John D'Arcy

dblp:39/962 · DBLP profile ↗
← Back
8ranked-venue papers in the field
2as first author
2since 2021 · last 2025
0000-0003-0286-5772ORCID · reported

Domains — venue-derived; a paper can count in several

Knowledge Engineering, Semantic Web & Information Systems · 8 (2 first)
YearPublicationVenuePosition
2025 An empirical comparison of prominent theories of social media discontinuance: Toward a synthesized model
Isaac Vaghefi, Ofir Turel, John D'Arcy
Inf. Manag.3
2021 Cybersecurity Awareness and Skills of Senior Citizens: A Motivation Perspective
abstract
Senior citizens are one of the most vulnerable groups of Internet users who are prone to cyberattacks. Thus, assessing senior citizens’ motivation to acquire cybersecurity skills is critical to help them understand the risks of cyber-attacks. This study investigated a set of constructs that contribute to senior citizens’ motivation to acquire cybersecurity skills and assessed the actual cybersecurity skill level of these individuals. Utilizing a Web-based survey and a hands-on scenario-based app called MyCyberSkills™, this research study measured the constructs of interest before and after cybersecurity awareness training. Study participants were 254 senior citizens with a mean age of approximately 70 years. The results indicated that the cybersecurity awareness training was effective in increasing the cybersecurity skill level of the senior citizens and empowered them with small but significant improvements in the requisite skills to take mitigating actions against cyberattacks. Theoretical and practical implications are discussed.
Carlene Blackwood-Brown, Yair Levy, John D'Arcy
J. Comput. Inf. Syst.3
2019 Predicting employee information security policy compliance on a daily basis: The interplay of security-related stress, emotions, and neutralization
John D'Arcy, Pei-Lee Teh
Inf. Manag.1
2017 Organizational information security policies: a review and research framework
abstract
A major stream of research within the field of information systems security examines the use of organizational policies that specify how users of information and technology resources should behave in order to prevent, detect, and respond to security incidents. However, this growing (and at times, conflicting) body of research has made it challenging for researchers and practitioners to comprehend the current state of knowledge on the formation, implementation, and effectiveness of security policies in organizations. Accordingly, the purpose of this paper is to synthesize what we know and what remains to be learned about organizational information security policies, with an eye toward a holistic understanding of this research stream and the identification of promising paths for future study. We review 114 influential security policy-related journal articles and identify five core relationships examined in the literature. Based on these relationships, we outline a research framework that synthesizes the construct linkages within the current literature. Building on our analysis of these results, we identify a series of gaps and draw on additional theoretical perspectives to propose a revised framework that can be used as a basis for future research.
W. Alec Cram, Jeffrey Proudfoot, John D'Arcy
Eur. J. Inf. Syst.3
2016 "Cargo Cult" science in traditional organization and information systems survey research: A case for using nontraditional methods of data collection, including Mechanical Turk and online panels
Paul Benjamin Lowry, John D'Arcy, Bryan I. Hammer, Greg D. Moody
J. Strateg. Inf. Syst.2
2015 What Drives Information Security Policy Violations among Banking Employees?: Insights from Neutralization and Social Exchange Theory
abstract
Employees' information security policy (ISP) violations are a major problem that plagues organizations worldwide, particularly in the banking/financial sector. Research shows that employees use neutralization techniques to rationalize their ISP violating behaviors; it is therefore important to understand what leads to and influences these neutralization techniques. The authors' study draws upon social exchange theory to develop a set of factors that drive employees' neutralization of ISP violations. The model specifies previously untested relationships between job satisfaction, organizational commitment, role conflict, role ambiguity, and neutralization techniques. Using a sample of Malaysian banking employees, the authors found a positive relationship between role conflict and neutralization of ISP violations, whereas organizational commitment was negatively related to neutralization in this context. The authors' findings offer fresh insights for scholars and practitioners in dealing with the problem of employees' intentional ISP violations while extending the reach of neutralization theory beyond North American and European cultures.
Pei-Lee Teh, Pervaiz K. Ahmed 0001, John D'Arcy
J. Glob. Inf. Manag.3
2012 Applying an extended model of deterrence across cultures: An investigation of information systems misuse in the U.S. and South Korea
Anat Hovav, John D'Arcy
Inf. Manag.2
2011 A review and analysis of deterrence theory in the IS security literature: making sense of the disparate findings
abstract
Deterrence theory is one of the most widely applied theories in information systems (IS) security research, particularly within behavioral IS security studies. Based on the rational choice view of human behavior, the theory predicts that illicit behavior can be controlled by the threat of sanctions that are certain, severe, and swift. IS scholars have used deterrence theory to predict user behaviors that are either supportive or disruptive of IS security, and other IS security-related outcome variables. A review of this literature suggests an uneven and often contradictory picture regarding the influence of sanctions and deterrence theory in general in the IS security context. In this paper, we set out to make sense of the discrepant findings in the IS deterrence literature by drawing upon the more mature body of deterrence literature that spans multiple disciplines. In doing so, we speculate that a set of contingency variables and methodological and theoretical issues can shed light on the inconsistent findings and inform future research in this area. The review and analysis presented in this paper facilitates a deeper understanding of deterrence theory in the IS security domain, which can assist in cumulative theory-building efforts and advance security management strategies rooted in deterrence principles.
John D'Arcy, Tejaswini C. Herath
Eur. J. Inf. Syst.1