VLDB 2026 Research / reviewers in the wild / expert
Peter Dornheim
dblp:275/0080
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2024
0000-0002-8121-8735ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Assessing information security culture: A mixed-methods approach to navigating challenges in international corporate IT departmentsabstractIn the digital era, fostering a strong information security culture in organizations, especially multinational IT departments, is essential to combat cyber threats. This study examines the effectiveness of a mixed-methods approach that combines quantitative surveys with qualitative insights from semi-structured interviews to assess information security culture comprehensively. Through a systematic literature review , the research identifies gaps and opportunities within the academic exploration of information security culture. Using semi-structured interviews with IT professionals from a multinational software company, the study complements an existing quantitative survey to delve deeper into six predefined dimensions of security culture. The qualitative data obtained from the interviews were analyzed using Mayring’s qualitative content analysis. The results provided nuanced insights into the organization’s security culture, with particular emphasis on aspects such as the accessibility of policies, the commitment of management, and the adequacy of training programs. Confirming the validity of the integrated approach, a comparative analysis of the qualitative findings with the survey data revealed no significant statistical differences in most dimensions. However, differences in certain areas highlighted the need for more transparent communication and specialized training initiatives. The study underscores the complexities involved in cultivating a resilient information security culture. It also demonstrates the value of a mixed-methods approach for a rigorous assessment. This study contributes to the academic discussion of information security culture and provides practical insights for organizations seeking to strengthen their security posture . It advocates further research into different organizational contexts and the cost-effectiveness of qualitative assessments. Anna Zanke, Thorsten Weber, Peter Dornheim, Mathias Engel |
Comput. Secur. | 3 |
| 2024 | Determining cybersecurity culture maturity and deriving verifiable improvement measuresabstractPurpose The human factor is the most important defense asset against cyberattacks. To ensure that the human factor stays strong, a cybersecurity culture must be established and cultivated in a company to guide the attitudes and behaviors of employees. Many cybersecurity culture frameworks exist; however, their practical application is difficult. This paper aims to demonstrate how an established framework can be applied to determine and improve the cybersecurity culture of a company. Design/methodology/approach Two surveys were conducted within eight months in the internal IT department of a global software company to analyze the cybersecurity culture and the applied improvement measures. Both surveys comprised the same 23 questions to measure cybersecurity culture according to six dimensions: cybersecurity accountability, cybersecurity commitment, cybersecurity necessity and importance, cybersecurity policy effectiveness, information usage perception and management buy-in. Findings Results demonstrate that cybersecurity culture maturity can be determined and improved if accurate measures are derived from the results of the survey. The first survey showed potential for improving the dimensions of cybersecurity accountability, cybersecurity commitment and cybersecurity policy effectiveness, while the second survey proved that these dimensions have been improved. Originality/value This paper proves that practical application of cybersecurity culture frameworks is possible if they are appropriately tailored to a given organization. In this regard, scientific research and practical application combine to offer real value to researchers and cybersecurity executives. Peter Dornheim, Rüdiger Zarnekow |
Inf. Comput. Secur. | 1 |