Asymmetric deterrence: strategic governance of organizational cybersecurity compliance and violation
Purpose Sanctions are a primary lever of cybersecurity governance. Traditional information systems deterrence models have assumed symmetrical effects – that reducing violations proportionally increases compliance. This study aims to challenge that assumption by theorizing deterrence as an asymmetric phenomenon rather than a binary mechanism. Design/methodology/approach We conducted a meta-analysis of 51 studies (N = 20,768) to examine the differential impact of sanctions across two behavioral trajectories: compliance intentions and violation intentions. We further investigate sanction celerity as a moderator of deterrence effects. Findings Results reveal a fundamental asymmetry in deterrence. While sanctions act as robust normative reinforcement mechanisms that significantly strengthen compliance, they exert no significant impact on the reduction of violation intentions. Moreover, sanction celerity is a critical moderator that amplifies the deterrent weight of both detection certainty and sanction severity, preventing temporal signal decay. Practical implications Managers should shift from volume-based punishment to agility-based governance. To foster compliance, sanctions should act as normative signals that reinforce organizational values, whereas to curb violations, managers must address situational strains (e.g. high workloads) that drive rule-breaking. Originality/value By demonstrating that compliance and violation are distinct domains, this study shows that the psychological mechanisms driving rule-following differ from those governing rule-breaking. The findings also underscore that celerity is a prerequisite for efficacy; without timely enforcement, sanctions lose their psychological salience and fail to influence decision-making.
Authors
- David Kocsis (ORCID: https://orcid.org/0000-0003-3922-1903)
- Sandeep Suntwal (ORCID: https://orcid.org/0000-0002-7746-7114)
- Sunitha Prabhu (ORCID: https://orcid.org/0000-0002-8743-5984)
Institutions
- Curtin University (AU)
- University of Colorado Colorado Springs (US)
Publication Details
- Journal
- Organizational Cybersecurity Journal Practice Process and People
- Published
- 2026-09-16
- DOI
- https://doi.org/10.1108/ocj-02-2026-0008
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00