Résumé
This research addresses the determinants of CEOs’ actions regarding the informationsecurity (ISS) of small and medium enterprises (SMEs). This article aims to (a) identify factorsinfluencing CEOs’ ISS actions, (b) examine the relevance of protection motivation theory(PMT) in explaining top management support (TMS, i.e., supportive actions), and (c) findpotential differentiated effects on protective vs. supportive actions.The results of a questionnaire-based survey (N=200) show that the PMT and social influenceconstructs, while explaining a significant amount of variance, exert differentiatedeffects: in contrast with protective actions, which are influenced mainly by self-efficacy, SMECEOs’ supportive actions are strongly affected by the social influence of peers (partners andcompetitors) and customers.At a theoretical level, this research validates the relevance of the PMT framework forthe study of TMS determinants in the context of ISS. This study is also the first to distinguishbetween these two types of actions and offers new insights on CEOs’ ISS-related behaviorliterature. For practitioners, the results imply that even when CEOs do not exert protectiveactions, it is important to build on their professional relations to trigger and enhance theirsupportive actions.