Simon Vrhovec

dblp:184/5049 · also Simon L. R. Vrhovec · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
6since 2021 · last 2024
0000-0002-6951-6369ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 6 since 2021
YearPublicationVenuePosition
2024 Security and privacy oriented information security culture (ISC): Explaining unauthorized access to healthcare data by nursing employees
abstract
Protecting sensitive healthcare data is particularly challenging. Nursing employees are critical in protecting healthcare data since they make up a large portion of the healthcare workforce and have direct access to healthcare data. Information security culture (ISC) plays a prominent role in protection of healthcare data albeit their relationship remains unclear. In this study, we first define and operationalize two new dimensions of organizational ISC related to security and privacy. Then, a survey of Slovenian nursing employees (n = 527) was conducted to validate the measurement instrument and examine the associations between the newly developed ISC dimensions and unauthorized access to healthcare data by nursing employees based on the theory of planned behavior (TPB). The measurement instrument was first validated with an exploratory and then with a confirmatory factor analysis. Both analyses indicate adequate validity and reliability of the newly developed ISC dimensions. The results of PLS-SEM analysis show that security oriented ISC is negatively associated with subjective norms and normative beliefs while privacy oriented ISC is negatively associated with attitude toward behavior. Additionally, they indicate that TPB explains well unauthorized access to healthcare data. The results of our study thus indicate an indirect relation between ISC and unauthorized access to healthcare data. Awareness training is considered as essential means for ensuring proper practical implementations of ethical norms, such as privacy-preserving behavior, by nursing employees. Our study suggests that such awareness interventions may aim either to strengthen the social influence on nursing employees, their attitudes or both. Awareness interventions aiming to strengthen the social influence of nursing employees may focus on established organizational data protection practices and other important organizational values, norms, and accepted ways of working in an organization. Attitudes of nursing employees may be strengthened with awareness interventions focusing on their personal beliefs and ethics.
Samanta Mikuletic, Simon Vrhovec, Brigita Skela-Savic, Bostjan Zvanut
Comput. Secur.2
2023 Balancing software and training requirements for information security
abstract
Information security is one of the key areas of consideration to assure reliable and dependable information systems (IS). Achieving an appropriate level of IS security requires concurrent consideration of the technical aspects of IS and the human aspects related to the end users of IS. These aspects can be described in the form of information security requirements. We propose an approach that helps select and balance information security software requirements (iSSR) and information security training requirements (iSTR) according to the information security performance of end users. The approach was tested in an experiment involving 128 IS professionals. The results showed that using the proposed approach helps IS professionals with limited experience in information security make significantly better decisions regarding iSSR and iSTR.
Damjan Fujs, Simon Vrhovec, Damjan Vavpotic
Comput. Secur.2
2023 Why people replace their aging smart devices: A push-pull-mooring perspective
abstract
During the last decade, the Internet of Things (IoT) has become a central enabler for technological developments and services, such as ambient assisted living and localization services. Billions of smart devices have been sold, with many aged devices still in use today. In several cases, such aged smart devices do not receive security updates after some time of operation, making them a threat to the privacy of end-users. For this reason, it is crucial to understand driving factors for users to keep older devices as well as factors that lead to device switches, which can be considered as a security measure against cyber threats in this context. In this paper, we analyze what factors people associate with replacing older smart devices with newer ones as a way to mitigate the risks linked to aged smart devices. To achieve this, we apply the push-pull-mooring framework to integrate privacy, adoption and switching theories into a unified framework. To empirically validate the framework, we conducted an online survey among N=513 owners of older smart devices (i.e., purchased more than a year ago) from the UK through the Prolific platform. The results of our study show that perceived usefulness of new devices was strongly associated with switching intention. These results offer only limited support for technology adoption theories, as switching intention was not associated with other adoption constructs (pull factors). Privacy concern regarding improper access to personal information collected by an older smart device and switching costs (a push and a mooring factor, respectively) were also associated with switching costs. The results also indicate support for the moderating role of age of smart device, since the latter associations were not significant for smart devices up to three years old. We also provide some practical implications for manufacturers with a green and sustainable future in mind.
Julia Lenz, Zdravko Bozakov, Steffen Wendzel, Simon Vrhovec
Comput. Secur.4
2023 Explaining information seeking intentions: Insights from a Slovenian social engineering awareness campaign
abstract
The human factor remains one of the key challenges in cybersecurity despite effective technical countermeasures in place. This study aims to determine what motivates individuals to seek information about social engineering by investigating the determinants of behavioral intention to follow the materials of a social engineering awareness campaign in Slovenia. A quantitative survey of individuals in Slovenia (N=542) aged 15 or older was administered with participants recruited through University of Maribor students. Data were collected on constructs related to the protection motivation theory (PMT) and the theory of planned behavior (TPB) as well as privacy concerns and perceived performance of authorities. The survey instrument was validated with a confirmatory factor analysis. Covariance-based structural equation modeling (CB-SEM) was used to determine relationships between constructs and analysis of differences between students and employed individuals. Results indicate perceived threat, subjective norm, attitude toward behavior and authorities performance are all significant predictors of behavioral intention. The associations between perceived threat and behavioral intention, and privacy concern and attitude towards behavior was not significant among employed individuals. Among students, trust in authorities was not a significant predictor of authorities performance. This study has several implications. The results of this study suggest that fear appeals may be effective in motivating individuals to seek information about social engineering attacks thus improving the effectiveness of awareness campaigns. They also offer some insights into how to improve messaging towards the target populations. Messaging emphasizing perceived threat may directly increase information seeking intention while messaging emphasizing coping with social engineering may do so indirectly through attitude towards behavior. This study also indicates that messaging should be tailored to the target population (e.g., messaging emphasizing perceived threat may be much less effective for employed individuals than students).
Simon Vrhovec, Igor Bernik, Blaz Markelj
Comput. Secur.1
2021 Crème de la Crème: Lessons from Papers in Security Publications
abstract
The number of citations attracted by publications is a key criteria for measuring their success. To avoid discriminating newer research, such a metric is usually measured in average yearly citations. Understanding and characterizing how citations behave have been prime research topics, yet investigations targeting the cybersecurity domain seem to be particularly scarce. In this perspective, the paper aims at filling this gap by analyzing average yearly citations for 6,693 papers published in top-tier conferences and journals in cybersecurity. Results indicate the existence of three clusters, i.e., general security conferences, general security journals, and cryptography-centered publications. The analysis also suggests that the amount of conference-to-conference citations stands out compared to journal-to-journal and conference-to-journal citations. Besides, papers published at top conferences attract more citations although a direct comparison against other venues is not straightforward. To better quantify the impact of works dealing with cybersecurity aspects, the paper introduces two new metrics, namely the number of main words in the title, and the combined number of unique main words in title, abstract and keywords. Collected results show that they can be associated with average yearly citations (together with the number of cited references). Finally, the paper draws some ideas to take advantage from such findings.
Simon Vrhovec, Luca Caviglione, Steffen Wendzel
ARES1
2021 Redefining threat appraisals of organizational insiders and exploring the moderating role of fear in cyberattack protection motivation
Simon Vrhovec, Anze Mihelic
Comput. Secur.1
2019 The power of interpretation: Qualitative methods in cybersecurity research
abstract
Cybersecurity is a hot topic and researchers have published extensively on studies conducted using a variety of different research methods. This paper aims to determine which qualitative research methods were most used and for studying which topics. A systematic literature review on Web of Science, Scopus and ACM DL has been conducted to achieve an overview of quantitative methods used in cybersecurity. The review covered the most recent research in different areas of cybersecurity (i.e., personal, organizational and state cybersecurity) in the period of 2017 to 2019. After careful inspection of papers, we identified 160 papers reporting on the use of qualitative methods. The most common qualitative methods are interviews, followed by case studies and observation. Other studied qualitative methods (i.e., focus groups, grounded theory, action research and Delphi method) seem to be much less frequent. Although qualitative methods are used when studying all key cybersecurity areas, they often lack the necessary rigor and detail observed in other research areas where qualitative methods are well-established.
Damjan Fujs, Anze Mihelic, Simon Vrhovec
ARES3