2021
DOI: 10.1177/1071181321651068
|View full text |Cite
|
Sign up to set email alerts
|

Influence of Cumulative Risk Priming on Security Update Decision Making

Abstract: Installing security updates is one of the important security actions individuals can take to prevent potential cybersecurity threats. The cumulative risk of delaying the installation of security updates over an extended period can be substantial, and yet, people often choose to delay such actions. Past research suggests that people neglect to update because the majority overestimate the cost (e.g., time) of an update and underestimate an attack risk. Utilizing the repeated protective decision paradigm, we cond… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2022
2022
2022
2022

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(3 citation statements)
references
References 11 publications
0
3
0
Order By: Relevance
“…As Rosoff et al (2013) found that negatively framed messages focused on risks and adverse consequences can prompt safer cyber behaviour, it may be that the use of affective priming will have more of an impact as it focuses on the negative implications for individuals of poor cyberhygiene behaviour. Given that Shieh and Rajivan (2021) show that some forms of priming have only short-lived, momentary effects on user behaviour, it is also likely that single-shot priming interventions alone are not sufficient in a cybersecurity context. More intensive interventions, potentially involving longer or multiple sessions for reinforcement, may be required to have a significant effect.…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…As Rosoff et al (2013) found that negatively framed messages focused on risks and adverse consequences can prompt safer cyber behaviour, it may be that the use of affective priming will have more of an impact as it focuses on the negative implications for individuals of poor cyberhygiene behaviour. Given that Shieh and Rajivan (2021) show that some forms of priming have only short-lived, momentary effects on user behaviour, it is also likely that single-shot priming interventions alone are not sufficient in a cybersecurity context. More intensive interventions, potentially involving longer or multiple sessions for reinforcement, may be required to have a significant effect.…”
Section: Discussionmentioning
confidence: 99%
“…Priming can be used to disrupt system 1 thinking and prompt individuals to activate system 2 thinking, thus heightening the likelihood that they will respond appropriately to, for example, cybersecurity risks they might be facing (Sharma et al, 2021). Empirical work is emerging to support this logic, with evidence that priming interventions can reduce risky behaviour related to information security (Sharma et al, 2021), that priming individuals with the negative outcomes of risky behaviours can prompt safer cybersecurity choices (Rosoff et al, 2013), and that "risk priming" can momentarily affect users' security update decisions (Shieh and Rajivan, 2021). However, there is also evidence that priming may be ineffective against more sophisticated forms of cyberattacks (Junger et al, 2017).…”
Section: Security Awareness and Practice Of University Studentsmentioning
confidence: 99%
See 1 more Smart Citation