VLDB 2026 Research / reviewers in the wild / expert
Henrik Karlzén
dblp:163/9508
· DBLP profile ↗
8ranked-venue papers
3as first author
2since 2021 · last 2025
0009-0009-4394-7695ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Training for improved information security culture: a longitudinal randomized controlled trialabstractPurpose The information security behaviors of individuals can pose a risk to their organization’s information security. To address employees’ information security behaviors and managers’ information security leadership behaviors, this paper aims to develop a behavioral training program called Training for Improved Information Security Culture (TIISC). TIISC consisted of information-security training for the employees and managerial behavioral training for the managers. The training program aimed at direct change of behavior as well as indirect change through improved information security culture, as manifested through information security climate. Design/methodology/approach The effects of TIISC on information security culture was assessed in a longitudinal randomized controlled trial. Data were collected over a 16-month period, using both behavioral measurements and questionnaires on behavior and climate. Latent growth modeling was used for the statistical analysis of change, in terms of how change differed between the control and experimental groups. Findings The results show that the training program had significant positive effects on the information security leadership of managers; but for employees, significant positive effects were only found for information security learning. Training programs that incorporate managerial behavioral training can realize important improvements in organizations’ information security culture, primarily by addressing managers’ information security leadership behaviors through behavior analysis and practice with performance feedback. Originality/value The authors report the results of a longitudinal randomized controlled trial testing the effects of information security training on multiple types of information security behaviors and approaches as indicators of information security culture. Longitudinal randomized controlled trials in security education training and awareness research are important because they advance the understanding of how information security culture can be effectively improved. Martin Grill, Teodor Sommestad, Henrik Karlzén, Anders Pousette |
Inf. Comput. Secur. | 3 |
| 2023 | Automatic incident response solutions: a review of proposed solutions' input and outputabstractMany organizations are exposed to the risk of cyber attacks that penetrate their computer networks. When such cyber attacks occur, e.g. a ransomware outbreak, it is desirable to quickly respond by containing the threat or limit its consequences. Technologies that support this process have been widely used for decades, including antivirus software and deep-packet inspection firewalls. A large number of researches on cyber security have been initiated to automate the incident handling process further, often motivated by the need to respond to more advanced cyber attacks or the increasing cyber risks at stake. This paper reviews the research on automatic incident response solutions published since the year 2000, in order to identify gaps as well as guide further research. The proposed solutions are categorized in terms of the input they use (e.g. intrusion signals) and the output they perform (e.g. reconfiguring a network) using the D3FEND framework. The solutions presented in 45 papers published in the academic literature are analyzed and compared to four commercially available solutions for automatic response. Many of the 45 papers described input and output in vague terms. The most common inputs were from asset inventories, platform monitoring and network traffic analysis. The most common output was network isolation measures, e.g. to reconfigure firewalls. Commercially available solutions focus more on looking for identifiers in reputation systems and individual analyzing files. Henrik Karlzén, Teodor Sommestad |
ARES | 1 |
| 2019 | The Theory of Planned Behavior and Information Security Policy ComplianceabstractMuch of the research on security policy compliance has tested the relationships posited by the theory of planned behavior. This theory explains far from all of the measurable variance in policy compliance intentions. However, it is associated with something called the sufficiency assumption, which essentially states that no variable is missing from the theory. This paper addresses this assumption in the context of information security policy compliance. A meta-analysis of published tests on information security behavior and a review of the literature in related fields are used to identify variables that have the potential to improve the theory’s predictions. These results are tested using a random sample of 645 white-collar workers. The results suggest that the variables anticipated regret and habit improve the predictions. The variables increase the explained variance by 3.4 and 2.6 percentage points, respectively, when they are added individually, and by 5.4 percentage points when both are added. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
J. Comput. Inf. Syst. | 2 |
| 2018 | A Test of Structured Threat Descriptions for Information Security Risk Assessments
Henrik Karlzén, Johan E. Bengtsson, Jonas Hallberg |
ICISSP | 1 |
| 2017 | Assessing Information Security Risks using Pairwise Weighting
Henrik Karlzén, Johan E. Bengtsson, Jonas Hallberg |
ICISSP | 1 |
| 2016 | An empirical test of the perceived relationship between risk and the constituents severity and probabilityabstractPurpose In methods and manuals, the product of an information security incident’s probability and severity is seen as a risk to manage. The purpose of the test described in this paper is to investigate if information security risk is perceived in this way, if decision-making style influences the perceived relationship between the three variables and if the level of information security expertise influences the relationship between the three variables. Design/methodology/approach Ten respondents assessed 105 potential information security incidents. Ratings of the associated risks were obtained independently from ratings of the probability and severity of the incidents. Decision-making style was measured using a scale inspired from the Cognitive Style Index; information security expertise was self-reported. Regression analysis was used to test the relationship between variables. Findings The ten respondents did not assess risk as the product of probability and severity, regardless of experience, expertise and decision-making style. The mean variance explained in risk ratings using an additive term is 54.0 or 38.4 per cent, depending on how risk is measured. When a multiplicative term was added, the mean variance only increased by 1.5 or 2.4 per cent. For most of the respondents, the contribution of the multiplicative term is statistically insignificant. Practical Implications The inability or unwillingness to see risk as a product of probability and severity suggests that procedural support (e.g. risk matrices) has a role to play in the risk assessment processes. Originality/value This study is the first to test if information security risk is assessed as an interaction between probability and severity using suitable scales and a within-subject design. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Inf. Comput. Secur. | 2 |
| 2015 | A Meta-Analysis of Studies on Protection Motivation Theory and Information Security BehaviourabstractIndividuals' willingness to take security precautions is imperative to their own information security and the information security of the organizations they work within. This paper presents a meta-analysis of the protection motivation theory (PMT) to assess how its efficacy is influenced by the information security behavior it is applied to. It investigates if the PMT explains information security behavior better if: 1) The behavior is voluntary? 2) The threat and coping method is concrete or specific? 3) The information security threat is directed to the person itself? Synthesized data from 28 surveys suggests that the answers to all three questions are yes. Weighted mean correlation coefficients are on average 0.03 higher for voluntary behavior than mandatory behavior, 0.05 higher for specific behaviors than studies of general behaviors, 0.08 higher to threat appraisal when the threat targets the individual person instead of the person's organization or someone else. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Int. J. Inf. Secur. Priv. | 2 |
| 2015 | The sufficiency of the theory of planned behavior for explaining information security policy complianceabstractPurpose – This paper aims to challenge the assumption that the theory of planned behaviour (TPB) includes all constructs that explain information security policy compliance and investigates if anticipated regret or constructs from the protection motivation theory add explanatory power. The TPB is an established theory that has been found to predict compliance with information security policies well. Design/methodology/approach – Responses from 306 respondents at a research organization were collected using a questionnaire-based survey. Extensions in terms of anticipated regret and constructs drawn from the protection motivation theory are tested using hierarchical regression analysis. Findings – Adding anticipated regret and the threat appraisal process results in improvements of the predictions of intentions. The improvements are of sufficient magnitude to warrant adjustments of the model of the TPB when it is used in the area of information security policy compliance. Originality/value – This study is the first test of anticipated regret as a predictor of information security policy compliance and the first to assess its influence in relation to the TPB and the protection motivation theory. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Inf. Comput. Secur. | 2 |