Security on Autopilot: Why Current Security Theories Hijack our Thinking and Lead Us Astray

Published: 25 April 2018


Most current information systems security theories assume a rational actor making deliberate decisions, yet recent research in psychology suggests that such deliberate thinking is not as common as we would expect. Much of human behavior is controlled by nonconscious automatic cognition (called System 1 cognition). The deliberate rational cognition of System 2 is triggered when System 1 detects something that is not normal; otherwise we often operate on autopilot. When we do engage System 2 cognition, it is influenced by the System 1 cognition that preceded it. In this paper we present an alternative theoretical approach to information security that is based on the nonconscious automatic cognition of System 1. In a System 1 world, cognition is a sub-second process of pattern-matching a stimulus to an existing person-context heuristic. These person-context heuristics are influenced by personality characteristics and a lifetime of experiences in the context. Thus System 1 theories are closely tied to individuals and the specific security context of interest. Methods to improve security compliance take on a very new form; the traditional approaches to security education and training that provide guidelines and ways to think about security have no effect when behavior is controlled by System 1, because System 1 cognition is instant pattern matching not deliberative. Thus in a System 1 world, we improve security by changing the heuristics used by System 1's pattern matching and/or by changing what System 1 sees as "normal" so that it triggers the deliberate cognition of System 2. In this article, we examine System 1 and System 2 cognition, while calling for increased research to develop theories of System 1 cognition in the cybersecurity literature.


  • (2024)Optimizing the Service Efficacy of Crowd Ratings in Curbing Fake News Dissemination on Social MediaInternational Journal of Crowd Science10.26599/IJCS.2024.91000208:3(110-121)Online publication date: Aug-2024
  • (2024)Virtual lab coats: The effects of verified source information on social media post credibilityPLOS ONE10.1371/journal.pone.030232319:5(e0302323)Online publication date: 29-May-2024
  • (2024)The Effect of Herd Behavior on Consumer Intention in Live Streaming E-Commerce: The Moderating Role of InteractionInternational Journal of Human–Computer Interaction10.1080/10447318.2024.2364464(1-14)Online publication date: 17-Jun-2024
Published In

ACM SIGMIS Database: the DATABASE for Advances in Information Systems  Volume 49, Issue SI
April 2018
120 pages
Publication History

Published: 25 April 2018
Published in SIGMIS Volume 49, Issue SI

Author Tags

  1. cybersecurity
  2. dual process cognition
  3. information security
  4. system 1 cognition
  5. system 2 cognition
  6. theory


  • (2024)Optimizing the Service Efficacy of Crowd Ratings in Curbing Fake News Dissemination on Social MediaInternational Journal of Crowd Science10.26599/IJCS.2024.91000208:3(110-121)Online publication date: Aug-2024
  • (2024)Virtual lab coats: The effects of verified source information on social media post credibilityPLOS ONE10.1371/journal.pone.030232319:5(e0302323)Online publication date: 29-May-2024
  • (2024)The Effect of Herd Behavior on Consumer Intention in Live Streaming E-Commerce: The Moderating Role of InteractionInternational Journal of Human–Computer Interaction10.1080/10447318.2024.2364464(1-14)Online publication date: 17-Jun-2024
  • (2024)Dual Routes of Training on Information Security Policy ComplianceJournal of Computer Information Systems10.1080/08874417.2023.2300637(1-17)Online publication date: 5-Jan-2024
  • (2024)Cutting corners as a coping strategy in information technology use: Unraveling the mind's dilemmaInformation & Management10.1016/j.im.2024.10405761:8(104057)Online publication date: Dec-2024
  • (2024)Fostering information security compliance as organizational citizenship behaviorInformation & Management10.1016/j.im.2024.10396861:5(103968)Online publication date: Jul-2024
  • (2024)Data avatars: A theory-guided design and assessment for multidimensional data visualizationInformation & Management10.1016/j.im.2023.10391161:2(103911)Online publication date: Mar-2024
  • (2024)Fortifying healthcare: An action research approach to developing an effective SETA programComputers & Security10.1016/j.cose.2023.103655138(103655)Online publication date: Mar-2024
  • (2024)A Novel DNN Object Contour Attack on Image RecognitionAttacks, Defenses and Testing for Deep Learning10.1007/978-981-97-0425-5_4(55-74)Online publication date: 4-Jun-2024
  • (2023)Behavioural Psychology Towards Artificial Intelligence in CybersecurityExploring Cyber Criminals and Data Privacy Measures10.4018/978-1-6684-8422-7.ch002(19-39)Online publication date: 30-Jun-2023
