A1 Journal article (refereed)
Shall We Follow? Impact of Reputation Concern on Information Security Managers’ Investment Decisions (2020)
Shao, X., Siponen, M., & Liu, F. (2020). Shall We Follow? Impact of Reputation Concern on Information Security Managers’ Investment Decisions. Computers and Security, 97, Article 101961. https://doi.org/10.1016/j.cose.2020.101961
JYU authors or editors
Publication details
All authors or editors: Shao, Xiuyan; Siponen, Mikko; Liu, Fufan
Journal or series: Computers and Security
ISSN: 0167-4048
eISSN: 1872-6208
Publication year: 2020
Volume: 97
Article number: 101961
Publisher: Elsevier BV
Publication country: Netherlands
Publication language: English
DOI: https://doi.org/10.1016/j.cose.2020.101961
Publication open access: Not open
Publication channel open access:
Publication is parallel published (JYX): https://jyx.jyu.fi/handle/123456789/71368
Abstract
Information security (infosec) is important for organizations. While budgeting for infosec is a crucial resource allocation decision, infosec managers may choose to follow other fellow experts’ recommendations or baseline practices. The present paper uses reputational herding theory to explain the decision made by infosec managers to use a “let's follow others” strategy in this context. Based on a sample of 106 organizations in Finland, we find that infosec managers’ ability to accurately predict the benefit of infosec investment, as well as their reputations, have significant effects on motivating them to discount their own information. Infosec managers’ discounting of their own information, together with the strength of information that relates to infosec investment and mandatory requirements, motivates infosec investment. Our empirical results highlight the “let's follow others” strategy as an important alternative to cost–benefit analysis in terms of budgeting for infosec investment.
Keywords: data security; organisations (systems); data security policy; chief information officers; decision making; reputation management
Free keywords: Infosec investment; decision making; uncertainty; discount own information; reputational herding
Contributing organizations
Ministry reporting: Yes
VIRTA submission year: 2020
JUFO rating: 2