Lea Gröber

dblp:181/8259 · also Lea Theresa Gröber · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
10since 2021 · last 2026
0009-0001-7921-9544ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors
abstract
Cybersecurity incident response has emerged as a critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology, human-computer interaction, organizational theory, and human factors. A comprehensive, integrative perspective on these factors can enable researchers to identify underexplored areas and more effectively target their empirical and theoretical investigations. Our study systematizes the factors that influence organizational preparedness for and response to cybersecurity incidents. Through a systematic review of academic literature (n = 417) and non-scientific publications (n = 40), we derived the "Cybersecurity Incident Response Influencing Factor Taxonomy" (\textit{CIR-IF Taxonomy}). Existing empirical findings were classified within this taxonomy, providing a comprehensive and up-to-date overview of knowledge from the period 1999 to mid-2024. The taxonomy categories were systematically compared with seven established scientific frameworks and with the \textit{NIST Cyber Security Framework} elements referenced in the \textit{NIST Special Publication 800-61r3} incident response profile. The results of this comparison show that the \textit{CIR-IF Taxonomy} delivers a richer, more rigorous, and more systematically organized view of the factors that drive and shape incident response.
Thomas Biege, Marius Brockhoff, Jonas Kaspereit, Fabian Ising, Lea Gröber, Sebastian Schinzel
EuroS&P5
2026 Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration Challenges
Sumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz, Mobin Javed
NDSS3
2025 Understanding the Security Advice Mechanisms of Low Socioeconomic Pakistanis
abstract
Figure 1: The helper (on the right) sets up a password for the user's new Android phone.
Sumair Ijaz Hashmi, Rimsha Sarfaraz, Lea Gröber, Mobin Javed, Katharina Krombholz
CHI3
2024 "I chose to fight, be brave, and to deal with it": Threat Experiences and Security Practices of Pakistani Content Creators
Lea Gröber, Waleed Arshad, Shanza, Angelica Goetzen, Elissa M. Redmiles, Maryam Mustafa, Katharina Krombholz
USENIX Security Symposium1
2024 Towards Privacy and Security in Private Clouds: A Representative Survey on the Prevalence of Private Hosting and Administrator Characteristics
Lea Gröber, Simon Lenau, Rebecca Weil, Elena Groben, Michael Schilling 0001, Katharina Krombholz
USENIX Security Symposium1
2024 Trust Me If You Can - How Usable Is Trusted Types In Practice?
Sebastian Roth, Lea Gröber, Philipp Baus, Katharina Krombholz, Ben Stock
USENIX Security Symposium2
2023 To Cloud or not to Cloud: A Qualitative Study on Self-Hosters' Motivation, Operation, and Security Mindset
Lea Gröber, Rafael Mrowczynski, Nimisha Vijay, Daphne A. Muller, Adrian Dabrowski, Katharina Krombholz
USENIX Security Symposium1
2021 12 Angry Developers - A Qualitative Study on Developers' Struggles with CSP
abstract
The Web has improved our ways of communicating, collaborating, teaching, and entertaining us and our fellow human beings. However, this cornerstone of our modern society is also one of the main targets of attacks, most prominently Cross-Site Scripting (XSS). A correctly crafted Content Security Policy (CSP) is capable of effectively mitigating the effect of those Cross-Site Scripting attacks. However, research has shown that the vast majority of all policies in the wild are trivially bypassable.
Sebastian Roth, Lea Gröber, Michael Backes 0001, Katharina Krombholz, Ben Stock
CCS2
2021 Exploring User-Centered Security Design for Usable Authentication Ceremonies
abstract
Security technology often follows a systems design approach that focuses on components instead of users. As a result, the users’ needs and values are not sufficiently addressed, which has implications on security usability. In this paper, we report our lessons learned from applying a user-centered security design process to a well-understood security usability challenge, namely key authentication in secure instant messaging. Users rarely perform these key authentication ceremonies, which makes their end-to-end encrypted communication vulnerable. Our approach includes collaborative design workshops, an expert evaluation, iterative storyboard prototyping, and an online evaluation.
Matthias Fassl, Lea Gröber, Katharina Krombholz
CHI2
2021 Investigating Car Drivers' Information Demand after Safety and Security Critical Incidents
abstract
Modern cars include a vast array of computer systems designed to remove the burden on drivers and enhance safety. As cars are evolving towards autonomy and taking over control, e.g. in the form of autopilots, it becomes harder for drivers to pinpoint the root causes of a car’s malfunctioning. Drivers may need additional information to assess these ambiguous situations correctly. However, it is yet unclear which information is relevant and helpful to drivers in such situations. Hence, we conducted a mixed-methods online survey (N = 60) on Amazon MTurk where we exposed participants to two security- and safety-critical situations with one of three different explanations. We applied Thematic and Correspondence Analysis to understand which factors in these situations moderate drivers’ information demand. We identified a fundamental information demand across scenarios that is expanded by error-specific information types. Moreover, we found that it is necessary to communicate error sources, since drivers might not be able to identify them correctly otherwise. Thereby, malicious intrusions are typically perceived as more critical than technical malfunctions.
Lea Gröber, Matthias Fassl, Abhilash Gupta, Katharina Krombholz
CHI1