benlian
,
A.
(
2024
), “
Time will tell: the case for an idiographic approach to behavioral cybersecurity research
”,
MIS Quarterly
, Vol. 
48
No. 
1
, pp. 
95
-
136
, doi: .
Crossler
,
R.E.
,
Long
,
J.H.
,
Loraas
,
T.M.
and
Trinkle
,
B.S.
(
2017
), “
The impact of moral intensity and ethical tone consistency on policy compliance
”,
Journal of Infrastructure Systems
, Vol. 
31
No. 
2
, pp. 
49
-
64
, doi: .
D'Arcy
,
J.
and
Lowry
,
P.B.
(
2019
), “
Cognitive‐affective drivers of employees' daily compliance with information security policies: a multilevel, longitudinal study
”,
Information Systems Journal
, Vol. 
29
No. 
1
, pp. 
43
-
69
, doi: .
D'Arcy
,
J.
,
Herath
,
T.
and
Shoss
,
M.K.
(
2014
), “
Understanding employee responses to stressful information security requirements: a coping perspective
”,
Journal of Management Information Systems
, Vol. 
31
No. 
2
, pp. 
285
-
318
, doi: .
Farayola
,
O.A.
and
Olorunfemi
,
O.L.
(
2024
), “
Ethical decision-making in IT governance: a review of models and frameworks
”,
International Journal of Science and Research Archive
, Vol. 
11
No. 
2
, pp. 
130
-
138
, doi: .
Fleischman
,
G.M.
,
Valentine
,
S.R.
,
Curtis
,
M.B.
and
Mohapatra
,
P.S.
(
2023
), “
The influence of ethical beliefs and attitudes, norms, and prior outcomes on cybersecurity investment decisions
”,
Business and Society
, Vol. 
62
No. 
3
, pp. 
488
-
529
, doi: .
Fox
,
J.
(
1991
),
Regression Diagnostics: Quantitative Applications in the Social Sciences
,
Sage Publications
,
Newbury Park, CA
.
Guillard
,
M.
,
Navarro
,
O.
,
Cortes
,
S.
and
Fleury-Bahi
,
G.
(
2021
), “
How do we adapt when we are faced with the effects of climate change?
”,
International Journal of Disaster Risk Reduction
, Vol. 
65
, 102586, doi: .
Guo
,
K.H.
,
Yuan
,
Y.
,
Archer
,
N.P.
and
Connelly
,
C.E.
(
2011
), “
Understanding nonmalicious security violations in the workplace: a composite behavior model
”,
Journal of Management Information Systems
, Vol. 
28
No. 
2
, pp. 
203
-
236
, doi: .
Han
,
M.
and
Vasquez
,
A.Z.
(
2020
), “
Examination of cyber aggression by adult consumers: ethical framework and drivers
”,
Journal of Information, Communication and Ethics in Society
, Vol. 
18
No. 
2
, pp. 
305
-
319
, doi: .
Hinsz
,
V.B.
(
2025
), “
Motivating cybersecurity behaviors: a beyond reasoned action conceptualization
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
5
No. 
1
, pp. 
60
-
78
, doi: .
Huang
,
H.H.
and
Lin
,
J.W.
(
2023
), “
Inconsistencies between information security policy compliance and shadow IT usage
”,
Journal of Computer Information Systems
, Vol. 
64
No. 
4
, pp. 
554
-
564
, doi: .
Hunt
,
S.D.
and
Vitell
,
S.
(
1986
), “
A general theory of marketing ethics
”,
Journal of Macromarketing
, Vol. 
6
No. 
1
, pp. 
5
-
16
, doi: .
Ismail
,
S.S.M.
and
Hilal
,
O.A.
(
2023
), “
Behaving green… who takes the lead? The role of responsible leadership, psychological ownership, and green moral identity in motivating employees green behaviors
”,
Global Business and Organizational Excellence
, Vol. 
42
No. 
4
, pp. 
11
-
29
, doi: .
Johnston
,
A.C.
,
Warkentin
,
M.
and
Siponen
,
M.
(
2015
), “
An enhanced fear appeal rhetorical framework: leveraging threats to the human asset through sanctioning rhetoric
”,
MIS Quarterly
, Vol. 
39
No. 
1
, pp. 
113
-
134
, doi: .
Jones
,
T.M.
(
1991
), “
Ethical decision making by individuals in organizations: an issue-contingent model
”,
Academy of Management Review
, Vol. 
16
No. 
2
, pp. 
366
-
395
, doi: .
Joosten
,
A.
,
van Dijke
,
M.
,
Van Hiel
,
A.
and
De Cremer
,
D.
(
2014
), “
Feel good, do-good!? On consistency and compensation in moral self-regulation
”,
Journal of Business Ethics
, Vol. 
123
, pp. 
71
-
84
, doi: .
Khalil
,
M.
(
2025
), “
Data breach statistics 2025: costs, causes, trends, and insights
”,
available at:
 Link to the website (
accessed
 2 March 2026).
Kim
,
H.L.
and
Han
,
J.
(
2019
), “
Do employees in a ‘good’ company comply better with information security policy? A corporate social responsibility perspective
”,
Information Technology and People
, Vol. 
32
No. 
4
, pp. 
858
-
875
, doi: .
Kini
,
R.B.
,
Ramakrishna
,
H.V.
and
Vijayaraman
,
B.S.
(
2003
), “
An exploratory study of moral intensity regarding software piracy of students in Thailand
”,
Behaviour and Information Technology
, Vol. 
22
No. 
1
, pp. 
63
-
70
, doi: .
Kos Koklic
,
M.
,
Vida
,
I.
,
Bajde
,
D.
and
Culiberg
,
B.
(
2014
), “
The study of perceived adverse effects of digital piracy and involvement: insights from adult computer users
”,
Behaviour and Information Technology
, Vol. 
33
No. 
3
, pp. 
225
-
236
, doi: .
Lankton
,
N.K.
,
Stivason
,
C.
and
Gurung
,
A.
(
2019
), “
Information protection behaviors: morality and organizational criticality
”,
Information and Computer Security
, Vol. 
27
No. 
3
, pp. 
468
-
488
, doi: .
Le
,
V.H.
and
Zamora
,
B.
(
2018
), “
The price of a data breach
”,
ISACA Journal
, Vol. 
4
,
available at:
 Link to the website (
accessed
 3 March 2026).
Li
,
H.
,
Sarathy
,
R.
,
Zhang
,
J.
and
Luo
,
X.
(
2014
), “
Exploring the effects of organizational justice, personal ethics and sanction on internet use policy compliance
”,
Information Systems Journal
, Vol. 
24
No. 
6
, pp. 
479
-
502
, doi: .
Li
,
Y.
,
Zhang
,
N.
and
Siponen
,
M.
(
2019
), “
Keeping secure to the end: a long-term perspective to understand employees' consequence-delayed information security violation
”,
Behaviour and Information Technology
, Vol. 
38
No. 
5
, pp. 
435
-
453
, doi: .
Lowry
,
P.B.
,
D'Arcy
,
J.
,
Hammer
,
B.
and
Moody
,
G.D.
(
2016
), “
‘Cargo Cult’ science in traditional organization and information systems survey research: a case for using nontraditional methods of data collection, including Mechanical Turk and online panels
”,
The Journal of Strategic Information Systems
, Vol. 
25
No. 
3
, pp. 
232
-
240
, doi: .
May
,
D.R.
and
Pauli
,
K.P.
(
2002
), “
The role of moral intensity in ethical decision making: a review and investigation of moral recognition, evaluation, and intention
”,
Business and Society
, Vol. 
41
No. 
1
, pp. 
84
-
117
, doi: .
Merhi
,
M.I.
and
Ahluwalia
,
P.
(
2019
), “
Examining the impact of deterrence factors and norms on resistance to Information Systems Security
”,
Computers in Human Behavior
, Vol. 
92
, pp. 
37
-
46
, doi: .
Mersinas
,
K.
and
Bada
,
M.
(
2024
), “
Behavior change approaches for cyber security and the need for ethics
”, in
Cook
,
D.
,
Abawajy
,
J.
and
Kim
,
T.H.
(Eds),
Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media (Cyber Science 2023)
,
Springer
, pp.
107
-
129
, doi: .
Mingers
,
J.
and
Walsham
,
G.
(
2010
), “
Toward ethical information systems: the contribution of discourse ethics
”,
MIS Quarterly
, Vol. 
34
No. 
4
, pp. 
833
-
854
, doi: .Refstyled
Moody
,
G.D.
,
Siponen
,
M.
and
Pahnila
,
S.
(
2018
), “
Toward a unified model of information security policy compliance
”,
MIS Quarterly
, Vol. 
42
No. 
1
, pp. 
285
-
311
, doi: .
Paolacci
,
G.
,
Chandler
,
J.
and
Ipeirotis
,
P.G.
(
2010
), “
Running experiments on Amazon mechanical Turk
”,
Judgment and Decision Making
, Vol. 
5
No. 
5
, pp. 
411
-
419
, doi: .
Pierce
,
J.L.
,
Kostova
,
T.
and
Dirks
,
K.T.
(
2001
), “
Toward a theory of psychological ownership in organizations
”,
Academy of Management Review
, Vol. 
26
No. 
2
, pp. 
298
-
310
, doi: .
Podsakoff
,
P.M.
,
MacKenzie
,
S.B.
,
Lee
,
J.Y.
and
Podsakoff
,
N.P.
(
2003
), “
Common method biases in behavioral research: a critical review of the literature and recommended remedies
”,
Journal of Applied Psychology
, Vol. 
88
No. 
5
, pp. 
879
-
903
, doi: .
Ponemon
,
L.
(
2017
), “
Cost of a data breach 2017: $225 per record lost — an all-time high
”,
Ponemon Sullivan Report, available at:
 Link to the website (
accessed
 3 March 2026).
Renaud
,
K.
(
2020
), “
Why companies should stop scaring employees about cybersecurity
”,
The Wall Street Journal
,
7 December, available at:
 Link to the website (
accessed
 3 March 2026).
Rest
,
J.R.
(
1986
),
Moral Development: Advances in Research and Theory
,
Praeger
,
New York, NY
.
Roberts
,
J.A.
and
Wasieleski
,
D.M.
(
2012
), “
Moral reasoning in computer-based task environments: exploring the interplay between cognitive and technological factors on individuals' propensity to break rules
”,
Journal of Business Ethics
, Vol. 
110
No. 
3
, pp. 
355
-
376
, doi: .
Ryan
,
R.M.
and
Deci
,
E.L.
(
2000
), “
Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being
”,
American Psychologist
, Vol. 
55
No. 
1
, pp. 
68
-
78
, doi: .
Sarstedt
,
M.
,
Ringle
,
C.M.
and
Hair
,
J.F.
(
2022
), “Partial least squares structural equation modeling”, in
Homburg
,
C.
,
Klarmann
,
M.
and
Vomberg
,
A.
(Eds),
Handbook of Market Research
,
Springer Nature Switzerland AG
,
Cham
, pp. 
587
-
632
. doi: .
Schuetz
,
S.W.
,
Benjamin Lowry
,
P.
,
Pienta
,
D.A.
and
Bennett Thatcher
,
J.
(
2020
), “
The effectiveness of abstract versus concrete fear appeals in information security
”,
Journal of Management Information Systems
, Vol. 
37
No. 
3
, pp. 
723
-
757
, doi: .
Sharma
,
K.
,
Zhan
,
X.
,
Nah
,
F.F.H.
,
Siau
,
K.
and
Cheng
,
M.X.
(
2021
), “
Impact of digital nudging on information security behavior: an experimental study on framing and priming in cybersecurity
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
1
No. 
1
, pp. 
69
-
91
, doi: .
Shawver
,
T.J.
and
Miller
,
W.F.
(
2017
), “
Moral intensity revisited: measuring the benefit of accounting ethics interventions
”,
Journal of Business Ethics
, Vol. 
141
No. 
3
, pp. 
587
-
603
, doi: .
Shrout
,
P.E.
and
Bolger
,
N.
(
2002
), “
Mediation in experimental and nonexperimental studies: new procedures and recommendations
”,
Psychological Methods
, Vol. 
7
No. 
4
, pp. 
422
-
445
, doi: .
Singhapakdi
,
A.
,
Vitell
,
S.J.
and
Kraft
,
K.L.
(
1996
), “
Moral intensity and ethical decision-making of marketing professionals
”,
Journal of Business Research
, Vol. 
36
No. 
3
, pp. 
245
-
255
, doi: .
Smith
,
A.E.
,
Zlatevska
,
N.
,
Chowdhury
,
R.M.M.I.
and
Belli
,
A.
(
2023
), “
A meta-analytical assessment of the effect of deontological evaluations and teleological evaluations on ethical judgments/intentions
”,
Journal of Business Ethics
, Vol. 
188
No. 
3
, pp. 
533
-
588
, doi: .
Solomon
,
R.C.
(
1992
), “
Corporate roles, personal virtues: an aristotelean approach to business ethics
”,
Business Ethics Quarterly
, Vol. 
2
No. 
3
, pp. 
317
-
339
, doi: .
Stanaland
,
A.
and
Gaither
,
S.
(
2021
), “
‘Be a man’: the role of social pressure in eliciting men's aggressive cognition
”,
Personality and Social Psychology Bulletin
, Vol. 
47
No. 
11
, pp. 
1596
-
1611
, doi: .
Stephan
,
E.
,
Liberman
,
N.
and
Trope
,
Y.
(
2010
), “
Politeness and psychological distance: a construal level perspective
”,
Journal of Personality and Social Psychology
, Vol. 
98
No. 
2
, pp. 
268
-
280
, doi: .
Trope
,
Y.
and
Liberman
,
N.
(
2003
), “
Temporal construal
”,
Psychological Review
, Vol. 
110
No. 
3
, pp.
403
-
421
, doi:
Trope
,
Y.
and
Liberman
,
N.
(
2010
), “
Construal-level theory of psychological distance
”,
Psychological Review
, Vol. 
117
No. 
2
, pp. 
440
-
463
, doi: .
Trope
,
Y.
,
Liberman
,
N.
and
Wakslak
,
C.
(
2007
), “
Construal levels and psychological distance: effects on representation, prediction, evaluation, and behavior
”,
Journal of Consumer Psychology
, Vol. 
17
No. 
2
, pp. 
83
-
95
, doi: .
Vadera
,
A.K.
,
Tenbrunsel
,
A.E.
and
Diekmann
,
K.A.
(
2025
), “
Bridging the chasm between intentions and behaviors: developing and testing a construal level theory of internal whistle-blowing
”,
Organization Science
, Vol. 
36
No. 
1
, pp. 
261
-
287
, doi: .
Van Dyne
,
L.
and
Pierce
,
J.L.
(
2004
), “
Psychological ownership and feelings of possession: three field studies predicting employee attitudes and organizational citizenship behavior
”,
Journal of Organizational Behavior
, Vol. 
25
No. 
4
, pp. 
439
-
459
, doi: .
Velasquez
,
M.G.
and
Rostankowski
,
C.
(
1985
),
Ethics: Theory and Practice
,
Prentice-Hall
,
Englewood Cliffs, NJ
.
Verizon
(
2025
), “
Data breach investigations report
”,
available at:
 Link to the website (
accessed
 3 March 2026).
Wang
,
X.
and
Xu
,
J.
(
2021
), “
Deterrence and leadership factors: which are important for information security policy compliance in the hotel industry
”,
Tourism Management
, Vol. 
84
, 104282, doi: .
Wang
,
J.
,
Keil
,
M.
and
Wang
,
L.
(
2015
), “
The effect of moral intensity on it employees' bad news reporting
”,
Journal of Computational Information Systems
, Vol. 
55
No. 
3
, pp. 
1
-
10
, doi: .
Wiesenfeld
,
B.M.
,
Reyt
,
J.N.
,
Brockner
,
J.
and
Trope
,
Y.
(
2017
), “
Construal level theory in organizational research
”,
Annual Review of Organizational Psychology and Organizational Behavior
, Vol. 
4
No. 
1
, pp. 
367
-
400
, doi: .
Xu
,
Z.X.
and
Ma
,
H.K.
(
2016
), “
How can a deontological decision lead to moral behavior? The moderating role of moral identity
”,
Journal of Business Ethics
, Vol. 
137
No. 
3
, pp. 
537
-
549
, doi: .
Xue
,
B.
,
Xu
,
F.
,
Luo
,
X.
and
Warkentin
,
M.
(
2021
), “
Ethical leadership and employee information security policy (ISP) violation: exploring dual-mediation paths
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol. 
1
No. 
1
, pp. 
5
-
23
, doi: .
Yazdani
,
N.
and
Murad
,
H.S.
(
2015
), “
Toward an ethical theory of organizing
”,
Journal of Business Ethics
, Vol. 
127
No. 
2
, pp. 
399
-
417
, doi: .
Yazdanmehr
,
A.
and
Wang
,
J.
(
2016
), “
Employees' information security policy compliance: a norm activation perspective
”,
Decision Support Systems
, Vol. 
92
, pp. 
36
-
46
, doi: .
Yazdanmehr
,
A.
,
Jawad
,
M.
,
Benbunan-Fich
,
R.
and
Wang
,
J.
(
2024
), “
The role of ethical climates in employee information security policy violations
”,
Decision Support Systems
, Vol. 
177
, 114086, doi: .
Yoon
,
C.
and
Kim
,
H.
(
2013
), “
Understanding computer security behavioral intention in the workplace: an empirical study of Korean firms
”,
Information Technology and People
, Vol. 
26
No. 
4
, pp. 
401
-
419
, doi: .
Zhang
,
C.
,
Simon
,
J.C.
and
Lee
,
E.T.
(
2016
), “
An empirical investigation of decision making in it-related dilemmas: impact of positive and negative consequence information
”,
Journal of Organizational and End User Computing
, Vol. 
28
No. 
4
, pp. 
73
-
90
, doi: .
Zhang
,
Y.
,
Liu
,
G.
,
Zhang
,
L.
,
Xu
,
S.
and
Cheung
,
M.W.L.
(
2021
), “
Psychological ownership: a meta-analysis and comparison of multiple forms of attachment in the workplace
”,
Journal of Management
, Vol. 
47
No. 
3
, pp. 
745
-
770
, doi: .
Zhen
,
J.
,
Xie
,
Z.
,
Dong
,
K.
and
Chen
,
L.
(
2022
), “
Impact of negative emotions on violations of information security policy and possible mitigations
”,
Behaviour and Information Technology
, Vol. 
41
No. 
11
, pp. 
2342
-
2354
, doi:
Zheng
,
D.
and
Walter
,
Z.
(
2025
), “Moral intensity dimensions of information security policy compliance: perspectives of construal level theory and ethical theories”, in
Bui
,
T.X.
and
Sprague
,
R.H.
(Eds),
Proceedings of the 58th Hawaii International Conference on System Sciences
, pp.
6181
-
6190
, doi: .
Published in Organizational Cybersecurity Journal: Practice, Process and People. Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) license. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this license may be seen at Link to the terms of the CC BY 4.0 licence.

Supplementary data

or Create an Account

Close Modal
Close Modal