<p>IBM's 2020 security report specified that 23.43% of data and security breaches were attributable to malicious insiders, which has tripled from 2016 to 2020. The average cost per malicious insider incident for firms is $756,760, leading to an annual total of $4.08 million. A study by the US Secret Service and Carnegie Mellon University found that identifying malicious insiders presents significant challenges and necessitates comprehensive considerations beyond mere software and hardware solutions. Yet, the predominant focus of research in this domain is on utilizing technology to detect and manage insider threats. Malicious insiders represent a behavioral issue that necessitates behavioral interventions. The human aspect of cybersecurity, particularly about malicious insiders, remains substantially underexplored. This research examines the interpretive dimensions of human behavior that lead to malicious intent. We interviewed 15 elite&#xa0;informants from the cybersecurity sector and utilized template analysis to discern two principal phenomena: personal benefits/greed&#xa0;and personal grievances or revenge that motivate individuals to exploit information for personal gains&#xa0;or retribution. The study advances theory by identifying two distinct moral disengagement pathways—personal benefit including greed and personal grievances that motivate revenge—that underlie malicious intent, extending Bandura's moral disengagement theory into the domain of information behavior. The findings of this research provide practical insights for organizations to explore non-technical solutions to address malicious information behavior, emphasizing the need for a comprehensive approach to understanding psychological processes that rationalize malicious behavior.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Determinants of Unethical Information Use by Insiders: Towards a Theory of Malicious Information Behavior

  • Kashif Saeed,
  • Vikas Sinha,
  • Victor Prybutok

摘要

IBM's 2020 security report specified that 23.43% of data and security breaches were attributable to malicious insiders, which has tripled from 2016 to 2020. The average cost per malicious insider incident for firms is $756,760, leading to an annual total of $4.08 million. A study by the US Secret Service and Carnegie Mellon University found that identifying malicious insiders presents significant challenges and necessitates comprehensive considerations beyond mere software and hardware solutions. Yet, the predominant focus of research in this domain is on utilizing technology to detect and manage insider threats. Malicious insiders represent a behavioral issue that necessitates behavioral interventions. The human aspect of cybersecurity, particularly about malicious insiders, remains substantially underexplored. This research examines the interpretive dimensions of human behavior that lead to malicious intent. We interviewed 15 elite informants from the cybersecurity sector and utilized template analysis to discern two principal phenomena: personal benefits/greed and personal grievances or revenge that motivate individuals to exploit information for personal gains or retribution. The study advances theory by identifying two distinct moral disengagement pathways—personal benefit including greed and personal grievances that motivate revenge—that underlie malicious intent, extending Bandura's moral disengagement theory into the domain of information behavior. The findings of this research provide practical insights for organizations to explore non-technical solutions to address malicious information behavior, emphasizing the need for a comprehensive approach to understanding psychological processes that rationalize malicious behavior.