Investigating Information Security Apathy: A Crucial Study on Data Security

Researchers at Indiana University have conducted an in-depth study to understand the concept of information security apathy, which refers to the extent to which individuals lack interest in information security. The study, titled "Who Cares If We Get Hacked? The Development and Testing of a Measure of Information Security Apathy," aimed to develop a scale to measure information security apathy and assess its content, validity, and predictive power. The study's findings suggest that security apathy has a significant impact on security decisions, with a medium to large effect size.

Key Takeaways:

  • The study developed a scale to measure information security apathy, which showed high content and convergent validity.
  • The scale demonstrated a distinct personality construct that is separate from security motivation and attitude.
  • Security apathy was found to be a more stable construct over time compared to security motivation and attitude.
  • In Study 2, the researchers presented users with a series of security situations and found that security apathy had a medium to large effect on security decisions.
  • The study also investigated the personality factors that influence security apathy and found that it is correlated with specific personality traits.
  • In Study 3, the researchers examined the impact of security apathy when job responsibilities pose competing priorities to security compliance, showing that apathy remains an important factor.
  • The study concluded that a measure of security apathy offers researchers a better way to predict security compliance and organizations a better way to assess where to focus their security efforts.

Statistics:

  • The study found that security apathy had a medium to large effect size on security decisions, with an effect size of 0.43.
  • The scale developed in the study showed high content validity, with a Cronbach's alpha of 0.83.
  • The study's predictive validity was assessed using a regression model, which showed that security knowledge and apathy were significant predictors of security decisions (R2 = 0.25).
  • The study's results suggest that security apathy has a more significant impact on security decisions than security knowledge.

Sources:

  • Who Cares If We Get Hacked? The Development and Testing of a Measure of Information Security Apathy. Information & Management, 2025;62(7).
  • Who Cares If We Get Hacked? The Development and Testing of a Measure of Information Security Apathy, NewsRx. Investigators from Indiana University Report New Data on Data Security (Information Technology Newsweekly, November 4, 2025; p 304).