"Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security
Jonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge, M. Angela Sasse
摘要
In larger organisations, the security controls and policies that protect employees are typically managed by a Chief Information Security Officer (CISO). In research, industry, and policy, there are increasing efforts to relate principles of human behaviour interventions and influence to the practice of the CISO, despite these being complex disciplines in their own right. Here we explore how well the concepts of humancentred security (HCS) have survived exposure to the needs of practice: in an action research approach we engaged with n = 30 members of a Swiss-based community of CISOs in five workshop sessions over the course of 8 months, dedicated to discussing HCS. We coded and analysed over 25 hours of notes we took during the discussions. We found that CISOs far and foremost perceive HCS as what is available on the market, namely awareness and phishing simulations. While they regularly shift responsibility either to the management (by demanding more support) or to the employees (by blaming them) we see a lack of power but also silo-thinking that prevents CISOs from considering actual human behaviour and friction that security causes for employees. We conclude that industry best practices and the state-of-the-art in HCS research are not aligned. We found that the attending CISOs -with a general interest into HCS topics -implement HCS, but in the absence of better solutions (which would account for real human behaviour and aim at supporting behaviour change in accordance with productive tasks [35] ) they use what is available on the market Workshop 1 Defining the scope
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 被引用 35 次
- The Effects of Group Discussion and Role-playing Training on Self-efficacy, Support-seeking, and Reporting Phishing Emails: Evidence from a Mixed-design ExperimentXiaowei Chen, Margault Sacré, Gabriele Lenzini, Samuel Greiff 等CHI 2024 · 被引用 21 次
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen 等CCS 2024 · 被引用 9 次
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 被引用 7 次
- "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing CampaignsLina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela SasseUSENIX Security 2023
它引用的顶会 Paper4
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- "Cyber security is a dark art": The CISO as SoothsayerJoseph Da Silva, Rikke Bjerg JensenCSCW 2022 · 被引用 25 次
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 被引用 18 次
相关 Paper
- "What Keeps People Secure is That They Met The Security Team": Deconstructing Drivers And Goals of Organizational Security AwarenessJonas Hielscher, Simon ParkinUSENIX Security 2024 · 被引用 7 次
- "Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business EnablerKimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass 等CHI 2025 · 被引用 1 次
- "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision MakingJens Opdenbusch, Jonas Hielscher, M. Angela SasseNDSS 2025
- SoK: A Framework and Guide for Human-Centered Threat Modeling in Security and Privacy ResearchWarda Usman, Daniel ZappalaS&P 2025
- Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' PromisesJonas Hielscher, Markus Schöps, Jens Opdenbusch, Felix Reichmann 等CCS 2024 · 被引用 4 次
