Does Fear Motivate Compliance?

December 22, 2020

One component of Foreign Corrupt Practices Act compliance so-called “best practices” is training. But what type of training best minimizes FCPA risk?

Consider two types of training: the first legalese, fear-based training and the second, spot the issues type of training.

As to the first type of training, what sort of participate reaction would result if the trainer begins with saying something along the following lines: “Today I will be talking about a U.S. law that makes it a crime to bribe foreign government officials to get business. Your failure to abide by this law could result in you going to jail.”

As to the second type of training, what might the participate reaction be if the trainer begins with saying something along the following lines: ““Today, I will be talking about a U.S. law that applies to all of you – regardless of whether you are in the sales and marketing department, the executive office suite, the finance and audit department, or the logistics department. This law can cover a wide range of conduct the company engages in when doing business in the global marketplace.  Your understanding of this law and how it may relate to your specific job function will best ensure that the company remains compliant with this law and is best able to achieve its business objectives.”

Which training is better?

Should fear play any role in compliance training? Is FCPA compliance motivated, at least in part, by participants understanding that there are individuals eating their lunch in federal prison today because of FCPA issues?

This recent article in the Wall Street Journal by Dr. Karen Renaud (Professor of Cybersecurity at Abertay University’s Division of Cybersecurity in Scotland) caught my eye. While it discusses the use of fear in corporate cybersecurity compliance, the article nevertheless is likely relevant to any substantive area of compliance.

In pertinent part, the article states:

“Companies often turn to a powerful emotion to get employees to be vigilant about cybersecurity. They scare them.

If you do this, or don’t do that, something awful will happen. Click on phishing messages, and the company’s network will be exposed to hackers. Use simple passwords, and your personal files will get stolen.

The problem: Fear doesn’t work. Sure, it may get people to act in that moment. But scare tactics don’t get people invested in security over the long term, as Marc Dupuis of the University of Washington and I discovered in research last year.

In fact, it can do the opposite. That is because fear can leave employees in a constant state of anxiety, which makes them unable to think clearly about threats. Alternatively, such heavy-handed, scare messaging can make employees disgruntled and uninterested in security, thinking that the threats are exaggerated—and that bosses don’t trust them to do the right thing.

[…]

[L]et’s dig deeper into why fear doesn’t work.

There is no question that fear can work to get people to perform a one-off action, like installing antivirus software. But long-term behaviors are where the problems come in—and long-term vigilance is the real point of cybersecurity. After the initial surge, fear will wear off and convert to an underlying state of anxiety, which makes people unlikely to get people to commit to frequent actions such as choosing strong passwords.

For example, consider that Jane is told during cyber-awareness training that any email could be a phishing message. If she clicks on an embedded link or opens an attachment, she learns, malware could be installed, and she will lose all the files on her machine and precipitate a major cyber incident at her place of work.

All of this will leave her in a permanent state of uncertainty. Her productivity is likely to plummet because she mistrusts every email that arrives in her inbox, and she isn’t sure if links in messages are safe to click on.

In other words, a fear-based approach doesn’t encourage genuine watchfulness. Once someone is in a state of heightened fear or anxiety, their brains are fully occupied in dealing with the emotion, making measured and thoughtful action unlikely or impossible, according to Paul Brown, Joan Kingsley and Sue Paterson in their book “The Fear-Free Organization.” That means Jane might be so anxious that she can’t make informed choices about messages and instead works entirely by impulse.

People have many things to fear in their lives—especially in 2020—and they resent people leveraging even more fear against them. Prof. Dupuis and I recently surveyed 400 people and one of the issues that emerged during the study was that while many people might believe in fear-based appeals too much—as with Jane in the above example—others think that such appeals exaggerate the risk to give the message more power. We found that only 20.6% agreed that these fear appeals were necessary—so, people are suspicious and reject the entire message.

Very often, fear appeals are coupled with harsh punishments for making security errors. Organizations do this for very understandable reasons: If people have an immediate, tangible personal stake in following the rules, the logic goes, they are more likely to stay on the straight and narrow.

One U.K. organization fined employees heavily if they opened attachments on test phishing messages the organization sent out itself. These fines were significant, up to 50% of employee salaries. Another company had a policy of firing staff who fell for such messages three times.

Yet another company posted a photo of people who fell for a phishing message on the communal fridge to embarrass them.

David Rock suggests in his research into the neuroscience of collaboration that an employee who is singled out this way already feels bad about being deceived—and will now experience the equivalent of physical pain at being shamed. One employee of a company using this kind of tactic told me that if she fell for a phishing message, she feared that it would be brought up during her yearly performance review and affect her chances of being promoted—leaving her in a permanent state of anxiety.

These organizations don’t seem to understand the harm that hey do to employer-employee relations with these campaigns. An organization needs workers to be committed to securing the organization’s devices and information. This can’t be achieved by eliciting fear and imposing sanctions.

Companies that rely on fear often make a demand of employees: Deal with the problem yourselves by following the rules. But those fixes are often difficult, at best. And might be impossible. So, in essence, workers are told the dire consequences of not following rules that they can’t follow.

For example, it is common for password policies to instruct employees to (a) choose strong passwords, (b) not write them down and (c) not reuse them anywhere else. But, given that most people have tens if not dozens of passwords, this rule is impossible to follow—so it is likely that employees will end up in a state of long-term anxiety or simply give up on following the rules altogether.”

If fear may not work to motivate compliance, what does?

The article suggests “creativity and trust.”

However, as highlighted in prior posts here and here, these concepts have their own set of problems.

FCPA Institute Online

The most comprehensive online FCPA training course available. Over 12 hours of narrated instruction from Professor Koehler allowing professionals to elevate their FCPA knowledge and practical skills at their own pace.

 

 

Purchase