Understanding work misrepresentation by contextualizing Protection Motivation Theory
DOI:
https://doi.org/10.66450/sim.v30i4.01Keywords:
Protection Motivation Theory (PMT), boundary conditions, alternative coping behaviour, complementary threats, competing threatsAbstract
We conducted an interview-based study in a work misrepresentation setting, where restaurant owners may register fewer sales and lower payments to employees than the actual sales and payments. If detected, such practices are penalized with sanctions. To gain a profound understanding of why actors may refrain from adopting the focal coping behaviour – limiting or stopping misrepresentation – when faced with the threat of such sanctions, the current research relies on interviews, which revealed rationales that aligned with Protection Motivation Theory (PMT), a theory frequently used to explain coping behaviour adoption in information systems studies. The narratives also suggested the need to contextualize PMT. While PMT offers valuable insights into coping behaviour adoption, it may also overlook critical contextual factors, including threats and coping behaviours that relate to the focal ones. The interplay between PMT’s boundary conditions and interview insights suggests a novel framework, the Related Threat and Coping Appraisals Framework (RTCAF), that practitioners can leverage to design controls that encourage specific coping behaviours. In addition, by exploring PMT’s boundary conditions, this article is directly relevant for IS researchers.
References
Ainsworth, R. T., & Hengartner, U. (2009). Quebec’s sales recording module (SRM): Fighting the zapper, phantomware and tax fraud with technology. Canadian Tax Journal, 57(4), 719-761.
Alvesson, M., & Kärreman, D. (2007). Constructing mystery: Empirical material in theory development. Academy of Management Review, 32, 1265–1281.
Anderson, C. L., & Agarwal, R. (2010). Practicing safe computing: a multimethod empirical examination of home computer user security behavioural intentions. MIS Quarterly, 34(3), 613-643.
Aurigemma, S., & Mattson, T. (2019). Generally speaking, context matters: making the case for a change from universal to particular ISP research. Journal of the AIS, 20(12), 1700-1742.
Barlette, Y., Gundolf, K., & Jaouen, A. (2017). CEO’s information security behavior in SMEs: does ownership matter? Systèmes d’Information et Management, 22(3), 7-45.
Barlette, Y., & Jaouen, A. (2019). Information security in SMEs: determinants of CEO’s protective and supportive behaviors. Systèmes d’Information et Management, 24(3), 7-40.
Beaudry, A., & Pinsonneault, A. (2005). Understanding user responses to information technology: a coping model of user adaptation. MIS Quarterly, 29(3), 493-524.
Beaudry, A., & Pinsonneault, A. (2010). The other side of acceptance: studying the direct and indirect effects of emotions on information technology use. MIS Quarterly, 34(4), 689-A3.
Bentham, J. (1780). Panopticon [Le Panoptique, traduit et publié par l’assemblé législative en 1791].
Berthevas, J. F. (2021). How protection motivation and social bond factors influence information security behavior. Systèmes d’Information et Management, 26(2), 77-115.
Boss, S. R., Galletta, D. F., Lowry, P. B., Moody, G. D. & Polak, P. (2015). What do systems users have to fear? Using fear appeals to engender threats and fear that motivate protective security behaviours. MIS Quarterly, 39(4), 837-864.
Burns, A. J., Roberts, T. L., Posey, C., Lowry, P. B., & Fuller, B. (2023). Going beyond deterrence: a middle-range theory of motives and controls for insider computer abuse. Information Systems Research, 34(1), 342-362.
Busse, C., Kach, A. P. & Wagner, S. M. (2017). Boundary conditions: what they are, how to explore them, why we need them and when to consider them. Organizational Research Methods, 20(4), 574-609.
Chen, C., Zhang, K. Z. K., Gong, X., Lee, M. K. O., & Wang, Y. (2020). Decreasing the problematic use of an information system: an empirical investigation of smartphone game players. Information Systems Journal, 30, 492–534.
Chen, Y., Ramamurthy, K., & Wen, K.-W. (2012). Organizations’ information security policy compliance: stick or carrot approach? Journal of Management Information Systems, 29(3), 157-188.
Chen, Y., & Zahedi, F. M. (2016). Individuals’ internet security perceptions and behaviors: polycontextual contrasts between the United States and China. MIS Quarterly, 40(1), 205-222.
Cromer, C. (2010). Understanding web 2.0’s influences on public e-services: a protection motivation perspective. Innovation, 12(2), 192-205.
Crossler, R. E., Long, J. H., Loraas, T. M., & Trinkle B. S. (2014). Understanding compliance with bring your own device policies utilizing protection motivation theory: bridging the intention-behavior gap. Journal of Information Systems, 28(1), 209-226.
Dambrot, S. M., de Kerchove, D., Flammini, F., Kinsner, W., MacDonald, G. L., & Saracco, R. (2018). Symbiotic autonomous systems. IEEE. Available at https://www.diva-portal.org/smash/get/diva2:1260812/FULLTEXT02.pdf.
Danermark, B., Ekström, M., & Karlsson, J. C. (2019). Explaining society (2nd ed.). Taylor & Francis.
Dang-Pham, D., & Pittayachawan S. (2015). Comparing intention to avoid malware across contexts in a BYOD-enabled Australian university: a protection motivation theory approach. Computers & Security, 48, 281-297.
Dey, D., Ghoshal, A., & Lahiri, A. (2022). Circumventing circumvention: an economic analysis of the role of education and enforcement. Management Science, 68(4), 2914-2931.
Doane, A. N., Boothe, L. G., Pearson, M. R., & Kelley, M. L. (2016). Risky electronic communication behaviors and cyberbullying victimization: an application of Protection Motivation Theory. Computers in Human Behavior, 60, 508-513.
Floyd, D. L., Prentice-Dunn, S., & Rogers, R. (2000). A meta-analysis of research on Protection Motivation Theory. Journal of Applied Social Psychology, 30(2), 407-429.
Fox, G., & Connolly, R. (2018). Mobile health technology adoption across generations: narrowing the digital divide. Information Systems Journal, 28, 995–1019.
Gao, Y., Li, H., & Luo, Y. (2015). An empirical study of wearable technology acceptance in healthcare. Industrial Management & Data Systems, 115(9), 1704-1723.
Gioia, D. A., Corley, K. G., & Hamilton, A. L. (2013). Seeking qualitative rigor in inductive research: notes on the Gioia methodology. Organizational Research Methods, 16(1), 15–31.
Grimes, M., & Marquardson, J. (2019). Quality matters: evoking subjective norms and coping appraisals by system design to increase security intentions. Decision Support Systems, 119, 23–34.
Gurung, A., Luo, X., & Liao, Q. (2009). Consumer motivations in taking action against spyware: an empirical investigation. Information Management & Computer Security, 17(3), 276-289.
Hakansson, H., & Ford, D. (2002). How should companies interact in business networks? Journal of Business Research, 55, 133-139.
Hanus, B., & Wu, Y. A. (2016). Impact of users’ security awareness on desktop security behaviour: a protection motivation theory perspective. Information Systems Management, 33(1), 2-16.
Hegtvedt, K. A., & Johnson, C. (2009). Power and justice: toward an understanding of legitimacy. American Behavioural Scientist, 53(3), 376-399.
Herath, T., Chen, R., Wang, J., Banjara, K., Wilbur, J., & Rao, H. R. (2014). Security services as coping mechanisms: an investigation into user intention to adopt an email authentication service. Information Systems Journal, 24(1), 61-84.
Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: a framework for security policy compliance in organisations. European Journal of Information Systems, 18 (2), 106-125.
Hong, W., Chan, F. K. Y., Thong, J. Y. L., Chasalow, L. C., & Gurpreet, D. (2014). A framework and guidelines for context-specific theorizing in information systems research. Information Systems Research, 25(1), 111-136.
Huyberechts, P. (2024, September 26). Na doping nu een uitgekiend plan met startnummers. Het Nieuwsblad. https://www.nieuwsblad.be/cnt/dmf20240925_96478315
Ifinedo, P. (2012). Understanding information systems security policy compliance: an integration of the theory of planned behavior and the protection motivation theory. Computers & Security, 31(1), 83-95.
Johnston, A. C., & Warkentin, M. (2010). Fear appeals and information security behaviours: an empirical study. MIS Quarterly, 34(3), 548-566.
Johnston, A. C., Warkentin, M., & Siponen, M. (2015). An enhanced fear appeal rhetorical framework: leveraging threats to the human asset through sanctioning rhetoric. MIS Quarterly, 39(1), 113-134.
Kirsch, L. J. (1997). Portfolio of control modes and IS project management. Information Systems Research, 8(3), 215-239.
Klein, H. K., & Myers, M. D. (1999). A set of principles for conducting and evaluating interpretive field studies in information systems. MIS Quarterly, 23(1), 67-94.
Komatsu, A., Takagi, D., & Takemura, T. (2013). Human aspects of information security: an empirical study of intentional versus actual behaviour. Information Management & Computer Security, 21(1), 5-15.
Lai, F., Li, D., & Hsieh C.-T. (2012). Fighting identity theft: the coping perspective. Decision Support Systems, 52(2), 353-363.
Laughlin, R. C. (1991). Environmental disturbances and organizational transitions and transformations: some alternative models. Organization Studies 12(2), 209–232.
Lazarus, R. S. (1991). Progress on a Cognitive–Motivational–Relational Theory of Emotion. American Psychologist, 46(8), 819-834.
Lazarus, R. S., & Folkman, S. (1984). Stress, appraisal, and coping. Springer.
Leclercq-Vandelannoitte, A., & Isaac, H. (2013). Technologies de l’information, contrôle et panoptique: pour une approche deleuzienne. Systèmes d’Information et Management, 18(2), 9-36.
Lee, D., Larose, R., & Rifon, N. (2008). Keeping our network safe: a model of online protection behaviour. Behaviour & Information Technology, 27(5), 445-454.
Lee, Y. (2011). Understanding anti-plagiarism software adoption: an extended protection motivation theory perspective. Decision Support Systems, 50(2), 361-369.
Lee, Y., & Larsen, K. R. (2009). Threat or coping appraisal: determinants of SMB executives’ decision to adopt anti-malware software. European Journal of Information Systems, 18(2), 177-187.
Leventhal, H. (1970). Findings and theory in the study of fear communications. In L. Berkowitz (Ed.) Advances in experimental social psychology (pp. 119-186). Academic Press.
Levi, M., Sacks, A., & Tyler, T. (2009). Conceptualizing legitimacy, measuring legitimating beliefs. American Behavioral Scientist, 53(3), 354-375.
Liang, H., & Xue, Y. (2010). Understanding security behaviors in personal computer usage: a threat avoidance perspective. Journal of the Association for Information Systems, 11(7), 394-413.
Liang, H., Xue, Y., & Wu, L. (2013). Ensuring employees’ IT compliance: carrot or stick? Information Systems Research, 24(2), 279-294.
Lowry, P.B., Moody, G.D., Parameswaran, S., & Brown, N.J. (2023). Examining the differential effectiveness of fear appeals in information security management using two-stage meta-analysis. Journal of Management Information Systems, 40(4), 1099-1138.
Lysyakov, M., & Viswanathan, S. (2023). Threatened by AI: analyzing users’ responses to the introduction of AI in a crowd-sourcing platform. Information Systems Research, 34(3), 1191-1210.
Markus, M.L., & Benjamin, R.I. (1997). The Magic Bullet Theory in IT-enabled transformation. Sloan Management Review, 38(2), 55-68.
Matyn, J. (2022, February 9) Helft van gecontroleerde horecazaken betrapt op zwartwerk. VRT. https://www.vrt.be/vrtnws/nl/2022/02/09/helft-van-horecazaken-die-gecontroleerd-worden-op-zwartwerk-loop.
Menard, P., Gatlin, R., & Warkentin, M. (2014). Threat protection and convenience: antecedents of cloud-based data backup. Journal of Computer Information Systems, 55(1), 83-91.
Mesgari, M., Mohajeri, K., & Azad, B. (2023). Affordances and information systems research: taking stock and moving forward. The Database for Advances in Information Systems, 54(2), 29-52.
Miles, M. B., Huberman, A. M., & Saldana, J. (2020). Qualitative data analysis: a methods sourcebook (4th ed.). Sage Publications.
Milne, G. R., Labrecque, L. I., & Cromer, C. (2009). Toward an understanding of the online consumer’s risky behaviour and protection practices. The Journal of Consumer Affairs, 43(3), 449-473.
Milne, S., Sheeran, P., & Orbell, S. (2000). Prediction and intervention in health-related behaviour: a meta-analytic review of Protection Motivation Theory. Journal of Applied Social Psychology, 30(1), 106-143.
Mingers, J. (2004). Re-establishing the real: Critical realism and information systems. In J. Mingers & L. Willcocks (Eds.), Social theory and philosophy for information systems (pp. 372–406). John Wiley & Sons.
Mohamed, N., & Ahmad, I. H. (2012). Information privacy concerns, antecedents and privacy measure use in social networking sites: evidence from Malaysia. Computers in Human Behavior, 28(6), 2366-2375.
Moody, G. D., Siponen, M., & Pahnila, S. (2018). Toward a unified model of information security policy compliance. MIS Quarterly, 42 (1), 285-311.
Mou, J., Cohen, J., Bhattacherjee, A., & Kim, J. (2022). A test of Protection Motivation Theory in the information security literature: a meta-analytic structural equation modelling approach. Journal of the AIS, 23(1), 196-236.
Nehme, A., & George, J. F. (2022). Approaching IT security & avoiding threats in the smart home context. Journal of Management Information Systems, 39(4), 1184-1214.
Ng, B.-Y., Kankanhalli, A., & Xu, Y. C. (2009). Studying users’ computer security behavior: a health belief perspective. Decision Support Systems, 46(4), 815-825.
Ng, K. C., Zhang, X., Thong, J. Y. L., & Tam, K. Y. (2021). Protecting against threats to information security: an attitudinal ambivalence perspective. Journal of Management Information Systems, 38(3), 732-764.
Pahnila, S., Siponen, M., & Mahmood, A. (2007). Employees’ behaviour towards IS security policy compliance. In R. H. Sprague (Ed.), Proceedings of the 40th Hawaii International Conference on System Sciences (p 156), IEEE Computer Society Press.
Patton, M. Q. (2002). Qualitative research & evaluation methods (3rd ed.). Sage Publications.
Posey, C., Roberts, T. L., & Lowry, P. B. (2015). The impact of organizational commitment on insiders’ motivation to protect organizational information assets. Journal of Management Information Systems, 32(4), 179-214.
Posey, C., Roberts, T. L., Lowry, P. B., & Hightower, R. T. (2014). Bridging the divide: a qualitative comparison of information security thought patterns between information security professionals and ordinary organizational insiders. Information & Management, 51(5), 551-567.
Rippetoe, P. A., & Rogers, R. W. (1987). Effects of components of a Protection Motivation Theory on adaptive and maladaptive coping with a health threat. Journal of Personality and Social Psychology, 52(3), 596-604.
Rogers, R. (1975). A Protection Motivation Theory of fear appeals and attitude change. Journal of Psychology, 91(1), 93-114.
Rogers, R. (1983). Cognitive and psychological processes in fear appeals and attitude change: a revised theory of protection motivation. In B. L. Cacioppoc, & L. L. Petty (Eds.), Social Psychophysiology: a sourcebook (pp. 153-176). Guilford Press.
Rogers, R. W., & Prentice-Dunn, S. (1997). Protection Motivation Theory. In D. Gochman (Ed.), Handbook of health behaviour research: Vol. 1. Determinants of health behaviour: Personal and social (pp. 113-132). Plenum Press.
Safa, N. S., Sookhak, M., Von Solms, R., Furnell, S., Ghani, N. A., & Herawan, T. (2015). Information security conscious care behaviour formation in organizations. Computers & Security, 53, 65-78.
Saldana, J. (2013). The coding manual for qualitative researchers (2nd ed.). Sage Publications.
Sarker, S., Xiao, X., & Beaulieu, T. (2013). Qualitative studies in information systems: a critical review and some guiding principles. MIS Quarterly, 37(4), iii-xviii.
Schuetz, S. W., Lowry, P. B., Pienta, D. A., & Thatcher, J. B. (2020). Effectiveness of abstract versus concrete fear appeals in Information security. Journal of Management Information Systems, 37(3), 723-757.
Sewell, G., & Wilkinson, B. (1992). Someone to watch over me: surveillance, discipline and the just-in-time labour process. Sociology, 26(2), 271-289.
Silverman, D. (2000). Doing qualitative research: a practical handbook. Sage Publications.
Siponen, M., Mahmood, M. A., & Pahnila, S. (2014). Employees’ adherence to information security policies: an exploratory field study. Information & Management, 51(2), 217-224.
Siponen, M., Rönkkö, M., Fufan, L., Haag, S., & Laatikainen, G. (2024). Protection Motivation Theory in information security behavior research: reconsidering the fundamentals. Communications of the Association for Information Systems, 53, 1136-1165.
Son, J.-Y. (2011). Out of fear or desire? Toward a better understanding of employees’ motivation to follow IS security policies. Information & Management, 48(7), 296–302.
Suchman, M. C. (1995). Managing legitimacy: strategic and institutional approaches. Academy of Management Review, 20(3), 571-610.
Sun, Y., Wang, N., Guo, X., & Peng, Z. (2013). Understanding the acceptance of mobile health services: a comparison and integration of alternative models. Journal of Electronic Commerce Research, 14(2), 183-200.
Tsai, H.-Y., Jiang, M., Alhabash, S., Larose, R., Rifon, N. J., & Cotton, S. R. (2016). Understanding online safety behaviors: a Protection Motivation Theory perspective. Computers & Security, 59, 138-150.
Tyler, T. R. (2002). Leadership and cooperation in groups. American Behavioral Scientist, 45(5), 769-782.
Van de Perre, S. (2014) Belastinggedrag en ‘tax culture’. Documentatieblad van het Ministerie van Financiën, 74(2), 23-65.
Vance, A., Eargle, D., Eggett, D., Straub, D. W., & Ouimet, K. (2022). Do security fear appeals work when they interrupt tasks? A multi-method examination of password strength. MIS Quarterly, 46(3), 1721-1738.
Vance, A., Siponen, M., & Pahnila, S. (2012). Motivating IS security compliance: insights from habit and Protection Motivation Theory. Information & Management, 49(3-4), 190-198.
Vieira da Cunha, J. (2013). A dramaturgical model of the production of performance data. MIS Quarterly, 37(3), 723-748.
Weber, R. (2003). Editor’s comments: still desperately seeking the IT artefact. MIS Quarterly, 27(2), iii–xi.
Whetten, D. A. (1989). What constitutes a theoretical contribution? Academy of Management Review, 14(4), 490-495.
Whetten, D. A .(2009). An examination of the interface between context and theory applied to the study of Chinese organizations. Management and Organization Review, 5(1), 29-55.
Willison, R. (2006). Understanding the perpetration of employee computer crime in the organisational context. Information and Organization, 16, 304-324.
Witte, K. (1992). Putting the fear back into fear appeals: the extended parallel process model. Communications Monographs, 59(4), 329-349.
Witte, K. (1994). Fear control and danger control: a test of the extended parallel process model. Communication Monographs, 61 (2), 113-134.
Woon, I. M. Y., Tan, G. W., & Low, R. T. (2005). A Protection Motivation Theory approach to home wireless security. In D. Avison, D. Galletta, & J. I. Degross (Eds.), Proceedings of the 26th International Conference on Information Systems (pp. 367-380).
Workman, M., Bommer, W. H., & Straub, D. (2008). Security lapses and the omission of information security measures: a threat control model and empirical test. Computers in Human Behavior, 24(6), 2799-2816.
Yoon, C., Hwang, J.-W., & Kim, R. (2012). Exploring factors that influence students’ behaviors in information security. Journal of Information Systems Education, 23(4), 407-415.
Yoon, C., & Kim, H. (2013). Understanding computer security behavioural intention in the workplace. An empirical study of Korean firms. Information Technology & People, 26(4), 401-419.
Youn, S. (2005). Teenagers’ perceptions of online privacy and coping behaviors: a risk-benefit appraisal approach, Journal of Broadcasting & Electronic Media, 49(1), 86-110.
Youn, S. (2009). Determinants of online privacy concern and its influence on privacy protection behaviors among young adolescents. The Journal of Consumer Affairs, 43(3), 389-418.
Zhang, L., & McDowell, W. C. (2009). Am I really at risk? Determinants of online users’ intentions to use strong passwords. Journal of Internet Commerce, 8(3-4), 180-197.
Downloads
Published
How to Cite
Issue
Section
License
The author bears the responsibility for checking whether material submitted is subject to copyright or ownership rights (e.g. figures, tables, photographs, illustrations, trade literature and data). The author will need to obtain permission to reproduce any such items, and include these permissions with their final submission.
It is our policy to ask all contributors to transfer for free the copyright in their contribution to the journal owner. There are two broad reasons for this:
- ownership of copyright by the journal owner facilitates international protection against infringement of copyright, libel or plagiarism;
- it also ensures that requests by third parties to reprint or reproduce a contribution, or part of it, in either print or electronic form, are handled efficiently in accordance with our general policy which encourages dissemination of knowledge within the framework of copyright.
In conformity with the French law, the author keeps the 'moral rights' related to the article:
- The 'authorship right': It is the author's right to have his name associated with each publication and exploitation of the article.
- The 'integrity right': It can be claimed by the author if he finds that during an exploitation, his work has been distorted (cutting, reassembly...).

