Aktuelles
Neue Veröffentlichung in der Zeitschrift Information Systems Research
Lins, S., Greulich, M., Pienta, D., Thatcher, J. B., Sunyaev, A. (2026). The Impact of Threatening Cybersecurity Situations on Employees: A Conceptualization of Security Perplexity. Information Systems Research. https://doi.org/10.1287/isre.2023.0626
Abstract
As the cybersecurity landscape shifts toward increasingly sophisticated, artificial intelligence–enabled, and unpredictable threats, employees are increasingly targeted as the primary entry points for organizational breaches. Modern incidents, such as zero-day exploits and ransomware attacks, often present employees with situations that are technically complex, unexpected, and ambiguous. In response to these developments, we investigate security perplexity, a tense cognitive state experienced by employees in threatening cybersecurity situations that arises from a conflict between perceived pressure to act and a simultaneous state of confusion and uncertainty about how to do so. Using qualitative surveys that provided accounts of 430 perplexing cybersecurity situations confronted by employees, multiple scenario-based surveys, and an online experiment, we conceptualize security perplexity, develop a scale to measure it, and examine its impact on employees’ coping processes. Drawing on coping theory and the extended parallel process model, we conceptualize security perplexity as a multidimensional construct characterized by the cognitive tension between three interdependent yet conflicting dimensions: confusion, response uncertainty, and pressure to act. Our findings suggest that employees who face perplexing situations engage in either adaptive or maladaptive coping behaviors and do so depending on a tipping point determined by their perceptions of the threat and their coping efficacy. This paper contributes to information security research by providing a rigorous conceptualization of security perplexity. This construct represents a novel lens for theorizing about employees’ responses to the increasingly complex and high-stakes environment of cybersecurity threats.