Noise and Stress Don't Help With Learning: A Qualitative Study to Inform Design of Effective Cybersecurity Awareness in Manufacturing Environments
Lina Brunken, Markus Schöps, Annalina Buckmann, Florian Meißner, M. Angela Sasse
Abstract
With Industry 4.0, cybersecurity risks in manufacturing contexts are increasing rapidly. Since mandatory cybersecurity awareness programs (CAP) are considered best practice, companies looking at adapting training for this group, and allowed us to conduct a study. We conducted semi-structured interviews with n=33 manufacturing workers in 6 locations, to determine what they knew about cybersecurity risks, to what extent they consider them relevant, and what their experiences with, and perceptions of cybersecurity measures and training were. The interviews were analyzed using qualitative content analysis. Most of our participants reported only occasional interaction with what they consider ''office'' information and communication technology (ICT) in the context of their daily work. For most, the only touchpoints were HR-related transactions (pay and vacation), conducted via shared digital shopfloor kiosk PCs, through which they also received corporate communications. Most participants did not consider cybersecurity their responsibility, associating it with ''office'' and ''management'' roles. Most ICT and cybersecurity as potential threats to ''smooth running'' of work processes and their productivity. At the same time, there was positive perception of safety measures and training, with a clear preference for face-to-face team-based training in situ, so they could ask questions and point out possible issues - very different from the company's idea of individual computer-based trained, which most would receive via shared kiosk PCs on a noisy shop floor. Our results suggest that successful CAP needs to tailor content not only according to relevant risks, but relating those to key values and work practices, and consider different ways of delivering it.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5ed1efb2-ba0b-408a-b508-c1310b5a2bc0Related papers
- Small Talk, Big Impact: The Role of Everyday Conversations in Cybersecurity PracticesDoruntina Murtezaj, Leonard Johannes Rössert, Yomna Abdelrahman, Viktorija Paneva et al.CHI 2026 · 1 citation
- "What Keeps People Secure is That They Met The Security Team": Deconstructing Drivers And Goals of Organizational Security AwarenessJonas Hielscher, Simon ParkinUSENIX Security 2024 · 7 citations
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- "You Just Assume It Is In There, I Guess": Understanding UK Families' Application and Knowledge of Smart Home Cyber SecuritySarah Turner, Nandita Pattnaik, Jason R. C. Nurse, Shujun LiCSCW 2022 · 16 citations
