Companies often turn to a powerful emotion to get employees to be vigilant about cybersecurity. They scare them.

If you do this, or don’t do that, something awful will happen. Click on phishing messages, and the company’s network will be exposed to hackers. Use simple passwords, and your personal files will get stolen.

The problem: Fear doesn’t work. Sure, it may get people to act in that moment. But scare tactics don’t get people invested in security over the long term, as Marc Dupuis of Washington University and I discovered in research last year.

In fact, it can do the opposite. That is because fear can leave employees in a constant state of anxiety, which makes them unable to think clearly about threats. Alternatively, such heavy-handed, scare messaging can make employees disgruntled and uninterested in security, thinking that the threats are exaggerated—and that bosses don’t trust them to do the right thing.

But fear not. Although scaring employees may not be an effective way to keep them vigilant, there are other tools that do work. First, let’s dig deeper into why fear doesn’t work.

This post first appeared on wsj.com

You May Also Like

FEC’s National Enquirer fine is a win for democracy. But it lets Trump off the hook.

This week, the Federal Election Commission notified Common Cause that it has…

Milwaukee Brewer teen outfielder signs $82 million deal before ever playing in an MLB game

NASHVILLE, Tenn. — Outfielder Jackson Chourio agreed to the largest contract for…

Silicon Valley county becomes first in U.S. to declare loneliness a health emergency

Loneliness is officially a health emergency in California’s San Mateo County, which…

Facebook Pauses Instagram Kids Project

Adam Mosseri, head of Instagram, said the company wants talk to parents,…