The increasing volume of cyber threats, combined with a critical shortage of skilled professionals and rising burnout among practitioners, highlights the urgent need for innovative solutions in cybersecurity operations. Generative Artificial Intelligence (GenAI) offers promising potential to augment human analysts in cybersecurity, but its integration requires rigorous validation of the fundamental competencies that enable effective collaboration of human-GenAI teams. This research study employed a mixed-methods research project designed to evaluate human-GenAI teams, emphasizing the role of expert consensus in shaping the experimental assessment of the Fundamental Cybersecurity Competency Index (FCCI) in a commercial cyber range. We engaged 20 Subject Matter Experts (SMEs) in a panel to validate the fundamental cybersecurity Knowledge, Skills, and Tasks (KSTs), which are the measures of competencies. The expert panel refined the cybersecurity scenarios and experimental procedures used in hands-on simulations, ensuring they align with current standards outlined in the United States (U.S.) Department of Defense (DoD) Cyber Workforce Framework (DCWF). Our findings indicated that 46 of 47 fundamental cybersecurity Knowledge, Skills, and Tasks (KSTs) were validated by the SMEs as essential components of the FCCI. The validated scenarios and experiments pave the way for future research on assessing cybersecurity competencies in a commercial cyber range with and without GenAI support (e.g., large language models such as ChatGPT). By establishing the baseline for competency assessment in this research, the SMEs’ feedback contributed to advancing cybersecurity workforce development and provided critical insights for integrating GenAI into collaborative cybersecurity human-GenAI teaming operations.
This study examined how influencer power (reach) and tier (number of followers) relate to social media engagement and personal information sharing, noting fluctuations of both over time. A combination of content analysis and machine learning methodologies was used to analyze the content of social media conversations and determine the general trends of engagements and disclosures over time. While most discussions were started by influencers, some viral content came from non-influencers. Around 29.41% of posts (N=122,904) included personal identifiable information disclosures. The study provides insights into the dynamics of social media engagement and personal information sharing, demonstrating a strong correlation between influencer reach, increased engagement and disclosures, and a decline of both engagements (79.78% of threads) and disclosures (66.12% of threads) in a sample of 183 conversational threads over time.Results confirmed all hypotheses, revealing a strong link between influencer reach, increased engagement, and personal identifiable information disclosures. The higher rate of personal information disclosures necessitates additional caution in influencer-led marketing activities to mitigate potential privacy risks with the audience. Social media users should also take care when interacting with influencers and be more selective in their sharing patterns to protect their personal information. Further research is required to continue refining influencer identification methods and examining their impact within community-based social media platforms.
The desire to “debunk” false information is a shared goal among government, social media platforms, and society. How can organizations determine whether a debunking technique is effective? Noting that simply debunking misinformation may not affect its spread, the user actions (clicking or not clicking on like, share, or comment) on postings need to be studied independently from whether a user finds a posting credible. New debunking techniques are routinely adopted social media platforms. Although popup warnings have been available for quite some time, these warnings have been newly repurposed by some platforms as a debunking tool. As such, this study focused on the effects of message popup warnings on credibility and effectiveness (user actions or inactions).
The currently most used method for authentication is the password because it is simple to implement, and computer users are very familiarized with it. However, passwords are vulnerable to attacks that can be mitigated by increasing the complexity of the chosen password, particularly in terms of length. One possible approach to accomplish this is through the usage of passphrases, which can be easier to remember than a standard password, thus reducing the loss of work time and productivity related to forgotten passwords. To achieve the required balance between complexity and memorability, the concept of passphrase categories can be used, i.e. more sensitive accounts or services should have more complex passphrases, and vice versa. This work-in-progress study proposes to develop and assess a method for educating users into creating complex, yet easy to remember passphrases, according to the category of account or service they want to protect. The work-in-progress study will be developed in three phases, including validation of the method by a panel of subject matter experts, a pilot test, and a main data collection and analysis phase.
Social engineering costs organizations billions of dollars. It exploits the weakest link of information systems security, the users. It is well-documented in literature that users continue to click on phishing emails costing them and their employers significant monetary resources and data loss. Training does not appear to mitigate the effects of phishing much; other solutions are warranted. Kahneman introduced the concepts of System-One and System-Two thinking. System-One is a quick, instinctual decision-making process, while System-Two is a process by which humans use a slow, logical, and is easily disrupted. The key aim of our experimental field study was to investigate if requiring the user to pause by presenting a countdown or count-up timer when a possible phishing email is opened will influence the user to enter System-Two thinking. In this study, we designed, developed, and empirically tested a Pause-and-Think (PAT) mobile app that presented a user with a warning dialog and a countdown or count-up timer. Our goal was to determine whether requiring users to wait with a colored warning and a timer has any effect on phishing attempts. The study was completed in three phases with 42 subject matter experts and 107 participants. The results indicated that a countdown timer set at 3-seconds accompanied by red warning text was most effective on the user’s ability to avoid clicking on a malicious link or attachment. Recommendations for future research include enhancements to the PAT mobile app and investigating what effect the time of day has on susceptibility to phishing.
We are happy to present four articles solicited from the many conference presentations at OLC Accelerate, held in fall 2021 and OLC Innovate, held in spring 2022. We encourage readers to continue to conduct research on innovation in the field and to consider presenting your rigorous research to OLC conferences and OLJ in the future.
Each year, OLJ presents a special section devoted to research shared at the Online Learning Consortium conferences. We are happy to present five research articles selected from the many presented at OLC Accelerate, held virtually November 9-18, 2020 and OLC Innovate, held virtually March 15-19, 2021. We invite the readers to consider presenting their research to OLC conferences in the future and submitting to OLJ to share their work with others in the field.
We reflect on our process of working with an adapted framework as an effective strategy for analyzing and interpreting the results of our qualitative study on the lived experiences of insulin pump trainers. Interpretative Phenomenological Analysis (IPA) was applied as the overarching research methodology and was encapsulated into a framework adapted from Bonello and Meehan (2019) and from Chong (2019). We describe this framework as the “embodiment of discovery” to posit the researcher’s tangible experience of discovering the meaning of data that also brought transparency to the researcher’s process for data analysis and interpretation. We present challenges the doctoral student researcher experienced working with the framework through three phases and various steps performed during the analysis. We recommend the framework may assist novice researchers as a tool for wayfinding and scoping the structure of data analysis and interpretation. We conclude that novice researchers should not fear finding their “embodiment of discovery” in adapting creative or alternate methods for qualitative analysis.
PurposeThis study introduces the concept of audiovisual alerts and warnings as a way to reduce phishing susceptibility on mobile devices.Design/methodology/approachThis study has three phases. The first phase included 32 subject matter experts that provided feedback toward a phishing alert and warning system. The second phase included development and a pilot study to validate a phishing alert and warning system prototype. The third phase included delivery of the Phishing Alert and Warning System (PAWSTM mobile app) to 205 participants. This study designed, developed, as well as empirically tested the PAWSTM mobile app that alerted and warned participants to the signs of phishing in emails on mobile devices.FindingsThe results of this study indicated audio alerts and visual warnings potentially lower phishing susceptibility in emails. Audiovisual warnings appeared to assist study participants in noticing phishing emails more easily and in less time than without audiovisual warnings.Practical implicationsThis study's implications to mitigation of phishing emails are key, as it appears that alerts and warnings added to email applications may play a significant role in the reduction of phishing susceptibility.Originality/valueThis study extends the existing information security body of knowledge on phishing prevention and awareness by using audiovisual alerts and warnings to email recipients tested in real-life applications.
Phishing emails, also defined as email spam messages, present a threat to both personal and organizational data loss. About 93% of cybersecurity incidents are due to phishing and/or social engineering. Users are continuing to click on phishing links in emails even after phishing awareness training. Thus, it appears that there is a strong need for creative ways to alert and warn users to signs of phishing in emails. ‘System 2 Thinking Mode’ (S2) describes an individual in a more aware state of mind when making important decisions. Ways to trigger S2 include audio alerts, visual alerts, and haptic/vibrations. Assisting the user in noticing signs of phishing in emails could possibly be studied through the delivery of audio, visual, and haptic (vibration) alerts and warnings. This study outlines the empirical results from 32 Subject Matter Experts (SMEs) on an initial prototype design and development of an email phishing alert and warning system. The prototype will be developed to alert and warn users to the signs of phishing in emails in an attempt to switch them to an S2 state of mind. The preliminary results of the SMEs indicated that several features for a phishing alert and warning system could be assembled, resulting in a mobile phishing alert and warning prototype. Visual icons were chosen for each sign of phishing used in the prototype, as well as voice over warnings and haptic vibrations. The preliminary results also determined task measurements, ‘ability to notice’, and ‘time to notice’ signs of phishing in emails.
We are happy to present five articles selected from the many presented at OLC Accelerate, held November 19-22, 2019 in Orlando, Florida and OLC Innovate, moved from Chicago to a virtual conference in June 15-26, 2020. We invite the readers to consider presenting their research to OLC conferences in the future.
The desire to maintain an independent lifestyle is one shared by an increasing number of older adults. Adult children, spouses, siblings, and other relatives, also known as family caregivers, play an integral role in helping their loved ones maintain independence. Remote monitoring technologies (RMTs) such as wearable sensors, mobile emergency devices, smartphone apps, and webcams can be used to monitor, sense, record, and communicate a person’s daily activities. However, understanding is limited of the family caregiver’s needs and perceptions of RMTs used in a home-based setting. The purpose was to explore how family caregivers perceive RMTs and their use for monitoring and supporting their care recipients who choose to live independently. We used a survey to capture some basic characteristics of family caregivers, what they know about RMTs, and to recruit interview participants. We conducted semi-structured interviews with four participants who shared the commonality of caring for a relative with dementia. We reported the survey data using descriptive statistics and we applied interpretative phenomenological analysis (IPA) to analyze and report results from the interviews. Four themes emerged including the unique relationships that exist in family care, the risk-benefit conundrum that accompanies benefits and tradeoffs of RMT use, human-technology interaction and usability, and the importance of creating tailored solutions to facilitate RMT adoption and use. Our findings provide insight into factors impacting adoption and use.
Insider threat mitigation is a growing challenge within organizations. The development of a novel alert visualization dashboard for the identification of potentially malicious cyber insider threats was identified as necessary to alleviate this challenge. This research developed a cyber insider threat dashboard visualization prototype for detecting potentially malicious cyber insider activities QUICK.v™. This study utilized Subject Matter Experts (SMEs) by applying the Delphi Method to identify the most critical cyber visualization variables and ranking. This paper contains the detailed results of a survey based experimental research study that identified the critical cybersecurity variables also referred to as cybersecurity vital signs. The identified vital signs will aid cybersecurity analysts with triage for potentially malicious insider threats. From a total of 45 analytic variables assessed by 42 cybersecurity SMEs, the top six variables were identified using a comprehensive data collection process. The results indicated that workplace satisfaction is one of the top critical cyber visualization variables that should be measured and visualized to aid cybersecurity analysts in the detection of potentially malicious cyber insider threat activities. The process of the data collection to identify and rank critical cyber visualization variables are described.
Introduction to the Special Issue: Select Papers Presented at the 2018 OLC Accelerate Conference and the 2019 OLC Innovate Conference
Introduction to the Special Issue: Best Papers Presented at the OLC 2017 Accelerate Conference on Online Learning and the Innovate 2018 Conference
To fully understand teaching presence and its implications for the intellectual climate of an online classroom it is necessary to explore the phenomenon from the perspective of the instructors who experience it. Informed by the theoretical perspective of the Community of Inquiry (CoI) model, the actions, intentions and perceptions of instructors were investigated through a collective case study. The goal of this study was to examine the decision processes employed in establishing teaching presence in a structured online environment in order to make a contribution to the body of knowledge from a practical pedagogical perspective. Using the lived experiences of instructors enabled the exploration of the influence pedagogical choices had on the creation of an intellectual climate in the online context. Using semi-structured interviews as the main source of data, the study utilized the Interpretative Phenomenological Analysis (IPA) method as an analytical tool to address concerns of rigor in the qualitative interpretation of experiential data. Results of the collective case revealed student engagement and intellectual curiosity were influenced most greatly by an instructor’s active interest and passion for teaching, an ability to identify the relevance of course topics to the student, and the encouragement for a shared responsibility in the learning process. The findings showed that the shared goal of learning extended beyond the stated learning objectives and expected outcomes of a course and served as a foundation in the creation of authentic relationships between instructor and students. In addressing the overarching research question of how instructors establish teaching presence and inspire intellectual curiosity in a structured teaching environment, the findings of this study contribute to knowledge related to the nature of teaching presence and its role in setting an academic climate in an online classroom.
Deception and dishonesty in online exams are believed to link to their unmonitored nature where users appear to have the opportunity to collaborate or utilize unauthorized resources during these assessments. The primary goal of this study was to investigate the deterrent effect of Webcam-based proctoring on misconduct during online exams. This study involved an experimental design in comparing an experimental group and a control group. Both groups attended the same course, used the same e-learning system, with the same instructor, and took the same set of online exams. One group was monitored by a Web-based proctor while the other was not monitored. The results indicated no statistically significant difference between the scores of the two groups, although the non-proctored group had slightly higher scores. There was a statistically significant difference found on the time taken to complete the online exams where the proctored group used significantly less time to complete their exams. The results of a post-experiment survey indicated that those who were not proctored perceived to have experienced greater levels of opportunity to engage in misconduct than those who were monitored by a Web-based proctor.
While the Internet is a major business tool nowadays, individuals are still challenged to form teams and collaboration virtually. To evaluate the success of team formation in a virtual setting, this research study assessed the role of different computer-mediated communications (CMC) employed on the success of team formation measured by task performance (TP), team cohesiveness (TC), computer skills (CS) and social bond (SB), while assessing the differences on such relationships when controlled for gender, age, education level, academic major, as well as academic year. This research used analysis of variance (ANOVA) and analysis of covariance (ANCOVA) to address the hypotheses proposed. Using three teams and 140 participants, the results indicated that there is a significance difference in the role of CMC levels employed on the level of perception of CS in team formation. Also, there is a significance difference in the role of CMC levels employed on the levels of TP, when controlled for gender. In addition, there is a significance difference in the role of CMC levels employed (No-CMS/F2F, OLS, & OLS+SNS) on the levels of CS, when controlled for education, academic major and academic year. The results of this study contribute to the body of knowledge by helping organizations identify ways to support effective team formations.
The market demand for online learning continues to increase and so do online enrollments in higher education. Online learning is gaining a strategic focus among academic leaders while at the same time we are seeing an emergence of new and innovative models of information systems (IS) graduate programs and instruction delivery methods. Given these trends, what does the future hold? What are our “blue oceans”? The objective is to engage in a conversation about how technology is changing teaching and learning in higher education and specifically, in the design and delivery of graduate degree programs in IS. An international panel with members representing academic administrators, faculty, and online learning researchers will share their perspectives about the progress and direction of online learning. The overarching questions are: How are online technologies transforming higher education for the better or worse? As IS educators, what are our blue oceans?