Abstract
Compliance with the Information Security Policy (ISP) is frequently regarded as being primarily dependent on employee initiative, influenced by sanctions (“sticks”) and incentives (“carrots”). Nevertheless, outcomes are inconsistent because crucial dynamics, such as peer effects, legitimacy, workload shocks, and path dependence, are rarely incorporated into models. We propose a contingent theory to elucidate the circumstances under which a combination of rewards and sanctions results in sustainable, organization-wide adherence rather than transient compliance. Using agent-based modeling, we simulate various employees under different levels of monitoring and legitimacy to identify tipping points, stability, and limitations in the balance between carrots and sticks.
Recommended Citation
Sikolia, David, "BALANCING CARROTS AND STICKS: DEVELOPING A CONTINGENCY THEORY OF INFORMATION SECURITY POLICY COMPLIANCE THROUGH AGENT-BASED SIMULATION" (2026). SAIS 2026 Proceedings. 23.
https://aisel.aisnet.org/sais2026/23