Stephen Flowerday

dblp:82/537 · also Stephen V. Flowerday · DBLP profile ↗
← Back
30ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-4591-3802ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 28 · 6 first-author · 8 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Bending the curve: Operational cyber epidemiology for ransomware
abstract
Ransomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In this ontology, Exposed denotes latent compromise and staging, including the dwell period before confirmed secondary compromise, while Infectious denotes active lateral propagation. Drawing on ISO 5477:2023 guidance for public health emergency preparedness and response information management and the 2025 UNDRR-ISC Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information for cross-incident comparison. Basic and effective reproduction numbers, R0 and Re, are used as directional, near-real-time decision aids for security operations centers. Propagation state is separated from observation status to avoid confusing spread dynamics with detection capability. Publicly reported incidents, including WannaCry, NotPetya, SolarWinds, and MGM and Caesars, illustrate how outbreak-style measures can support earlier isolation, credential containment, and restoration sequencing. The paper also derives practical protection-threshold heuristics aimed at reducing Re below 1 and provides a tool-agnostic playbook card linking operational information to explicit action triggers. The primary contribution is a shared language that connects technical telemetry to containment decisions under resource constraints.
Stephen Flowerday, Nikolay Lipskiy, Steven Furnell, Callum E. Flowerday, John Hale
Comput. Secur.1
2026 Human-factor vulnerabilities of automation in SOCs: A mixed-methods multigroup analysis
Jack Laurie Tilbury, Stephen Flowerday, Gregory Bott, Yi Ting Chua 0001, Eric Olson, Bryan Foltz
Comput. Secur.2
2025 Detecting Cybercrime in Online Video Gaming
James Higgs, Stephen Flowerday
Comput. Secur.2
2024 Optimism bias in susceptibility to phishing attacks: an empirical study
abstract
Purpose Researchers looking for ways to change the insecure behaviour that results in phishing have considered multiple possible reasons for such behaviour. Therefore, the purpose of this paper is to understand the role of optimism bias (OB – defined as a cognitive bias), which characterises overly optimistic or unrealistic individuals, to ensure secure behaviour. Research that focused on issues such as personality traits, trust, attitude and Security, Education, Training and Awareness (SETA) was considered. Design/methodology/approach This study built on a recontextualized version of the theory of planned behaviour to evaluate the influence that optimism bias has on phishing susceptibility. To model the data, an analysis was performed on 226 survey responses from a South African financial services organisation using partial least squares (PLS) path modelling. Findings This study found that overly optimistic employees were inclined to behave insecurely, while factors such as attitude and trust significantly influenced the intention to behave securely. Practical implications Our contribution to practice seeks to enhance the effectiveness of SETA by identifying and addressing the optimism bias weakness to deliver a more successful training outcome. Originality/value Our study enriches the Information Systems literature by evaluating the effect of a cognitive bias on phishing susceptibility and offers a contextual explanation of the resultant behaviour.
Morné Owen, Stephen Flowerday, Karl van der Schyff
Inf. Comput. Secur.2
2023 The mediating role of perceived risks and benefits when self-disclosing: A study of social media trust and FoMO
Karl van der Schyff, Stephen Flowerday
Comput. Secur.2
2023 Unraveling the behavioral influence of social media on phishing susceptibility: A Personality-Habit-Information Processing model
Edwin Donald Frauenstein, Stephen Flowerday, Syden Mishi, Merrill Warkentin
Inf. Manag.2
2022 Intensity of Facebook use: a personality-based perspective on dependency formation
abstract
Despite recent privacy scandals, the intensity with which individuals use Facebook has not declined. This indicates that individuals still place significant value on the psychosocial development afforded by using Facebook. As such, the objective of this study was to develop a research model to evaluate the influence of specific individual differences (gender and personality traits) on the intensity of Facebook use. Data was collected from 576 United States Facebook users and subsequently analysed using partial least squares (PLS) path modelling including multi-group analysis. Results indicate the existence of a significant positive relationship between the intensity of Facebook use and extraversion as well as agreeableness. The results further indicate that males high in extraversion use Facebook more intensively than females making them particularly vulnerable to the development of a Facebook dependency.
Karl van der Schyff, Stephen Flowerday, Hennie A. Kruger, Nikitha Patel
Behav. Inf. Technol.2
2022 Usability of the login authentication process: passphrases and passwords
abstract
Purpose The average employee spends a total of 18.6 h every two months on password-related activities, including password retries and resets. The problem is caused by the user forgetting or mistyping the password (usually because of character switching). The source of this issue is that while a password containing combinations of lowercase characters, uppercase characters, digits and special characters (LUDS) offers a reasonable level of security, it is complex to type and/or memorise, which prolongs the user authentication process. This results in much time being spent for no benefit (as perceived by users), as the user authentication process is merely a prerequisite for whatever a user intends to accomplish. This study aims to address this issue, passphrases that exclude the LUDS guidelines are proposed. Design/methodology/approach To discover constructs that create security and to investigate usability concerns relating to the memory and typing issues concerning passphrases, this study was guided by three theories as follows: Shannon’s entropy theory was used to assess security, chunking theory to analyse memory issues and the keystroke level model to assess typing issues. These three constructs were then evaluated against passwords and passphrases to determine whether passphrases better address the security and usability issues related to text-based user authentication. A content analysis was performed to identify common password compositions currently used. A login assessment experiment was used to collect data on user authentication and user – system interaction with passwords and passphrases in line with the constructs that have an impact on user authentication issues related to security, memory and typing. User–system interaction data was collected from a purposeful sample size of 112 participants, logging in at least once a day for 10 days. An expert review, which comprised usability and security experts with specific years of industry and/or academic experience, was also used to validate results and conclusions. All the experts were given questions and content to ensure sufficient context was provided and relevant feedback was obtained. A pilot study involving 10 participants (experts in security and/or usability) was performed on the login assessment website and the content was given to the experts beforehand. Both the website and the expert review content was refined after feedback was received from the pilot study. Findings It was concluded that, overall, passphrases better support the user during the user authentication process in terms of security, memory issues and typing issues. Originality/value This research aims at promoting the use of a specific type of passphrase instead of complex passwords. Three core aspects need to be assessed in conjunction with each other (security, memorisation and typing) to determine whether user-friendly passphrases can support user authentication better than passwords.
Bhaveer Bhana, Stephen Flowerday
Inf. Comput. Secur.2
2021 Mediating effects of information security awareness
Karl van der Schyff, Stephen Flowerday
Comput. Secur.2
2021 Understanding the disclosure of personal data online
abstract
Purpose Social media has created a new level of interconnected communication. However, the use of online platforms brings about various ways in which a user’s personal data can be put at risk. This study aims to investigate what drives the disclosure of personal information online and whether an increase in awareness of the value of personal information motivates users to safeguard their information. Design/methodology/approach Fourteen university students participated in a mixed-methods experiment, where responses to Likert-type scale items were combined with responses to interview questions to provide insight into the cost–benefit analysis users conduct when disclosing information online. Findings Overall, the findings indicate that users are able to disregard their concerns due to a resigned and apathetic attitude towards privacy. Furthermore, subjective norms enhanced by fear of missing out (FOMO) further allows users to overlook potential risks to their information in order to avoid social isolation and sanction. Alternatively, an increased awareness of the personal value of information and having experienced a previous privacy violation encourage the protection of information and limited disclosure. Originality/value This study provides insight into privacy and information disclosure on social media in South Africa. To the knowledge of the researchers, this is the first study to include a combination of the theory of planned behaviour and the privacy calculus model, together with the antecedent factors of personal valuation of information, trust in the social media provider, FOMO.
Heather J. Parker, Stephen Flowerday
Inf. Comput. Secur.2
2020 Passphrase and keystroke dynamics authentication: Usable security
Bhaveer Bhana, Stephen Flowerday
Comput. Secur.2
2020 Susceptibility to phishing on social network sites: A personality information processing model
Edwin Donald Frauenstein, Stephen Flowerday
Comput. Secur.2
2020 Evaluating the strength of a multilingual passphrase policy
Pardon Blessings Maoneke, Stephen Flowerday, Naomi Isabirye
Comput. Secur.2
2020 Duplicitous social media and data surveillance: An evaluation of privacy risk
Karl van der Schyff, Stephen Flowerday, Steven Furnell
Comput. Secur.2
2020 Privacy risk and the use of Facebook Apps: A gender-focused vulnerability assessment
Karl van der Schyff, Stephen Flowerday, Steven Furnell
Comput. Secur.2
2020 A Clark-Wilson and ANSI role-based access control model
abstract
Purpose An electronic health record (EHR) enables clinicians to access and share patient information electronically and has the ultimate goal of improving the delivery of healthcare. However, this can create security and privacy risks to patient information. This paper aims to present a model for securing the EHR based on role-based access control (RBAC), attribute-based access control (ABAC) and the Clark-Wilson model. Design/methodology/approach A systematic literature review was conducted which resulted in the collection of secondary data that was used as the content analysis sample. Using the MAXQDA software program, the secondary data was analysed quantitatively using content analysis, resulting in 2,856 tags, which informed the discussion. An expert review was conducted to evaluate the proposed model using an evaluation framework. Findings The study found that a combination of RBAC, ABAC and the Clark-Wilson model may be used to secure the EHR. While RBAC is applicable to healthcare, as roles are linked to an organisation’s structure, its lack of dynamic authorisation is addressed by ABAC. Additionally, key concepts of the Clark-Wilson model such as well-formed transactions, authentication, separation of duties and auditing can be used to secure the EHR. Originality/value Although previous studies have been based on a combination of RBAC and ABAC, this study also uses key concepts of the Clark-Wilson model for securing the EHR. Countries implementing the EHR can use the model proposed by this study to help secure the EHR while also providing EHR access in a medical emergency.
Tamir Tsegaye, Stephen Flowerday
Inf. Comput. Secur.2
2018 The Influence of Native Language on Password Composition and Security: A Socioculture Theoretical View
Pardon Blessings Maoneke, Stephen Flowerday, Naomi Isabirye
SEC2
2018 Is the responsibilization of the cyber security risk reasonable and judicious?
Karen Renaud, Stephen Flowerday, Merrill Warkentin, W. Paul Cockshott, Craig P. Orgeron
Comput. Secur.2
2017 Human-centred cyber security
Karen Renaud, Stephen Flowerday
J. Inf. Secur. Appl.2
2017 Contemplating human-centred security & privacy research: Suggesting future directions
Karen Renaud, Stephen Flowerday
J. Inf. Secur. Appl.2
2016 Information security policy development and implementation: The what, how and who
Stephen Flowerday, Tite Tuyikeze
Comput. Secur.1
2016 Why don't UK citizens protest against privacy-invading dragnet surveillance?
abstract
Purpose The purpose of this study was to identify to identify reasons for the lack of protest against dragnet surveillance in the UK. As part of this investigation, a study was carried out to gauge the understanding of “privacy” and “confidentiality” by the well-informed. Design/methodology/approach To perform a best-case study, the authors identified a group of well-informed participants in terms of security. To gain insights into their privacy-related mental models, they were asked first to define the three core terms and then to identify the scenarios. Then, the participants were provided with privacy-related scenarios and were asked to demonstrate their understanding by classifying the scenarios and identifying violations. Findings Although the participants were mostly able to identify privacy and confidentiality scenarios, they experienced difficulties in articulating the actual meaning of the terms privacy, confidentiality and security. Research limitations/implications There were a limited number of participants, yet the findings are interesting and justify further investigation. The implications, even of this initial study, are significant in that if citizens’ privacy rights are being violated and they did not seem to know how to protest this and if indeed they had the desire to do so. Practical implications Had the citizens understood the meaning of privacy, and their ancient right thereto, which is enshrined in law, their response to the Snowden revelations about ongoing wide-scale surveillance might well have been more strident and insistent. Originality/value People in the UK, where this study was carried out, do not seem to protest the privacy invasion effected by dragnet surveillance with any verve. The authors identify a number of possible reasons for this from the literature. One possible explanation is that people do not understand privacy. Thus, this study posits that privacy is unusual in that understanding does not seem to align with the ability to articulate the rights to privacy and their disapproval of such widespread surveillance. This seems to make protests unlikely.
Karen Renaud, Stephen Flowerday, Rosanne English, Melanie Volkamer
Inf. Comput. Secur.2
2015 Information Security Behaviour Profiling Framework (ISBPF) for student mobile phone users
Bukelwa Ngoqo, Stephen Flowerday
Comput. Secur.2
2015 Exploring the relationship between student mobile information security awareness and behavioural intent
abstract
Purpose – The purpose of this paper was to analyse existing theories from the social sciences to gain a better understanding of factors which contribute to student mobile phone users’ poor information security behaviour. Two key aspects associated with information security behaviour were considered, namely, awareness and behavioural intent. This paper proposes that the knowing-and-doing gap can possibly be reduced by addressing both awareness and behavioural intent. This research paper explores the relationship between student mobile phone user information security awareness and behavioural intent in a developmental university in South Africa. Design/methodology/approach – Information security awareness interventions were implemented in this action research study, and student information security behavioural intent was observed after each cycle. Findings – The poor security behaviour exhibited by student mobile phone users, which was confirmed by the findings of this study, is of particular interest in the university context, as most undergraduate students are offered a computer-related course which covers certain information security-related principles. Existing researchers in the field of information security still grapple with the “knowing-and-doing” gap, where user information security knowledge/awareness sometimes does not result in safer behavioural practises. Originality/value – Zhang et al. (2009) suggest that understanding human behaviour is important when dealing with the problems caused by human errors. Harnesk and Lindstrom (2011) expressed a concern that existing research does not address the interlinked relationship between anticipated security behaviour and the enactment of security procedures. This study acknowledges Choi et al. (2008) contribution in their discussions on the “knowing-and-doing gap” suggests a link between awareness and actual behaviour that is confirmed by the findings of this study.
Bukelwa Ngoqo, Stephen Flowerday
Inf. Comput. Secur.2
2014 Smartphone information security awareness: A victim of operational pressures
abstract
Smartphone information security awareness describes the knowledge, attitude and behaviour that employees apply to the security of the organisational information that they access, process and store on their smartphone devices. The surge in the number of smartphone devices connecting to organisational systems and used to process organisational data has enabled a new level of operational efficiency. While employees are aware of the benefits they enjoy by bringing their personal devices into the workplace, managers too are aware of the benefits of having a constantly connected workforce. Unfortunately, those aware of the risks to information security do not share an equal level of enthusiasm. These devices are owned by employees who are not adequately skilled to configure the security settings for acceptable security of that information. Moreover, routine information security awareness programmes, even if applied, gradually fade into the daily rush of operations from the day they are completed. This paper explores the factors which influence these oscillating levels of information security awareness. By applying an adapted version of an awareness model from the domain of accident prevention, the factors which cause diminishing awareness levels are exposed. Subsequently, information security awareness emerges as a symptom of such factors. Through geometrical modelling of the boundaries and pressures that govern our daily operations, an awareness model emerges. This model ensures that organisations are better equipped to monitor their information security awareness position, their boundaries and the daily pressures affecting the organisation, thus allowing them to design better integrated policies and procedures to encourage safe operating limits. The model is evaluated using a theory evaluation framework through an expert review process.
Sean Allam, Stephen Flowerday, Ethan Flowerday
Comput. Secur.2
2012 A Log File Digital Forensic Model
Himal Lalla, Stephen Flowerday, Tendai Sanyamahwe, Paul Tarwireyi
IFIP Int. Conf. Digital Forensics2
2007 Identification Now and in the Future: Social Grant Distribution Process in South Africa
Stephen Flowerday, Gideon Ranga
SEC1
2006 Trust: An Element of Information Security
Stephen Flowerday, Rossouw von Solms
SEC1
2006 Continuous auditing technologies and models: A discussion
Stephen Flowerday, A. W. Blundell, Rossouw von Solms
Comput. Secur.1
2005 Real-time information integrity = system integrity + data integrity + continuous assurances
Stephen Flowerday, Rossouw von Solms
Comput. Secur.1