Can you hear the ROAR of software security? How Responsibility, Optimism And Risk shape developers’ security perceptions
preprint
OA: closed
Abstract
How do software developers view issues of secure software development? Drawing upon psychological theories of social identity and cognitive processing, we engage with software engineers about security in their software to illustrate how self-defined social identities affect approaches to development. We also identify behaviours indicative of increased risk of project delays or failure. Professional freelance software developers together with computer science students addressed perceptions of risk and security during development. A thematic analysis extracted three core themes of Responsibility, Optimism and Risk (ROAR). We show how language about responsibility for security is framed through concepts of diffusion, displacement, and acceptance of responsibility. We also examine the way developers orientate to risk awareness, appetites for risk, and risk mitigation strategies. Examples of unrealistic optimism biases are highlighted and discussed. We discuss our findings in relation to psychological theories of responsibility, decision making and heuristics and biases.
My notes (saved in your browser only)
Citation neighborhood (no data yet)
We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.
Source provenance
- europepmc
- last seen: 2026-05-19T01:45:01.086888+00:00