{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T04:49:09Z","timestamp":1784090949518,"version":"3.55.0"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2019,12,11]],"date-time":"2019-12-11T00:00:00Z","timestamp":1576022400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2019,12,11]],"date-time":"2019-12-11T00:00:00Z","timestamp":1576022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Inf Syst Front"],"published-print":{"date-parts":[[2021,4]]},"DOI":"10.1007\/s10796-019-09977-z","type":"journal-article","created":{"date-parts":[[2019,12,11]],"date-time":"2019-12-11T03:05:52Z","timestamp":1576033552000},"page":"361-373","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":70,"title":["The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence"],"prefix":"10.1007","volume":"23","author":[{"given":"Eunkyung","family":"Kweon","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hansol","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sangmi","family":"Chai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kyeongwon","family":"Yoo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,12,11]]},"reference":[{"key":"9977_CR1","doi-asserted-by":"crossref","unstructured":"Amankwa, E., Loock, M., and Kritzinger, E. 2014. \u201cA Conceptual Analysis of Information Security Education, Information Security Training and Information Security Awareness Definitions,\u201d in Internet Technology and Secured Transactions (ICITST), 2014 9th International Conference, pp. 248\u2013252.","DOI":"10.1109\/ICITST.2014.7038814"},{"issue":"4","key":"9977_CR2","doi-asserted-by":"crossref","first-page":"411","DOI":"10.1111\/j.1468-232X.1994.tb00349.x","volume":"33","author":"AP Bartel","year":"1994","unstructured":"Bartel, A. P. (1994). Productivity gains from the implementation of employee training programs. Industrial relations: a journal of economy and society, 33(4), 411\u2013425.","journal-title":"Industrial relations: a journal of economy and society"},{"key":"9977_CR3","doi-asserted-by":"crossref","unstructured":"Blundell, R., Griffith, R., & Van Reenen, J. (1995). Dynamic count data models of technological innovation. The Economic Journal, 333\u2013344.","DOI":"10.2307\/2235494"},{"issue":"3","key":"9977_CR4","doi-asserted-by":"publisher","first-page":"523","DOI":"10.2307\/25750690","volume":"34","author":"B Bulgurcu","year":"2010","unstructured":"Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523\u2013548.","journal-title":"MIS Quarterly"},{"issue":"3","key":"9977_CR5","doi-asserted-by":"publisher","first-page":"509","DOI":"10.1007\/s10796-015-9608-8","volume":"19","author":"AJ Burns","year":"2017","unstructured":"Burns, A. J., Posey, C., Courtney, J. F., Roberts, T. L., & Nanayakkara, P. (2017). Organizational information security as a complex adaptive system: Insights from three agent-based models. Information Systems Frontiers, 19(3), 509\u2013524.","journal-title":"Information Systems Frontiers"},{"issue":"3","key":"9977_CR6","doi-asserted-by":"publisher","first-page":"347","DOI":"10.1016\/0304-4076(90)90014-K","volume":"46","author":"AC Cameron","year":"1990","unstructured":"Cameron, A. C., & Trivedi, P. K. (1990). Regression-based tests for Overdispersion in the Poisson model. Journal of Econometrics, 46(3), 347\u2013364.","journal-title":"Journal of Econometrics"},{"issue":"4","key":"9977_CR7","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1016\/j.dss.2010.08.017","volume":"50","author":"S Chai","year":"2011","unstructured":"Chai, S., Kim, M., & Rao, H. R. (2011). Firms' information security investment decisions: Stock market evidence of investors' behavior. Decision Support Systems, 50(4), 651\u2013661.","journal-title":"Decision Support Systems"},{"issue":"5","key":"9977_CR8","doi-asserted-by":"publisher","first-page":"484","DOI":"10.1108\/09685220810920558","volume":"16","author":"N Choi","year":"2008","unstructured":"Choi, N., Kim, D., Goo, J., & Whitmore, A. (2008). Knowing is doing: An empirical validation of the relationship between managerial information security awareness and action. Information Management & Computer Security, 16(5), 484\u2013501.","journal-title":"Information Management & Computer Security"},{"issue":"4","key":"9977_CR9","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1002\/hrm.20082","volume":"44","author":"FL Cooke","year":"2005","unstructured":"Cooke, F. L., Shen, J., & McBride, A. (2005). Outsourcing HR as a competitive strategy? A literature review and an assessment of implications. Human Resource Management, 44(4), 413\u2013432.","journal-title":"Human Resource Management"},{"key":"9977_CR10","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.cose.2012.09.010","volume":"32","author":"RE Crossler","year":"2013","unstructured":"Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M., & Baskerville, R. (2013). Future directions for behavioral information security research. Computers & Security, 32, 90\u2013101.","journal-title":"Computers & Security"},{"issue":"1","key":"9977_CR11","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1287\/isre.1070.0160","volume":"20","author":"J D\u2019Arcy","year":"2009","unstructured":"D\u2019Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79\u201398.","journal-title":"Information Systems Research"},{"issue":"4","key":"9977_CR12","doi-asserted-by":"publisher","first-page":"223","DOI":"10.1016\/j.istr.2010.05.002","volume":"14","author":"M Emina\u011fao\u011flu","year":"2009","unstructured":"Emina\u011fao\u011flu, M., U\u00e7ar, E., & Eren, \u015e. (2009). The positive outcomes of information security awareness training in companies\u2014A case study. Information Security Technical Report, 14(4), 223\u2013229.","journal-title":"Information Security Technical Report"},{"issue":"4","key":"9977_CR13","doi-asserted-by":"publisher","first-page":"763","DOI":"10.1177\/014920630002600408","volume":"26","author":"KM Gilley","year":"2000","unstructured":"Gilley, K. M., & Rasheed, A. (2000). Making more by doing less: An analysis of outsourcing and its effects on firm performance. Journal of Management, 26(4), 763\u2013790.","journal-title":"Journal of Management"},{"issue":"3","key":"9977_CR14","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1016\/S0148-2963(02)00304-1","volume":"57","author":"KM Gilley","year":"2004","unstructured":"Gilley, K. M., Greer, C. R., & Rasheed, A. A. (2004). Human resource outsourcing and organizational performance in manufacturing firms. Journal of Business Research, 57(3), 232\u2013240.","journal-title":"Journal of Business Research"},{"issue":"14","key":"9977_CR15","doi-asserted-by":"publisher","first-page":"2892","DOI":"10.1080\/09585192.2011.606113","volume":"22","author":"N Glaveli","year":"2011","unstructured":"Glaveli, N., & Karassavidou, E. (2011). Exploring a possible route through which training affects organizational performance: The case of a Greek bank. The International Journal of Human Resource Management, 22(14), 2892\u20132923.","journal-title":"The International Journal of Human Resource Management"},{"issue":"7","key":"9977_CR16","doi-asserted-by":"publisher","first-page":"821","DOI":"10.1016\/j.im.2006.07.002","volume":"43","author":"R Gonzalez","year":"2006","unstructured":"Gonzalez, R., Gasco, J., & Llopis, J. (2006). Information systems outsourcing: A literature analysis. Information & Management, 43(7), 821\u2013834.","journal-title":"Information & Management"},{"issue":"6","key":"9977_CR17","doi-asserted-by":"publisher","first-page":"1135","DOI":"10.1108\/ITP-10-2017-0322","volume":"31","author":"T Herath","year":"2018","unstructured":"Herath, T., Yim, M. S., D\u2019Arcy, J., Nam, K., & Rao, H. R. (2018). Examining employee security violations: Moral disengagement and its environmental influences. Information Technology & People, 31(6), 1135\u20131162.","journal-title":"Information Technology & People"},{"issue":"3","key":"9977_CR18","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1111\/j.1468-232X.1990.tb00761.x","volume":"29","author":"HJ Holzer","year":"1990","unstructured":"Holzer, H. J. (1990). The determinants of employee productivity and earnings. Industrial Relations: A Journal of Economy and Society, 29(3), 403\u2013422.","journal-title":"Industrial Relations: A Journal of Economy and Society"},{"issue":"6","key":"9977_CR19","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/S1353-4858(02)06011-7","volume":"2002","author":"K H\u00f6ne","year":"2002","unstructured":"H\u00f6ne, K., & Eloff, J. H. P. (2002). What makes an effective information security policy? Network Security, 2002(6), 14\u201316.","journal-title":"Network Security"},{"issue":"4","key":"9977_CR20","doi-asserted-by":"publisher","first-page":"615","DOI":"10.1111\/j.1540-5915.2012.00361.x","volume":"43","author":"Q Hu","year":"2012","unstructured":"Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615\u2013660.","journal-title":"Decision Sciences"},{"key":"9977_CR21","unstructured":"Huntley, H., Ng, F., Young, A., Tramacere, G., Blackmore, D., Petri, G., Nag, S., and Ackerman, D. E. 2016. \u201cForecast overview: IT outsourcing, 2016 update,\u201d Gartner. https:\/\/www.gartner.com\/doc\/3450217\/forecast-overview-it-outsourcing-."},{"key":"9977_CR22","unstructured":"Intermedia, 2015. \u201cIntermedia\u2019s 2015 Insider Risk Report.\u201d https:\/\/kapost-files-prod.s3.amazonaws.com\/published\/562550633289114280000062\/intermedias-2015-insider-risk-report.pdf?kui=OI7JDeo39LQZYGu7fhaYvg."},{"issue":"12","key":"9977_CR23","doi-asserted-by":"publisher","first-page":"1280","DOI":"10.1108\/01443570610710551","volume":"26","author":"B Jiang","year":"2006","unstructured":"Jiang, B., Frazier, G. V., & Prater, E. L. (2006). Outsourcing effects on firms\u2019 operational performance: An empirical study. International Journal of Operations & Production Management, 26(12), 1280\u20131300.","journal-title":"International Journal of Operations & Production Management"},{"issue":"3","key":"9977_CR24","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1109\/MSP.2007.59","volume":"5","author":"ME Johnson","year":"2007","unstructured":"Johnson, M. E., & Goetz, E. (2007). Embedding information security into the organization. IEEE Security & Privacy, 5(3), 16\u201324.","journal-title":"IEEE Security & Privacy"},{"key":"9977_CR25","doi-asserted-by":"crossref","unstructured":"Khan, B., Alghathbar, K. S., Nabi, S. I., and Khan, M. K. 2011. \u201cEffectiveness of Information Security Awareness Methods Based on Psychological Theories,\u201d African Journal of Business Management (5:26), p. 10862.","DOI":"10.5897\/AJBM11.067"},{"issue":"1","key":"9977_CR26","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1111\/j.1744-6570.1999.tb01816.x","volume":"52","author":"BS Klaas","year":"1999","unstructured":"Klaas, B. S., McClendon, J., & Gainey, T. W. (1999). HR outsourcing and its impact: The role of transaction costs. Personnel Psychology, 52(1), 113\u2013136.","journal-title":"Personnel Psychology"},{"issue":"1","key":"9977_CR27","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1108\/09685220610648355","volume":"14","author":"KJ Knapp","year":"2006","unstructured":"Knapp, K. J., Marshall, T. E., Kelly Rainer, R., & Nelson Ford, F. (2006). Information security: Management\u2019s effect on culture and policy. Information Management & Computer Security, 14(1), 24\u201336.","journal-title":"Information Management & Computer Security"},{"key":"9977_CR28","volume-title":"Survey on information security (business)","author":"Korea Information & Security Agency","year":"2014","unstructured":"Korea Information & Security Agency. (2014). Survey on information security (business). Seoul: Ministry of Science, ICT, and Future Planning."},{"issue":"4","key":"9977_CR29","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1016\/j.cose.2006.02.008","volume":"25","author":"HA Kruger","year":"2006","unstructured":"Kruger, H. A., & Kearney, W. D. (2006). A prototype for assessing information security awareness. Computers & Security, 25(4), 289\u2013296.","journal-title":"Computers & Security"},{"issue":"8","key":"9977_CR30","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1016\/0167-4048(96)81709-3","volume":"14","author":"KR Lindup","year":"1995","unstructured":"Lindup, K. R. (1995). A new model for information security policies. Computers & Security, 14(8), 691\u2013695.","journal-title":"Computers & Security"},{"issue":"1","key":"9977_CR31","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1080\/07421222.1992.11517945","volume":"9","author":"L Loh","year":"1992","unstructured":"Loh, L., & Venkatraman, N. (1992). Determinants of information technology outsourcing: A cross-sectional analysis. Journal of Management Information Systems, 9(1), 7\u201324.","journal-title":"Journal of Management Information Systems"},{"key":"9977_CR32","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1016\/j.chb.2016.11.065","volume":"69","author":"A McCormac","year":"2017","unstructured":"McCormac, A., Zwaans, T., Parsons, K., Calic, D., Butavicius, M., & Pattinson, M. (2017). Individual differences and information security awareness. Computers in Human Behavior, 69, 151\u2013156.","journal-title":"Computers in Human Behavior"},{"key":"9977_CR33","unstructured":"Miranda, M. J. (2018). Enhancing cybersecurity awareness training: a comprehensive phishing exercise approach. International Management Review, 14(2), 5-10."},{"key":"9977_CR34","unstructured":"Morgan, S. (2016). One million cybersecurity job openings in 2016. Forbes, January, 2."},{"key":"9977_CR35","unstructured":"NIST, S. 1998. 800\u201316, National Institute of Standards and Technology (NIST).\u201c Information Technology Training Requirements: A Role-and Performance-Based Model\u201d (NIST Special Publication 800\u201316)."},{"issue":"1","key":"9977_CR36","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1023\/A:1007521427059","volume":"16","author":"DW Osgood","year":"2000","unstructured":"Osgood, D. W. (2000). Poisson-based regression analysis of aggregate crime rates. Journal of Quantitative Criminology, 16(1), 21\u201343.","journal-title":"Journal of Quantitative Criminology"},{"key":"9977_CR37","doi-asserted-by":"crossref","unstructured":"Pahnila, S., Siponen, M., and Mahmood, A. 2007. \u201cEmployees\u2019 Behavior towards IS Security Policy Compliance,\u201d in System Sciences, 2007. HICSS 2007. 40th Annual Hawaii International Conference on (pp. 156b-156b). IEEE.","DOI":"10.1109\/HICSS.2007.206"},{"key":"9977_CR38","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/j.cose.2013.12.003","volume":"42","author":"K Parsons","year":"2014","unstructured":"Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., & Jerram, C. (2014). Determining employee awareness using the human aspects of information security questionnaire (HAIS-Q). Computers & Security, 42, 165\u2013176.","journal-title":"Computers & Security"},{"key":"9977_CR39","volume-title":"Top 10 threats to SME data security","author":"S Pinzon","year":"2008","unstructured":"Pinzon, S. 2008. Top 10 threats to SME data security. WatchGuard Technologies."},{"key":"9977_CR40","unstructured":"PricewaterhouseCoopers, 2015. \u201c2015 Information Security Breaches Survey,\u201d Technical Report. https:\/\/www.pwc.co.uk\/assets\/pdf\/2015-isbs-technical-report-blue-digital.pdf."},{"key":"9977_CR41","doi-asserted-by":"crossref","unstructured":"Puhakainen, P., & Siponen, M. (2010). Improving employees\u2019 compliance through information systems security training: An action research study. MIS Quarterly, pp., 757\u2013778.","DOI":"10.2307\/25750704"},{"issue":"11","key":"9977_CR42","doi-asserted-by":"publisher","first-page":"1033","DOI":"10.1002\/smj.559","volume":"27","author":"FT Rothaermel","year":"2006","unstructured":"Rothaermel, F. T., Hitt, M. A., & Jobe, L. A. (2006). Balancing vertical integration and strategic outsourcing: Effects on product portfolio, product success, and firm performance. Strategic Management Journal, 27(11), 1033\u20131056.","journal-title":"Strategic Management Journal"},{"key":"9977_CR43","unstructured":"Rowe, B. R., and Gallaher, M. P. 2006. \u201cPrivate Sector Cyber Security Investment Strategies: An Empirical Analysis,\u201d in The Fifth Workshop on the Economics of Information Security (WEIS06)."},{"key":"9977_CR44","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1016\/j.cose.2015.05.012","volume":"53","author":"NS Safa","year":"2015","unstructured":"Safa, N. S., Sookhak, M., Von Solms, R., Furnell, S., Ghani, N. A., & Herawan, T. (2015). Information security conscious care behaviour formation in organizations. Computers & Security, 53, 65\u201378.","journal-title":"Computers & Security"},{"key":"9977_CR45","doi-asserted-by":"crossref","unstructured":"Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS quarterly, pp., 487\u2013502.","DOI":"10.2307\/25750688"},{"issue":"2","key":"9977_CR46","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1016\/j.im.2013.08.006","volume":"51","author":"M Siponen","year":"2014","unstructured":"Siponen, M., Mahmood, M. A., & Pahnila, S. (2014). Employees\u2019 adherence to information security policies: An exploratory field study. Information & Management, 51(2), 217\u2013224.","journal-title":"Information & Management"},{"issue":"2","key":"9977_CR47","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1108\/ICS-04-2014-0025","volume":"23","author":"T Sommestad","year":"2015","unstructured":"Sommestad, T., Karlz\u00e9n, H., & Hallberg, J. (2015). The sufficiency of the theory of planned behavior for explaining information security policy compliance. Information & Computer Security, 23(2), 200\u2013217.","journal-title":"Information & Computer Security"},{"issue":"3","key":"9977_CR48","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1287\/isre.1.3.255","volume":"1","author":"DW Straub Jr","year":"1990","unstructured":"Straub Jr., D. W. (1990). Effective IS security: An empirical study. Information Systems Research, 1(3), 255\u2013276.","journal-title":"Information Systems Research"},{"issue":"4","key":"9977_CR49","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1108\/09685229810227649","volume":"6","author":"ME Thomson","year":"1998","unstructured":"Thomson, M. E., & von Solms, R. (1998). Information security awareness: Educating your users effectively. Information Management & Computer Security, 6(4), 167\u2013173.","journal-title":"Information Management & Computer Security"},{"issue":"8","key":"9977_CR50","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1016\/j.im.2009.08.006","volume":"46","author":"MF Thouin","year":"2009","unstructured":"Thouin, M. F., Hoffman, J. J., & Ford, E. W. (2009). IT outsourcing and firm-level performance: A transaction cost perspective. Information & Management, 46(8), 463\u2013469.","journal-title":"Information & Management"},{"key":"9977_CR51","doi-asserted-by":"crossref","unstructured":"Trang, S., & Brendel, B. (2019). A meta-analysis of deterrence theory in information security policy compliance research. Information Systems Frontiers, pp., 1\u201320.","DOI":"10.1007\/s10796-019-09956-4"},{"key":"9977_CR52","doi-asserted-by":"crossref","unstructured":"Vroom, C., and von Solms, R. 2002. \u201cA Practical Approach to Information Security Awareness in the Organization,\u201d in Security in the Information Society, Springer US, pp. 19\u201337.","DOI":"10.1007\/978-0-387-35586-3_2"},{"key":"9977_CR53","first-page":"50","volume":"800","author":"M Wilson","year":"2003","unstructured":"Wilson, M., & Hash, J. (2003). Building an information technology security awareness and training program. NIST Special Publication, 800, 50.","journal-title":"NIST Special Publication"},{"key":"9977_CR54","doi-asserted-by":"crossref","unstructured":"Yang, C. G., & Lee, H. J. 2016. A study on the antecedents of healthcare information protection intention. Information systems Frontiers, (18;2), pp.253-263.","DOI":"10.1007\/s10796-015-9594-x"}],"container-title":["Information Systems Frontiers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-019-09977-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10796-019-09977-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-019-09977-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,8]],"date-time":"2022-10-08T04:38:40Z","timestamp":1665203920000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10796-019-09977-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,11]]},"references-count":54,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,4]]}},"alternative-id":["9977"],"URL":"https:\/\/doi.org\/10.1007\/s10796-019-09977-z","relation":{},"ISSN":["1387-3326","1572-9419"],"issn-type":[{"value":"1387-3326","type":"print"},{"value":"1572-9419","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,12,11]]},"assertion":[{"value":"11 December 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}