Skip to content
Research Article Open access CC BY 4.0

Institutional Apathy and Security Fatigue in Information Privacy and Data Security Governance: A Critical Narrative Review of Psychological Limits and Organisational Design

Onyii Henry, Tunbosun Oyewale Oladoyinbo, Oluseyi Peter Adeoye, Christopher Ugbong Akeke, Oluwadayo Mafolasere Olaniyi

Asian Journal of Research in Computer Science · pp. 152–171 · Published 29 Jul 2026

10.9734/ajrcos/2026/v19i8898

Abstract

Information privacy and data security governance increasingly depend on sustained human attention: employees must interpret warnings, follow changing policies, report anomalies, manage credentials, make disclosure decisions and repeatedly consent to data practices. Yet governance arrangements commonly treat attention, motivation and self-control as effectively unlimited. This critical narrative review examines how security fatigue, privacy fatigue, habituation, burnout, cynicism, organisational silence and institutional decoupling interact to weaken protective behaviour and governance legitimacy. Literature published from 1 January 2000 to 20 May 2026 was identified through accessible scholarly indexes, bibliographic databases, disciplinary digital libraries, DOI metadata services, institutional repositories and citation chaining, with foundational earlier works retained where conceptually necessary. Evidence was appraised for design quality, behavioural measurement, temporal ordering, ecological validity, theoretical coherence and relevance to organisational governance. The synthesis indicates that fatigue is not adequately explained as individual carelessness. Repeated low-value warnings, work-impeding controls, opaque privacy choices, excessive policy demands and punitive reporting climates create cumulative cognitive and emotional costs. These costs can produce attentional habituation, rational workarounds, reduced self-efficacy, resignation and silence. At institutional level, audit-oriented programmes may become decoupled from operational risk reduction, allowing training completion, policy acknowledgement and nominal consent to substitute for observed protective outcomes. Evidence is strongest for warning habituation, compliance-cost reasoning, privacy concern–behaviour discrepancies and associations between exhaustion and silence. Confidence is lower regarding long-term causal pathways and the effectiveness of organisation-wide interventions because much of the literature is cross-sectional, self-reported and based on behavioural intention. An integrated burden–efficacy–legitimacy cycle is proposed to explain how security demands, perceived control, organisational credibility and voice climate jointly shape behaviour. Sustainable governance should reduce unnecessary security work, prioritise high-consequence actions, automate where safe, design adaptive warnings, preserve meaningful choice, support non-punitive reporting and evaluate real behaviour and risk outcomes rather than ceremonial indicators.

Cybersecurity culture employee compliance human factors organisational silence privacy fatigue security fatigue usable security institutional decoupling.

Cited by 0

No indexed citations yet.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

0

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.