VLDB 2026 Research / reviewers in the wild / expert
Daniel Sturman
dblp:171/2798
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0002-5025-598XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Security awareness, decision style, knowledge, and phishing email detection: Moderated mediation analysesabstractThis study examines whether the negative relationship between email information security awareness and phishing email susceptibility is mediated by less intuitive decision-making when assessing emails, and whether this relationship is moderated by phishing email knowledge. Participants ( N = 291) completed an online email sorting task, a measure of email use information security awareness, a measure of preference for intuitive decision-making with emails, and a measure of phishing email knowledge. Moderated mediation analyses indicated that information security awareness predicted positive behavioural intentions directly and indirectly through lower preference for intuitive decision-making, and these relationships were stronger when phishing email knowledge was lower. Further, both the direct and indirect relationships between information security awareness and sensitivity through intuitive decision styles were moderated by phishing email knowledge, with information security awareness positively predicting ability to discriminate phishing from genuine emails when phishing knowledge was average or high but not low. These findings suggest that in the absence of phishing knowledge, information security awareness and less intuitive decision styles reduce susceptibility to phishing attacks through increased caution. Further, the findings provide strong support for the proposition that some level of phishing knowledge is required before email security behaviours and decision-making processes aid in the detection of phishing emails. From an applied perspective, the outcomes suggest that focusing on a combination of awareness, knowledge, and decision-making processes could increase the effectiveness of anti-phishing and cybersecurity training programs. Daniel Sturman, Jaime C. Auton, Ben W. Morrison |
Comput. Secur. | 1 |
| 2025 | Hey "CSIRI", should I report this? Investigating the factors that influence employees to report cyber security incidents in the workplaceabstractPurpose Cyber security incidents pose a major threat to organisations. Reporting cyber security incidents and providing organisations with information about their true nature, type and volume, is crucial to inform risk-based decisions. Despite the importance of reporting cyber security incidents, little research has addressed employees’ motivations to do so. Therefore, the purpose of this study is to investigate the factors that influence employees to report cyber security incidents using the theory of planned behaviour as a theoretical framework. Design/methodology/approach Survey data were collected from a sample of 549 working Australian adults. Demographics were gathered, in addition to data using the Cyber Security Incident Reporting Inventory (CSIRI; pronounced, “Siri”). Findings Attitude towards reporting, subjective norms and perceived behavioural control each significantly predicted intention-to-report cyber security incidents. Perceived behavioural control also significantly predicted actual reporting behaviour. Research limitations/implications The results of this study validate the application of the theory of planned behaviour to the cyber security incident reporting context, also indicating that the relationship between intention to report a cyber security incident and actual reporting behaviour may be facilitated by perceived behavioural control. Practical implications These findings can be applied to inform the development of strategies that increase employees’ cyber security incident reporting behaviour. Originality/value This study outlines the development of a new tool to measure attitudes, subjective norms and perceived behavioural control in relation to the reporting of cyber security incidents. To the best of the authors’ knowledge, this is the first study of its kind to identify the relationship between these factors and intentions to report cyber security incidents. Kristiina Ahola, Marcus A. Butavicius, Agata McCormac, Daniel Sturman |
Inf. Comput. Secur. | 4 |
| 2025 | Persuasion under pressure: the influence of persuasion principles and time constraints on phishing email susceptibilityabstractPurpose This study aims to examine how commonly used persuasion principles (authority, scarcity) and less commonly used principles (reciprocity, social proof) influenced users’ ability to differentiate between phishing and genuine emails and whether this effect was moderated by time pressure. Design/methodology/approach In an online email management study, participants (n = 200) categorised 60 emails (50 genuine, 10 phishing) and assessed the safety of embedded URL links. Time pressure was experimentally manipulated, with participants given either 7 s (greater time pressure) or 15 s (lesser time pressure) to review each email. Emails varied in containing a common, uncommon or no persuasion principle. Findings Participants were most skilled at detecting phishing emails and unsafe links when they contained scarcity and social proof principles, indicating that a persuasion principle’s ability to deceive users may not rely on its frequency in real-world phishing attacks. While participants demonstrated greater phishing detection and URL safety awareness under lesser time pressure, the effect of persuasion principles was not significantly moderated by time constraints. Practical implications Training interventions should focus on helping users recognise persuasion principles and encourage systematic email evaluation, even under time constraints, to mitigate phishing risks. Jaime C. Auton, Daniel Sturman |
Inf. Comput. Secur. | 2 |
| 2024 | Exploring the evidence for email phishing training: A scoping reviewabstractPhishing emails are a pervasive threat to the security of confidential information. To mitigate this risk, a range of training measures have been developed to target the human factors involved in phishing email susceptibility. Despite the widespread use of anti-phishing training programs, there is no clear understanding of the extent to which these approaches have been assessed. The primary aim of this scoping review was to identify and describe the nature of available training interventions and their measurable outcomes on user susceptibility, as reported in published articles. Systematic searches identified 42 studies that met the inclusion criteria. Each study was critically analysed, and a standardised data extraction spreadsheet used to systemise the data that informed the descriptive narrative review. Findings revealed that near-term training impact is well documented, however evidence on the success of programs in driving sustained behavioral change is limited. Components of training design influencing the effectiveness of outcomes included training intensity, active approaches to learning, the provision of detailed feedback, and supplementing attentional awareness skills-based training with traditional cue-based approaches. Improved user resilience to phishing emails confirms the utility of training as an important defensive mechanism, although current approaches continue to leave trainees at risk. Nina Marshall, Daniel Sturman, Jaime C. Auton |
Comput. Secur. | 2 |