
The shift towards digitized identities and electronic ID cards presents significant information security management challenges for identity organisations like the NIA. The transition from securing paper records to electronic records and digital assets, such as citizen biometrics, is critical due to the potential implications of security issues on transactions requiring citizen identification and the protection of citizens' privacy. Our study, based on interviews with nine current and former senior managers of the NIA, reveals that the NIA faces unique challenges due to its nature as a public sector organisation and the political context within which it operates. These challenges include taking a holistic view of information security, instilling an information security culture, developing comprehensive information security policies, and ensuring policy compliance. Additionally, the NIA struggles with aligning its information security policies with relevant legislation, managing relationships with other government stakeholders and private sector organisations, and operating within government constraints. These challenges have significant implications for the NIA and other identity organisations facing similar issues. Understanding and addressing these challenges can enhance information security management, safeguard digital assets, and ensure citizen privacy. However, these challenges occur in a context where management continuity is difficult due to political appointments and interference. These challenges are not unique to the NIA, as identity organisations in other developing countries face similar issues. Further research is needed to best address these challenges and ensure secure digitised identification.
Older adults are particularly vulnerable to phishing attacks. Gamification has been shown to be less effective to develop confidence in distinguishing between genuine and phishing emails in this demographic. To overcome this, we present our novel, open source interactive training platform, Phish&Tips, based on a simulated inbox. Our multi-analysis approach provides comprehensive data that enables us to compare participant's self-assessed competence with their performance on the training platform. We present results based on pre- and post-training surveys, focus groups and the analysis of the training platform data (N = 37). Over half the participants demonstrated an improved understanding of various detection strategies and an increase in confidence in being able to interpret emails. However, these results were not evident in the analysis of the platform data. This disparity between participants' perceived knowledge and their performance on the platform highlights the challenges of applying their knowledge effectively.
Addressing the global challenge of digital piracy, this study concludes a research series that explores the multifaceted drivers behind copyright infringement activities. Integrating findings from a PRISMA-guided systematic literature review and the application of behavioural psychology through the Theoretical Domains Framework (TDF), this work identifies key factors of digital piracy, including accessibility, awareness, education and social and cultural influences, alongside a consideration of previous behaviour. Crucially, the research leverages expert reviews analysed through ATLAS.ti, enhancing the development of the Digital Piracy Conceptual Framework (DPCF). The study's findings, derived from interviews with one (1) participant from each of the six (6) sectors, provide sector-specific insights that, while informative, should not be interpreted as broadly generalisable across industries. This detailed approach has refined the DPCF, offering a comprehensive blueprint for devising effective digital piracy intervention strategies, marking a significant step towards mitigating this pervasive issue and protecting intellectual property rights globally.
Risk analysis is a key activity for organisations that are looking to protect their valuable information assets against threats, such as malicious actors. It is one of the essential parts of risk management and is used to justify and prioritise what assets require the attention of which potential security controls. Risk management, and more specifically, risk analysis, is an activity that should be performed continuously. However, recent studies indicate that this is not always the case. As such, this paper investigates risk analysis as it is performed in practice in different Swedish public sector organisations. The results are based on semi-structured interviews with 17 senior security experts, an analysis of standards, and a national method support aiming to fill the gap between standard and practice. The results are presented in three themes: how, when and why risk analysis is performed. Of note, we identify that there is an issue of overlooking specific assets or systems when establishing an organisational-wide risk profile and a general recognition of the necessity for risk analysis, albeit not always in alignment with a classic risk analysis.
Phishing is a danger to both private users and businesses. Industry and academia have proposed several approaches to deal with this threat, many of which developed with a supposedly human-centric design. Yet, to our knowledge, there is no research focused on the misconceptions that users might have on phishing. This glaring gap is a problem, as previous research has shown that not engaging with the mental model of users can lead to lack of effectiveness of an approach in the real world. To address this gap, we conducted a systematic literature review starting from papers published at CHI in the last ten years, and expanding to other venues through a backward and a forward search based on the initial relevant CHI papers. We identified 15 misconceptions about phishing in 21 papers that researchers should address in their solutions to enhance the effectiveness of their approaches.
The African continent is a veritable cornucopia of opportunity for information security threat actors with large number of organisations that fall victim to security attacks and breaches every year. Despite the prevalence of attacks, many organizations lack comprehensive security strategies, leaving them vulnerable. The human aspect of information security, specifically human behaviour, is of great concern. While many studies focus on the security behaviour of the individual, preciously few studies delve into the evaluation of security group behaviour, which makes group behaviour in this context an under-researched field. Behavioural threshold analysis has been established as a method to measure and predict security behaviour in groups and can be used by organisations to evaluate the security awareness and assess behaviour of the members of the organisations. This research describes the application of information security behavioural threshold analysis in the context of the South African retail sector. This research contributes to the sparse literature on security group behaviour by conducting an empirical evaluation of a South African retail organisation's security group behaviour. Practical contributions include the measurement and analysis of a number of security focus areas and predictions on the eventual group behaviour, and recommendations for addressing these through awareness programmes and group behaviour dynamics.
The SolarWinds attack of 2020 was one of the most impactful cyberattacks on the US. Our interdisciplinary research team had the opportunity to observe and analyze the human aspects of the corresponding incident response as it unfolded. Four main themes were identified through a series of interviews and incident observations. This led to an understanding of the importance of establishing the following for highly effective and efficient incident response teams: 1) a portfolio of tools for increasing communication, collaboration, comfort level, and cohesion, 2) a team with diverse education, training, and experience, especially military leadership experience, and 3) teams with long established relationships to achieve high levels of trust, cohesion, and resilience. Ultimately, this analysis resulted in recommendations for further enhancing teams operating at this scale and intensity.
Despite the efforts to mitigate the risks posed by social media, no organisation can be completely protected from hackers. Therefore, specialists are increasingly relying on the training and education of the organisations' workforce to prevent cyberattacks. To investigate the best training strategies available, we have conducted a survey among a large and diverse sample of employees working in various sectors, and we have interviewed people who possess expertise in policymaking and cybersecurity training-either as trainers or trainees. Our analysis reveals that the efficiency of cybersecurity training varies among individuals due to aspects such as motivation, simplicity, the expertise of the trainer, the experience of the trainee, the training environment, customisation, and the delivery methods employed. Moreover, we have concluded that cybersecurity training is contingent upon the trainees' specific job roles within the organisation. Our findings have the potential to improve cybersecurity training, as well as the productivity of the trainers involved in its development.
Cyberattacks pose a persistent threat to organizations worldwide. These attacks often target employees as entry points to organizational systems through tactics like phishing and credential theft. Recognizing employees as an organization's "last line of defense", motivating employees toward security-compliant behavior becomes paramount. While existing literature investigates theoretical frameworks for enhancing individuals' motivation, studies regarding their practical implementation within organizational contexts remain scarce. This paper seeks to address this research gap by exploring how organizations motivate and incentivize security-compliant behavior among employees in Germany. We conducted semi-structured interviews with 18 participants from diverse organizational backgrounds, illuminating the topic from three perspectives: Executive managers, security specialists, and regular employees. Utilizing a classification derived from existing literature, we examine our findings to identify which motivational strategies are currently implemented effectively within organizational contexts. On this basis, we offer a set of actionable recommendations on how organizations can enhance and complement existing motivational strategies.
This study proposes three measures for assessing the survival of beliefs in a population subjected to a disinformation attack. The intent of these three measures was to simplify the task of assessing damage effects arising from disinformation attacks, and provide a means for comparing the relative effectiveness of alternate defensive or damage mitigation strategies. To define these measures and to bound the measures problem, disinformation attacks are characterised, disinformation effects and propagation behaviours are surveyed and summarised. Nine attributes are identified spanning scalability relative to a population and disinformation attack, propagation media independence, target attributes, media propagation attributes, effects of uncertainty, use of established models, probabilistic measures, and measurement methods. The three proposed measures were critically assessed against these nine desirable attributes. The three proposed measures are capable of capturing the aggregated effects of a disinformation attack, exposure effects produced by propagation through channels such as digital media, and the direct effects against the individuals or population being subjected to an attack. The separation of exposure and cognitive effects makes these measures suitable for use in defensive or damage mitigation strategies that include measures against disinformation propagation, and measures to increase individual or population resistance to disinformation.
Multi-Factor Authentication (MFA) is commonly suggested as a good mechanism to overcome inherent security problems with the use of passwords. However, research suggests that MFA has so far failed to attract enough interest from users. Additionally, older users seem to be even more reluctant to use MFA. In Sweden, users are more or less required to use MFA to use services such as online banking, book doctors appointments online, and complete tax reports online. As such, Sweden is an interesting case for studying MFA adoption. This paper reports on mixed-methods research investigating how Swedish users in different age groups compare with respect to the adoption of MFA. The results suggest that users of different age are willing to adopt MFA when it is required for services they want or need to use. However, younger users appear to be more prone to voluntarily adopt MFA.
This research paper aims to build and explore a Linux kernel module capable of logging keystrokes that a user would make on a Linux-based system. The module captures credentials which is a process known as keylogging. The kernel of the operating system manages all resources and data, and a breach in this area is a serious information security risk. This paper provides substantial evidence that kernel-level keyloggers are a very serious risk to information security in operating systems and computer systems in general. Such keyloggers can log user information, such as passwords, usernames and other information without much of the user's knowledge.
Insecure user behavior is the most common cause of cybersecurity incidents. Insecure behavior includes failing to detect phishing, insecure password management, and more. The problem has been known for decades, and state-of-the-art mitigation methods include security education, training, and awareness (SETA). A common problem with SETA is, however, that users do not seem to adopt it to a high enough extent. When users are not adopting SETA, its intended benefit is lost. Previous research argues for personalized SETA and suggests that different user groups have different SETA needs and preferences. The characteristics of those groups are, however, unknown. To that end, this research draws on an existing dataset to identify how different populations perceive different SETA methods. A quantitative analysis shows that users in different demographic groups have different SETA preferences, with age being the most impactful demographic. A qualitative analysis reveals further factors that impact user adoption of SETA, with cost and ease of use being important factors for further research.
This paper examines high-level gamification properties, including mechanics, principles, engagement, and cybersecurity considerations suitable for educational settings. Utilising a literature review, the study consolidates these facets. Through this synthesis, the paper aims to present a unified understanding of gamification's theoretical constructs and its pragmatic implications in education, specifically focusing on imparting cybersecurity concepts. A set of five properties that describe gamification in cybersecurity training is identified. The properties are described, and the relationship between the properties is described. The properties and their relationships form a foundation when developing cybersecurity training games.
Cyber-attacks are increasing at an exponential rate, targeting organisation irrespective of size. Small to medium sized enterprises (SMEs) are particularly vulnerable yet often lack cybersecurity awareness. This entails that an individual or organisation becomes aware of the cyber threats they face in addition to the protective actions and behaviours they can take. Despite the positive intentions of current cybersecurity awareness initiatives, there is a lack of adoption by SMEs. To better understand the situation this study explores SME owner or manager perceptions of cybersecurity awareness messages, leveraging psychological heuristics and message framing. Empirical data was collected through interviews with 16 participants representing SMEs in the North-East of England. Findings reflect that the framing of messages towards fear is more accepted by SMEs as opposed to positivity messages. Moreover, heuristics of self-efficacy and cost are seen to instil a desire to comply with cyber security behaviours. However, not all SMEs could agree on an approach thus suggesting that SMEs require bespoke messaging relating to the businesses and the owner.
Security Education, Training, and Awareness (SETA) is considered among the prominent strategies to develop a cybersecurity culture. Even though many SETA programs have been developed, their effectiveness is questionable as evident by the ongoing struggle of organizations to create a sustainable cybersecurity culture. A key factor that often challenges the design of effective SETA programs is the lack of expertise to create engaging and tailored initiatives to influence employees changing their unsafe behavior and adopting best practices. To address this challenge, organizations can leverage the expertise from multiple cybersecurity career roles, formulating a strong SETA development team that can exhibit a diverse range of perspectives and skills which are essential to design impactful SETA programs. Enabling such a collective design and development approach might be a solution to the pursuit of achieving a sustainable cybersecurity culture. This research work identifies: 1) the core knowledge areas and transferable skills that professionals responsible to design effective SETA programs should demonstrate, 2) which career roles in the ENISA European Cybersecurity Skills Framework cover relevant knowledge areas and transferable skills, 3) the prominent career roles for demonstrating knowledge and skills across multiple essential areas for SETA program development, and 4) the significance of lifelong learning in cybersecurity for developing sustainable SETA programs.
Digital technology is incredibly crucial in today's world. The use of technology is considered a right for both able and disabled users. Accessibility and security are two important concepts in the technology context. Accessibility refers to the level to which a product or service is designed to be utilized by people with disabilities. While security focuses on protecting a product or service from threats and harm. Accessible security refers to the practice of ensuring that digital products and services are not only secure but also accessible to everyone, including people with disabilities. Numerous studies have been conducted on the usage of technologies among people with disabilities. However, little research has been undertaken on accessible cybersecurity. Understanding encounters of disabled individuals with cybersecurity challenges can help develop more accessible and secure technologies and improve user experience. The first step to improving the accessibility of cybersecurity safeguards for users with disabilities is assessing their attitudes and needs. The aim of the study is to explore the cybersecurity attitude, behavior and awareness of people with various types of disability. The survey used to determine the most significant gap for people with disabilities in the accessible cybersecurity context to help them better handle and understand cyber threats in their everyday lives. The survey findings point out that having cybersecurity awareness does not always result in preventing security breaches. There is a gap between theoretical knowledge and practical application. There is a notable concern regarding insufficient technological safeguards. Recommendations are included for software developers to create a more accessible and secure digital environment.
The ability to handle threats, such as disinformation, manipulation of public opinion, and disruption of critical supplies, is becoming increasingly important, thus, necessitating, among other strategies, efforts to establish a proper risk communication to the public. This paper addresses the need for more empirical research in this area to contribute to the development of an in-depth understanding of public risk communication that includes information-related threats and cyber issues. The study involves officials of three public organizations entrusted with safety and security in society: the police, the rescue service, and the county administrative board of a county in the middle of Sweden. The results detail the recognition of risks to be communicated, the organization of the communication process, the messages that these actors seek to bring forth, and to whom as well as challenges of public risk communication in the digital era. The findings indicate that information-related and cyber risks are increasingly essential to consider as an additional layer of public communication. Two implications emerged as particularly important: (1) all communication about risks and crises must consider the systemic risk of mis- and disinformation, and (2) tailored communication about the risks interrelated with disinformation should use human-centered, dialogue-based, and moderated approaches. Further research can focus on associated challenges, considering the distribution of responsibilities, inter-organizational information sharing and cooperation, and the possibly stochastic effects on critical (information) infrastructures and, ultimately, societal values.
Ensuring the safety and well-being of young children in online environments has emerged as a critical priority. This paper introduces a cybersafety curriculum for pre-school learners through The CyberSmart Squad, a group of animated characters based on the Big Five in South Africa. The overarching focus of The Cybersmart Squad is that learners should use 'superpowers' of Courage, Kindness, Safety, Respect and Honesty whether on the 'real-life playground' or in the 'digital playground'. The competencies of Digital Citizenship Identity, Cyberbullying Management, Critical Thinking and Digital Empathy are encouraged through this cybersafety curriculum. This paper introduces The CyberSmart Squad curriculum, and related content, and uses the spiral curriculum approach to integrate cybersafety topics into the pre-school curriculum in South Africa. By empowering young children with essential cybersafety skills from an early age, this curriculum aims to contribute to building a foundation for lifelong digital citizenship in an increasingly digital world.
Small and Medium-Sized Enterprises (SMEs) share many of the same cyber security needs and challenges as larger organisations, but often have significantly less knowledge and capability to deal with them. One of the fundamental issues can be where to find information in the first instance, to explain the nature of cyber threats and the subsequent actions that SMEs should be taking. In many cases, the natural route for interested or concerned SMEs is to seek and refer to related guidance that can be found online. However, this in itself can be a challenge considering the volume and variety of sources that can be located as a consequence. This paper investigates and analyses the situation, based upon a sample of over 30 UK-based guidance sources, and an assessment of their coverage, completeness and clarity. The results reveal that there is indeed a significant diversity in the materials that SMEs may be presented with, and this in turn could lead to inconsistent and potentially ill-informed decision-making. Additionally, in many cases, there will be a limit to how far the online support will take them, with the potential that questions remain unresolved, and SMEs could be more confused as a result of their efforts.