Studies
8 studies · CSV
- Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital Tolsdorf et al. (2025). Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25) Susceptibility and intervention effectiveness varied sharply by staff group, and risk from a few phishing emails lingered about three days. Technical measures (filtering, in-email warnings) worked best, generic [EXTERNAL] tags did little, and some staff reacted to the simulation with fear, shame, guilt, and hostility.
- Cyber security fear appeals: unexpectedly complicated Renaud & Dupuis (2019). Proceedings of the New Security Paradigms Workshop (NSPW '19) A review of the wider fear-appeal literature finds real disagreement over whether fear appeals are helpful or advisable, and wide variation in how cyber security fear-appeal experiments are designed. The authors propose a standard protocol for such studies.
- Moving from a ‘human-as-problem” to a ‘human-as-solution” cybersecurity mindset Zimmermann & Renaud (2019). International Journal of Human-Computer Studies, 131, 169-187 A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.
- Is the responsibilization of the cyber security risk reasonable and judicious? Renaud et al. (2018). Computers & Security, 78 Argues that governments shifting cyber risk onto individual citizens ('responsibilization'), by issuing advice and leaving consequences to them, is contributing to cybercrime's success. Proposes a more active risk-regulation regime instead.
- Scaring and Bullying People into Security Won't Work Sasse (2015). IEEE Security & Privacy, 13(3), 80-83 Argues that people heed reliable, credible risk signals, but high false-positive security mechanisms teach users to ignore them. Instead of scaring, tricking or bullying users, security needs more accurate detection and less obstructive tools.
- Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations Siponen & Vance (2010). MIS Quarterly, 34(3), 487-502 Employees' rationalizations for rule-breaking ('neutralization' techniques from criminology) explained intentions to violate security policy better than deterrence theory's sanctions. The authors argue policies should address these rationalizations.
- User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach D'Arcy et al. (2009). Information Systems Research, 20(1) User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.
- Users are not the enemy Adams & Sasse (1999). Communications of the ACM, 42(12) Insecure password practices (e.g., writing passwords down, linking passwords) stemmed from memory overload and poorly designed policies, not user carelessness. Security departments that withheld information and treated users as a threat worsened motivation and compliance.