Cybersecurity compliance remains a major challenge because employees’ daily decisions often determine whether security policies are effectively implemented. While organizations rely on technical safeguards, mandatory procedures, and awareness training, these approaches may increase cognitive burden and security fatigue, leading users to delay, ignore, or bypass recommended security practices. This conceptual paper proposes a behavioral nudging framework for cybersecurity compliance. Drawing on behavioral decision theory and the socio-technical perspective of information systems, it focuses on three psychological mechanisms: cognitive ease, digital trust, and security fatigue. The framework suggests that nudges such as visual framing, social proof, and secure default settings may enhance compliance by increasing cognitive ease and digital trust. However, security fatigue may weaken these effects by reducing users’ motivation to engage with security recommendations.
목차
Abstract Introduction Cognitive Ease as a Factor in Security Compliance Digital Trust: The Foundation of Willingness to Comply Security Fatigue: When Protection Becomes a Burden Social Engineering Attacks: Exploiting Psychological Vulnerabilities Organizational Factors and Security Culture Technological Solutions to Support Safe Behavior The Digital Divide Problem and Differentiated Training Concluding Remarks References