Abstract
This study tests the effects of behavioral and cognitive measures of self-control on computer-focused cyber deviance and cyber victimization with survey data from 1,036 adult employees. We examine moderating effects of cyber deviant peers and gender in the relationship between self-control, and cyber deviance and victimization. Cognitive and behavioral measures of self-control are negativity associated with cyber deviance, whereas only behavioral self-control predicted reduced cyber victimization. Moderation analyses show that cyber deviant peer associations condition the relationship between self-control, and both cyber deviance and victimization. Gender moderation models reveal no consistent significant effects. The results have implications for the understanding of cognitive predictors of computer-focused cybercrime and victimization, as well as institutional cybercrime prevention policies. Our findings can inform the future integration of self-control and social learning theories in cyberspace.
In the past two decades, the incidence and prevalence of cybercrime within organizations has increased substantially worldwide (Bissell et al., 2019; Furnell, 2002; Mickelberg et al., 2014), while the rate of in-person crimes has declined on average across the United States (Sharkey et al., 2017). The 2019 Cost of Cybercrime Study of 355 large companies in 11 nations found that the average annual cost of cybercrime was $13 million per company, with an average of 145 major security breaches in the past year (Bissell et al., 2019, p. 11). The Federal Bureau of Investigation’s (FBI; 2005, 2018) Internet Crime Complaint Center has experienced a steady increase in the number of complaints between 2004 and 2018, while the total reported financial losses increased more than 12-fold. Given that many cybercrimes are not reported to law enforcement (Bureau of Justice Statistics, 2016) and official statistics underestimate the actual amount of crime incidents (Gove et al., 1985), the total number of cybercrimes, quantity of victims, and economic impacts are likely far greater than estimates.
Despite the substantial increase in cybercrime offenses and sizable harm imposed by it, relatively few studies (see Holt & Bossler, 2014; 2016; Maimon & Louderback, 2019 for reviews) have investigated predictors of cybercrime and victimization using theories of individual-level offending such as self-control (Higgins, 2007; Higgins & Makin, 2004; Holt & Bossler, 2010, 2016; Moon et al., 2010), rational choice (Bachmann, 2010; Louderback & Antonaccio, 2017), and social learning (Higgins et al., 2006; Holt et al., 2010, 2012; Skinner & Fream, 1997). Although there is a considerable body of literature on the perpetration of computer-facilitated (i.e., person-focused) crimes in the cyberworld (e.g., cyberbullying/cyberstalking), less attention has been paid to computer-focused cybercrime, defined as “those crimes that have emerged in tandem with the establishment of the Internet and could not exist apart from it, for example, hacking, viral attacks, website defacement” (Yar, 2005, p. 409). Some research has investigated relationships between cognitively based predictors such as self-control and computer-focused cyber deviance (Higgins & Makin, 2004; Holt & Bossler, 2016; Holt et al., 2012; Moon et al., 2010) and victimization (Bossler & Holt, 2010) but primarily using student samples and cognitive self-control measures. Moreover, few studies on self-control and cybercrime or cyber victimization examine moderating variables, such as peer deviance or gender (Higgins & Makin, 2004; Holt et al., 2019; 2012).
Using unique survey data from a sample of 1,036 employees, this study fills these gaps in the literature by comparing the effects of cognitive and behavioral self-control measures on four types of computer-focused cyber deviance and four types of computer-focused cyber victimization. It tests gender and peer cyber deviance as moderators of the relationships between the two measures of self-control, and cyber deviance and cyber victimization.
Theoretical Background and Literature Review
The self-control theory of crime argues that individuals with low self-control have a greater propensity to commit criminal offenses, defined as “acts of force or fraud undertaken in the pursuit of self-interest” (Gottfredson & Hirschi, 1990, p. 15). Gottfredson and Hirschi (1990) posit that low self-control is a psychological trait that develops during childhood due to ineffective parenting. They argue that individuals with low levels of self-control possess six characteristics including: being impulsive, insensitive to others, risk taking, short sighted, adventurous, self-centered, and having a preference for physical tasks over mental ones. As individuals with low levels of self-control are unable to consider and weigh the consequences and benefits of their actions, they are more likely to engage in risky behaviors, delinquency, and crime (Gottfredson & Hirschi, 1990; Grasmick et al., 1993; Pratt & Cullen, 2000), and are more likely to be victimized (Pratt et al., 2014).
The self-control theory of crime has received considerable support since its development as demonstrated by meta-analyses (Pratt & Cullen, 2000; Pratt et al., 2014; de Ridder et al., 2012). They found that low self-control is a moderate and consistent predictor of criminal deviance, criminal victimization, and analogous behaviors (e.g., excessive drinking, drug use, and risky sexual behaviors).
Self-control theory is relevant for explaining computer-focused cyber deviance involvement for two reasons. First, since individuals with low self-control are less able to foresee the long-term consequences of their actions, they may engage in more online deviance (e.g., hacking, digital piracy, or copyright infringement) with less concern about potential personal, social, and legal consequences. Second, the impulsivity dimension of low self-control may compel individuals to act in the moment to fulfill immediate gratifications (Gottfredson & Hirschi, 1990), such as by committing hacking offenses to obtain money (e.g., cryptocurrency such as Bitcoin) or by maliciously deleting another person’s files out of anger or jealously. Indeed, these arguments are supported by Holt et al.’s (2012) study of low self-control and juvenile computer-focused cyber deviance, who argue that such cyber offenders “are likely to choose the immediate gains of crime” despite the chance of greater repercussions (p. 380).
Self-control may increase the chance of victimization by computer-focused cybercrime for two reasons. First, one’s victimization risk may increase due to the impulsivity component of self-control, as impulsive individuals may be more likely without much thinking to get involved in risky online activities (e.g., clicking on suspicious popup windows, entering unsafe websites, and publicly sharing sensitive information), which may result in cyber victimization. Second, individuals with low self-control may be more easily lured by promised immediate payoffs (e.g., free software downloads and online lottery winnings) and may not be able to anticipate possible negative consequences of actions undertaken online (e.g., browsing suspicious sites and sharing personal information) that may expose them to risk of cybercrime victimization.
It is also possible that associations between self-control and cybercrime/victimization are moderated by various factors. First, criminal opportunity plays an important role in self-control theory, with the theory implying that the self-control–crime relationship is enhanced by the presence of criminal opportunity (Gottfredson & Hirschi, 1990; Grasmick et al., 1993). The low self-control and victimization relationship has been found to be amplified in the context of greater exposure to opportunity for criminal and risky behaviors (Pratt et al., 2014; Schreck, 1999). Since associations with deviant peers have been traditionally viewed as indicative of exposure to social environments with plentiful opportunities for misbehavior, especially in the realm of cybercrime (Higgins & Makin, 2004; Holt et al., 2010, 2012; Skinner & Fream, 1997), the presence of deviant peers may amplify the relationships between self-control and computer-focused cyber deviance/victimization. Following this logic, it is also plausible to assume that males may encounter more situations where involvement in risky online behaviors is possible than females, and the relationship between self-control and cyber deviance/victimization may be conditioned by gender and is expected to be more pronounced for males.
The direction of these interaction effects may also be in the opposite direction. Some studies suggest a reduced impact of individual-level characteristics on behavioral outcomes in social contexts with increased criminogenic exposure because strong orientations toward deviance in those environments may attenuate the effects of individual-level factors on behavior (e.g., Anderson, 1999; Raine, 1993). Thus, it is also foreseeable that the impact of self-control on individual cyber deviance involvement/victimization may be less pronounced when deviant peer associations are high, or are presumed to be higher due to one’s gender (i.e., being male).
Empirical Research on Self-Control Theory and Cyber Deviance
Although self-control theory has received considerable empirical support for predicting in-person forms of criminal perpetration (Pratt & Cullen, 2000), relatively few studies have investigated the relationship between self-control and cyber deviance (Bossler & Burruss, 2012; Burruss et al., 2013; Donner et al., 2014; Higgins, 2005, 2007; Higgins & Makin, 2004; Higgins et al., 2006, 2009, 2012; Holt et al., 2012; Holtfreter et al., 2008; Moon et al., 2010).
Research focusing on computer-focused cyber deviance has found that individuals with low self-control engage in more digital piracy. For example, Hinduja and Ingram (2008) used survey data from undergraduate students at a large Midwestern public university and found that a 6-item cognitive low self-control scale predicted greater involvement in music piracy. Furthermore, using similar self-reported survey data from undergraduate students, Higgins (2005) and Higgins et al. (2006) found that low self-control (measured cognitively) predicted greater digital piracy. Using data from Korean high school students, Moon et al. (2010) tested the effects of cognitive self-control on illegal downloading of software online and involvement in identity theft and found significant effects on both outcomes. Moreover, Bossler and Burruss (2012) used survey data from a sample of college students to investigate the relationship between self-control and three low-level types of hacking and found that low self-control predicted these outcomes. They concluded that—when accounting for social learning measures including deviant peer associations and definitions favorable to deviance—participants with lower levels on these predictors actually needed higher levels of self-control to engage in computer-focused cyber deviance (i.e., hacking). Holt et al. (2012) tested the effects of low self-control on an index of five types of cyber deviance 1 with survey data from 435 middle and high school students in Central Kentucky. They found that cognitively measured self-control and deviant peers predicted more involvement in all cyber deviance types individually and in the index.
Taken together, these studies show that low self-control is a weak-to-moderate predictor of involvement in computer-focused cyber deviance. However, these studies have exclusively used samples of high school or college students, which may yield findings that are not representative of the prevalence and predictors of computer-focused cyber deviance in adult populations. This body of literature is also limited in its focus to piracy and illegal downloading, with other computer-focused cybercrime (e.g., hacking and data tampering) receiving less attention.
Only one study to our knowledge tested gender as a moderator of the relationship between self-control and cybercrime (Holt et al., 2019). 2 Therefore, this contingency should be examined in more detail to determine if self-control is a general predictor of cyber deviance involvement for males and females, as has been found for self-control and street crimes (Burton et al., 1998). Very few studies have empirically investigated conditioning effects of deviant peer associations on the relationship between self-control and various forms of cyber deviance (e.g., Higgins & Makin, 2004; Holt et al., 2012). Holt et al. (2012) found that more deviant peer associations amplified the effect of low self-control on a cyber deviance index. Similarly, Higgins and Makin (2004) showed that deviant peer associations amplified 3 the effects of low self-control on digital piracy.
Empirical Research on Self-Control Theory and Cyber Victimization
Most studies on cybercrime victimization examine various correlates of victimization by person-focused (i.e., computer-facilitated) cyber deviance such as online harassment, cyberbullying, and cyberstalking, (e.g., Choi, 2008; Holt et al., 2016; Ngo & Paternoster, 2011; Van Wilsem, 2013). However, there is a dearth of criminological research that has investigated predictors of victimization by computer-focused cyber deviance such as phishing, malware infection, unauthorized password access, and computer file tampering (Bossler & Holt, 2009, 2010; Reyns et al., 2019; Ngo & Paternoster, 2011). To date, only two studies to our knowledge have applied the concept of self-control to explain computer-focused cyber victimization. Bossler and Holt (2010) found that the Grasmick et al. (1993) scale—a cognitive measure of low self-control—was associated with unauthorized password access and file tampering using a convenience sample of 573 undergraduate students from a southeastern university context. In contrast, Ngo and Paternoster (2011) used the same cognitive measure of self-control and found no significant effects of levels of self-control on phishing or virus infection victimization with a sample of 295 undergraduates, suggesting that findings are mixed on the self-control and computer-focused cybercrime victimization relationship.
Cognitive versus Behavioral Self-Control, Cybercrime, and Victimization
Several researchers have drawn attention to various measures of self-control and have highlighted their strengths/weaknesses (Hirschi & Gottfredson, 1993; Longshore et al., 1996; Tittle et al., 2003b; Ward et al., 2010). For example, Gottfredson and Hirschi (1993) identified issues with cognitive self-control scales. Tittle et al. (2003b) noted that both measures appeared to be valid predictors of various types of offending, yet the behavioral self-control measure operates better for some populations and crimes. A behavioral self-control measure has been shown to have a greater validity by Ward et al. (2010). Studies of computer-focused cybercrime have only measured self-control cognitively, and no research to our knowledge has conducted a comparative analysis of cognitive/behavioral self-control measures for outcomes in cyberspace.
The Present Study
This study makes four contributions to the literature on self-control and cyber offending/victimization. First, it extends current research by testing the relationship between self-control and various types of computer-focused cyber deviance using an adult sample. Previous research applying self-control to computer-focused cybercrime has predominantly used student samples. Second, it compares the effects of two types of self-control measures—cognitive and behavioral—on several kinds of computer-focused cyber deviance and victimization.
Third, our study adds to the literature on the effects of moderating variables in relationships between self-control and computer-focused cyber deviance and victimization. It assesses moderating effects of gender on relationships between self-control and cyber deviance/victimization to test if the effects of self-control on cyber deviance/victimization are general across genders or are gender specific. It also tests deviant peer associations as a moderator of self-control–cyber deviance/victimization associations. Fourth, it is the first study of self-control and cybercrime to use projected measures 4 of computer-focused cyber deviance involvement, while controlling for past involvement in computer-focused cyber deviance.
Methods
This study uses data from a survey 5 of employees at a large organization conducted during the spring of 2015. The targeted population was all full-time employees. Overall, 1,039 eligible employees completed the survey (response rate = 26%). This response rate is more than double the typical response rate for web-based surveys (usually less than 10%; see Nulty, 2008; Schonlau et al., 2002). To assess the sample’s representativeness, we compared the distribution of demographics of the survey participants with the population of employee demographics. 6 The faculty was 62% male and 38% female, with a racial/ethnic composition of 62% White, 21% Hispanic/Latino, and 4% African American. This composition resembles that of our sample for faculty, which was composed of 55.1% males and 44.9% females, and 69.6% White, 16.1% Hispanic/Latino, and 3.7% African American, with overrepresentation of females/whites.
Measures: Dependent Variables
Computer-Focused Cyber Deviance Involvement Indices
A 4-item projected computer-focused cyber deviance index was constructed by summing four items measuring the likelihood of the respondent’s future computer-focused deviance involvement. Consistent with past research (Holt & Bossler, 2009), the survey items asked respondents about four types of computer-focused misconduct ranging from digital piracy to unauthorized computer access (see Appendix Table A1 for all survey items). As is common in research on crime etiology using cross-sectional data, a measure of projected 7 (instead of past) deviance is used because it allows models to establish causal order and has demonstrated validity and reliability (Antonaccio & Tittle, 2008; Green, 1989; Murray & Erickson, 1987; Pogarsky, 2004; Tittle & Botchkovar, 2005; Wikström et al., 2012).
To construct the measures, individual item scores were summed. The index of projected computer-focused cyber deviance involvement ranged from 0 to 16 and had an alpha of 0.755. We also constructed an index of past computer-focused cyber deviance involvement, which ranged from 0 to 16 and had an alpha of 0.764. Both indices were positively skewed, so they were logged (after 1 was added to their values) to mitigate potential problems with regression model specifications. Higher values on the indices indicate a greater projected/past frequency of computer-focused cyber deviance.
Computer-Focused Cybercrime Victimization Index
Based on past research (Holt & Bossler, 2010), one measure of computer-focused cybercrime victimization index is a 4-item additive index of several types of computer-focused cybercrime victimization within the past 12 months. Participants were asked to report the number of times they had experienced four incidents ranging from unauthorized access to data/files to the compromise of financial details online. The index was constructed by summing individual item scores and ranged from 0 to 14, with higher values indicating more victimization. The alpha for this measure was 0.245.
Independent Variables
Cognitive Self-Control Scale
Based on the commonly used self-control scale constructed by Grasmick et al. (1993), a cognitive attitudinal self-control measure was constructed. The scale items tap the dimensions of self-control including impulsivity, self-centeredness, frustration over complex problems, preference for physicality over mental stimulation, and risk seeking (Gottfredson & Hirschi, 1990; Grasmick et al., 1993). Due to survey length constraints, the original 24-item scale was consolidated to 18 items by randomly selecting and removing one item from each of the six dimensions of self-control. Each item tapped a separate dimension of cognitive self-control and consisted of statements to which respondents could respond “strongly agree,” which was coded as 1, to “strongly disagree,” which was coded as 5. The survey items were summed to create a scale with values ranging from 18 to 90. The alpha was 0.816.
Behavioral Self-Control Scale
We also constructed a behavioral self-control scale 8 that research by Tittle et al. (2003b) and Ward et al. (2010) has found to have advantages over the cognitive scale (e.g., greater validity). The behavioral self-control scale included seven items tapping the multidimensional concept of self-control such as risky behaviors including tobacco use and excessive alcohol use, incurring debt without being able to pay it off, and not seeking treatment for illness. Each item had response categories ranging from “very often,” which was coded as 1, to “never,” which was coded as 5. The survey items were summed to create a scale with values ranging from 7 to 35. The alpha was 0.602, which is a value that is higher than those usually found in the studies of behavioral self-control (e.g., see Antonaccio & Tittle, 2008). Higher values on each self-control scale indicate higher levels of self-control.
Peer Cyber Deviance Involvement Index
We constructed a 4-item peer computer-focused cyber deviance involvement index. This index is consistent with previous research on peer deviance and cyber deviance (Bossler et al., 2012) and includes four items, tapping the computer-focused cybercrimes of digital piracy, unauthorized access, data/file tampering, and illegal downloading. Respondents were asked how many times their close friends had engaged in each of the four types of computer-focused cybercrime and response categories ranged from never (coded as 0) to very often (coded as 4). These four items were then summed. The alpha was 0.746. Higher values on the index indicate higher levels of peer cyber deviance.
Control variables
We controlled for sociodemographic variables including age (an ordinal measure ranging from 1 “18–29 years old,” to 7 “80 or more years old”), gender (a dummy variable coded with 1 = male) and race (a dummy variable coded with 1 = African American).
Analytic Strategy
Ordinary least squares (OLS) regression was used to test the effects of behavioral and cognitive self-control on the computer-focused cyber deviance and victimization outcomes. Since the past and projected computer-focused cyber deviance indices were non-normally distributed and positively skewed, they were logged. To test the hypothesized interaction effects, we constructed interaction terms between both self-control measures and peer deviance, and both self-control measures and gender. All variables were mean-centered prior to constructing the interaction terms. Since the variance inflation factors (VIFs) were all below 4, multicollinearity did not bias the estimates. To compare the effect sizes and explanatory power of the behavioral and cognitive self-control measures, we compared the statistical significance, standardized regression coefficients, and R2 values for the models with each of the two self-control measures predicting cyber deviance involvement and victimization.
Results
Descriptive and Correlational Analyses
Table 1 shows the descriptive statistics for the variables used in the analyses. It also includes the total percentage of respondents with any amount of cyber deviance involvement and victimization and peer cyber deviance (i.e., total % reporting greater than “no involvement/victimization”). These summary statistics indicate that there are differences in individuals’ and peers’ computer-focused cyber deviance involvement and victimization, by deviance type. The total percentage of respondents who had engaged in digital piracy was the highest (15.5%), followed by illegal downloading (9.3%), unauthorized access to computer systems (3.1%), and data and/or file tampering (2.3%). The same general patterns are replicated for the projected cybercrime involvement measure and the peers’ cyber deviance measures.
Descriptive Statistics for Variables Used in the Analyses. a
Total n = 1,036.
“Total %” is the percentage of respondents who reported any cyber deviance involvement or cyber victimization.
Second, substantial differences in cyber victimization are present across crime types. Specifically, 68.9% participants had experienced at least one phishing incident in the past year, followed by 26.2% for electronic credit card hacking, 5.2% for unauthorized access, and 4.2% for data/file tampering. Both behavioral and cognitive self-control measures exhibit considerable variation with values ranging from 14 to 35 and 27 to 90, respectively.
The bivariate correlations in Table 2 reveal several notable results. The bivariate correlations for both behavioral and cognitive self-control indices with past and projected cyber deviance are significant and negative, indicating that self-control, as hypothesized, reduces cyber deviance involvement. Yet, their effect sizes differ. Specifically, for projected cyber deviance, the correlations are r = −.285 for behavioral self-control and r = −.224 for cognitive self-control. Moreover, the association between behavioral self-control and cyber victimization is negative and significant (r = −.180), while cognitive self-control is not significant.
Bivariate Correlations Between Variables.
p < .05 (two-tailed). **p < .01 (two-tailed).
Several other correlations in this table are important to note. First, the past and projected cyber deviance involvement measures are significantly correlated (r = .857), as are the past cyber deviance and cybervictimization measures (r = .178). Second, males are more likely to be involved in past cyber deviance and to experience cybervictimization (r = .107 and r = .068, respectively), older respondents are significantly less likely to be involved in cyber deviance but not to be victimized (r = −.212 and r = .014, respectively), and race does not significantly predict either outcome. Third, peer cyber deviance involvement is strongly associated with projected cyber deviance involvement, with a bivariate correlation coefficient of r = .702.
Multivariate Analyses
Table 3 shows the OLS regression models estimating the effects of both self-control measures on projected cyber deviance involvement and victimization with control variables. Models 1 and 2 show the effects of behavioral and cognitive self-control on projected cyber deviance, while Models 3 and 4 show the effects of both self-control measures on victimization. In Models 1A and 2A, which include controls for gender, race, and age, the unstandardized coefficients for both behavioral and cognitive self-control indices are statistically significant (p < .05) in the expected direction (b = −0.053 and b = −0.014, respectively). These effects are robust, although somewhat attenuated, when a control for past cybercrime involvement is added (Models 1B and 2B). Models 3 and 4 show the results for cyber victimization. In Model 3A, where behavioral self-control predicts cyber victimization with controls, the effect of behavioral self-control is significant and negative (b = −0.104). This effect (b = −0.086) remains significant when adding a control for past cyber deviance involvement (Model 3B). The effects of cognitive self-control are not significant in any of the cyber victimization models (Models 4A and 4B).
OLS Regression Coefficients Estimating Effects of Behavioral and Cognitive Self-Control Indices on Computer-Focused Cyber Deviance Involvement Index and Cyber Victimization Index.
Note. n = 881 in Models 1A and 1B; n = 880 in Models 2A and 2B; n = 884 in Model 3A and n = 882 in Model 3B; n = 881 in Model 4A and n = 880 in Model 4B. Models show regression coefficients, standard errors (in parentheses), and standardized regression coefficients. Cyber deviance was transformed by adding 1 and computing the natural logarithm.
p < .05 (one-tailed). **p < .01 (one-tailed).
Comparing the effects of both measures of self-control, the standardized coefficients for the behavioral and cognitive self-control measures from the cyber deviance Models 1B and 2B are β = −0.162 and β = −0.045, respectively. The explained variance (R2) is higher for the behavioral (vs. cognitive) self-control model for both outcomes. Thus, behavioral self-control appears to be a better predictor of both cyber deviance and cybervictimization outcomes.
Moderation Analyses
Table 4 shows OLS regression models estimating the main and interaction effects of both self-control indices and the deviant peer association measure on projected cyber deviance involvement and victimization controlling for gender, race, age, and past cyber deviance. Model 1A tests for the interaction between behavioral self-control and deviant peer associations, while Model 1B tests for the interaction between cognitive self-control and deviant peer associations. Models 2A and 2B test the interaction effect between being male and behavioral and cognitive self-control, respectively. Finally, Models 3A and 3B, as well as Models 4A and 4B, test the same interaction effects described above for the cyber victimization outcome.
OLS Regression Coefficients Estimating Interaction Effects between Self-Control and Peer Cyber Deviance and Gender on Computer-Focused Cyber Deviance Involvement Index and Cyber Victimization Index.
Note. n = 879 in Models 1A and 2A; n = 878 in Models 1B and 2B; n = 881 in Models 3A and 4A; n = 879 in Models 3B and 4B. Models show regression coefficients, standard errors (in parentheses), and standardized regression coefficients. Cyber deviance was transformed by adding 1 and computing the natural logarithm.
p < .05 (one-tailed). **p < .01 (one-tailed).
Across Models 1A and 1B, the interaction effect between both self-control measures and the peer deviance measure is significant and positive, indicating that the effects of self-control on computer-focused cyber deviance involvement are smaller in a context with more deviant peers. For example, the estimated effect sizes of behavioral self-control on cyber deviance are as follows: b = −0.033 (p < .05) for respondents with the minimum value of peer deviance, b = −0.029 (p < .05) for respondents with mean value of peer deviance, b = −0.020 (p < .05) for respondents with one standard deviation above the mean of peer deviance, and b = −0.011 (not statistically significant) for respondents with two standard deviations above the mean of peer cyber deviance. Overall, these findings provide support for conditioning influences of deviant peer associations and demonstrate that the protective effects of high self-control on computer-focused cyber deviance are reduced with more exposure to peer cyber deviance.
Model 2A tests the interaction between behavioral self-control and male gender, while Model 2B tests for the interaction between cognitive self-control and male gender. The interaction terms are significant and negative only for behavioral self-control for cyber deviance, suggesting that behavioral self-control is more effective in preventing computer-focused cyber deviance for males. The unstandardized regression coefficients for behavioral self-control are b = −0.040 for males and b = −0.019 for females. These findings on behavioral self-control were also probed with split-sample models by gender, and the equality of regression coefficients test verified that the gender differences are significant (p < .05). These results provide partial support for the conditioning effects of gender for cyber deviance involvement.
For the moderation analyses with the cyber victimization outcome, Models 3A and 3B in Table 4 show that the interaction effects between behavioral and cognitive self-control, and deviant peer associations, are both significant and negative. The protective effects of self-control on computer-focused cyber victimization are stronger in a context with more deviant peers. For example, the estimated effect sizes of behavioral self-control on computer-focused cyber victimization are as follows: b = −0.044 (not statistically significant) for respondents with the minimum value of peer deviance, b = −0.076 (p < .05) for respondents with the mean value of peer deviance, b = −0.139 (p < .05) for respondents with one standard deviation above the mean of peer deviance, and b = −0.202 (p < .05) for respondents with two standard deviations above the mean of peer cyber deviance. For the moderation analyses of self-control and gender in Models 4A and 4B, only the interaction term between behavioral self-control and male gender was significant and positive. However, split-sample models using the equality of regression coefficients test indicated that this relationship was not statistically significant (z = −1.182). Therefore, for behavioral self-control and cyber victimization, the protective effects of self-control on computer-focused cyber victimization appear to be similar for males and females.
Sensitivity Analyses
Several sets of sensitivity analyses were conducted using alternative analytic strategies and different model specifications to verify the robustness of the main findings. First, OLS models predicting projected cyber deviance were re-estimated with negative binomial regression. The results from these analyses (available upon request) reveal that, although the main effects of behavioral and cognitive self-control measures as well as all peer deviance/self-control interactions are robust to using this analytical strategy, the gender interactions are not significant.
Second, the analyses were rerun with each cyber deviance and victimization item as a separate outcome and matching individual peer deviance items. As shown in Appendix Table A2, these analyses confirmed the general pattern of findings on main effects of self-control on cyber deviance and nonrobust (nonsignificant in most instances) gender interactions. They also revealed some disparate findings on interaction effects between self-control and peer deviance in the cyber deviance involvement models. These models demonstrate that positive self-control–peer deviance interactions are replicated (p < .05) only for the two computer-focused cyber deviance items, digital piracy and illegal downloading, whereas the interactions of self-control and peer deviance items for the other two items (unauthorized access and data/file tampering) are in the opposite direction—negative. The sensitivity analyses with each cybervictimization item individually (table available upon request) revealed fewer disparate findings when compared with the cyber deviance models. The main effects of behavioral self-control are significant for all but one type of cybervictimization (data/file tampering), whereas the main effects of cognitive self-control are not significant for any of the four outcomes. The significant negative interaction terms between both self-control measures and each peer cyber deviance item on each cyber victimization outcome was replicated for all three outcomes except phishing emails.
Third, the models were all rerun 9 with the past cyber deviance index as the outcome instead of projected cyber deviance involvement. The results using this alternative dependent variable (available upon request) were similar for the main effects. The results with this specification were most robust for the behavioral self-control measure.
Discussion
Using survey data collected from 1,036 adult employees in a large organization, this study contributed to the literature on the understudied topic of computer-focused cybercrime by testing the effects of behavioral and cognitive self-control measures of on several types of computer-focused cyber deviance and victimization, as well as examining the moderating effects of peer deviance and gender. The analyses have revealed several important findings. First, consistent with the prior research (e.g., Burruss et al., 2013; Higgins, 2005, 2007; Higgins & Makin, 2004; Higgins et al., 2006; Holt & Bossler, 2016; Holt et al., 2012), the results confirm that higher levels of self-control decrease involvement in computer-focused cybercrime. Yet, the effects found in this study are stronger and more robust when compared with past studies, which used student samples and showed varying levels of empirical support for the effect of self-control (Higgins & Makin, 2004; Holt & Bossler, 2014; Holt et al., 2012; Li et al., 2016).
Second, the findings showing an inverse relationship between behavioral self-control and computer-focused cyber victimization are consistent with the results of some studies of self-control and other types of victimization by computer-focused and computer-facilitated cybercrime (Bossler & Holt, 2010; Choi, 2008; Van Wilsem, 2013). Most importantly, the crime-preventive and victimization-reducing effects of behavioral self-control are consistent, even when controlling for as past involvement in cyber deviance. These results suggest that social psychological traits such as self-control may play an important role in reducing not just cyber deviance but also cyber victimization among adults of all ages. Our findings are also consistent with research on computer-focused cyber deviance and victimization, showing that other cognitive factors such as thoughtfully reflective decision making (TRDM) matter in an adult sample (Louderback & Antonaccio, 2017).
The explanations for our findings regarding such influences of self-control on computer-focused cyber deviance involvement are threefold. First, those with low self-control may act impulsively and be overpowered by negative emotions when, for example, maliciously deleting another person’s files out of anger or jealously. Second, it is possible that respondents with low self-control, who are less future oriented, are not be able to save enough money and will resort to downloading pirated media for free from a torrent website instead of purchasing the media. Finally, they may also be unable to foresee all possible long-term negative consequences of such actions (e.g., penalties and fines).
The findings regarding the predictive ability of two types of self-control measures—a behavioral measure and a cognitive measure—have advanced the literature on self-control, and cybercrime and victimization methodologically, as our study was the first to our knowledge to empirically test and compare the effects of both types of self-control measures on any type of cyber deviance or victimization. Similar to Tittle et al. (2003b), our results show that both measures of self-control have some predictive utility for computer-focused cyber deviance. Yet, they demonstrate that the behavioral measure has a significantly stronger effect 10 on computer-focused deviance, and only the behavioral measure significantly predicts cyber victimization.
Next, the analyses revealed nuanced conditioning effects of deviant peer associations on the self-control–cyber deviance/victimization relationships, suggesting that the specific direction of interactions depends on the type of computer-focused cyber deviance or victimization. Consistent with theorizing by self-control scholars regarding opportunities for crime and some previous research on cybercrime (Holt et al., 2012), our results show that the effects of high self-control on involvement and victimization by hacking-like offenses (i.e., unauthorized access, data/file tampering, and credit card fraud) may be enhanced in contexts with more deviant peers. This could mean that more deviant peers are indicative of greater opportunity for cyber deviance and exposure to risky online environments, where one is more likely to be victimized.
However, like some research on conditioning effects on the relationship between self-control and crime (Meldrum et al., 2009), our findings suggest that high self-control may be less effective in reducing involvement in other types of computer-focused cyber deviance such as illegal downloading and digital piracy when respondents are exposed to more deviant peer associations. The reduced impact of personal characteristics such as self-control in social contexts with increased criminogenic exposure could occur because strong orientations toward deviance in those environments may mute the effects of various individual-level factors on one’s overall behavior (e.g., Anderson, 1999; Raine, 1993). This is especially plausible because both illegal downloading and digital piracy are quite widespread and have become increasingly socially acceptable. It is foreseeable that individuals who are surrounded by people who engage in such misconduct are influenced by their favorable orientations toward these types of deviance and may engage in those activities despite high self-control. Overall, these results suggest that self-control and social learning theories may be helpful, independently and jointly, for explaining cyber deviance and victimization, instead of being considered as opposing frameworks (Evans et al., 1997). Both perspectives could also inform future attempts at creating an integrated theory of cyber offending or victimization (Higgins et al., 2006; Tittle, 1995, 2004).
Our results regarding the moderating effects of gender on the self-control and cyber deviance and victimization relationships are much less robust than the findings for peer deviance as a moderator. The main analyses show that the interactions between gender and the behavioral self-control measure were only significant for behavioral self-control for cyber deviance and victimization outcomes. Substantively, the interaction effect was in the negative direction for cyber deviance, indicating that the crime-deterring effect of self-control is greater for males than females. The stronger effect of self-control on cyber deviance for males may be due to more opportunities to commit cybercrime, suggesting that self-control is more important in predicting male offending. Overall, these findings are consistent with the results of the previous research 11 on the generality-specificity of theoretical predictors of street crime and delinquency by gender (e.g., Burton et al., 1998; Daigle et al., 2007; Tittle et al., 2003a).
Our study is not without limitations. First, even though the response rate to the web-based survey data was substantially higher than in other studies, and our sample demographics are similar to the study population, it is still lower than the desired response rate to maximize the generalizability of our results. Second, due to the substantive focus of this study on computer-focused cyber deviance and victimization, we did not test and compare predictive powers of behavioral and cognitive self-control measures on all types of cybercrime and victimization (e.g., cyberbullying/cyberstalking). Future studies should test different self-control measurement approaches with all types of cybercrime/victimization (e.g., cyberbullying and cyberstalking) to evaluate whether effects of behavioral measures are stronger for these outcomes.
Despite these limitations, our findings have importance for computer-focused cybercrime and victimization research with adult populations, contribute to research on methodological approaches to measuring the key criminological concept of self-control, and add to knowledge on the role of peer deviance and gender as contingencies in the self-control and cyber deviance/victimization relationships. Our methodological findings on the greater utility of a behavioral self-control measure suggest that future work in this area should utilize this alternative measure. More broadly, the results from this study can inform the development of targeted institutional and criminal justice policies across the world aimed at reducing the incidence of cybercrime, while highlighting the importance of using samples of adults when applying criminological theories to explain misconduct and victimization in cyberspace.
Footnotes
Appendix
Sensitivity Analyses of Main and Interactive Effects of Behavioral and Cognitive Self-Control Measures on Projected Computer-Focused Cyber Deviance Items.
| Variables | Model 1 | Model 2 | Model 3 | Model 4 | ||||
|---|---|---|---|---|---|---|---|---|
| A | B | A | B | A | B | A | B | |
| Digital piracy | Digital piracy | Unauthorized access | Unauthorized access | Data/File tampering | Data/File tampering | Illegal downloading | Illegal downloading | |
| b/SE/β | b/SE/β | b/SE/β | b/SE/β | b/SE/β | b/SE/β | b/SE/β | b/SE/β | |
| Behavioral Self-Control Scale | −.014**
(.003) −.109 |
−.004*
|
−.003*
|
−.010**
|
||||
| Cognitive Self-Control Scale | .000 |
−.002**
|
−.001*
|
.000 |
||||
| Peer cyber deviance (digital piracy) | .150**
|
.162**
|
||||||
| Peer cyber deviance (unauthorized access) | .152**
|
.133**
|
||||||
| Peer cyber deviance (data/file tampering) | .177**
|
.148**
|
||||||
| Peer cyber deviance (illegal downloading) | .148**
|
.152**
|
||||||
| Behavioral self-control × peer cyber deviance item | −.002 |
−.013**
|
−.007**
|
.005*
|
||||
| Cognitive self-control × peer cyber deviance item | .005**
|
−.004**
|
−.004**
|
.005**
|
||||
| Gender (male) | .048**
|
.038*
|
.011 |
.008 |
.001 |
.000 |
.071**
|
.068**
|
| Race (African American) | −.037 |
−.037 |
−.008 |
−.006 |
−.008 |
−.006 |
.006 |
.009 |
| Age | −.008 |
−.010 |
.000 |
−.001 |
.001 |
.001 |
−.015*
|
−.016**
|
| Intercept | .178** | .191** | .022 | .025 | .010 | .009 | .117** | .121** |
| R 2 | .504 | .498 | .411 | .403 | .475 | .475 | .504 | .499 |
Note. n = 880 in Models 1A and 2A; n = 879 in Models 1B and 2B; n = 879 in Model 3A and n = 880 in Model 4A; n = 878 in Model 3B and n = 879 in Model 4B. Models show regression coefficients, standard errors (in parentheses), and standardized regression coefficients. All models also control for past cyber deviance involvement (not shown due to space limitations). Each cyber deviance outcome was transformed by adding 1 and computing the natural logarithm.
p < .05 (one-tailed). **p < .01 (one-tailed).
Declaration of Conflicting Interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This work was supported by the National Science Foundation (grant no. 1343430).
Human Subjects Research
This study was approved by the University of Miami IRB and informed consent was obtained from all participants.
