VLDB 2026 Research / reviewers in the wild / expert
Jason R. C. Nurse
dblp:14/4905
· DBLP profile ↗
35ranked-venue papers
3as first author
18since 2021 · last 2026
0000-0003-4118-1680ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 2 first-author · 14 since 2021Human-computer interaction and ubiquitous computing · 6 · 4 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cybersecurity and Cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamicsabstractCyber insurance is increasingly positioned as a complementary tool for managing cyber risk, yet Small to Medium-Sized Enterprises (SMEs) remain underrepresented in its adoption. This study investigates the perceptions, decision-making dynamics, and support needs of SMEs regarding cyber insurance, drawing on 38 semi-structured interviews with SMEs, insurers, brokers, and other relevant stakeholders. The findings reveal that many SMEs deprioritise cyber insurance; not because they dismiss its importance outright, but due to a combination of limited awareness, concerns over cost, and a perception that its value is minimal unless required by clients or regulators. This hesitation is further shaped by several key barriers: complex policy language, a lack of trust in insurers, and unclear internal ownership of cybersecurity responsibilities. Despite these challenges, the study identifies promising strategies to boost adoption. These include simplifying policy structures, fostering trust through collaborative awareness efforts, introducing financial incentives tailored to SME budgets, and offering accessible, user-friendly tools that help businesses assess their cyber risks and insurance needs. By identifying actionable strategies and addressing both cultural and structural barriers, this study contributes to efforts to enhance cybersecurity resilience in the SME sector. Rodney Adriko, Jason R. C. Nurse |
Comput. Secur. | 2 |
| 2026 | Inside ransomware groups: An analysis of their origins, structures, and dynamicsabstractRansomware is a major cybersecurity threat facing organisations worldwide and has evolved into a highly lucrative criminal enterprise. Over the past five years, Conti, LockBit, and BlackCat/ALPHV have emerged as three of the most prominent ransomware groups, responsible for major cyberattacks across sectors including healthcare, banking, and critical national infrastructure. While these groups are well-known by name and have been discussed in industry articles, blogs, and government briefs, there remains a notable lack of academic research into the groups themselves, particularly regarding their origins, values, membership, and organisational structures. This paper addresses this research gap and aims to advance academic understanding of these and other ransomware threat actors, contributing to the evidence base through which they may be better understood and disrupted. Drawing on the PRISMA systematic review approach and a critical analysis of over 500 dispersed sources, including ransomware group communications, we examine the origins, structure, organisation, dynamics and nature of Conti, LockBit, and BlackCat/ALPHV. Our findings reveal that, while each group is unique, they share several noteworthy similarities: Russian origins, business-like operations, an emphasis on brand-building, strong leadership structures, a propensity for retaliation, use of ransomware-as-a-service models, and deployment of multi-level extortion tactics. These insights provide an evidence-based understanding of how such groups function and compare, while also offering important leads for wider mitigation strategies. Consequently, we make several actionable recommendations to disrupt the ransomware ecosystem including undermining ransomware group branding, targeting affiliate networks, and publicly exposing key members. To our knowledge, this is the first academic study to leverage an understanding of these groups, to synthesise such an extensive body of dispersed material, and to apply robust qualitative methods to derive comparative insights for the security research community. In addition, we leverage our findings to introduce a new conceptual framework through which other ransomware groups can be studied, profiled, and compared in the future. Andrew Phipps, Jason R. C. Nurse |
Comput. Secur. | 2 |
| 2025 | Designing Cyber Security Communities of Support to Improve SME Cyber Hygiene and Resilience
Neeshe Khan, Ram Herkanaidu, Steven Furnell, Jason R. C. Nurse, Maria Bada, Matthew Rand |
CRITIS | 4 |
| 2025 | Investigating the experiences of providing cyber security support to small- and medium-sized enterprisesabstractSmall- and Medium-Sized Enterprises or SMEs comprise of 99.9 % of all businesses in the UK and make a significant contribution the overall economy. In UK's path to digitalisation, ensuring the cyber security and resilience of SMEs becomes an integral element that must be adequately safeguarded to protect national interests. Despite playing a crucial role, there is limited research on SMEs adopting cyber security practices, becoming cyber secure or improving their resilience to attacks. To examine this journey, a qualitative study was designed to learn from the experiences of organisations that provide cyber security advice or solutions. The three aims of the study were to: (1) understand the various types of support offered by providers; (2) topics for which support is sought and the circumstances that trigger the need for assistance; and (3) the perceived effectiveness of the support provided, associated challenges and opportunities to improve from the lived experiences of providers. Following semi-structured interviews with 12 participants, findings confirm results presented in earlier literature and provides new insights. Each participant had exposure to numerous SMEs, in some instances hundreds, at a regional or national level due to their roles at their respective organisations. The inherent knowledge gained from this exposure results in each participant's experience representing the cumulative experience of several SMEs as opposed to a singular view of one. We conclude that there is a vast amount of cyber security related content aimed at SMEs and our findings reveal providers are playing an assistive role in the understanding, education and implementation of cyber security defences. Despite significant efforts being made, cyber hygiene amongst SMEs remains low and they are unlikely to proactively reach out for support. Additionally, SMEs have low knowledge levels and are hampered in their efforts due to comprehension, capability, attitudes, and resources whilst providers face numerous internal and external challenges when delivering this support. Insights from data reveal several opportunities for improvement can be realised through the creation of security focused communities that can provide support, collaboration and learning. Neeshe Khan, Steven Furnell, Maria Bada, Matthew Rand, Jason R. C. Nurse |
Comput. Secur. | 5 |
| 2024 | "I don't think we're there yet": The practices and challenges of organisational learning from cyber security incidentsabstractLearning from cyber incidents is crucial for organisations to enhance their cyber resilience and effectively respond to evolving threats. This study employs neo-institutional and organisational learning theories to examine how organisations learn from incidents and gain insights into the challenges they face. Drawing on qualitative research methods, interviews were conducted with 34 security practitioners from organisations operating in the UK spanning a range of industries. The findings highlight the importance of consciously evaluating learning practices and creating a culture of openness to hear about incidents from employees, customers and suppliers. Deciding which incidents to learn from, as well as who should participate in the learning process, emerged as critical considerations. Overcoming defensiveness and addressing systemic causes were recognised as barriers to effective learning. The study emphasises the need to assess the value and impact of identified lessons and to avoid superficial reviews that treat symptoms rather than underlying causes to improve resilience. While progress has been made in learning from incidents, further enhancements are needed. Practical recommendations have been proposed to suggest how organisations may gain valuable insights for maximising the benefits derived from incident learning. This research contributes to the existing knowledge on organisational learning and informs future studies exploring the social and political influences on the learning process. By considering the suggested recommendations, organisations may strengthen their cyber security, foster a culture of continuous improvement, and respond effectively to the dynamic cyber security landscape. Clare M. Patterson, Jason R. C. Nurse, Virginia N. L. Franqueira |
Comput. Secur. | 2 |
| 2024 | Cybersecurity, cyber insurance and small-to-medium-sized enterprises: a systematic ReviewabstractPurpose This study aims to offer insights into the state of research covering cybersecurity, cyber insurance and small- to medium-sized enterprises (SMEs). It examines benefits of insurance to an SME’s security posture, challenges faced, and potential solutions and outstanding research questions. Design/methodology/approach Research objectives were formulated, and the Preferred Reporting Items for Systematic Reviews and Meta-Analyses Protocol was used to perform a systematic literature review (SLR). A total of 19 papers were identified from an initial set of 451. Findings This research underscores the role of cybersecurity in the value proposition of cyber insurance for SMEs. The findings highlight the benefits that cyber insurance offers SMEs including protection against cyber threats, financial assistance and access to cybersecurity expertise. However, challenges hinder SME’s engagement with insurance, including difficulties in understanding cyber risk, lack of cybersecurity knowledge and complex insurance policies. Researchers recommend solutions, such as risk assessment frameworks and government intervention, to increase cyber insurance uptake/value to SMEs. Research limitations/implications There is a need for further research in the risk assessment and cybersecurity practices of SMEs, the influence of government intervention and the effectiveness of insurers in compensating for losses. The findings also encourage innovation to address the unique needs of SMEs. These insights can guide future research and contribute to enhancing cyber insurance adoption. Originality/value To the best of the authors’ knowledge, this is the first SLR to comprehensively examine the intersection of cybersecurity and cyber insurance specifically in the context of SMEs. Rodney Adriko, Jason R. C. Nurse |
Inf. Comput. Secur. | 2 |
| 2024 | Security and Privacy Perspectives of People Living in Shared Home EnvironmentsabstractSecurity and privacy (S&P) perspectives of people in a multi-user home are a growing area of research, with many researchers reflecting on the complicated power imbalance and challenging access control issues of the devices involved. However, these studies primarily focused on the multi-user scenarios in traditional family home settings, leaving other types of multi-user home environments, such as homes shared by co-habitants without a familial relationship, under-studied. This paper closes this research gap via quantitative and qualitative analysis of results from an online survey and qualitative content analysis of sampled online posts on Reddit. The study explores the complex roles of shared home users, which depend on various factors unique to the shared home environment, e.g., who owns what home devices, how home devices are used by multiple users, and more complicated relationships between the landlord and people in the shared home and among co-habitants. Half (50.7%) of our survey participants thought that devices in a shared home are less secure than in a traditional family home. This perception was found statistically significantly associated with factors such as the fear of devices being tampered with in their absence and (lack of) trust in other co-habitants and their visitors. We observed cyber-physical threats being a prominent topic discussed in Reddit posts. Our study revealed new user types and user relationships in a multi-user environment such as ExternalPrimary-InternalPrimary while analysing the landlord and shared home resident relationship with regard to shared home device use. Based on the results of the online survey and the Reddit data, we propose a threat actor model for shared home environments, which has a focus on possible malicious behaviours of current and past co-habitants of a shared home, as a special type of insider threat in a home environment. We also recommend further research to understand the complex roles co-habitants can play in navigating and adapting to a shared home environment's security and privacy landscape. Nandita Pattnaik, Shujun Li 0001, Jason R. C. Nurse |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2023 | Between a rock and a hard(ening) place: Cyber insurance in the ransomware eraabstractCyber insurance and ransomware are two of the most studied areas within security research and practice to date, and their interplay continues to raise concerns in industry and government. This article offers substantial new insights and analysis into the complex question of whether cyber insurance can help organisations in mitigating the threat of ransomware, particularly its impacts. Having conducted an interview or workshop with 96 industry professionals spanning the cyber insurance, cyber security, ransomware negotiations, policy, and law enforcement sectors, we identify that ransomware has been a key cause of the ‘hardening’ of the cyber insurance market, which is exhibited at almost all levels of the market. Such hardening has been beneficial in raising the security standards required prior to purchase, but has also created a situation where some organisations may not be able to acquire viable cyber insurance at all. In presenting the outcomes of our thematic analysis of the interview and workshop outputs, the paper provides significant new empirical evidence to support the theory that cyber insurance can act as a form of governance for improving cyber security amongst organisations. Nonetheless, the hardening market does nothing to increase the penetration of cyber insurance. Questions were also raised as to the likelihood of unintended unethical – and potentially illegal – outcomes given the professionalisation of a remediation process that has to determine the most cost-effective solution to an organisation being held ransom. We conclude that insurance, at best, can help to mitigate the ransomware threat for those that can access it, as part of a wider basket of actions that must also come from different stakeholders. Gareth Mott, Sarah Turner, Jason R. C. Nurse, Jamie MacColl, James Sullivan, Anna Cartwright 0001, Edward J. Cartwright |
Comput. Secur. | 3 |
| 2023 | Learning from cyber security incidents: A systematic review and future research agendaabstractCyber security incidents are now prevalent in many organisations. Arguably, those who can learn from security incidents and address the underlying causes will reduce the prevalence of similar ones in the future. This research provides a new examination of how organisations learn from incidents by systematically reviewing academic research on organisational learning from cyber security incidents and identifying further research needed in this area. To do this, it considers three research questions: what research has been conducted on learning from cyber security incidents, what learning practices in organisations have been found by research and what improvements have been recommended, and what further research is needed as organisations learn from such incidents. Using the PRISMA method, a total of 3,986 articles were extracted and, from these, a relevant set of 30 were selected for analysis to map the body of research, and to identify future research avenues. Despite learning lessons being recommended by both researchers and industry standards, our findings suggest that this advice is not being fully adopted by organisations. Importantly, these studies have found inadequate participation in learning activities, with superficial causal investigations, scarce effort on ensuring lessons are implemented and no evaluation of whether the actions taken actually reduce future security incidents. More research is needed to understand the right level and which learning practices to invest in for the greatest impact. For practitioners, this review discusses the essential elements of an effective process to learn from incidents. This review provides academics with a novel synthesis of the research undertaken on this topic, enabling them to incorporate the significant findings into their work and potentially explore the research agenda suggested. Clare M. Patterson, Jason R. C. Nurse, Virginia N. L. Franqueira |
Comput. Secur. | 2 |
| 2023 | Perspectives of non-expert users on cyber security and privacy: An analysis of online discussions on twitterabstractMany researchers have studied non-expert users’ perspectives of cyber security and privacy aspects of computing devices at home, but their studies are mostly small-scale empirical studies based on online surveys and interviews and limited to one or a few specific types of devices, such as smart speakers. This paper reports our work on an online social media analysis of a large-scale Twitter dataset, covering cyber security and privacy aspects of many different types of computing devices discussed by non-expert users in the real world. We developed two new machine learning based classifiers to automatically create the Twitter dataset with 435,207 tweets posted by 337,604 non-expert users in January and February of 2019, 2020 and 2021. We analyzed the dataset using both quantitative (topic modeling and sentiment analysis) and qualitative analysis methods, leading to various previously unknown findings. For instance, we observed a sharp (more than doubled) increase of non-expert users’ tweets on cyber security and privacy during the pandemic in 2021, compare to in the pre-COVID years (2019 and 2020). Our analysis revealed a diverse range of topics discussed by non-expert users, including VPNs, Wi-Fi, smartphones, laptops, smart home devices, financial security, help-seeking, and roles of different stakeholders. Overall negative sentiment was observed across almost all topics in all the three years. Our results indicate the multi-faceted nature of non-expert users’ perspectives on cyber security and privacy and call for more holistic, comprehensive and nuanced research on their perspectives. Nandita Pattnaik, Shujun Li 0001, Jason R. C. Nurse |
Comput. Secur. | 3 |
| 2022 | Out of the Shadows: Analyzing Anonymous' Twitter Resurgence during the 2020 Black Lives Matter Protests
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 2 |
| 2022 | Are You Robert or RoBERTa? Deceiving Online Authorship Attribution Models Using Neural Text Generators
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 2 |
| 2022 | A system to calculate Cyber Value-at-RiskabstractIn the face of increasing numbers of cyber-attacks, it is critical for organisations to understand the risk they are exposed to even after deploying security controls. This residual risk forms part of the ongoing operational environment, and must be understood and planned for if resilience is to be achieved. However, there is a lack of rigorous frameworks to help organisations reason about how their use of risk controls can change the nature of the potential losses they face, given an often changing threat landscape. To address this gap, we present a system that calculates Cyber Value-at-Risk (CVaR) of an organisation. CVaR is a probabilistic density function for losses from cyber-incidents, for any given threats of interest and risk control practice. It can take account of varying effectiveness of controls, the consequences for risk propagation through infrastructures, and the cyber-harms that result. We demonstrate the utility of the system in a real case study by calculating the CVaR of an organisation that experienced a significant cyber-incident. We show that the system is able to produce predictions representative of the actual financial loss. The presented system can be used by insurers offering cyber products to better inform the calculation of insurance premiums, and by organisations to reason about the effects of using particular risk control setups on reducing their exposure to cyber-risk. Arnau Erola, Ioannis Agrafiotis, Jason R. C. Nurse, Louise Axon, Michael Goldsmith, Sadie Creese |
Comput. Secur. | 3 |
| 2022 | Personal information: Perceptions, types and evolutionabstractAdvances in technology have made us as a society think more about cyber security and privacy, particularly how we consider and protect personal information. Such developments have introduced a temporal dimension to the definition of personal information and we have also witnessed new types of data emerging (e.g., phone sensor data, stress level measurements). These rapid technological changes introduce several challenges as legislation is often inadequate, and therefore questions regularly arise pertaining whether information should be considered personal or sensitive and thereby better protected. In this paper, therefore, we look to significantly advance research into this domain by investigating how personal information is regarded in governmental legislations/regulations, privacy policies of applications, and academic research articles. Through an assessment of how personal information has evolved and is perceived differently (e.g., in the context of sensitivity) across these key stakeholders, this work contributes to the understanding of the fundamental disconnects present and also the social implications of new technologies. Furthermore, we introduce a series of novel taxonomies of personal information which can significantly support and help guide how researchers and practitioners work with, or develop tools to protect, such information. Rahime Belen Saglam, Jason R. C. Nurse, Duncan Hodges |
J. Inf. Secur. Appl. | 2 |
| 2022 | "You Just Assume It Is In There, I Guess": Understanding UK Families' Application and Knowledge of Smart Home Cyber SecurityabstractThe Internet of Things (IoT) is increasingly present in many family homes, yet it is unclear precisely how well families understand the cyber security threats and risks of using such devices, and how possible it is for them to educate themselves on these topics. Using a survey of 553 parents and interviews with 25 families in the UK, we find that families do not consider home IoT devices to be significantly different in terms of threats than more traditional home computers, and believe the major risks to be largely mitigated through consumer protection regulation. As a result, parents focus on teaching being careful with devices to prolong device life use, exposing their families to additional security risks and modeling incorrect security behaviors to their children. This is a risk for the present and also one for the future, as children are not taught about the IoT, and appropriate cyber security management of such devices, at school. We go on to suggest that steps must be taken by manufacturers and governments or appropriate trusted institutions to improve the cyber security knowledge and behaviors of both adults and children in relation to the use of home IoT devices. Sarah Turner, Nandita Pattnaik, Jason R. C. Nurse, Shujun Li 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2021 | Practitioners' Views on Cybersecurity Control Adoption and EffectivenessabstractCybersecurity practitioners working in organisations implement risk controls aiming to improve the security of their systems. Determining prioritisation of the deployment of controls and understanding their likely impact on overall cybersecurity posture is challenging, yet without this understanding there is a risk of implementing inefficient or even harmful security practices. There is a critical need to comprehend the value of controls in reducing cyber-risk exposure in various organisational contexts, and the factors affecting their usage. Such information is important for research into cybersecurity risk and defences, for supporting cybersecurity decisions within organisations, and for external parties guiding cybersecurity practice such as standards bodies and cyber-insurance companies. Louise Axon, Arnau Erola, Alastair Janse van Rensburg, Jason R. C. Nurse, Michael Goldsmith, Sadie Creese |
ARES | 4 |
| 2021 | Cyber security in the age of COVID-19: A timeline and analysis of cyber-crime and cyber-attacks during the pandemic
Harjinder Singh Lallie 0001, Lynsay A. Shepherd, Jason R. C. Nurse, Arnau Erola, Gregory Epiphaniou, Carsten Maple, Xavier J. A. Bellekens |
Comput. Secur. | 3 |
| 2021 | Developing a cyber security culture: Current practices and future needs
Betsy Uchendu, Jason R. C. Nurse, Maria Bada, Steven Furnell |
Comput. Secur. | 2 |
| 2020 | Behind the Mask: A Computational Study of Anonymous' Presence on Twitter
Keenan Jones, Jason R. C. Nurse, Shujun Li 0001 |
ICWSM | 2 |
| 2020 | A framework for effective corporate communication after cyber security incidents
Richard Knight, Jason R. C. Nurse |
Comput. Secur. | 2 |
| 2020 | Cyber risk at the edge: current and future trends on cyber risk analytics and artificial intelligence in the industrial internet of things and industry 4.0 supply chainsabstractAbstract Digital technologies have changed the way supply chain operations are structured. In this article, we conduct systematic syntheses of literature on the impact of new technologies on supply chains and the related cyber risks. A taxonomic/cladistic approach is used for the evaluations of progress in the area of supply chain integration in the Industrial Internet of Things and Industry 4.0, with a specific focus on the mitigation of cyber risks. An analytical framework is presented, based on a critical assessment with respect to issues related to new types of cyber risk and the integration of supply chains with new technologies. This paper identifies a dynamic and self-adapting supply chain system supported with Artificial Intelligence and Machine Learning (AI/ML) and real-time intelligence for predictive cyber risk analytics. The system is integrated into a cognition engine that enables predictive cyber risk analytics with real-time intelligence from IoT networks at the edge. This enhances capacities and assist in the creation of a comprehensive understanding of the opportunities and threats that arise when edge computing nodes are deployed, and when AI/ML technologies are migrated to the periphery of IoT networks. Petar Radanliev, David De Roure, Kevin R. Page, Jason R. C. Nurse, Rafael Mantilla Montalvo, Omar Santos 0002, La Treall Maddox, Pete Burnap |
Cybersecur. | 4 |
| 2020 | A Semi-Supervised Approach to Message Stance ClassificationabstractSocial media communications are becoming increasingly prevalent; some useful, some false, whether unwittingly or maliciously. An increasing number of rumours daily flood the social networks. Determining their veracity in an autonomous way is a very active and challenging field of research, with a variety of methods proposed. However, most of the models rely on determining the constituent messages' stance towards the rumour, a feature known as the “wisdom of the crowd.” Although several supervised machine-learning approaches have been proposed to tackle the message stance classification problem, these have numerous shortcomings. In this paper, we argue that semi-supervised learning is more effective than supervised models and use two graphbased methods to demonstrate it. This is not only in terms of classification accuracy, but equally important, in terms of speed and scalability. We use the Label Propagation and Label Spreading algorithms and run experiments on a dataset of 72 rumours and hundreds of thousands messages collected from Twitter. We compare our results on two available datasets to the state-of-the-art to demonstrate our algorithms' performance regarding accuracy, speed, and scalability for real-time applications. Georgios Giasemidis, Nikolaos Kaplis, Ioannis Agrafiotis, Jason R. C. Nurse |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2019 | Understanding the Radical Mind: Identifying Signals to Detect Extremist Content on TwitterabstractThe Internet and, in particular, Online Social Networks have changed the way that terrorist and extremist groups can influence and radicalise individuals. Recent reports show that the mode of operation of these groups starts by exposing a wide audience to extremist material online, before migrating them to less open online platforms for further radicalization. Thus, identifying radical content online is crucial to limit the reach and spread of the extremist narrative. In this paper, our aim is to identify measures to automatically detect radical content in social media. We identify several signals, including textual, psychological and behavioural, that together allow for the classification of radical messages. Our contribution is threefold: (1) we analyze propaganda material published by extremist groups and create a contextual text-based model of radical content, (2) we build a model of psychological properties inferred from these material, and (3) we evaluate these models on Twitter to determine the extent to which it is possible to automatically identify online radical tweets. Our results show that radical users do exhibit distinguishable textual, psychological, and behavioural properties. We find that the psychological properties are among the most distinguishing features. Additionally, our results show that textual models using vector embedding features significantly improves the detection over TF-IDF features. We validate our approach on two experiments achieving high accuracy. Our findings can be utilized as signals for detecting online radicalization activities. Mariam Nouh, Jason R. C. Nurse, Michael Goldsmith |
ISI | 2 |
| 2019 | Cyber risk assessment in cloud provider environments: Current models and future needs
Olusola Akinrolabu, Jason R. C. Nurse, Andrew P. Martin, Steve New |
Comput. Secur. | 2 |
| 2019 | (Smart)Watch Out! encouraging privacy-protective behavior through interactive games
Meredydd Williams, Jason R. C. Nurse, Sadie Creese |
Int. J. Hum. Comput. Stud. | 2 |
| 2019 | Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)abstractPurpose The purpose of this study is to focus on organisation’s cybersecurity strategy and propose a high-level programme for cybersecurity education and awareness to be used when targeting small- and medium-sized enterprises/businesses (SMEs/SMBs) at a city-level. An essential component of an organisation’s cybersecurity strategy is building awareness and education of online threats and how to protect corporate data and services. This programme is based on existing research and provides a unique insight into an ongoing city-based project with similar aims. Design/methodology/approach To structure this work, a scoping review was conducted of the literature in cybersecurity education and awareness, particularly for SMEs/SMBs. This theoretical analysis was complemented using a case study and reflecting on an ongoing, innovative programme that seeks to work with these businesses to significantly enhance their security posture. From these analyses, best practices and important lessons/recommendations to produce a high-level programme for cybersecurity education and awareness were recommended. Findings While the literature can be informative at guiding education and awareness programmes, it may not always reach real-world programmes. However, existing programmes, such as the one explored in this study, have great potential, but there can be room for improvement. Knowledge from each of these areas can, and should, be combined to the benefit of the academic and practitioner communities. Originality/value The study contributes to current research through the outline of a high-level programme for cybersecurity education and awareness targeting SMEs/SMBs. Through this research, literature in this space was examined and insights into the advances and challenges faced by an on-going programme were presented. These analyses allow us to craft a proposal for a core programme that can assist in improving the security education, awareness and training that targets SMEs/SMBs. Maria Bada, Jason R. C. Nurse |
Inf. Comput. Secur. | 2 |
| 2019 | The language of biometrics: Analysing public perceptions
Oliver Buckley, Jason R. C. Nurse |
J. Inf. Secur. Appl. | 2 |
| 2017 | Privacy is the Boring Bit: User Perceptions and Behaviour in the Internet-of-ThingsabstractIn opinion polls, the public frequently claim to value their privacy. However, individuals often seem to overlook the principle, contributing to a disparity labelled the 'Privacy Paradox'. The growth of the Internet-of-Things (IoT) is frequently claimed to place privacy at risk. However, the Paradox remains underexplored in the IoT. In addressing this, we first conduct an online survey (N = 170) to compare public opinions of IoT and less-novel devices. Although we find users perceive privacy risks, many still decide to purchase smart devices. With the IoT rated less usable/familiar, we assert that it constrains protective behaviour. To explore this hypothesis, we perform contextualised interviews (N = 40) with the public. In these dialogues, owners discuss their opinions and actions with a personal device. We find the Paradox is significantly more prevalent in the IoT, frequently justified by a lack of awareness. We finish by highlighting the qualitative comments of users, and suggesting practical solutions to their issues. This is the first work, to our knowledge, to evaluate the Privacy Paradox over a broad range of technologies. Meredydd Williams, Jason R. C. Nurse, Sadie Creese |
PST | 2 |
| 2016 | The Perfect Storm: The Privacy Paradox and the Internet-of-ThingsabstractPrivacy is a concept found throughout human history and opinion polls suggest that the public value this principle. However, while many individuals claim to care about privacy, they are often perceived to express behaviour to the contrary. This phenomenon is known as the Privacy Paradox and its existence has been validated through numerous psychological, economic and computer science studies. Several contributory factors have been suggested including user interface design, risk salience, social norms and default configurations. We posit that the further proliferation of the Internet-of-Things (IoT) will aggravate many of these factors, posing even greater risks to individuals' privacy. This paper explores the evolution of both the paradox and the IoT, discusses how privacy risk might alter over the coming years, and suggests further research required to address a reasonable balance. We believe both technological and socio-technical measures are necessary to ensure privacy is protected in a world of ubiquitous technology. Meredydd Williams, Jason R. C. Nurse, Sadie Creese |
ARES | 2 |
| 2016 | A Pragmatic System-failure Assessment and Response ModelabstractSeveral attack models exist today that attempt to describe cyber-attacks to varying degrees of granularity. Fast and effective decision-making during cyber-attacks is often vital, especially during incidents in which reputation, finance and physical damage can have a crippling effect on people and organisations. Such attacks can render an organisation paralysed, and it may cease to function, we refer to such an incident as a “System Failure”. In this paper we propose a novel conceptual model to help analysts make pragmatic decisions during a System Failure. Our model distils the essence of attacks and provides an easy-to-remember framework intended to help analysts ask relevant questions at the right time, irrespective of what data is available to them. Using abstraction-based reasoning our model allows enterprises to achieve “some” situational awareness during a System Failure, but more importantly, enable them to act upon their understanding and to justify their decisions. Abstraction drives the reasoning process making the approach relevant today and in the future, unlike several existing models that become deprecated over time (as attacks evolve). In the future, it will be necessary to trial the model in exercises to assess its value. Jassim Happa, Graham Fairclough, Jason R. C. Nurse, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
ICISSP | 3 |
| 2015 | Exploring a Controls-Based Assessment of Infrastructure Vulnerability
Oliver J. Farnan, Jason R. C. Nurse |
CRiSIS | 2 |
| 2014 | Inferring social relationships from technology-level device connectionsabstractTechnology is present in every area of our lives and, for many, life without it has become unthinkable. As a consequence of this dependence and the extent to which technology devices (computers, tablets and smartphones) are being used for work and social activities, a clear coupling between devices and their owners can now be observed. By coupling, we specifically refer to the fact that information present on a person's device, be it user-generated or created by the native OS, can produce great insight into their life. In this paper, we look to exploit this coupling to investigate whether connections between technology devices recorded in system log-files, can be used to make inferences about the social relationships between device owners. A key motivation here is to better understand and elucidate the privacy risks associated with the digital footprints that we as humans (often inadvertently) create. Our work draws upon Social Network Analysis and basic Computer Forensics to develop and achieve the inference goals. From our preliminary experimentation, we demonstrate that human social relationships can indeed be inferred even within our limited initial scope. To further investigate the level of privacy exposure from technology-level links, we outline a more comprehensive plan of experimentation that will be conducted in future work. Jason R. C. Nurse, Jess Pumphrey, Thomas Gibson-Robinson, Michael Goldsmith, Sadie Creese |
PST | 1 |
| 2013 | Communicating trustworthiness using radar graphs: A detailed lookabstractThe amount of trust we, as human-beings, place in each other or an object (e.g., online information) is typically guided by several trust factors and antecedents. These factors can vary in importance depending on the individual making the trust decision and also on the situation - such is actually the subjective nature of trust. In this paper, we explore this notion of factors' importance by delving into detail on some of our recent user experiments and subsequent findings, partly described in previous work. These experiments used radar graphs to communicate trustworthiness as a function of five trust factors, namely competence, popularity, recency, corroboration and proximity. Here, we expand that work by further considering the importance of each of the factors to participants, while also investigating the correlations between individuals' perceptions of trust, and aspects such as graph area or size and expected scores as calculated by linear regression analysis. More specifically, we focus on outliers and endeavour to understand what is the cause of their existence. This research contributes to the field of communicating trustworthiness now, but is also meant to act as a platform for future, more directed research on visuals intended to communicate trustworthiness. Jason R. C. Nurse, Ioannis Agrafiotis, Sadie Creese, Michael Goldsmith, Koen Lamberts |
PST | 1 |
| 2012 | A Data-Reachability Model for Elucidating Privacy and Security Risks Related to the Use of Online Social NetworksabstractPrivacy and security within Online Social Networks (OSNs) has become a major concern over recent years. As individuals continue to actively use and engage with these mediums, one of the key questions that arises pertains to what unknown risks users face as a result of unchecked publishing and sharing of content and information in this space. There are numerous tools and methods under development that claim to facilitate the extraction of specific classes of personal data from online sources, either directly or through correlation across a range of inputs. In this paper we present a model which specifically aims to understand the potential risks faced should all of these tools and methods be accessible to a malicious entity. The model enables easy and direct capture of the data extraction methods through the encoding of a data-reachability matrix for which each row represents an inference or data-derivation step. Specifically, the model elucidates potential linkages between data typically exposed on social-media and networking sites, and other potentially sensitive data which may prove to be damaging in the hands of malicious parties, i.e., fraudsters, stalkers and other online and offline criminals. In essence, we view this work as a key method by which we might make cyber risk more tangible to users of OSNs. Sadie Creese, Michael Goldsmith, Jason R. C. Nurse, Elizabeth Phillips |
TrustCom | 3 |
| 2009 | BOF4WSS: A Business-Oriented Framework for Enhancing Web Services Security for e-BusinessabstractWhen considering Web services' (WS) use for online business-to-business (B2B) collaboration between companies, security is a complicated and very topical issue. This is especially true with regard to reaching a level of security beyond the technological layer, that is supported and trusted by all businesses involved. With appreciation of this fact, our research draws from established development methodologies to develop a new, business-oriented framework (BOF4WSS) to guide e-businesses in defining, and achieving agreed security levels across these collaborating enterprises. The approach envisioned is such that it can be used by businesses-in a joint manner-to manage the comprehensive concern that security in the WS environment has become. Jason R. C. Nurse, Jane E. Sinclair |
ICIW | 1 |