Abstract
Cybersecurity breaches have rapidly become a high-impact crisis for many corporations. Thus, it is critically important for corporations to know how to protect their reputation through effective crisis communication. Considering the scarcity of empirical research on cybersecurity breaches in crisis communication, the current study attempts to fill this research gap. This study compared 108 official statements issued by organizations in the United States and South Korea when cybersecurity breaches threatened the reputations of various corporations. The characteristics of an apology (responsibility admittance, sympathetic expression, reassurance, compensation) and other features of crisis response (use of excuses, functions of apology, and organizational representation) were examined. This study found that the features of the official statements differed by cultural dimension (individualism vs. collectivism, small vs. large power distance) and by communication style (low-context vs. high-context communication).
Introduction
The potential for digital information theft has increased due to the ease of data collection and its massive distribution throughout the digital world. Personally identifying information (PII) is digitally stored in cyberspace, where it is exposed to the potential risk of misuse. Data breach incidents are irrevocable crises: once the PII is disclosed on the Web, it is almost impossible to recall the stolen information and keep it safe again. According to the Identity Theft Resource Center (2017), the number of data breach incidents in the United States reached a record high of 1,093 cases in 2016. This trend appears to be similar on a global scale. For all types of organizations, the explicit costs of stolen or lost records have increased by 23% since 2013 (Ponemon Institute, 2015). Observing the sheer amount of cybersecurity breach cases, people have grown to distrust corporations’ competence. According to the TRUSTe’s (2015) Consumer Confidence Privacy Index, only 55% of Americans trust a company’s ability to protect consumers’ personal information. More than 90% of the consumers surveyed said they are concerned about cyber privacy (TRUSTe, 2015).
Benoit’s (1997, 2015) theory of image restoration and Coombs’ (1995, 2012) situational crisis communication theory (SCCT) systematically explore how people perceive crisis situations in order to identify the best crisis response strategy in a particular environment. Apologies have been favored in crisis communication research, compared with other less accommodative strategies (Coombs & Holladay, 2008), and a string of research has attempted to address the features of effective apology statements (e.g., Fehr & Gelfand, 2010; Hill & Boyd, 2013; Lazare, 2005; Lee & Chung, 2012). However, very little literature has paid attention to culture as a proxy to explore the characteristics of an apology. A single apology statement may be interpreted differently across cultures (Janssens, Lambert, & Steyaert, 2004). A corporate apology statement is supposed to reflect the prevailing values in a particular society and to follow its accepted social norms. Organizations are likely to create apology statements to satisfy the expectations of the people in the county of its operation; as a result, corporate statements are likely to represent cultural characteristics and communication styles.
The purpose of this study is to investigate the characteristics of corporate apologies in terms of responsibility admittance, sympathetic expression, reassurance, and compensation when cybersecurity breaches threaten corporate reputation. It also examines the use of excuses, the function of an apology, and organizational representation. Last, this study investigates whether national culture (the United States vs. South Korea) may affect the characteristics of corporate apologies.
This study also provides a new context for crisis communication research. There is a lack of research, particularly concerning post-breach analysis in terms of an organization’s crisis response strategy. Previous studies on cybersecurity breaches have mainly focused on information security behavior (e.g., Herath & Rao, 2009; Johnston & Warkentin, 2010), the negative impacts of data breaches on firms’ financial performance (e.g., Acquisti, Friedman, & Telang, 2006; Goel & Shawky, 2009; Schatz & Bashroush, 2016; Yayla & Hu, 2011), and consumers’ withdrawal behavior as a proxy (e.g., Chakraborty, Lee, Bagchi-Sen, Upadhyaya, & Rao, 2016; Janakiraman, Lim, & Rishika, 2018). Thus, looking at an organization’s communication response under a cybersecurity breach crisis is a legitimate context for further investigation.
Literature Review
Cybersecurity Breach
A cybersecurity breach indicates an event in which data that can identify an individual (e.g., name, driver’s license number, social security number, medical financial records, etc.) is endangered by the potential risk of exposure, either in paper or electronic format (Identity Theft Resource Center, 2017). Cybersecurity breaches are irrevocable once personal data are publicized in cyberspace. It is impossible to control the stolen data, and the information can diffuse almost boundlessly in cyberspace.
There is no consensus on the definition of cybersecurity among scholars. Luiijf, Besseling, and De Graaf (2013) explored 18 countries’ national cybersecurity strategies and found that each nation had a different understanding of the issue; furthermore, 6 of these nations discussed cybersecurity without even defining it. Similarly, researchers do not employ unified terms when exploring cybersecurity issues; rather, they choose different words that best fit within the scope of their studies. For example, Prakash and Singaravel (2015) use “privacy breach” in referring to the potential invasion of privacy from information leakage in data mining. Others have used “data breach” to describe the general leakage of health information in the United States (Appari & Johnson, 2010).
Considering the scope of previous studies and contexts, cybersecurity is widely used to indicate the issue as a risk or crisis that needs to be managed, before or after an occurrence (Boyes, 2015; Davis, Garcia, & Zhang, 2009; Öğüt, Raghunathan, & Menon, 2011). A cybersecurity breach incurs both tangible (e.g., loss of sales, increase in expenses, decline in stock value) and intangible (e.g., loss of reputation, eroded customer loyalty) negative consequences to organizations. Scholars have found that cybersecurity breaches negatively affected the market value of corporations (Acquisti et al., 2006; Goel & Shawky, 2009) and the post-breach online shopping intention of customers (Chakraborty et al., 2016). As negative news, data-security breaches can threaten an organization’s invisible assets as well, such as the reputation and credibility of corporations (Veltsos, 2012).
Despite the magnitude of this issue, cybersecurity has rarely been studied in regard to public relations crises. Cybersecurity breaches can happen at the individual, organizational, state, or national level. This study examines cybersecurity breaches at the organizational level when the organization has failed to protect its clients’ personal data.
Crisis Response Strategy
People often describe a bad experience as a crisis; however, not all bad experiences are necessarily crises (Ulmer, Sellnow, & Seeger, 2014). A crisis is much greater than an unpleasant occurrence. More specifically, a crisis is a serious event that can bring about significant damage to organizations (Barton, 1993; Coombs, 2010). Sometimes the existence of an organization can be threatened by the crisis (Fearn-Banks, 2017), and unlike other incidents, a crisis requires substantial resources and careful management-level attention (Coombs, 2010) to restore a situation to its precrisis condition.
A crisis can serve as momentum for an organization to be better or worse (Fink, 1986), depending on how an organization manages it (Coombs, 2010). Communication is critical in crisis management, as information is collected, processed, and disseminated through communication (Coombs, 2010). Successful crisis management can reduce the negative consequences of a crisis and its ensuing reputational damage (Coombs & Holladay, 2005; Kiambi & Shafer, 2016).
From the 1990s, the theory of image restoration (Benoit, 1997, 2015) and SCCT (Coombs, 1995, 2012) have provided a theoretical background for vast amounts of research in the area of crisis management (Avery, Lariscy, Kim, & Hocke, 2010). Benoit’s (1997) theory of image restoration identifies five crisis response strategies: (1) denial, (2) evasion of responsibility, (3) reduction of offensiveness, (4) corrective action, and (5) mortification. The denial and evasion of responsibility are used to eliminate or reduce the organization’s responsibility. Reducing offensiveness and corrective action diminish any negativity associated with the organization. Mortification involves accepting the fault and making an apology. The effectiveness of each strategy is contingent on its situation (Benoit, 1997). An organization should analyze the accusations it faces (blame or offense) and the audience members’ beliefs and values underlying their attitudes. Such an analytical process can provide insights into the particular options that are most appropriate for the situation so as to change people’s attitudes in restoring the organization’s image (Benoit, 1997, 2015).
Based on Benoit’s (1997, 2015) work, Coombs (1995, 2012) developed SCCT, which provides a more systematic framework for crisis managers to select effective crisis communication response strategies for a specific type of crisis. Similar to the theory of image restoration (Benoit, 1997, 2015), SCCT identifies three crisis response strategies: denial, diminishment, and rebuilding. Each strategy has its own advantage in minimizing reputational damage and restoring an organization’s tarnished image in different situations. Crisis managers can choose one of these strategies, based on the level of the organization’s attribution of crisis responsibility (victim, accidental, intentional), a history of similar crises, and prior reputation (Coombs, 2007, 2012).
Both Benoit (1997, 2015) and Coombs (2010) acknowledge that what defines a situation as a crisis depends on the perception of the public, as the meaning of a crisis is socially constructed. Even if an organization is not responsible for the crisis, it can be accused of creating the crisis if the public perceives the organization as culpable. Regardless of the actual causes of data breach incidents, cybersecurity breaches are viewed as an organization’s failure to maintain a reliable security system and protect consumer data. When consumers provide their PII to an organization, there is a tacit agreement between the consumer and an organization that protecting consumer data is a fundamental responsibility of an organization. Therefore, the public will expect the organization to provide an account in order to address the crisis situation (Benoit, 2015), while at least a minimal level of responsibility is attributed to the organization for the crisis. Organizational responses can vary due to the different contexts of each crisis; however, apologies (or mortification) were evaluated as the most effective crisis response strategy by the authors of subsequent research that was derived from the theory of image restoration or SCCT from 1991 to 2009 (S. Kim, Avery, & Lariscy, 2009).
Corporate Apology
An apology is a communicative response that acknowledges guilt for a wrongdoing (Hearit, 2006). When a corporation faces issues for which it has been publicly criticized, it seeks the public’s forgiveness by delivering public apologies to restore its damaged image (Benoit, 2015; Hearit, 2006). Scholars agree that an apology or mortification reduces the negative consequences of a crisis and helps restore the organization’s image or reputation (Benoit, 1997; Benoit & Drew, 1997). Apologies are also known to mitigate public anger (Thomas & Millar, 2008) and retribution against the perpetrating organization (Ohbuchi, Kameda, & Agarie, 1989). Lyon and Cameron (2004) further argue that apologies help corporations gain a prosocial status and favorable image after a crisis.
An apology can comprise various components, but the main components most widely used for a corporate apology include responsibility admittance, sympathetic expression, reassurance, and compensation (Lee & Chung, 2012). Gill (2000) argues that a full apology includes acknowledgement of responsibility, expression of remorse, and intention to prevent future events of a similar nature. Compensation can be added to the main components of a full apology, given that victims’ financial damage or physical loss cannot be fully reimbursed with the other three components of an apology.
The most essential component of an apology includes admitting responsibility or accepting fault for a crisis (Benoit 1997; Benoit & Drew, 1997; Fuchs-Burnett, 2002). When an organization issues an apology, it is assumed that the organization accepts its responsibility, even without an explicit expression of doing so (Pace, Fediuk, & Botero, 2010). Depending on how explicitly the corporation accepts responsibility, the effect of an apology statement can differ. Not admitting responsibility in an apology could result in negative consequences, such as a major loss of reputation (Lazare, 2005). A company can rebuild its reputation through active responsibility admittance; however, passive responsibility admittance does not decrease the victims’ negative feelings when the company is responsible for a crisis situation (Robbennolt, 2003). Some scholars have empirically tested the effects of apology statements with different levels of responsibility admittance (e.g., none, implicit/passive, explicit/active); according the findings of these scholars, an apology statement that actively admits responsibility mitigates the public’s anger more than one that passively acknowledges responsibility (Lee & Chung, 2012; Pace et al., 2010).
Sympathy is perceived in apologies when corporations try to express their understanding and concern for the stakeholders involved in the crisis. An organization can take responsibility for a crisis without expressing any sympathy. A strong sympathetic expression makes apologies appear more sincere (Gobodo-Madikizela, 2002) and has an effect equivalent to when corporations admit responsibility (Coombs & Holladay, 2008). However, expressing concern and sympathy for victims does not necessarily mean that an organization admits responsibility for the crisis (Coombs, 2012). Thus, an organization can express sympathy so as to increase the efficacy of making an apology without taking responsibility.
Reassurance is a corporation’s effort to prevent the same or similar negative event from happening again (Lazare, 2005; Leape, 2012). Furthermore, reassurance can be interpreted as a responsibility component, indicating that actual efforts will be made to ensure that a similar crisis does not reoccur (Lee, 2004).
Compensation refers to offering something that can offset victims’ suffering (Coombs & Holladay, 2008). The form of compensation can vary, such as providing goods, services, or monetary offerings (Benoit, 2015). The victim’s perceived severity of damage or offensiveness of the events can be reduced with compensation; therefore, organizations can strategically use compensation for image restoration (Benoit, 2015). Compensation alone is not a major component of an apology; however, it can increase the likelihood of a successful apology when it is integrated with other components. For instance, Braaten, Cody, and DeTienne (1993) found that an apologetic statement can have a greater impact when responsibility admittance includes compensation.
The four components of an apology stipulate what an apology should include in order to be successful. In the real world, there can be other notable attributes of apologies to consider. An excuse is a type of account that denies full responsibility, while admitting the inappropriateness of an event (Scott & Lyman, 1968). Making an apology indicates admitting responsibility (Benoit, 1997); however, an excuse can appear in apology statements, as well. Apologies involving responsibility admittance can be costly to corporations, as they can be used as evidence in lawsuits against them (Patel & Reinsch, 2003; Tyler, 1997). In this sense, some scholars argue that not admitting responsibility can be a strategic option for organizations when the responsibility is ambiguous or unknown (Coombs & Holladay, 2008).
There are four ways that an organization can reduce or evade responsibility, by emphasizing that (1) the situation was due to inadequate information or a lack of control over the crisis (defeasibility); (2) the crisis was an accidental event (accident); (3) the trigger of the crisis was in response to another’s wrongful behavior (provocation); or (4) the original intent of an action or event was benevolent (good intention; Benoit, 2015). An organization can also use victimization as an excuse strategy. An organization can pose as the victim of a crisis by saying that it was also the unwitting subject of a malicious act (Coombs, 2010).
An official statement of apology is a purposive message that an organization sends to the public. The function of an apology is indicated by its content. The goal of the apology is to protect the public by disseminating two types of information: instructing and adjusting information (Coombs, 2012). Instructing information concerns what needs to be done to ensure the physical safety of victims in a crisis, while adjusting information involves how psychological threats or distress should be handled (Coombs, 2012). Official apology statements regarding cybersecurity breaches may tend to focus on providing adjusting information because a cyberattack is not supposed to be physically harmful to the public. The two types of adjusting information can be about analyzing the crisis situation or expressing concern and sympathy for the victims. People engage in emotional or rational coping strategies to logically understand a crisis situation or to ease their negative emotions, respectively (Jin, 2009). Specifically, people want to know what happened or how the crisis was handled so as to reassure them. They may also need to receive expressions of concern and sympathy to address their psychological suffering (Coombs, 2012). Based on the type of adjusting information, this study classified the functions of an apology statement as (1) providing analytic accounts, (2) expressing concern and sympathy, or (3) both.
Organizational Representation
Not only the content of a statement but also the individual who delivers it is important in realizing the desirable outcome of communication. A spokesperson may appear in the discourse itself (e.g., “I am the manager of . . .”) or may be identifiable in an apology statement through signatures or names at the end of the written statement. For major issues, people expect an individual in a higher position to communicate with the public. Men (2012) stated that a natural association exists between the CEO and the organization, indicating that a CEO can serve as a representative spokesperson regarding an event. A corporation’s reputation is positively linked with the CEO’s reputation (Alsop, 2006) and also with his or her own credibility (Men, 2012).
Several scholars have demonstrated the significant role of the CEO as a spokesperson in a crisis response (Lucero, Tan Teng Kwang, & Pang, 2009; Murray & Shohen, 1992; Turk, Jin, Stewart, Kim, & Hipple, 2012). Specifically, Lucero et al. (2009) found that a CEO needs to come to the forefront when a crisis is a result of the organization’s transgression, or when the crisis negatively affects the organization’s reputation. Presumably, the visibility of a CEO, as part of the response to a crisis, can affect the message’s effectiveness. However, it is still possible that an organization may not identify its spokesperson in its public written statement, or it may use different types of spokespeople, such as other managers, or a collective of individuals using the company’s name.
Along with these key components of an apology, cultural characteristics are also mirrored in apology statements. In other words, the norms of an apology vary from culture to culture (Maddux, Kim, Okumura, & Brett, 2011).
Cultural Differences and Corporate Apology
The definition of culture is a complex entity acquired by people in the process of adapting to given human and physical surroundings (Kluckhohn & Kelly, 1945; Tylor, 1871). Culture includes not only material acquisitions, such as physical artifacts, but also capabilities and habits, such as knowledge, beliefs, art, and customs (Tylor, 1871). As a standardized social procedure (Kroeber & Kluckhohn, 1952), culture tells people what is desirable or what should be avoided within a society. Each culture originated from its own natural setting of society; accordingly, cultures differ from place to place and from time to time.
Diverse perspectives explain how culture influences the way people think, communicate, and build relationships with one another. One of the most popular dimensions of culture is that of individualism-collectivism suggested by Hofstede (1984). The distinction between an individualistic and a collectivistic society is based on the degree to which individuals integrate into or separate themselves from a group (Hofstede, 1994).
People in individualistic cultures see themselves as being independent of their in-groups, favoring values such as individual effort and goals (Hofstede, 1994; Ju & Power, 1998; Triandis, 2001). An intentional action or event is regarded as the result of an individual’s behavior (Morris, Menon, & Ames, 2001; Taylor, 1985). Thus, people’s misbehavior in individualistic societies may result in guilt and a loss of self-respect for individuals (Hofstede & Hofstede, 2005). In contrast, people in collectivistic cultures view themselves as being interdependent within their in-groups, prioritizing collective efforts, group goals, and unquestioning loyalty (Hofstede, 1994; Ju & Power 1998; Triandis, 2001). Therefore, the responsibility for an event is attributed to groups (Morris et al., 2001), and individual misbehavior tends to be associated with shame and loss of face for groups (Hofstede & Hofstede, 2005).
The clarification of culture within an individualistic-collectivistic continuum relates to communication style; an individualistic culture entails mostly low-context communication, whereas a collectivistic culture involves more high-context communication (Gudykunst & Nishida, 1986; Gudykunst, Ting-Toomey, & Chua, 1988). Context refers to “the information that surrounds an event” (Hall & Hall, 1989, p. 6), and the level of context determines whether the meaning is contained in a message itself or outside the context. Relationships concern another context in communication; thus, communication in a collectivistic culture involves a higher level of context.
Communication in a collective culture involves indirect and implicit messages (Hall, 1976). Not everything is stated explicitly in writing or speech in a high-context culture (Nishimura, Nevgi, & Tella, 2008; e.g., South Korea, Japan, and other Middle Eastern countries). Nonverbal communication cues, closeness of relationships, and sociocultural contexts such as social hierarchies or norms greatly influence the communication process in high-context cultures (Hall & Hall, 1989; D. Kim, Pan, & Park, 1998). On the other hand, communication in an individualistic culture mainly concerns whether the message itself is well delivered, given that people in such a culture care less about how the relational context affects the message’s interpretation. Communication in an individualistic culture consists of direct and explicit messages. Most of the information is transmitted as a part of the message in a low-context culture (Hall, 1976; e.g., the United States, Germany, and other Northern European countries). The interpretation of the message tends to be unequivocal (Gudykunst & Nishida, 1994); diverse contexts are less likely to affect the message’s interpretation because what a speaker expresses is actually what he or she intends.
Power distance is another cultural dimension in which countries differ, based on their value orientation. Power distance refers to the extent to which an individual accepts the fact that power in society is unequally distributed (Hofstede & Hofstede, 2005). Power distance serves as a relational norm within the society. When power distance is large, subordinates with less power are unlikely to contradict authority figures (Hofstede & Hofstede, 2005). Large power distance reflects a wider distance between the public and organizations, which would result in the public’s higher expectation of how they want to be treated in their relationship with the organization. The gap between the social positions of the public and the organization will be wider in a crisis situation and will require more effort from the organization to restore the balance of the relationship in a postcrisis situation.
The main research question of this study is whether cultural differences in value orientation (individualism vs. collectivism, large vs. small power distance) and communication style (high- vs. low-context communication) appear in apology statements when cybersecurity breaches threaten the reputation of a corporation. Differences in expressing the four components of an apology may be the result of the different value orientations. Usually collectivistic cultures have larger power distance than individualistic cultures. In a crisis situation, collectivistic cultures are more likely to adopt a highly accommodative strategy to avoid further conflict with the public; thus, organizations may consider using all of the components of an apology to maximize the effect of the response strategy. At the same time, organizations from collectivistic cultures may tend to use more excuses in an apology statement, hoping that the perception of reduced responsibility can help them save face. For example, Sugimoto (1997) compared different response messages created in response to hypothetical offensive events. The result showed that the people from collectivistic cultures (e.g., Japan) were more likely to utilize strategies such as remorse expression, compensation, promises not to repeat the same action, compared with people from individualistic cultures (e.g., the United States; Sugimoto, 1997). However, the response messages rarely contained an explicit assessment of responsibility for the offensive event, regardless of the cultural orientation (Sugimoto, 1997).
With respect to different communication styles, the two types of cultures may recognize the functions of an apology differently: individualistic cultures may use an apology to provide facts in an analytical manner, whereas collectivistic cultures are more likely to use an apology to express an organization’s concern and sympathy in a crisis situation. For example, Maddux et al. (2011) found that people in an individualistic culture (e.g., the United States) tended to regard apologies as analytical statements that assess blame, while those in a collectivistic culture (e.g., Japan) viewed apologies as a mean of expressing remorse. These results align with the idea that individualistic cultures often use explicit expressions, avoiding any uncertainty (low-context message), while collectivistic cultures focus more on the sociocultural context of the communication (high-context message).
Last, the individualistic–collectivistic cultural dimension may affect who appears as an organizational representative in issuing an apology. Individualistic societies are supposed to present an organizational representative as an independent self and individual, whereas collectivistic societies tend to use both an interdependent self and a collective to represent an organization.
Based on the literature reviewed, this study asks the following research questions:
Method
Selection of Data-Breach Cases and Official Statements
A content analysis was conducted to examine 108 official statements issued by organizations in two countries: The United States and South Korea. The official statements are original versions of apology statements published by organizations in the form of website announcements, e-mail letters, and official blog posts. Following the cultural dimension index (Hall, 1976; Hofstede & Hofstede, 2005), the United States represents an individualistic, low-context, and low power-distance culture; on the other hand, South Korea represents a collectivistic, high-context, and large power distance culture. The two countries are similar in Internet access per population (74% in the United States and 89% in South Korea; International Telecommunication Union, 2016), and they have both experienced data breach crises that leaked large amounts of their populations’ personal data in the 2000s. The unit of analysis in this research is a written statement officially released by an organization to handle a cybersecurity breach crisis in the United States and South Korea from 2008 to 2016.
Given that there was no comprehensive source of sampling frame for this study, the convenience sampling method was used to identify a comparable volume of cybersecurity breach cases in the United States and South Korea and their corresponding official statements by organizations.
To identify cybersecurity breach cases in the United States and South Korea, this study used a website called the Gemalto Breach Level Index (http://breachlevelindex.com). This website provides a list of cybersecurity breaches per country around the world. Contrary to expectation, this website provided substantially skewed numbers of cybersecurity cases in the United States (more than a hundred cases) and South Korea (20 cases).
For South Korea, Google’s image search feature was used to secure a sizeable number of cybersecurity cases. Using the search terms “personally identifying information breach cases” and “statement of apology for personally identifying information breach cases,” image files of apology statements were found, while duplicate statements were eliminated from the search results. Cases and apology statements were concurrently identified for South Korea. The total number of apology statements was 54.
Researchers decided to select an equal number (54) of cases with apology statements in the United States for a fair comparison. Because the Gemalto website did not provide apology statements, cases and apology statements were selected in two steps for the United States. First, researchers examined each case from the highest risk score on the Gemalto website and then searched for official apology statements elsewhere, such as organizations’ websites, news articles, legal documents, and blog posts. This search continued until researchers secured 54 cases. Cases were not selected (1) if the organization did not release any written apology statement or (2) if it was impossible to find the original copy of the apology statement.
Operationalization of Variables
The descriptive variables, such as country, industry, source of breach, and type of breach were adopted from the Gemalto Breach Level Index. Country was coded as 0 = the United States and 1 = South Korea. Industry was coded as 0 = education, 1 = financial, 2 = government, 3 = health care, 4 = retail, 5 = technology, and 6 = other. Source of breach was coded as 0 = accidental loss, 1 = malicious insider, 2 = malicious outsider, and 3 = other. Type of breach was coded as 0 = nuisance, 1 = account access, 2 = financial access, 3 = identity theft, and 4 = existential data.
Responsibility admittance was coded as 0 = absence of responsibility admittance, 1 = presence of passive responsibility admittance, and 2 = presence of active responsibility admittance. Passive responsibility was assigned when organizations made general apologies for what happened without specifying responsibility of attribution (e.g., “We are sorry for the incident . . .”). A statement was coded as active only when the responsibility admittance explicitly appeared in the statement (e.g., “We take full responsibility . . .” or “We admit our fault in . . .”).
Sympathetic expression was coded as 0 = absence of sympathetic expression, and 1 = presence of sympathetic expression. A statement was coded as a sympathetic expression when the phrases acknowledged victims’ feelings, pain, or frustration about their loss of personal information (e.g., “We are sorry/regretful for your concern/frustration/inconvenience . . .” or “We join in/understand your pain/frustration . . .”).
Reassurance was coded as 0 = absence of reassurance and 1 = presence of reassurance. A statement was coded as having a presence of reassurance when it explicitly promised to innovate, reform, or restructure the system so as to prevent future data breaches (e.g., “We assure you that we will do everything we can to further secure your data . . .” or “We will do our best to avoid a similar breach from reoccurring . . .”).
Compensation was coded as 0 = absence of compensation and 1 = presence of compensation. A statement was coded as having a presence of compensation when it explicitly offered free privacy protection consultation, service upgrades, discounted fees, and so on.
Use of excuses was coded as 0 = absence of excuses and 1 = presence of excuses. A statement was coded as having a presence of excuses when organizations emphasized the inevitable circumstances under which data breach crises could happen, regardless of their devotion to protecting personal data, or when organizations framed themselves as victims of the crisis, as well (e.g., “Despite our efforts and the state-of-the-art security system, this data breach happened . . .” or “We were the victims of . . .”).
The functions of an apology were operationalized as either analytic accounts or expressions of concern and sympathy in the first paragraph of an apology, given that the opening paragraph is supposed to provide readers with motivation to continue reading. The introduction should capture an indifferent reader’s attention with the most important messages that the organization wants to deliver. The variable was coded as 0 = providing analytic accounts, 1 = expressing concern and sympathy, and 2 = other. Analytic accounts were assigned when organizations provided detailed information, such as how the data breach incidents occurred, and what the corporation did during the crisis situation, as indicated in the opening paragraph of the apology. Expressions of concern and sympathy were assigned when organizations referred to their concern and compassion for the victims in the first paragraph of the apology.
Organizational representation in an apology was operationalized as the signatory authority of an official statement. It was coded as 0 = CEO or president, 1 = all members of the organization, 2 = name of organization, 3 = other managers (public relations manager, human resources manager, or IT manager), and 4 = unknown.
Intercoder Reliability
Two coders recruited from a large Midwestern research university were trained. A pretest was conducted for the coding scheme to meet an acceptable level of inter-coder reliability using all statements. Two coders studied the codebook and coded the content independently. In order to ensure reliability of the coding sheets in two different languages (English and Korean), the original coding sheet in English was translated into Korean. It was then retranslated into English by another translator. Both translators were bilingual and fluent in English and Korean. Finally, the original version of the coding sheet was compared with the retranslated version, and there seemed to be no issues in using the original coding sheet. The intercoder reliability coefficients for all variables were above .83 (Holsti’s formula) and .81 (Cronbach’s alpha), suggesting a good level of agreement between the two coders.
Findings
For Research Question 1, the descriptive statistics for the industry, source, and type of data breach were as follows (see Table 1). The most frequent area of data breaches was retail (25.9%, n = 28), followed by technology (13.9%, n = 15) and health care (12%, n = 13). Organizations in education, finance, and government combined were approximately one fifth of all cases (22.2%, n = 24). Meanwhile, most of the incidents were caused by malicious outsiders (78.7%, n = 85), indicating that hacking activity was the most common cause of the data breach crises. Identity theft (71.3%, n = 77), account access (13.9%, n = 15), and financial access (12%, n = 13) were the most prevalent types of incidents.
Count and Percentage for Country, Industry, Source, and Type of Breach (N = 108).
For Research Question 2, Table 2 presents the chi-square tests of the four components of an apology (responsibility, sympathy, reassurance, compensation) by respective cultural origin (individualistic vs. collectivistic).
Cross-Tabulation of Responsibility, Sympathy, Reassurance, and Compensation by Country (N = 54 for Each Country).
The results showed that responsibility admittance was significantly more visible in the statements from South Korea for both active and passive types (20.4%, n = 11, and 46.3%, n = 25, respectively), while less than half of the statements from the United States actively or passively showed intention of taking responsibility for the incidents (3.7%, n = 2, and 38.9%, n = 21, respectively; χ2[2, 108] = 10.03, p = .007). More sympathetic expression appeared in the statements from South Korea (72.2%, n = 39), compared with those from the United States (63%, n = 34); however, this difference was not statistically significant (χ2[1, 108] = 0.68, p = .411). For reassurance, half of the statements from the United States provided reassurance (55.6%, n = 30), while most of the statements from South Korea did (88.9%, n = 48; χ2[1, 108] = 13.34, p = .000). Regarding compensation, more than half of the statements from the United States mentioned compensation (55.6%, n = 30), compared with a fewer number of statements with compensation from South Korea (11.1%, n = 6; χ2[1, 108] = 22.04, p = .000).
For Research Question 3, Table 3 shows the chi-square tests for the use of excuses, functions of an apology, and organizational representation in the apology by cultural difference (individualistic versus collectivistic). Regarding the use of excuses in an apology, almost half of the of statements from South Korea (46.3%, n = 25) excused the companies, while only a few statements from the United States (14.8%, n = 8) attempted to evade responsibility (χ2[1, 108] = 11.17, p < .001).
Cross-Tabulation of the Use of Excuses, Functions of an Apology, and Organizational Representation by Country (N = 54 for Each Country).
Note. For functions of apology and organizational representation, Fisher’s exact tests were conducted due to the small number of observations in some categories; however, the p values were still lower than any significant α level.
Individual was recoded by combining the CEO or president, and other managers (PR, HR, or IT).
Collective was recoded by combining all members of the organization, and name of organization.
For the functions of an apology, statements from the United States tended to provide analytic accounts in the first paragraph (72.2%, n = 39), whereas apology statements from South Korea tended to express concern or sympathy for the victims first (74.1%, n = 40; χ2[2, 108] = 38.83, p = .000). Additionally, a Fisher’s exact test was conducted due to the small number of observations in some categories and the p value was lower than any significant α level.
As for organizational representation, the most visible organizational representatives were the CEO or president (61.1%, n = 33), unknown (18.5%, n = 10), and other managers (PR, HR, or IT) (14.8%, n = 8) for the statements from the United States, whereas it was unknown (42.6%, n = 23) or appeared as all members of the organization (31.5%, n = 17) or the CEO or president (13%, n = 7) in the statements from South Korea (χ2[4, 108] = 43.69, p = .000). As a complement to the small number of cases in some categories, a Fisher’s exact test was conducted and the p value was lower than any significant α level.
An organizational representation was recoded by combining the CEO or president and other managers (individuals), as well as all members of the organization and name of organization (collectives). The difference between the two countries was still clear: a majority of the statements from the United States were delivered by an individual (75.9%, n = 41), while only a few statements from South Korea (13.8%, n = 8) were communicated by an individual representative (χ2[2, 108] = 42.73, p = .000).
Discussion
The results of this study provide several implications concerning crisis responses to cybersecurity breaches. First, identity theft is the most common type of cybersecurity breach, and almost every industry is vulnerable to this risk. E-commerce and digital payments have rapidly increased as a result of retail shopping online, but cybersecurity technology has not necessarily caught up with the speed of these transactions. Health care organizations digitize and share sensitive patient information, which is at risk of inappropriate dissemination; even the technology industry is vulnerable to hackers and malicious insiders. People today live in risky societies, where the severity of risk and vulnerability of cybersecurity are substantially high, while response and self-efficacy are relatively low. In this climate, public relations professionals are facing cybersecurity crises more frequently than ever before, regardless of the type of organization or industry they represent.
Second, the fact that the internal security vulnerability of organizations was the second major factor in data breach crises should be a wake-up call to many organizations. The combined proportion of malicious insiders and accidental loss accounted for almost one sixth of all breach incidents (16.6%, n = 18). Usually organizations assume that cyberattacks are perpetrated by external factors, such as professional hackers and malicious outsiders. The current study not only confirms this general assumption but also reveals that betrayal by employees and inadvertent mistakes should not be ignored. This can serve as a reminder for organizations of the sheer importance of internal public relations in building and retaining mutually beneficial relationships with their employees.
Third, different cultural origins affect the characteristics of apologies. Our study revealed that South Korean organizations were less hesitant to admit responsibility, in both a passive and active manner. In addition, the statements from South Korea displayed reassurance by vigorously promising that a data breach would never happen again. From the perspective of SCCT (Coombs, 1995, 2012), organizations from South Korea utilized a highly accommodative strategy to minimize potential reputational damage. One possible explanation for this finding is that people from high-context and collectivistic cultures tend to be more affective and intuitive in conflict situations, while members from low-context and individualistic cultures are more likely to be factual and inductive (Ting-Toomey, 1985). Organizations in South Korea might have expected more negative sentiment (e.g., anger and anxiety) from the public; as a result, they may have chosen a crisis response strategy to reduce hostile feelings. Another possible explanation is the way that people from each country manage conflict, based on the level of power distance. In South Korea, there is the saying that “customers are the king”; this expression reflects the large power distance between the public and organizations in South Korea. In a crisis situation, an organization’s position becomes inferior in the relationship with its public when the organization is accused of, or is perceived to be responsible for, the harmful event. On the other hand, the public gains relative power in the relationship within the given situation. Therefore, in large power distance cultures, an organization may make it a priority to avoid immediate (or additional) confrontation with its public and may choose a highly accommodative strategy rather than being defensive in the crisis situation in order to ease public anger and protect the organization’s reputation.
Fourth, the use of excuses, functions of an apology, and organizational representation differed considerably, depending on the national culture. The use of excuses was more visible in the statements from South Korea. The level of reputational damage is closely related to the amount of responsibility that an organization has to manage with respect to the crisis (Coombs, 2007, 2012). By reducing its responsibility, an organization can minimize the negative impact on its reputation. This finding can be interpreted as organizations in South Korea trying harder to avoid blame.
Individuals from low-context cultures are more likely to prefer analytical accounts from messages because they prefer to manage crises in a factual and axiomatic manner (Ting-Toomey, 1985). On the other hand, people from high-context cultures are more likely to favor messages that engage their feelings (Ting-Toomey, 1985). These varying audience expectations are likely to be differently reflected in organizations’ messages to the public. The findings of this study concur with this argument. Statements from the United States (low-context culture) emphasized delivering analytic accounts, while statements from South Korea (high-context culture) tended to express their concern for the incidents and show sympathy for the victims.
Statements from the United States (individualistic culture) were also more likely to come from individual representatives, such as CEOs, presidents, and other managers (PR, HR, and IT). On the other hand, statements from South Korea (collectivistic culture) tended to come from collective group identities, such as all members of an organization and the name of an organization. These findings provide evidence related to how individualistic and collectivistic cultures form different individual and organizational identities, suggesting the need to select organizational representation, based on these findings.
Finally, the relationship between responsibility admittance and the use of excuses as a crisis response strategy may be overlooked when considering the impact of apology statements. The purpose of making an excuse is to reduce one’s responsibility (Benoit & Drew, 1997); thus, one might expect a negative relationship between active responsibility and excuses. However, at least from this study, Korean organizations often showed both active responsibility and excuses. In other words, even when organizations fully accepted responsibility, they still tried to avoid further blame by saying that there could have been no way to prevent the crisis from occurring because they had done everything they could.
There are several limitations to address in this research. First, this study was exploratory in nature and not rigorous enough to make directional hypotheses to test. Second, when comparing the United States and South Korea, there may be factors other than national culture that could affect the differences in the results of this study. For example, organizational culture might affect the outcome of this study because it may differ from the national culture. Ownership and the nationalities of individual CEOs and senior management may also be different from the national culture. Unfortunately, these variables were not part of this study but merit future research. Finally, selection bias exists when identifying cyberbreach crises and apology statements via convenience sampling.
This study offers a great deal of potential for future research. First, future study may use an experimental setting to directly measure the impact of cultural differences on apologies. For example, the efficacy of a certain type of apology statement may be tested by engaging subjects from different cultures. Another interesting study could involve testing the interrelationships among the four apology components and the use of excuses. Second, adopting SCCT (Coombs, 1995, 2012) is necessary to identify the optimal combination of apology statements. This optimal combination, used to minimize reputational damage, will differ, based on the source of the cybersecurity breach. Last, future research may also use data breach cases from the same source, if possible, or may collect data using the identical selection method for both countries so as to avoid sampling bias.
Footnotes
Declaration of Conflicting Interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
