Jan Tolsdorf

dblp:204/2573 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0002-1961-100XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 LISA: A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of Organizational Information Security Awareness in Heterogeneous Organizations
David Langer, Jan Tolsdorf, Luigi Lo Iacono
SP2
2025 Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University Hospital
abstract
Phishing attacks via email remain a major entry point for security and privacy breaches in hospitals. In the European Union, faced with both regulatory pressure to act and limited resources for cybersecurity, hospitals may resort to minimal-effort, off-the-shelf anti-phishing interventions such as warning banners in enterprise email systems. However, their effectiveness remains uncertain, particularly given the highly diverse workforce comprising medical, nursing, functional, administrative, IT, and other staff groups. We conducted a large-scale phishing simulation at a German university hospital, targeting 7,044 email accounts, to analyze how phishing susceptibility varies across staff groups, how email characteristics---such as timing, tone, context, and persuasive framing---influence susceptibility, and how 11 common in-situ anti-phishing interventions affect risky staff behavior. We found that susceptibility but also intervention effectiveness differed markedly across staff groups. Even a small number of phishing emails posed a substantial risk that persisted for about three days. The most effective interventions involved robust technical detection, including spam filtering and in-email phishing warnings. Friction-based measures, such as disabling links and active warning pages, showed mixed but promising effects. In contrast, display name suppression and the widely used method of generic [EXTERNAL] email tagging had no or inconsistent effects. Surveys revealed that some staff reacted with fear, shame, guilt, and hostility, highlighting the ethical challenges of such simulations. Our findings provide actionable guidance for phishing resilience in healthcare and similarly complex organizations.
Jan Tolsdorf, David Langer, Luigi Lo Iacono
CCS1
2025 Safety Perceptions of Generative AI Conversational Agents: Uncovering Perceptual Differences in Trust, Risk, and Fairness
Jan Tolsdorf, Alan F. Luo, Monica Kodwani, Junho Eum, Mahmood Sharif, Michelle L. Mazurek, Adam J. Aviv
SOUPS1
2024 Internet Users' Willingness to Disclose Biometric Data for Continuous Online Account Protection: An Empirical Investigation
abstract
Continuous authentication has emerged as a promising approach to increase user account security for online services. Unlike traditional authentication methods, continuous authentication provides ongoing security throughout the session, protecting against session takeover attacks due to illegitimate access. The effectiveness of continuous authentication systems relies on the continuous processing of users' sensitive biometric data. To balance security and privacy trade-offs, it's crucial to understand when users are willing to disclose biometric data for enhanced account security, addressing inevitable privacy concerns and user acceptance. To address this knowledge gap, we conducted an online study with 830 participants from the U.S., aiming to investigate user perceptions towards continuous authentication across different classes of online services. Our analysis identified four groups of biometric traits that directly reflect users' willingness to disclose them. Our findings demonstrate that willingness to disclose is influenced by both the specific biometric traits and the type of online service involved. User perceptions are strongly shaped by factors such as response efficacy, perceived privacy risks associated with the biometric traits, and concerns about the service providers' handling of such data. Our results emphasize the inadequacy of one-size-fits-all solutions and provide valuable insights for the design and implementation of continuous authentication systems.
Florian Dehling, Jan Tolsdorf, Hannes Federrath, Luigi Lo Iacono
Proc. Priv. Enhancing Technol.2
2022 Data cart - designing a tool for the GDPR-compliant handling of personal data by employees
abstract
Employees who process personal data as part of their job play a critical role in protecting privacy. They are expected to follow strict data protection guidelines and protect personal data adequately. However, few studies have addressed the needs of these employees in terms of appropriate tools to assist them in complying with privacy laws. To develop a suitable tool, we used a human-centred design approach and held a series of eight workshops with 19 employees from two German public institutions. Based on the metaphor of a data cart, we developed a concept for a tool that supports employees in data management and data protection compliance. Qualitative usability testing revealed that participants expected the tool to raise their data protection awareness, reduce errors, and increase work efficiency. Our findings also suggest that if Privacy by Design becomes an integral part of digitalisation, employee perceptions of data protection may be positively altered. Employers, IT engineers, and researchers benefit from gaining insights into ways to improve the usability of data protection compliant personal data management tools. Simultaneously, we highlight how they can improve and promote compliance.
Jan Tolsdorf, Florian Dehling, Luigi Lo Iacono
Behav. Inf. Technol.1
2022 Employees' privacy perceptions: exploring the dimensionality and antecedents of personal data sensitivity and willingness to disclose
abstract
Abstract The processing of employees’ personal data is dramatically increasing, yet there is a lack of tools that allow employees to manage their privacy. In order to develop these tools, one needs to understand what sensitive personal data are and what factors influence employees’ willingness to disclose. Current privacy research, however, lacks such insights, as it has focused on other contexts in recent decades. To fill this research gap, we conducted a cross-sectional survey with 553 employees from Germany. Our survey provides multiple insights into the relationships between perceived data sensitivity and willingness to disclose in the employment context. Among other things, we show that the perceived sensitivity of certain types of data differs substantially from existing studies in other contexts. Moreover, currently used legal and contextual distinctions between different types of data do not accurately reflect the subtleties of employees’ perceptions. Instead, using 62 different data elements, we identified four groups of personal data that better reflect the multi-dimensionality of perceptions. However, previously found common disclosure antecedents in the context of online privacy do not seem to affect them. We further identified three groups of employees that differ in their perceived data sensitivity and willingness to disclose, but neither in their privacy beliefs nor in their demographics. Our findings thus provide employers, policy makers, and researchers with a better understanding of employees’ privacy perceptions and serve as a basis for future targeted research on specific types of personal data and employees.
Jan Tolsdorf, Delphine Reinhardt, Luigi Lo Iacono
Proc. Priv. Enhancing Technol.1
2021 Components and Architecture for the Implementation of Technology-Driven Employee Data Protection
Florian Dehling, Denis Feth, Svenja Polst, Bianca Steffes, Jan Tolsdorf
TrustBus5
2021 Exploring mental models of the right to informational self-determination of office workers in Germany
abstract
Abstract Applied privacy research has so far focused mainly on consumer relations in private life. Privacy in the context of employment relationships is less well studied, although it is subject to the same legal privacy framework in Europe. The European General Data Protection Regulation (GDPR) has strengthened employees’ right to privacy by obliging that employers provide transparency and intervention mechanisms. For such mechanisms to be effective, employees must have a sound understanding of their functions and value. We explored possible boundaries by conducting a semi-structured interview study with 27 office workers in Germany and elicited mental models of the right to informational self-determination, which is the European proxy for the right to privacy. We provide insights into (1) perceptions of different categories of data, (2) familiarity with the legal framework regarding expectations for privacy controls, and (3) awareness of data processing, data flow, safeguards, and threat models. We found that legal terms often used in privacy policies used to describe categories of data are misleading. We further identified three groups of mental models that differ in their privacy control requirements and willingness to accept restrictions on their privacy rights. We also found ignorance about actual data flow, processing, and safeguard implementation. Participants’ mindsets were shaped by their faith in organizational and technical measures to protect privacy. Employers and developers may benefit from our contributions by understanding the types of privacy controls desired by office workers and the challenges to be considered when conceptualizing and designing usable privacy protections in the workplace.
Jan Tolsdorf, Florian Dehling, Delphine Reinhardt, Luigi Lo Iacono
Proc. Priv. Enhancing Technol.1
2017 On the Security Expressiveness of REST-Based API Definition Languages
Hoai Viet Nguyen, Jan Tolsdorf, Luigi Lo Iacono
TrustBus2