Shame in cyber security : effective behavior modification tool or counterproductive foil?

Renaud, Karen and Searle, Rosalind and Dupuis, Marc; (2021) Shame in cyber security : effective behavior modification tool or counterproductive foil? In: NSPW '21 : New Security Paradigms Workshop. ACM, New York, NY., 70–87. ISBN 9781450385732 (https://doi.org/10.1145/3498891.3498896)

[thumbnail of Renaud-etal-NSPW-2021-Shame-in-cyber-security-effective-behavior-modification-tool-or-counterproductive-foil]
Preview
Text. Filename: Renaud_etal_NSPW_2021_Shame_in_cyber_security_effective_behavior_modification_tool_or_counterproductive_foil.pdf
Accepted Author Manuscript

Download (1MB)| Preview

Abstract

Organizations often respond to cyber security breaches by blam- ing and shaming the employees who were involved. There is an intuitive natural justice to using such strategies in the belief that the need to avoid repeated shaming occurrences will encourage them to exercise more care. However, psychology highlights sig- nificant short- and long-term impacts and harmful consequences of felt shame. To explore and investigate this in the cyber domain, we asked those who had inadvertently triggered an adverse cyber security incident to tell us about their responses and to recount the emotions they experienced when this occurred. We also examined the impact of the organization’s management of the incident on the “culprit’s” future behaviors and attitudes. We discovered that those who had caused a cyber security incident often felt guilt and shame, and their employers’ responses either exacerbated or ameliorated these negative emotions. In the case of the former, there were enduring unfavorable consequences, both in terms of employee well-being and damaged relationships. We conclude with a set of recommendations for employers, in terms of responding to adverse cyber security incidents. The aim is to ensure that negative emotions, such as shame, do not make the incident much more damaging than it needs to be.