
Despite technological advancements in cybersecurity, phishing emails remain a primary vector for cyberattacks due to their sophisticated exploitation of human psychology. While existing research has examined phishing susceptibility, studies have typically relied on small scale datasets and text analysis methods, limiting our understanding of how these attacks evolve and target specific cultural contexts. This paper addresses this gaps of knowledge by investigating phishing emails targeting the Dutch population through an analysis of linguistic patterns, thematic content, and psychological manipulation techniques. Using a dataset of 8,000 phishing emails, we employ advanced natural language processing techniques, including BERTopic modelling and frequency analysis. Our findings reveal that phishing emails predominantly utilize business and financial terminology, emphasising essential Dutch services. Our thematic analysis of the email contents identifies eight distinct narratives, demonstrating the attackers' detailed understanding of Dutch institutional frameworks. The analysis of psychological triggers shows a sophisticated evolution beyond simple urgency-based tactics, combining elements of authority, trust, and urgency. These insights contribute to understanding modern phishing tactics and suggest the need for improved, contextually aware security training approaches.
Video generation models have opened new opportunities for simulating business processes through realistic visualizations. However, current video generation approaches often fall short of capturing the inherent dynamics and structure of business processes and tend to produce inconsistent simulations that lack the rigor provided by formal process models. To address these limitations, we introduce a novel method termed Petri Net structure-driven video generation, which integrates the inherent structural information from process models to tailor video simulations more closely to the dynamics of business processes. We explore multiple strategies for this tailoring, including i) the use of domain knowledge-rich prompting, ii) a storyboard employing image references extracted from process evidence data, and iii) generated image references informed by process models. We evaluate our method across diverse domains, and demonstrate that the Petri Net structure-driven approach improves the perceived usefulness and consistency of the simulated video, marking a step forward in the use of generative AI for more realistic business process simulation.
Data spaces have become a strategic pillar of Europe's digital agenda, enabling sovereign, legally compliant data sharing within decentralized ecosystems. As data space initiatives evolve, personalized recommendations are increasingly recognized as key use cases. However, traditional recommendation approaches typically rely on centralized aggregation of user behavior data-directly conflicting with the core ethos of data spaces: sovereignty, privacy, and trust. Federated recommendation systems offer a promising alternative by training models locally and exchanging only intermediate parameters to build a global model. Despite this potential, the integration of federated recommendation techniques and data space architectures remains largely underexplored in research and practice. This paper addresses this gap by designing and evaluating a prototype of a federated recommendation system specifically tailored for data spaces and compliant with their underlying infrastructure. Our findings highlight the viability of developing privacy-preserving, collaborative recommendation systems within data spaces, and contribute to the broader adoption of AI across these emerging ecosystems.
As data-driven applications gain traction in smart living environments, ensuring high data quality becomes a critical prerequisite for reliable analytics and Artificial Intelligence (AI)based services. However, due to the wide range of hardware and software providers as well as the variety of use cases in the smart living domain, the resulting data are characterized by highly heterogeneous structures and nesting levels. The diversity of systems, their strong reliance on context, and the rapid growth of Internet of Things (IoT) devices make it difficult to ensure consistency, accuracy, and reliability in data quality assessments within smart living environments. This paper addresses the need for a consistent assessment of data quality within heterogeneous smart living datasets. We present a prototype that generates quality reports for datasets with an unknown structure based on established data quality metrics A Large Language Model component generates structured metadata describing the dataset's structure and suggesting applicable quality checks, which then serve as input for an implemented code base to perform standardized quality checks. This approach not only supports the assessment of data quality within individual organizations but also facilitates cross-organizational assessments, enabling better comparability and evaluation of datasets from different sources or providers. The prototype was evaluated using a variety of synthetic and real-world smart living datasets. The results demonstrate the feasibility of the proposed approach, although certain limitations remain, which are discussed in detail within the paper.
Organizational responsiveness has become critical for organizations, particularly in the software development industry, leading to the widespread adoption of agile methodologies. While agile practices have demonstrated effectiveness in smallscale settings, their implementation at scale introduces considerable challenges related to coordination, communication, alignment, and collaboration between teams and units. Communities of Practice (CoPs) can be a mechanism to address these challenges by connecting roles or individuals interested in a specific topic within the scaled agile setting. However, insights on the role and functioning of CoPs across different large-scale agile contexts remain limited. Therefore, we conducted a literature review that systematically synthesizes 53 empirical studies to examine how CoPs support organizations in successfully scaling agility. Our review provides a consolidated understanding of CoPs as enablers of adopting agile methods at scale, gives recommendations for practitioners, and identifies areas for future research.
In complex digital business ecosystems like MUSIC360, practitioners develop various requirement perspectives concurrently and independently due to time constraints and time-to-market considerations, but by doing so also create alignment issues between these perspectives. We argue that a knowledge graph-based approach enables systematic analysis and reasoning about traceability between these perspectives: in our case, the business value model of the ecosystem, associated data models, and security requirement items. In the knowledge graph, the elements of the business value model (e.g., economic actors), data elements (e.g., data assets), and security requirement item elements (e.g. access controls) are nodes connected by edges representing semantic/logic relationships (e.g., protects, authorizes). We illustrate the use of the traceability knowledge graph using the EU MUSIC360 project. The resulting traceability knowledge graph allows us to identify the perspectives' incompleteness and inconsistency, analyze the causes, and derive suggestions for improving model and requirements quality while using concurrent engineering. Theoretically, we contribute a cross-perspective traceability framework that unifies value-oriented, data-oriented, and security-oriented requirement-related artefacts into a single semantic network, plus reusable traceability patterns and rules to guide early-phase alignment. Practically, we show how to embed traceability analysis into concurrent engineering to improve requirement quality without sacrificing speed.
Data spaces aim to facilitate inter-organizational data sharing using a common governance framework and standardized components. These enable data sharing in a secure and trusted manner and support joint value creation. The fact that data spaces involve multiple stakeholders, data sources, and technical infrastructures leads to complex projects, bearing significant risks. To lower the risks involved when joining or creating data space, a decision framework is necessary that supports the systematic assessment of a data space. In this paper, we developed a feasibility assessment framework that aims to support decision-makers in assessing the viability and potential success of data spaces on a use case level. To develop the framework, we followed a design science research methodology and conducted two design cycles, combining insights from science and practice. We demonstrated the applicability and validity of our framework by applying it to three use cases of established data spaces.
Decentralization and governance can be at odds. Werbach posits that a blockchain will fail if there is no governance, for instance, to resolve disputes, while, on the other hand, the existence of any (in)formal governance structure means there is no longer decentralization: a paradox. This paper discusses that paradox by reviewing empirical input from day- to-day practitioners (blockchain experts) who draw on their practical experience. The findings presented in this paper show an overwhelming rejection of the paradox. This suggests that governance and decentralization coexist. Experts believe that governance provides procedural legitimacy and guidelines rather than centralized control. Governance does not provide decisions; it provides boundaries and guidelines, and sets the procedure of how decisions are being made. In addition, governance is seen as an important mechanism, as it is required to adapt to changes, manage disputes, and ensure legitimacy without compromising decentralization. A key objection to the paradox is that it is a generalization that omits the principle of compromise and the assumption that governance implies control. The study concludes that the paradox is inaccurate and points to the importance of community participation and critical reflection to avoid complacency. However, nuance is needed. Simply rejecting or ignoring the paradox can seriously jeopardize decentralization, while accepting the paradox would imply that there cannot be blockchain governance. The panel of blockchain experts was asked about the need for governance and the relationship between technology and governance. This gave a more philosophical insight into blockchain governance and contributes to an even deeper understanding of governance and decentralization and how they interact.
Six of the nine planetary boundaries have already been crossed, and pressure on most of them continues to rise. This urgent situation calls for a critical examination of our lifestyles to minimize the environmental impact as much as possible. In this paper, we focus on information systems' governance. We propose a method aimed at supporting a systemic approach that enables organizations to control and continuously improve their environmental performance through their business processes. We propose a generic solution that analyzes all utilized resources by considering their environmental impacts using a life cycle-based approach. To facilitate this, we extend the BPMN meta-model by incorporating several environment-related concepts, allowing for the development of environmentally-aware business processes. A prototype demonstrating key features of our approach is also introduced.
Systematic literature reviews (SLRs) are foundational for research but resource-intensive to conduct. With the rise of large language models (LLMs) such as ChatGPT, generative AI (GenAI) tools are being increasingly explored for their potential to support and transform the SLR process. This study presents a systematic review of peerreviewed articles that examine how LLM-based GenAI tools are used in different SLR phases. Following the PRISMA 2020 guidelines, we screened 1,846 publications published since January 2021 until April 2025 and selected 54 for in-depth analysis. Each study was coded by review phase, prompting approach, automation level, validation type and challenges. Our findings show that GenAI is most often used to support in the screening, search, and writing phases, typically through Basic Prompting and under human oversight. While many studies report efficiency gains, concerns remain regarding validity, transparency, and methodological rigor. Moreover, GenAI is frequently applied to isolated tasks but is rarely embedded in a structured, methodologically guided review processhighlighting the need for clearer phase-specific guidance and standards. We offer a structured, phase-specific synthesis that highlights both the promise and the current limitations of GenAI in literature reviews and thereby offer practical recommendations for the responsible use of GenAI in literature reviews.
The continuous evolution of information technologies has long driven business transformation, a trend reinforced by the paradigm shift introduced by cloud computing. In particular, the ability to combine services from multiple cloud providers offers organizations unprecedented scalability, flexibility, and resilience, becoming a catalyst for innovation. However, despite these advantages, organizations face significant challenges in designing cloud architectures that align with multicloud strategies, often resulting in vendor lock-in. In response, we propose a provider-agnostic, function-based solution to model cloud architectures within Enterprise Architecture using the ArchiMate language. Emphasizing modularity and neutrality, the solution abstracts 148 core functionalities from five leading public cloud providers, grouped into three fundamental IT domains: Networking, Compute, and Data. The applicability of the solution was demonstrated through five distinct scenarios, with qualitative and quantitative evaluations conducted on them. The results indicate that this solution effectively reduces vendor lock-in by supporting cross-provider compatibility. It also enhances architectural clarity, simplifies management, and fosters knowledge retention through reusable components, strengthening an organization's ability to manage multicloud and hybrid environments more efficiently.
The rising frequency of cyberattacks, data breaches, and regulatory pressures has increased the importance of board-level involvement in Information Security Governance (ISG). While prior conceptual research has defined six fundamental board roles, how these roles are understood and enacted in practice remains unclear. To address this gap, this study investigates board-level ISG involvement through twelve semi-structured interviews with Chief Information Security Officers (CISOs). Using an inductive thematic analysis followed by deductive interpretive mappings of the six conceptual board roles, the study provides empirical insights into their actual manifestations. Although many aspects of conceptual role definitions align with practice, important nuances emerged, including the reactive and compliance-driven nature of board engagement. In addition to refining theoretical understanding, the paper analyzes board-level responsibilities, challenges, and contextual influences; identifies key barriers to implementation; and proposes future research directions to reduce the gap between boards' theoretical responsibilities and practical activities.
Despite the various potential benefits of diagrammatic representations in the legal domain, empirical evidence of their suitability for use by legal professionals is still scarce. In this paper, we address this gap specifically for BPMN models representing a complex and highly specialized procedure in the Brazilian legal system. We assess whether the model can be used by legal professionals to guide decision making correctly. We further investigate whether the process model is perceived to be easy to use, useful and whether there is an intention to use the artifact, following the guidelines of the Technology Acceptance Model (TAM).
As Cyber-Physical Systems (CPS) become more prevalent in a wide variety of domains, they are increasingly enriched with digital intelligence. Consequently, the role of humans, as well as their interplay with automation, have become important facets of CPS development, which has driven research in Human-Machine Interaction and Teaming. As technology and possible interaction patterns continuously evolve, requirements and system design become moving targets. This makes it challenging to manage complexity, unless the right degree of abstraction is found. Stakeholders involved in development may also easily lose track of the different perspectives on future CPS-supported work realities. Therefore, in this paper, we present a structured design process, using adaptable models to capture role-specific behaviors, communication, and interaction details. Our approach aims to guide stakeholders and establish a traceable engineering process with transparent and informed decisions. We propose a model-based framework for exploring Human-Machine Teaming requirements in the context of CPS. Our layered methodology encompasses defining the system scope, exploring automation scenario variants, detailing functional requirements, and finding an early candidate design. It enables continuous stakeholder control of a CPS development process based on Human-Machine Teaming requirements. A first demonstration and evaluation show its feasibility and applicability in a real-world context.
As a sustainable mobility solution, carsharing contributes to reducing energy consumption and CO2 emissions by complementing existing public transport services and addressing spatial and temporal service gaps through a selective and flexible mode of transport. However, only 8.5 % of German municipalities in rural areas and small towns currently have access to carsharing. Research on the unique requirements of rural areas is scarce. The goal of this paper is to understand the specific needs of rural areas and provide a granular planning map showing expected carsharing demand. Drawing on existing booking data, we develop a demand prediction model based on highly detailed sociodemographic, geographic, and public transportation data. To gain deeper insights into the underlying factors, the prediction model is analyzed using explainable AI methods. Our model achieved an average prediction deviation of 14 %. Feature analysis revealed that incorporating detailed public transport data, as opposed to relying solely on location data of public transport stations, substantially enhanced the model's explanatory power.
In today's world, organizations face increasing complexity and continuous challenges. Younger generations like Generation $Z$ are reshaping workplace expectations by prioritizing autonomy, flexible schedules, and the ability to work remotely. In addition, global crises such as armed conflicts, pandemics, and climate change challenge conventional organizational models. Traditional hierarchical structures, still prevalent in many companies, often lack the agility to navigate such volatility. Consequently, there is a growing demand for organizational models supporting adaptability and fostering innovation. New Work has emerged as a response to these needs, promoting alternative approaches like evolutionary Teal Organizations. These approaches emphasize self-management, wholeness, and a dynamic sense of purpose, enabling organizations to respond more effectively and meaningfully to emerging challenges. Our study investigates the introduction and implementation of New Work practices and principles within software development and IT-intensive organizations through an interview study with practitioners from 20 different organizations in the DACH region. The findings, including motivations, positive effects, challenges, and good practices for New Work adoptions, contribute actionable insights for organizations aiming to adopt New Work.
Most IoT solutions are built in industrial settings and therefore need to comply with various requirements regarding availability, robustness, and reliability. These solutions are therefore expensive, and financial investments are required to build and run them. This article demonstrates how rather simple IoT solutions based on a widespread and readilyavailable technology - Long Range WAN - can be built with low efforts and a positive cost-benefit ratio. The paper focuses on the implications on the business level and is based on five cases that we implemented in southern Germany, covering different purposes and settings. We will also provide guidance when building this kind of IoT solution is recommended. The realworld impact of the article is to provide guidelines for companies, organizations in the public domain or individuals who try to build cost-effective IoT solutions. The paper contributes to the scientific discourse by developing a checklist for decision-making as well as defining cost and benefit types based on the cases.
This article examines how strategic decisions can influence the outcomes of digital transformation in small and medium-sized enterprises (SMEs). Using the example of a German SME, its development is tracked over a three-year period during which elements of Spetzler's Decision Quality Framework were introduced. The study focuses on five specific areas in which decisions played a central role: Data Access, Use of Camera-Based Recognition, Object Tracking, Structural Reasoning, and Warehouse Space Optimization. Based on these use cases, the impact of the project was evaluated using a retrospective joint-assessment based on Spetzler's six dimensions. The results show that the SME was able to improve its decision-making practices in a meaningful way. Although the results are based on a single case, they indicate the potential of evaluating the decision quality in an early stage of Digital transformation. The article is one of the first practical investigations into how ex-ante decision quality methods can be applied in SMEs undergoing digital transformation.
Large-scale multi-objective optimization problems (LSMOPs) face computational challenges due to high-dimensional search spaces and variable correlations. Existing algorithms often struggle to balance convergence, diversity, and efficiency in high-dimensional scenarios. We propose ATSPCA, a two-stage adaptive algorithm employing PCA-guided perturbation. The first stage uses PCA-based dynamic variable screening to identify key decision variable groups, applying adaptive Gaussian perturbation to guide optimization. The second stage enhances convergence and diversity through an improved competitive swarm optimizer (CSO) and reference pointbased environmental selection. An adaptive transition mechanism bridges the two stages. Tested on LSMOP and WFG benchmarks against state-of-the-art large-scale multi-objective evolutionary algorithms(LSMOEAs), ATSPCA demonstrates superior performance.