Marcus Gerdin

dblp:352/8576 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0003-0658-4548ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 4 since 2021
YearPublicationVenuePosition
2026 You get the answers you ask for: Experimental evidence on the influence of inconsistent variable definitions on non-/compliance research findings
abstract
The research literature on employee non-/compliance with information security policies (ISPs) suffers from inconsistent findings. The aim of this paper is to investigate a promising, yet largely unexplored cause of these inconsistencies, namely, differences in how key variables have been conceptualized and operationalized into questionnaire measurement items across this literature. Specifically, by means of a survey experiment with 215 participants from a Swedish university, we formally tested whether alternative operationalizations of two key variables from Protection Motivation Theory—Perceived vulnerability and Perceived severity of a threat—lead to statistically significant differences in mean values across responder groups. Regarding the former variable, we found significant differences between operationalizations focusing on the probability and vulnerability of the threat. Regarding the latter, we found significant differences between whether the target of the consequences of the threat was unclear or clear to respondents, but not between clearly stated targets in terms of individuals and organizations . Overall, therefore, this study contributes to the field by highlighting the importance of conceptual clarity and precision in measuring key variables. It also highlights the potential of survey experiments—an underutilized method in ISP compliance research—for exploring the empirical impact of the different variable operationalizations which currently characterize much of the extant literature.
Marcus Gerdin, Martin Karlsson, Ella Kolkowska, Åke Grönlund
Comput. Secur.1
2025 Conceptual inconsistencies in variable definitions and measurement items within ISP non-/compliance research: A systematic literature review
abstract
The rich stream of research focusing on employee non-/compliance with information security policies (ISPs) suffers from inconsistent results. Attempts to explain such inconsistencies have included investigation of possible contextual moderating factors. Another promising, yet not systematically investigated, explanation concerns conceptual inconsistencies in variable definitions and in questionnaire measurement items. Based on a systematic literature review covering 36 ISP non-/compliance articles using Protection Motivation Theory (PMT) and/or Theory of Planned Behavior (TPB), we found four major types of conceptual inconsistencies and unclarities within and across studies; (i) inconsistencies in variable definitions; (ii) inconsistencies between variable measurement items; (iii) inconsistencies between variable definitions and measurement items; and (iv) unclearly/vaguely worded measurement items. The review contributes to the field by demonstrating that the inconsistent results in the field may not only be due to unknown contextual moderators, but also to conceptual incongruences within and across studies.
Marcus Gerdin, Åke Grönlund, Ella Kolkowska
Comput. Secur.1
2025 Validating and extending the unified model of information security policy compliance
abstract
Purpose The purpose of this study is to further validate and extend the unified model of information security policy compliance (UMISPC) developed by Moody et al. (2018). Design/methodology/approach To be able to compare the results of this study and those reported by Moody et al. (2018) (and followers), the same quantitative data collection method (questionnaire) and variable measurement instruments were used. Specifically, questionnaire data were collected from a department within a Swedish governmental organization comprising 150 employees. Of these, 90 answered the questionnaire which rendered a response rate of 60%. Following Moody et al. (2018), the collected data were analyzed by means of structural equation modeling. Findings This study generally provides empirical support for the original UMISPC as a large majority of the findings are in line with those reported by Moody et al. (2018). However, it also suggests important differences and boundary conditions. Originality/value This study extends the original study of Moody et al. (2018) and subsequent replication studies by testing it in a new national/organizational context. Based on their call for future research, it also develops and empirically tests the effects of a new, socially visible information system security violation scenario. Related to this, this study also revisits the role of the variable subjective norms for better understanding employee non-/compliance to information security policies by suggesting that their effects may be indirect (i.e. running through other variables in the UMISPC) rather than direct.
Marcus Gerdin
Inf. Comput. Secur.1
2024 What goes around comes around: an in-depth analysis of how respondents interpret ISP non-/compliance questionnaire items
abstract
Purpose Research on employee non-/compliance to information security policies suffers from inconsistent results and there is an ongoing discussion about the dominating survey research methodology and its potential effect on these results. This study aims to add to this discussion by investigating discrepancies between what the authors claim to measure (theoretical properties of variables) and what they actually measure (respondents’ interpretations of the operationalized variables). This study asks: How well do respondents’ interpretations of variables correspond to their theoretical definitions? What are the characteristics of any discrepancies between variable definitions and respondent interpretations? Design/methodology/approach This study is based on in-depth interviews with 17 respondents from the Swedish public sector to understand how they interpret questionnaire measurement items operationalizing the variables Perceived Severity from Protection Motivation Theory and Attitude from Theory of Planned Behavior. Findings The authors found that respondents’ interpretations in many cases differ substantially from the theoretical definitions. Overall, the authors found four principal ways in which respondents interpreted measurement items – referred to as property contextualization, extension, alteration and oscillation – each implying more or less (dis)alignment with the intended theoretical properties of the two variables examined. Originality/value The qualitative method used proved vital to better understand respondents’ interpretations which, in turn, is key for improving self-reporting measurement instruments. To the best of the authors’ knowledge, this study is a first step toward understanding how precise and uniform definitions of variables’ theoretical properties can be operationalized into effective measurement items.
Marcus Gerdin, Ella Kolkowska, Åke Grönlund
Inf. Comput. Secur.1