Asymmetric deterrence: strategic governance of organizational cybersecurity compliance and violation

Purpose Sanctions are a primary lever of cybersecurity governance. Traditional information systems deterrence models have assumed symmetrical effects – that reducing violations proportionally increases compliance. This study aims to challenge that assumption by theorizing deterrence as an asymmetric phenomenon rather than a binary mechanism. Design/methodology/approach We conducted a meta-analysis of 51 studies (N = 20,768) to examine the differential impact of sanctions across two behavioral trajectories: compliance intentions and violation intentions. We further investigate sanction celerity as a moderator of deterrence effects. Findings Results reveal a fundamental asymmetry in deterrence. While sanctions act as robust normative reinforcement mechanisms that significantly strengthen compliance, they exert no significant impact on the reduction of violation intentions. Moreover, sanction celerity is a critical moderator that amplifies the deterrent weight of both detection certainty and sanction severity, preventing temporal signal decay. Practical implications Managers should shift from volume-based punishment to agility-based governance. To foster compliance, sanctions should act as normative signals that reinforce organizational values, whereas to curb violations, managers must address situational strains (e.g. high workloads) that drive rule-breaking. Originality/value By demonstrating that compliance and violation are distinct domains, this study shows that the psychological mechanisms driving rule-following differ from those governing rule-breaking. The findings also underscore that celerity is a prerequisite for efficacy; without timely enforcement, sanctions lose their psychological salience and fail to influence decision-making.

Authors

Institutions

Publication Details

Journal
Organizational Cybersecurity Journal Practice Process and People
Published
2026-09-16
DOI
https://doi.org/10.1108/ocj-02-2026-0008
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Asymmetric deterrence: strategic governance of organizational cybersecurity compliance and violation

David Kocsis, Sandeep Suntwal, Sunitha Prabhu
Organizational Cybersecurity Journal Practice Process and People
Information and Cyber Security
article

Asymmetric deterrence: strategic governance of organizational cybersecurity compliance and violation

David Kocsis, Sandeep Suntwal, Sunitha Prabhu
article en

Abstract

Purpose Sanctions are a primary lever of cybersecurity governance. Traditional information systems deterrence models have assumed symmetrical effects – that reducing violations proportionally increases compliance. This study aims to challenge that assumption by theorizing deterrence as an asymmetric phenomenon rather than a binary mechanism. Design/methodology/approach We conducted a meta-analysis of 51 studies (N = 20,768) to examine the differential impact of sanctions across two behavioral trajectories: compliance intentions and violation intentions. We further investigate sanction celerity as a moderator of deterrence effects. Findings Results reveal a fundamental asymmetry in deterrence. While sanctions act as robust normative reinforcement mechanisms that significantly strengthen compliance, they exert no significant impact on the reduction of violation intentions. Moreover, sanction celerity is a critical moderator that amplifies the deterrent weight of both detection certainty and sanction severity, preventing temporal signal decay. Practical implications Managers should shift from volume-based punishment to agility-based governance. To foster compliance, sanctions should act as normative signals that reinforce organizational values, whereas to curb violations, managers must address situational strains (e.g. high workloads) that drive rule-breaking. Originality/value By demonstrating that compliance and violation are distinct domains, this study shows that the psychological mechanisms driving rule-following differ from those governing rule-breaking. The findings also underscore that celerity is a prerequisite for efficacy; without timely enforcement, sanctions lose their psychological salience and fail to influence decision-making.

Organizational Cybersecurity Journal Practice Process and People
Curtin University (AU), University of Colorado Colorado Springs (US)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.