Beyond Deterrence: A Systematic Review of the Role of Autonomous Motivation in Organizational Security Behavior Studies

Honorable Mention
Cybersecurity Training & AwarenessCybersecurity EngineersLawyers & Legal Researchers

Research Background and Issues

  • Problem or Challenge: Current research on employees' information security behavior within organizations primarily focuses on improving security behavior through external control measures such as deterrence and sanctions. However, as cyberattacks become more complex, relying solely on policy compliance is insufficient to address new threats. There is a need to focus on intrinsic, autonomous motivations, such as fulfilling psychological needs and aligning with personal values, which can drive more flexible and sustainable security behaviors.
  • Significance: Unlocking the potential of autonomous motivation can help develop more effective, human-centered information security strategies. This represents a sustainable approach to addressing modern information security challenges rather than solely relying on external controls.
  • Research Motivation and Related Work: Although previous studies suggest that autonomous motivation may influence employees' behavior in information security, the research is scattered, with diverse theoretical frameworks and inconsistent conclusions. Therefore, it is necessary to systematically consolidate these studies and propose a clearer theoretical framework.

Solution

  • Method or Solution: The authors conducted a systematic review of studies based on different theoretical frameworks, summarizing the forms of autonomous motivation in organizational information security behavior, related security behaviors, and the mechanisms through which these motivations influence employee behavior.
  • Innovations:
    • Proposed a refined classification of autonomous motivations, including five categories: interest-driven, task-driven, psychological needs, value-driven, and outcome expectations.
    • Conducted a comparative analysis of existing literature, linking motivations to types of security behaviors, and revealed specific forms of motivation that influence security behaviors.
    • Provided a set of theory-driven recommendations to guide future information security policy design, interventions, and research.
  • Implementation Steps and Key Techniques:
    1. Initially established the research scope and key terms;
    2. Screened literature from Scopus and ACM Digital Library (collected 432 papers, ultimately included 45);
    3. Adopted a pre-registered systematic literature review method to analyze motivations, behavior types, and theoretical frameworks;
    4. Proposed the classification and quantified and summarized the research findings.

Research Outcomes

  • Specific Outcomes:
    • Identified 17 unique autonomous motivations and categorized them into five groups: interest-driven, task-driven, psychological needs, value-driven, and outcome expectations.
    • Confirmed the association between three types of security behaviors and autonomous motivations: policy compliance behaviors, extra-role security behaviors (e.g., spontaneous sharing of security knowledge), and violation behaviors.
    • Summarized how autonomous motivations relate to security behaviors and found that certain motivations (e.g., personal responsibility, response efficacy, autonomy) are negatively correlated with violation behaviors.
  • Comparative Advantages Over Existing Solutions:
    • Compared to numerous studies based on deterrence theory or protection motivation theory, this work more comprehensively focuses on willingness-driven security behaviors, proposing a more human-centered motivation classification.
    • The study clarifies how motivation theories can go beyond mere compliance behaviors to promote more proactive security practices.
  • Experimental or Evaluation Results:
    • Using a systematic literature review approach, security behaviors were categorized based on five types of autonomous motivations.
    • Empirical studies supported the positive impact of motivations such as personal responsibility and value alignment on policy compliance and extra-role behaviors, while revealing mixed results for self-efficacy.
  • Limitations and Future Directions:
    • Limitations:
      1. The classification of autonomous motivations requires further validation, and their causal relationship with security behaviors remains unclear.
      2. There is a lack of large-scale empirical studies across cultures and industries.
      3. Data collection primarily relies on surveys, with limited objective behavior records, which may introduce self-report bias.
    • Future Directions:
      1. Conduct longitudinal experiments and replication studies to observe the long-term impact of motivations on behavior.
      2. Explore under-researched motivations (e.g., organizational fairness) and their applicability on a global scale.
      3. Advance the development of security management tools, such as designing motivation theory-based evaluation systems for security training.

Conclusion

This study systematically summarizes the relationship between autonomous motivations and organizational security behaviors, proposing a theory-driven classification framework and practical recommendations. Future research can further expand this direction by exploring motivational mechanisms in multivariable contexts and designing more human-centered and dynamic security measures and interventions.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/189394/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713122
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
Honorable Mention
group
Authors
4 authors
sell
Subtopics
Cybersecurity Training & Awareness
work
Professions
Cybersecurity Engineers, Lawyers & Legal Researchers
article
Content Status
Full text indexed
hub
Related Papers
3 related papers