Don’t break promises: psychological contracts in information security noncompliance and breach
Abdul Kader Khan, Prashant PalviaPurpose
This study adopts the theoretical lens of psychological contracts to explain information security policy (ISP) noncompliance and empirically examine the link between noncompliance and security breach.
Design/methodology/approach
Data for this empirical research were gathered via an online survey with non-IT employees as participants. Data were analyzed using partial least squares structural equation modeling.
Findings
Psychological contract breach (PCB) leads to ISP noncompliance, following an intense emotional reaction. A link between ISP noncompliance and security breach is supported.
Research limitations/implications
The findings of this study may not apply to economies and countries where perceptions of PCB may differ because of cultural differences.
Originality/value
This research identifies a path to ISP noncompliance resulting from a negative emotional reaction to social reciprocity. By identifying the factors that cause such emotional reactions, this research offers practical steps that information systems (IS) professionals may take to reduce the likelihood of employee-perceived PCB and resulting ISP noncompliance. The study also provides design suggestions to minimize security breaches resulting from ISP noncompliance.