USENIX Security2024Top-tier venue
"What Keeps People Secure is That They Met The Security Team": Deconstructing Drivers And Goals of Organizational Security Awareness
Jonas Hielscher, Simon Parkin
Abstract
Security awareness campaigns in organizations now collectively cost billions of dollars annually. There is increasing focus on ensuring certain security behaviors among employees. On the surface, this would imply a user-centered view of security in organizations. Despite this, the basis of what security awareness managers do and what decides this are unclear. We conducted n=15 semi-structured interviews with full-time security awareness managers, with experience across various national and international companies in European countries, with thousands of employees. Through thematic analysis, we identify that success in awareness management is fragile while having the potential to improve; there are a range of restrictions, and mismatched drivers and goals for security awareness, affecting how it is structured, delivered, measured, and improved. We find that security awareness as a practice is underspecified, and split between messaging around secure behaviors and connecting to employees, with a lack of recognition for the measures that awareness managers regard as important. We discuss ways forward, including alternative indicators of success, and security usability advocacy for employees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsJuliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha FahlS&P 2025
Builds on5
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- "Cyber security is a dark art": The CISO as SoothsayerJoseph Da Silva, Rikke Bjerg JensenCSCW 2022 · 25 citations
- "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing CampaignsLina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela SasseUSENIX Security 2023
- A Comprehensive Quality Evaluation of Security and Privacy Advice on the WebElissa M. Redmiles, Noel Warford, Amritha Jayanti, Aravind Koneru et al.USENIX Security 2020
Related papers
- "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred SecurityJonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge et al.USENIX Security 2023
- Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' PromisesJonas Hielscher, Markus Schöps, Jens Opdenbusch, Felix Reichmann et al.CCS 2024 · 4 citations
- "All Sorts of Other Reasons to Do It": Explaining the Persistence of Sub-optimal IoT Security AdviceVeerle van Harten, Carlos Hernandez Gañán, Michel van Eeten, Simon ParkinCHI 2025 · 4 citations
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong et al.S&P 2025
- I Think They're Trying to Tell Me Something: Advice Sources and Selection for Digital SecurityElissa M. Redmiles, Amelia R. Malone, Michelle L. MazurekS&P 2016 · 151 citations
