VLDB 2026 Research / reviewers in the wild / expert
Bibi van den Berg
dblp:69/8686
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0002-4810-0460ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Assessing the effect of cybersecurity training on End-users: A Meta-analysisabstractCybersecurity behaviour of end-users continues to be a growing topic of conversation, both in organisations and in academia, as end-users are often said to be the last line of defence against cyberattacks. Unfortunately, end-users are often not aware that they engage in risky cyber behaviours and can, in turn, make themselves and the organisations that they work for vulnerable. Attempting to change end-user behaviour through training programs has become common practice in many organisations, a trend that is reflected in the academic literature as well. While a variety of literature reviews on the topic are available, an assessment of the effectiveness of these training programs through a meta-analysis has so far not been conducted. We carried out a meta-analysis based on a systematic literature review on the topic and an updated literature search in order to assess the overall effectiveness of cybersecurity training programs. We identified 69 studies that were eligible for inclusion. Our analysis shows that training overall has a positive effect on end-users ( d = 0.75, 95%CI [0.58, 0.92]), particularly when assessing predictors of behaviour such as attitudes or knowledge ( d = 1.02, 95%CI [0.58, 1.46]). Interestingly, studies assessing changes in behaviour are not able to match these results ( d = 0.36, 95%CI [-0.09, 0.80]), showcasing a clear inability of current training approaches to change behaviour. The effect sizes obtained in this meta-analysis can act as smallest effect sizes of interest (SESOIs) for future research on end-user cybersecurity training. Further findings with regards to the effectiveness of individual training methods and other moderators are discussed. Julia Prümmer, Tommy van Steen, Bibi van den Berg |
Comput. Secur. | 3 |
| 2024 | Shielding software systems: A comparison of security by design and privacy by design based on a systematic literature reviewabstractThe design of software systems plays a crucial role in mitigating cybersecurity incidents. Security by Design (SbD) aims to ensure foundational security throughout the design process. However, it lacks a precise interdisciplinary definition. Comparing it with Privacy by Design (PbD), which has seen more conceptual development, highlights the need for a comprehensive understanding of SbD. This study systematically searches and reviews relevant definitions of SbD in comparison with PbD. Following PRISMA guidelines, we conducted a systematic review of SbD and PbD definitions, searching ACM Digital Library, EBSCO Library, IEEE Xplore, ProQuest, Scopus, and Web of Science. A total of 46 studies were included, identifying 86 definitions. Thirteen themes were identified, including ontology, object of protection, outcome to avoid, means of implementation, added value, and focus of the definition. Definitions varied in their descriptions of SbD and PbD, the objects of protection, outcomes to avoid, means of implementation, and lifecycle focus. PbD definitions adopted a rights-based approach, anchored in Ann Cavoukian's principles and an interdisciplinary perspective. SbD and PbD definitions lack clarity and uniformity. PbD is better defined, while SbD lacks anchorage and has varied approaches. Both should protect individuals and organizations, address cyber-attacks, and be implemented early in the development process. PbD is more comprehensive, involving technology and organization, while SbD focuses mainly on the technical product. PbD is associated with recognized rights, but the connection between SbD and human rights is unclear. Future research should clarify the specific value protected by SbD, adopt principles from PbD, and take an interdisciplinary approach. Cristina Del-Real, Els De Busser, Bibi van den Berg |
Comput. Law Secur. Rev. | 3 |
| 2024 | Dealing with uncertainty in cyberspaceabstractWhile cyberspace as a globally interconnected network offers economic, social and informational potential, at the same time this space also produces a wide variety of risks, for which no easy solutions exist. For the international community, for nation states, for organizations and even for individuals, uncertainty is a common thread for interaction, communication and the general use of (systems connected to) cyberspace. This research shows that there are five different common reactions to dealing with this uncertainty in cyberspace: (1) using risk management to control uncertainty; (2) recovering from uncertainty through resilience; (3) influencing uncertainty with laws and regulation; suspending uncertainty by engaging in trust; and (5) ignoring uncertainty through inaction. Some of these approaches are used more often than others. For instance, risk management is currently the dominant way of responding to uncertainty in cyberspace, with resilience gaining prominence. Other strategies, such as relying on trust or inaction, are less common. Oftentimes, using a mixture of strategies may be helpful, because some strategies may strengthen one another, for instance when a combination of risk management and resilience approaches is used. Each strategy has particular use for specific contexts, but since we lack an overview of which strategies are being used, we also cannot establish under which conditions which strategy is most beneficial. Solving this lack of knowledge can help us be more effective in dealing with uncertainties of a wide variety in cyberspace. Bibi van den Berg |
Comput. Secur. | 1 |
| 2024 | A systematic review of current cybersecurity training methodsabstractCybersecurity continues to be a growing issue, with cyberattacks causing financial losses and loss of productivity and reputation. Especially in an organisational setting, end-user behaviour plays an essential role in achieving a high level of cybersecurity. One way to improve end-user cybersecurity behaviour is through comprehensive training programmes. There are many contradictory statements and findings with regard to the optimal way to conduct a behavioural cybersecurity training. We conducted a systematic review to create a comprehensive overview of the methods used in cybersecurity training and their effectiveness in improving organisational cybersecurity behaviours. Web of Science, ACM Digital Library, ProQuest, PubMed and PsycINFO were searched and 16771 papers were identified. After title, abstract and full text screenings were conducted, 142 relevant papers were included in our analysis. The analysis shows that the majority of studies report positive effects of training, regardless of the cybersecurity topic that was addressed or the training method that was employed. Game-based training methods were used most often. Most studies used a non-experimental design to test effectiveness, with pretest-posttest designs being the most frequent. Sample sizes were often small and many interventions were not tested on employees but other populations. Further findings with regard to intervention design, characteristics and evaluation are discussed. Julia Prümmer, Tommy van Steen, Bibi van den Berg |
Comput. Secur. | 3 |