Yair Levy

dblp:81/6917 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Comparing experts' and users' perspectives on the use of password workarounds and the risk of data breaches
abstract
Purpose The increased use of Information Systems (IS) as a working tool for employees increases the number of accounts and passwords required. Despite being more aware of password entropy, users still often participate in deviant password behaviors, known as “password workarounds” or “shadow security.” These deviant password behaviors can put individuals and organizations at risk, resulting in a data breach. This paper aims to engage IS users and Subject Matter Experts (SMEs), focused on designing, developing and empirically validating the Password Workaround Cybersecurity Risk Taxonomy (PaWoCyRiT) – a 2x2 taxonomy constructed by aggregated scores of perceived cybersecurity risks from Password Workarounds (PWWAs) techniques and their usage frequency. Design/methodology/approach This research study was a developmental design conducted in three phases using qualitative and quantitative methods: (1) A set of 10 PWWAs that were identified from the literature were validated by SMEs along with their perspectives on the PWWAs usage and risk for data breach; (2) A pilot study was conducted to ensure reliability and validity and identify if any measurement issues would have hindered the results and (3) The main study data collection was conducted with a large group of IS users, where also they reported on coworkers' engagement frequencies related to the PWWAs. Findings The results indicate that statistically significant differences were found between SMEs and IS users in their aggregated perceptions of risks of the PWWAs in causing a data breach, with IS users perceiving higher risks. Engagement patterns varied between the two groups, as well as factors like years of IS experience, gender and job level had statistically significant differences among groups. Practical implications The PaWoCyRiT taxonomy that the we have developed and empirically validated is a handy tool for organizational cyber risk officers. The taxonomy provides organizations with a quantifiable means to assess and ultimately mitigate cybersecurity risks. Social implications Passwords have been used for a long time to grant controlled access to classified spaces, electronics, networks and more. However, the dramatic increase in user accounts over the past few decades has exposed the realization that technological measures alone cannot ensure a high level of IS security; this leaves the end-users holding a critical role in protecting their organization and personal information. Thus, the taxonomy that the authors have developed and empirically validated provides broader implications for society, as it assists organizations in all industries with the ability to mitigate the risks of data breaches that can result from PWWAs. Originality/value The taxonomy the we have developed and validated, the PaWoCyRiT, provides organizations with insights into password-related risks and behaviors that may lead to data breaches.
Michael J. Rooney, Yair Levy, Wei Li 0025, Ajoy Kumar
Inf. Comput. Secur.2
2024 The Role of Heuristics and Biases in Linux Server Administrators' Information Security Policy Compliance at Healthcare Organizations
John McConnell, Yair Levy, Marti Snyder
ICISSP2
2024 Comparing Phishing Training and Campaign Methods for Mitigating Malicious Emails in Organizations
abstract
Although there have been numerous technological advancements in the last several years, there continues to be a real threat as it pertains to social engineering, especially phishing, spear-phishing, and Business Email Compromise (BEC). While the technologies to protect corporate employees and network borders have gotten better, there are still human elements to consider. No technology can protect an organization completely, so it is imperative that end users are provided with the most up-to-date and relevant Security Education, Training, and Awareness (SETA). Phishing, spear-phishing, and BEC are three primary vehicles used by attackers to infiltrate corporate networks and manipulate end users into providing them with valuable company information. Many times, this information can be used to hack the network for ransom or impersonate employees so that the attacker can steal money from the company. Analysis of successful attacks show not only a lack of technology adoption by many organizations, but also the end user's susceptibility to attacks. One of the primary mediums in which attackers enjoy success is through business email. This dissertation study was aimed at researching several phishing mitigation methods, including phishing training and campaign methods, as well as any human characteristics which create a successful cyberattack through business email. Phase 1 of this study validated the approach and measures through 27 cybersecurity experts’ opinions. Phase 2 was a pilot study that produced a procedure for data collection and analysis and gathered 172 data points across three groups containing 86 users. Phase 3, the main study, used the established data approach and gathered 1,104 data points across three groups containing 552 users. The results of the experiments were analyzed using Analysis of Variance (ANOVA) and Analysis of Covariance (ANCOVA) to address the research questions. Several significant findings are documented, including results that showed there were no statistical differences in phishing training methods. This study indicates that current training methods, such as annual awareness or continuous customized training appear to provide little to no added value compared to no training at all. In addition, this study indicates that phishing campaign methods have a significant impact on phishing success, specifically a Red Team campaign. Lastly, recommendations for future research and opinions for industry stakeholders on ways to strengthen their cybersecurity posture are provided.
Jackie Scott, Yair Levy, Wei Li 0025, Ajoy Kumar
ICISSP2
2024 The role of artificial intelligence (AI) in improving technical and managerial cybersecurity tasks' efficiency
abstract
Purpose Artificial intelligence (AI) can assist in the worldwide shortage of cybersecurity workers in technical and managerial roles. Thus, the purpose of this study was to investigate the role of AI in automating many of the routine tasks associated with cybersecurity. As such, AI enables cybersecurity personnel to reduce their workloads and focus on more strategic aspects of their work. Design/methodology/approach This study is an exploratory field study. The authors started by conducting a literature review to assess the possibility that AI tools can provide and how they can improve cybersecurity efficacy. Following this, the authors identified the specific core tasks for two cybersecurity work roles (technical and managerial) and searched for specific commercial tools that can perform each of the tasks. Then, the authors used the free ChatGPT 3.5 to list the current cybersecurity systems that use AI for the associated tasks, which the authors then reviewed with the tools’ documentation and websites to confirm these tasks were conducted or assisted by AI. Findings Results indicated that all 14 cybersecurity tasks of the technical work role are currently noted to be performed by commercial cybersecurity systems with AI-integrated capabilities, while only 11 of the 17 managerial work role tasks currently appear to be performed by AI. Practical implications The rapid integration of AI capabilities into commercial cybersecurity systems may suggest that the cybersecurity workforce must be currently trained on how to use AI tools in their daily operations, especially as it pertains to technical cybersecurity work roles. Social implications The cybersecurity workforce shortage is reported to exceed four million cybersecurity workers worldwide in 2023. Thus, further understanding of the role of AI in improving the efficiency of technical and managerial cybersecurity tasks is significant. Originality/value The value of this research lies in the initial assessment of the current AI capabilities of commercial cybersecurity systems, which will ultimately provide the “super-human” performances resulting from human-AI teaming.
Ruti Gafni, Yair Levy
Inf. Comput. Secur.2
2023 Experts' feedback on the cybersecurity footprint elements: in pursuit of a quantifiable measure of SMBs' cybersecurity posture
abstract
Purpose While data breaches are reported daily, organizations are struggling with quantifying their cybersecurity posture. This paper aims to introduce the Universal Cybersecurity Footprint Index (UCFI), an organizational measure of Cybersecurity Footprint. The UCFI helps organizations understand the challenges related to their overall cybersecurity posture and be able to assess it for their supply chain cybersecurity. The Theory of Cybersecurity Footprint states that the risk and damage that can be caused by an attacked organization are not related to the size of the organization but to a range of parameters that may affect the interconnected entities in their supply chain. Design/methodology/approach Based on the 26 elements found in prior research, a survey was conducted, using 27 subject matter experts to reveal the most relevant elements and then specify their importance level to calculate their relative weight. Findings Results indicated that 20 of the 26 elements were validated, and their weights were calculated. Finally, an equation representing the UCFI for an organization is introduced. Practical implications Organizations can choose their partners according to a minimum value of the UCFI to reduce their cybersecurity risks. Social implications Supply chain cybersecurity incidents have demonstrated in the past several years to provide a massive impact on society. Thus, further assisting in mitigation of cyberattacks to the supply chain is significant. Originality/value This research aims to provide further assistance for organizations in quantifying their cybersecurity footprint in effort to help reduce cyber incidents, especially those for small organizations.
Ruti Gafni, Yair Levy
Inf. Comput. Secur.2
2021 Introducing the concept of cybersecurity footprint
abstract
Purpose This paper aims to introduce the concept of cybersecurity footprint. Design/methodology/approach Characteristics of cybersecurity footprint are presented based on documented cases, and the domino effect of cybersecurity is illustrated. Organizational and individual cybersecurity footprints are outlined. Active and passive – digital vs cybersecurity footprints are then reviewed. Taxonomy of aware/unaware vs active/passive cybersecurity footprints are presented, followed by brief discussion of the implications for future research. Findings The concept of cybersecurity footprint is defined, and the evidence from prior cyber incidents is shown to emphasize the concept. Smaller organizations may have a large cybersecurity footprint, whereas larger organizations may have smaller one. Cyberattacks are focusing on the individuals or small organizations that are in the supply chain of larger organizations causing the domino effect. Practical implications Implications of cybersecurity footprint to individuals, organizations, societies and governments are discussed. The authors present organizations with ways to lower cybersecurity footprint along with recommendations for future research. Social implications Cybersecurity has a significant social implication worldwide, as the world is becoming cyber dependent. With the authors’ introduction of the cybersecurity footprint concept and call to further understand how organizations can measure and reduce it, the authors envision it as another perspective of assessing cyber risk and further help mitigate future cyber incidents. Originality/value This paper extends the existing information and computer security body of knowledge on the concept of cybersecurity footprint with illustrated cases.
Yair Levy, Ruti Gafni
Inf. Comput. Secur.1
2021 Employees' Mobile Cyberslacking and Their Commitment to the Organization
abstract
While the introduction of the Internet facilitated communication channels at the workplace to improve employees’ productivity, it also raised new challenges, such as cyberslacking. The problem that this research study addresses is mobile device cyberslacking at the workplace as it relates to productivity. A mobile cyberslacking-commitment taxonomy (MCCT) was developed to classify employees’ potential for productivity based on the self-reported frequency of cyberslacking (FCyS) and employee’s commitment to the organization (EC2O). Results of a Web-based survey showed that employees were dispersed across the developed taxonomy, with 4.91% identified as potentially problematic. Significant differences between the constructs and demographics suggest that an employee’s potential for productivity is affected by age, gender, education level, and industry type. The results of this study contributed to information systems’ (IS) body of knowledge by providing researchers and practitioners a novel benchmarking tool of the MCCT to enable the measure of productivity in the context of the workplace.
Saleh Hamed Alharthi, Yair Levy, Inkyoung Hur
J. Comput. Inf. Syst.2
2021 Cybersecurity Awareness and Skills of Senior Citizens: A Motivation Perspective
abstract
Senior citizens are one of the most vulnerable groups of Internet users who are prone to cyberattacks. Thus, assessing senior citizens’ motivation to acquire cybersecurity skills is critical to help them understand the risks of cyber-attacks. This study investigated a set of constructs that contribute to senior citizens’ motivation to acquire cybersecurity skills and assessed the actual cybersecurity skill level of these individuals. Utilizing a Web-based survey and a hands-on scenario-based app called MyCyberSkills™, this research study measured the constructs of interest before and after cybersecurity awareness training. Study participants were 254 senior citizens with a mean age of approximately 70 years. The results indicated that the cybersecurity awareness training was effective in increasing the cybersecurity skill level of the senior citizens and empowered them with small but significant improvements in the requisite skills to take mitigating actions against cyberattacks. Theoretical and practical implications are discussed.
Carlene Blackwood-Brown, Yair Levy, John D'Arcy
J. Comput. Inf. Syst.2
2019 Mitigating cyber attacks through the measurement of non-IT professionals' cybersecurity skills
abstract
Purpose Users’ mistakes due to poor cybersecurity skills result in up to 95 per cent of cyber threats to organizations. Threats to organizational information systems continue to result in substantial financial and intellectual property losses. This paper aims to design, develop and empirically test a set of scenarios-based hands-on tasks to measure the cybersecurity skills of non-information technology (IT) professionals. Design/methodology/approach This study was classified as developmental in nature and used a sequential qualitative and quantitative method to validate the reliability of the Cybersecurity Skills Index (CSI) as a prototype-benchmarking tool. Next, the prototype was used to empirically test the demonstrated observable hands-on skills level of 173 non-IT professionals. Findings The importance of skills and hands-on assessment appears applicable to cybersecurity skills of non-IT professionals. Therefore, by using an expert-validated set of cybersecurity skills and scenario-driven tasks, this study established and validated a set of hands-on tasks that measure observable cybersecurity skills of non-IT professionals without bias or the high-stakes risk to IT. Research limitations/implications Data collection was limited to the southeastern USA and while the sample size of 173 non-IT professionals is valid, further studies are required to increase validation of the results and generalizability. Originality/value The validated and reliable CSI operationalized as a tool that measures the cybersecurity skills of non-IT professionals. This benchmarking tool could assist organizations with mitigating threats due to vulnerabilities and breaches caused by employees due to poor cybersecurity skills.
Melissa Carlton, Yair Levy, Michelle M. Ramim
Inf. Comput. Secur.2
2017 Initial Empirical Testing of Potential Factors Contributing to Patient Use of Secure Medical Teleconferencing
abstract
Providing timely and cost-effective healthcare appears to be significantly desired. Factors such as computer skills and comprehension of instructions impact people’s perception of the accessibility of such alternatives, especially for medical professionals. There are limited studies examining the aforementioned factors in information systems (IS) literature in the context of medical teleconferencing (ehealth) from the patients’ perspective. Thus, the purpose of this research study was to examine the underlying structure of four factors, namely IS usage (ISU), computer self-efficacy (CSE), ethical severity of misusing IS (ESMIS), and the resistance to use IS (RESUIS). Based on data gathered from 140 participants, confirmatory factor analysis (CFA) was conducted, using the partial least squares (PLS) technique. Results indicated a very strong validity and reliability of the constructs, however, with a relatively low overall model predictability. Furthermore, the constructs of CSE and RESUIS appear to demonstrate significant contribution toward ISU.
Neelima Bhatnagar, Harold Madden, Yair Levy
J. Comput. Inf. Syst.3
2013 Assessing Ethical Severity of e-Learning Systems Security Attacks
abstract
Security and ethical issues with information systems (IS) are important concerns for most organizations. However, limited attention has been given to unethical behaviors and severity of cyber-security attacks, while these instances appear to be critically important. Although managers have been embracing e-learning systems for training and virtual-team collaborations, little is known about motivations for cyber-security attacks on such systems.Our research includes quantitative and qualitative study of 519 end-users who rated the ethical severity of five common cyber-security attacks. This study investigated five types of security attacks for differences in perceived severity according to gender, academic level, and age. Our findings reveal that the majority of users (90%) reported their sense of severity as unethical across all five cyber-security attacks, while only a small minority of users (3.24%) reported these cyber-security attacks to be ethical. This study also presents a further grounded analysis through follow-up interviews.
Yair Levy, Michelle M. Ramim, Ray Hackney
J. Comput. Inf. Syst.1