VLDB 2026 Research / reviewers in the wild / expert
Øyvind Anders Arntzen Toftegaard
dblp:224/9512
· DBLP profile ↗
6ranked-venue papers
5as first author
5since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Operational Technology resilience in the 2023 draft delegated act on cybersecurity for the power sector - An EU policy process analysis
Øyvind Anders Arntzen Toftegaard, Guro Grøtterud, Bernhard M. Hämmerli |
Comput. Law Secur. Rev. | 1 |
| 2023 | Relationships Between Security Management and Technical Security of Norwegian Energy Entities
Øyvind Anders Arntzen Toftegaard, Janne Merete Hagen, Bernhard M. Hämmerli |
critis | 1 |
| 2022 | An Effect Analysis of ISO/IEC 27001 Certification on Technical Security of Norwegian Grid OperatorsabstractDigital vulnerabilities and the risk of cyberattacks against the electric grid are a concern for both governments and businesses. There are several opportunities for authorities to impose security measures on grid operators to reduce risks. German legislation requires grid operators to certify their information security management system according to the ISO/IEC 27001 standard. Some researchers have tried to measure various effects of ISO/IEC 27001 certification, but nobody has so far assessed the effect of certification on technical security performance. This study hypothesizes that ISO/IEC 27001 certification will lead to increased technical security performance for Norwegian grid operators. A Quasi-Experimental methodology based on Difference in Differences logic is applied to test the hypothesis. 11.010 technical security scores from 400 entities were collected through BlackKite’s Technical Cyber Rating tool and Security Scorecard’s Security Rating tool. The effect of ISO/IEC 27001 certification was estimated by taking the difference in technical security performance between uncertified Norwegian grid operators and certified German grid operators, and subtracting the difference between a control group of Norwegian and German banks. The analysis predicts a significant positive effect for small Norwegian grid operators, it is inconclusive for medium-sized grid operators, and it indicates a negative effect for large grid operators. Since the research was limited to externally identifiable security mechanisms only, more research is necessary to fully understand the effect of ISO/IEC 27001 certification on technical security performance. Øyvind Anders Arntzen Toftegaard |
IEEE Big Data | 1 |
| 2022 | Is There a Relationship Between Grid Operators' Cybersecurity Level and Electricity Outages?
Øyvind Anders Arntzen Toftegaard, Bernhard M. Hämmerli, Jon-Martin Storm |
CRITIS | 1 |
| 2021 | A Survey of Using Process Data and Features of Industrial Control Systems in Intrusion DetectionabstractProtecting industrial control systems against cyber threats has become more pressing in the last decades. An increasing number of released vulnerabilities specifically targeting industrial systems makes protecting them exceedingly challenging. Incident detection is essential in protecting industrial systems, and this paper examines the state of the art in this area. The focus is on the research aspect, and the paper investigates "How has the research on the detection of cyber threats in industrial control systems evolved over the years?" This survey has explored research covering incident detection in industrial control systems from 1950 until today and reviewed a total of 750 papers, most of them published after 2003. After screening, 239 papers were relevant for a deeper exploration. The study reveals an increasing trend of published papers addressing detection capabilities in industrial control systems, with a rise in published papers from 2011. 86% of these research papers address standard features characteristic of industrial control systems, and 58% of the papers suggest using data from physical processes. However, most studies have a low technology readiness level; only 38 papers cover testing in a live test environment, and none cover testing in a system in operation. The overall findings show that, given the development of the threat landscape, and the urgency of good detection capabilities, there is a need for further research on detecting cyber threats using combined data sources in a live testing environment. Jon-Martin Storm, Janne Merete Hagen, Øyvind Anders Arntzen Toftegaard |
IEEE BigData | 3 |
| 2018 | Towards an Operable Evaluation System for Evidence of IdentityabstractIdentity fraud is a serious problem which can be used to conduct crimes such as economic fraud, human trafficking and terrorism. Many organizations have pointed out challenges in performing identity control, and a more operable framework for identity proofing and verification is desired in many practical applications. Although there are several guidelines and international standardization activities available on identity proofing and verification routines, complexity and variation among these frameworks can make them complicated to interpret and understand and thus little operable, particularly for smaller organizations performing identity control. Against the increasing trend of identity fraud worldwide, this paper proposes an Evidence of Identity (EoI) evaluation system design aiming at operationalizing requirements to evidence of identities in ID proofing and verification processes. The suggested system is designed to be included in a computer application, allowing easy use by front-desk officers. Øyvind Anders Arntzen Toftegaard, Bian Yang |
COMPSAC (2) | 1 |