The Fog of Warnings: How Non-Security-Related Notifications Diminish the Efficacy of Security Warnings

dc.contributor.authorVance, Anthonyen
dc.contributor.authorEargle, Daveen
dc.contributor.authorKirwan, C. Brocken
dc.contributor.authorAnderson, Bonnie Brintonen
dc.contributor.authorJenkins, Jeffrey L.en
dc.date.accessioned2026-01-16T19:33:50Zen
dc.date.available2026-01-16T19:33:50Zen
dc.date.issued2025-12-01en
dc.description.abstractUsers’ disregard of security warnings is a critical problem in cybersecurity. This problem worsens when people confuse security warnings with common, non-security-related notifications, which they learn to routinely disregard. We investigate this problem through the neurobiological phenomenon of generalization of habituation, where habituation to one stimulus transfers to another stimulus that shares similar characteristics. Generalization of habituation suggests that because of habituation to frequent notifications, people may also be deeply habituated to security warnings they have never seen before, leading to warning disregard. Furthermore, because generalization of habituation occurs unconsciously at the neurobiological level, this may occur even though a person can consciously distinguish security warnings from notifications. We address this problem through three experiments—two in the field and one using functional magnetic resonance imaging. These experiments demonstrate how generalization of habituation occurs and can be mitigated by differentiating warnings from notifications in terms of their visual appearance or mode of interaction. These findings provide guidance to software developers for designing warnings that resist generalization of habituation and promote greater warning adherence.en
dc.description.versionPublished versionen
dc.format.extentPages 1357-1384en
dc.format.mimetypeapplication/pdfen
dc.identifier.doihttps://doi.org/10.25300/MISQ/2025/18531en
dc.identifier.eissn2162-9730en
dc.identifier.issn0276-7783en
dc.identifier.issue4en
dc.identifier.orcidVance, Anthony [0000-0002-4554-6176]en
dc.identifier.urihttps://hdl.handle.net/10919/140860en
dc.identifier.volume49en
dc.language.isoenen
dc.publisherAssociation for Information Systemsen
dc.rightsCreative Commons Attribution-NonCommercial-NoDerivatives 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/en
dc.subjectSecurity warningen
dc.subjecthabituationen
dc.subjectgeneralizationen
dc.subjectfMRIen
dc.subjectfield experimenten
dc.subjectNeuroISen
dc.titleThe Fog of Warnings: How Non-Security-Related Notifications Diminish the Efficacy of Security Warningsen
dc.title.serialMIS Quarterlyen
dc.typeArticle - Refereeden
dc.type.dcmitypeTexten
dc.type.otherJournal Articleen
pubs.organisational-groupVirginia Techen
pubs.organisational-groupVirginia Tech/Pamplin College of Businessen
pubs.organisational-groupVirginia Tech/Pamplin College of Business/Business Information Technologyen
pubs.organisational-groupVirginia Tech/All T&R Facultyen
pubs.organisational-groupVirginia Tech/Pamplin College of Business/PCOB T&R Facultyen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Vance et al. 2025.pdf
Size:
1.7 MB
Format:
Adobe Portable Document Format
Description:
Published version
License bundle
Now showing 1 - 1 of 1
Name:
license.txt
Size:
1.5 KB
Format:
Plain Text
Description: