Anders Pousette

dblp:322/8483 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2025
0000-0003-2146-9396ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021
YearPublicationVenuePosition
2025 Training for improved information security culture: a longitudinal randomized controlled trial
abstract
Purpose The information security behaviors of individuals can pose a risk to their organization’s information security. To address employees’ information security behaviors and managers’ information security leadership behaviors, this paper aims to develop a behavioral training program called Training for Improved Information Security Culture (TIISC). TIISC consisted of information-security training for the employees and managerial behavioral training for the managers. The training program aimed at direct change of behavior as well as indirect change through improved information security culture, as manifested through information security climate. Design/methodology/approach The effects of TIISC on information security culture was assessed in a longitudinal randomized controlled trial. Data were collected over a 16-month period, using both behavioral measurements and questionnaires on behavior and climate. Latent growth modeling was used for the statistical analysis of change, in terms of how change differed between the control and experimental groups. Findings The results show that the training program had significant positive effects on the information security leadership of managers; but for employees, significant positive effects were only found for information security learning. Training programs that incorporate managerial behavioral training can realize important improvements in organizations’ information security culture, primarily by addressing managers’ information security leadership behaviors through behavior analysis and practice with performance feedback. Originality/value The authors report the results of a longitudinal randomized controlled trial testing the effects of information security training on multiple types of information security behaviors and approaches as indicators of information security culture. Longitudinal randomized controlled trials in security education training and awareness research are important because they advance the understanding of how information security culture can be effectively improved.
Martin Grill, Teodor Sommestad, Henrik Karlzén, Anders Pousette
Inf. Comput. Secur.4
2023 The impact of psychosocial working conditions on information security behaviour in the nuclear industry
abstract
Purpose The purpose of this paper is to investigate the relations among job resources, value conflicts, information security climate and information security behaviour in the nuclear industry. Design/methodology/approach Longitudinal questionnaire data on information security climate and psychosocial working conditions were collected from two organisations in Sweden (response rate 62% and 59%, respectively). Findings A high occurrence of value conflicts decreased the participative information security behaviour, while psychosocial job resources and high job demands had positive effects on such behaviour. High rule-compliant information security behaviour led to fewer perceived value conflicts. When job resources were high, high job demands had a positive effect on rule compliance. Information security climate had a strong and positive cross-sectional relationship with information security behaviour but no longitudinal influence on behaviour. This suggests that the time interval, one year between measurements, may have been too long and events between measurements may have masked the causal process. Originality/value As one of very few longitudinal studies of information security, this study illuminated causal relationships regarding information security behaviour that have not been possible to identify in previous cross-sectional research. This enables better understanding of psychosocial phenomena and processes of importance for information security. This study does not provide conclusive results but indicates new important directions for research.
Kristina Gyllensten, Marianne Törner, Anders Pousette
Inf. Comput. Secur.3
2022 Value conflicts and information security - a mixed-methods study in high-risk industry
abstract
Purpose The purpose of this study is to investigate the influence of work-related value conflicts on information security in two organisations in nuclear power production and related industry. Design/methodology/approach A mixed-methods design was applied. Individual interviews were conducted with 24 employees of two organisations in Sweden and questionnaire data on information security climate were collected from 667 employees (62%) in the same two organisations. Findings The qualitative part of the study identified five different types of value conflicts influencing information security behaviour. The quantitative part of the study found that value conflicts relating to information security had a negative relationship with rule-compliant behaviour. The opposite was found for participative security behaviour where there was a positive relationship with value conflicts. A high climate of information security was positively related to both rule-compliant and participative information security behaviour. It also moderated the effect of value conflicts on compliant information security behaviour. Originality/value This paper highlights organisational contextual conditions that influence employees’ motivation and ability to manage value conflicts relating to information security in a high-risk industry. It also enables a better understanding of the influence of the information security climate on information security in the presence of value conflicts in this type of industry.
Kristina Gyllensten, Anders Pousette, Marianne Törner
Inf. Comput. Secur.2