The Long View Revisited: What My 2012 Research on Telework Security Still Teaches Us
Dr. Timothy Godlove
Long before remote and hybrid work became routine for millions of employees, organizations were already confronting an important cybersecurity question: What makes employees working outside the traditional office willing to follow information security policies?
In 2012, I examined that question in a peer-reviewed study published in Information Security Journal: A Global Perspective. The article, “Examination of the Factors that Influence Teleworkers’ Willingness to Comply with Information Security Guidelines,” explored the human side of information security—specifically, the attitudes and motivations that influence teleworkers' compliance with organizational security requirements.
More than a decade later, technology has changed dramatically. Cloud computing is pervasive. Artificial intelligence is transforming the workplace. Employees routinely access organizational information from homes, hotels, airports, mobile devices, and other locations far beyond the traditional security perimeter.
Yet one conclusion remains remarkably relevant: cybersecurity depends not only on technology but also on people and their willingness to use it responsibly.
Studying the Human Side of Cybersecurity
My original research applied the Theory of Planned Behavior to information security compliance among teleworkers. The theory considers three broad influences on behavioral intentions: personal attitudes, social influences, and an individual's perceived sense of control.
The study examined these concepts through three areas:
• Personal attitude — how teleworkers viewed information security, data protection, organizational policies, and the consequences of failing to protect information.
• Social pressure — the influence of managers, coworkers, organizational expectations, and workplace norms.
• Sense of control — whether individuals believed they possessed the responsibility, knowledge, and ability to protect organizational information.
A sample of 150 teleworkers completed a security survey designed to examine these relationships.
The results presented a more complicated picture than simply assuming that employees who understand cybersecurity risks will automatically follow security policies.
Employees Generally Wanted to Do the Right Thing
One of the strongest findings was encouraging: teleworkers reported a high willingness to follow their organizations' information security guidelines.
Participants also recognized that organizational information is vulnerable to security incidents and the importance of protecting the confidentiality and integrity of organizational data.
They generally believed that adopting security technologies and practices was important. They also recognized their personal responsibility for protecting information under their control.
This distinction remains important today.
Employees do not necessarily disregard cybersecurity because they do not care about it. An employee can recognize that cybersecurity is important and still make decisions that create security vulnerabilities.
Understanding the difference between security awareness and security behavior is therefore essential.
Personal Attitudes Were Not Enough
The research found relationships between positive attitudes toward information security and willingness to follow security guidelines, but those relationships were generally weak.
That finding deserves attention.
Organizations frequently approach cybersecurity by attempting to convince employees that security is important. Awareness campaigns, mandatory training, policy statements, warning messages, and annual security courses are all intended to reinforce that message.
These efforts have value, but awareness by itself does not guarantee secure behavior.
An employee may understand perfectly well that organizational information is sensitive, yet still take a shortcut because the approved process is inconvenient. Another may understand the danger of unauthorized applications but use one because it makes completing a task easier.
The lesson is that organizations cannot simply tell employees that cybersecurity matters. They must create environments in which secure behavior becomes understandable, practical, and achievable.
Leadership Matters
The study also examined social pressure and organizational influence.
Teleworkers strongly indicated they would follow their managers' advice on security measures. They also believed that every employee could make a difference in protecting organizational information.
At the same time, pressure from coworkers was considerably less influential.
That finding highlights something leaders sometimes overlook: managers help establish an organization's cybersecurity culture.
Employees observe what leaders emphasize, what they ignore, and what behaviors they model.
If leaders routinely circumvent security procedures because those procedures are inconvenient, employees notice. If managers consistently reinforce the importance of protecting organizational information and demonstrate good security practices themselves, employees notice.
Cybersecurity culture is therefore not created exclusively by the chief information security officer or information technology department. It is reinforced—or weakened—by leadership throughout the organization.
A Sense of Control May Be Especially Important
One of the more interesting findings concerned employees' sense of control.
Participants generally believed that protecting organizational information was a personal responsibility and that they could take meaningful actions to reduce security risks.
When personal attitude, social pressure, and sense of control were examined together, sense of control was the only statistically significant predictor of willingness to follow organizational security guidelines.
The overall predictive model was weak, so this finding should not be interpreted as explaining all security behavior. Instead, it points toward an important principle: people may be more willing to follow security requirements when they believe they understand what to do and have the ability to do it.
That principle remains highly relevant.
Organizations should not merely issue security requirements. They should provide employees with the tools, knowledge, authority, and support necessary to follow them.
Technology Has Changed. The Human Challenge Has Not.
The technology environment of 2026 is vastly different from the environment in which this research was conducted.
Today's remote worker may operate within cloud-based environments, collaborate through multiple digital platforms, use mobile devices, access software-as-a-service applications, interact with artificial intelligence tools, and connect to organizational systems from locations around the world.
Security architectures have also evolved. Multifactor authentication, endpoint detection and response, zero-trust approaches, identity-centered security, cloud security controls, and increasingly sophisticated monitoring capabilities provide organizations with tools that were far less mature when the original study was conducted.
But technology does not eliminate human judgment.
Employees still decide whether to follow procedures.
They still respond to organizational culture.
They still observe managers' and coworkers' behavior.
And they still make daily decisions involving convenience, productivity, information sharing, access, and security.
The cybersecurity environment has changed dramatically, but the relationship between people, technology, policy, and leadership remains central.
What Leaders Can Take Away Today
Looking back at this research more than a decade later, I see several lessons that remain applicable.
First, awareness is necessary but insufficient. Employees can understand cybersecurity risks without consistently translating that understanding into secure behavior.
Second, leadership behavior matters. Managers play an important role in communicating expectations and creating organizational norms around information security.
Third, employees need a sense of control. Security requirements should be understandable and achievable, and organizations should provide employees with appropriate tools and training.
Fourth, security policies must support the work rather than unnecessarily obstruct it. When security becomes overly burdensome, employees may seek alternative ways to fulfill their responsibilities.
Finally, cybersecurity remains a human and organizational challenge as much as a technological one.
Organizations can invest heavily in sophisticated security technologies. Still, those investments are most effective when employees understand their responsibilities, leaders reinforce appropriate behaviors, and security becomes part of the organizational culture.
Taking the Long View
One reason for creating Long View Review is to examine how ideas evolve.
Research does not necessarily become irrelevant simply because technology changes. Sometimes looking backward provides a clearer understanding of the challenges ahead.
My 2012 research examined teleworkers at a time when remote work was still emerging as an important organizational practice. Today, distributed work has become an established part of the modern workplace.
The technologies have changed.
The threats have changed.
The workplace has changed.
But one principle has endured:
Effective cybersecurity ultimately requires people who understand their responsibilities, believe they can make a difference, and work within an organizational culture that enables secure behavior.
________________________________________
Original Research
Godlove, T. (2012). Examination of the factors that influence teleworkers' willingness to comply with information security guidelines. Information Security Journal: A Global Perspective, 21(4), 216–229.
The original peer-reviewed article is available from Taylor & Francis.