Gurpreet Dhillon

dblp:d/GDhillon · DBLP profile ↗
← Back
36ranked-venue papers
18as first author
5since 2021 · last 2025
0000-0002-0487-4050ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 10 first-author · 4 since 2021Databases, data management, data science and information retrieval · 10 · 7 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorArtificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Information security policy compliance: a replication study in Ethiopia
abstract
Purpose This study aims to replicate and assess the applicability and generalizability of Bulgurcu et al.'s (2010) information security policy compliance model to participants from Ethiopia, focusing on understanding compliance behavior with information security policies (ISPs). Design/methodology/approach The study replicates Bulgurcu et al.’s (2010) research methodology. They empirically tested their model using data collected through a survey of 464 employees from a diverse set of organizations in the United States. In this study, the authors used a self-administered survey approach to collect data from 318 valid responses from university students in Ethiopia. The structural equation modeling technique with SmartPLS 4.0 is used to test hypotheses derived from the original model. Findings The replication results confirm most of the hypotheses from the original study, indicating that their model is generalizable to the Ethiopian population. However, the study also identifies differences between the original and replicated results, suggesting potential cultural variations requiring further examination. Originality/value This study contributes to the literature by replicating and extending the original study’s findings in a different cultural context, namely Ethiopia. It highlights the importance of understanding compliance behavior with ISPs across diverse populations and emphasizes the need for future replication studies to explore the impact of culture on intention toward information security behavior.
Berhanu Aebissa, Gurpreet Dhillon, Million Meshesha
Inf. Comput. Secur.2
2025 Understanding the impact of positive and negative user affect on information security
abstract
Purpose Individual consumer data is a critical asset separating companies from their competitors and giving them strategic advantages. The paradox arises as users strive to safeguard their personal data while online businesses need consumer data for customer relationships and business intelligence. It is unclear whether positive and negative user behavior affects information security in rural settings where consumers are unaware of privacy and security risks. This study aims to examine the effect of such positive and negative emotions on users’ perception of privacy and trust. Design/methodology/approach Based on responses from 201 individuals in an extremely rural setting in India who engaged in two commercial websites, the study uses a model that is empirically tested using PLS-SEM. Findings Findings suggest that positive emotional states affect trust in websites and privacy-related beliefs, which influence the likelihood of users sharing personal information. Despite the positive relationship between internet security beliefs and website privacy, individuals may not disclose their personal information on an unfamiliar site in a rural setting. Negative affect also has no effect on the intention to disclose personal information. Originality/value This paper contributes to the information privacy literature by highlighting the nuanced individual differences as the context changes.
Smriti Srivastava, Gurpreet Dhillon, Rasleen Kaur, Simran Dhillon
Inf. Comput. Secur.2
2023 The direct and indirect effect of organizational justice on employee intention to comply with information security policy: The case of Ethiopian banks
Berhanu Aebissa, Gurpreet Dhillon, Million Meshesha
Comput. Secur.2
2023 When expectation fails and motivation prevails: the mediating role of awareness in bridging the expectancy-capability gap in mobile identity protection
abstract
Identity theft poses a significant threat to mobile users, yet mobile identity protection is often overlooked in cybersecurity literature.Despite various technical solutions proposed, little attention has been given to the motivational aspects of protection.Moreover, the disparity between individuals' expectations and their ability to safeguard their mobile identities exacerbates the problem.This study adopts a mixed-methods approach and draws on expectancy-value theory to address these gaps and explore the impact of expectations, capabilities, motivational values, technical measures, and awareness on individuals' intentions to achieve mobile identity protection.Our research reveals that protection awareness acts as a crucial mediator between individuals' expectations and capabilities.Additionally, motivational values not only enhance technical protection measures but also significantly influence identity protection intentions.Furthermore, we identify the moderating effect of protection experience on individuals' expectations and perceived value of identity protection.This study contributes to mobile security literature by highlighting the pivotal role of protection awareness in bridging the divide between individual expectations and actual capabilities in mobile identity protection.
Yasser Alhelaly, Gurpreet Dhillon, Tiago Oliveira 0001
Comput. Secur.2
2021 Information systems security research agenda: Exploring the gap between research and practice
Gurpreet Dhillon, Kane Smith, Indika Dissanayaka
J. Strateg. Inf. Syst.1
2019 Cloud privacy objectives a value based approach
abstract
Purpose To effectively develop privacy policies and practices for cloud computing, organizations need to define a set of guiding privacy objectives that can be applied across their organization. It is argued that it is important to understand individuals’ privacy values with respect to cloud computing to define cloud privacy objectives. Design/methodology/approach For the purpose of this study, the authors adopted Keeney’s (1994) value-focused thinking approach to identify privacy objectives with respect to cloud computing. Findings The results of this study identified the following six fundamental cloud privacy objectives: to increase trust with cloud provider, to maximize identity management controls, to maximize responsibility of information stewardship, to maximize individual’s understanding of cloud service functionality, to maximize protection of rights to privacy, and to maintain the integrity of data. Research limitations/implications One limitation is generalizability of the cloud privacy objectives, and the second is research bias. As this study focused on cloud privacy, the authors felt that the research participants’ increased knowledge of technology usage, including that of cloud technology, was a benefit that outweighed risks associated with not having a random selection of the general population. The newness and unique qualities of privacy issues in cloud computing are better fitted to a qualitative study where issues can emerge naturally through a holistic approach opposed to trying to force fit an existing set of variables or constructs into the context of privacy and cloud computing. Practical implications The findings of this research study can be used to assist management in the process of formulating a cloud privacy policy, develop cloud privacy evaluation criteria as well as assist auditors in developing their privacy audit work plans. Originality/value Currently, there is little to no guidance in the literature or in practice as to what organizations need to do to ensure they protect their stakeholders privacy in a cloud computing environment. This study works at closing this knowledge gap by identifying cloud privacy objectives.
David Lewis Coss, Gurpreet Dhillon
Inf. Comput. Secur.2
2018 Reconciling value-based objectives for security and identity management
abstract
Purpose In this paper, using values of individuals in a Swedish health-care organization, electronic identity management objectives related to security are defined. Design/methodology/approach By using value-focused thinking, eliciting values from interviews of three groups of health-care staff’s objective hierarchies for three stakeholder groups are identified and defined. Objective hierarchies allow comparison across multiple stakeholder groups such that strategic objectives for identity management can be compared and contrasted. Findings This qualitative investigation, which used value-focused thinking, revealed 94 subobjectives, grouped into 12 fundamental and 14 means objectives, which are essential for developing measures that address potential value conflicts in a health-care organization around electronic identity management. The objectives developed in this study are grounded socioorganizationally and provide a way forward in developing measures aimed to reducing potential conflicts at a policy level. Originality/value In a final synthesis, congruence (or lack thereof) in the electronic identity management approach for a Swedish health organization is suggested. This also creates a foundation to evaluate and weight different objectives for strategic decision management.
Kane Smith, Gurpreet Dhillon, Karin Hedström
Inf. Comput. Secur.2
2017 Blockchain for Privacy and Security: The Case of Health Informatics
Gurpreet Dhillon, Kane Smith, Monica C. Tremblay
AMIA1
2017 Information security concerns in IT outsourcing: Identifying (in) congruence between clients and vendors
Gurpreet Dhillon, Romilla Syed, Filipe de Sá-Soares
Inf. Manag.1
2016 Defining Objectives for Preventing Cyberstalking
Gurpreet Dhillon, Chandrashekar Challa, Kane Smith
SEC1
2016 Developing a Human Activity Model for Insider IS Security Breaches Using Action Design Research
Gurpreet Dhillon, Spyridon Samonas, Ugochukwu O. Etudo
SEC1
2016 Interpreting information security culture: An organizational transformation case study
Gurpreet Dhillon, Romilla Syed, Cristiane Pedron
Comput. Secur.1
2015 Disassociations in Security Policy Lifecycles
abstract
Continued high profile security breaches indicate that Information Systems Security remains a significant problem within organizations. The authors argue that one of the major contributors to this ongoing problem is a disconnect between security policy formulation and implementation. This disconnect can lead to a failure of policy. This paper is aimed at understanding the disconnect by analyzing the meanings that are attributed to policy formulation and implementation by the stakeholders involved in the process. A case study was carried out and a “snapshot in time” of the lifecycle of IS Security Policy formulation at the organization under study demonstrated that a disconnect is evident between these two sides of security policy.
Michael Lapke, Gurpreet Dhillon
Int. J. Inf. Secur. Priv.2
2015 From Adoption to Routinization of B2B e-Commerce: Understanding Patterns Across Europe
abstract
The authors present an in depth understanding of B2B e-commerce adoption and routinization across Europe. The research was informed by the technology, organization, and environment (TOE) framework. A sample of 7,172 firms across Europe was used. A seven factor model is presented that includes technology readiness, technology integration, firm size, obstacles, education level, competitive pressure, and trading partner collaboration, which inform B2B adoption and routinization. Based on adoption and routinization, clusters of European countries, are identified and factors presented that ensure movement from one cluster to the other.
Tiago Oliveira 0001, Gurpreet Dhillon
J. Glob. Inf. Manag.2
2014 Organizational Transformation and Information Security Culture: A Telecom Case Study
Gurpreet Dhillon, Romilla Chowdhuri, Cristiane Pedron
SEC1
2013 Secure Outsourcing: An Investigation of the Fit between Clients and Providers
Gurpreet Dhillon, Romilla Chowdhuri, Filipe de Sá-Soares
SEC1
2013 Organizational power and information security rule compliance
Ella Kolkowska, Gurpreet Dhillon
Comput. Secur.2
2013 Defining value-based objectives for ERP systems planning
Jeffrey May, Gurpreet Dhillon, Mário M. Caldeira
Decis. Support Syst.2
2012 When Convenience Trumps Security: Defining Objectives for Security and Usability of Systems
Gurpreet Dhillon, Tiago Oliveira 0001, Santa R. Susarapu, Mário M. Caldeira
SEC1
2012 Interpreting Deep Structures of Information Systems Security
abstract
Confidentiality, integrity and availability, while being key requirements for ensuring security, have had limitations in providing an integral security model that incorporates the benefits of all predominant designs. Heeding to the call that security models cater to unique operational characteristics of individual firms, this paper presents a deep structure framework of information systems (ISs) security. The framework incorporates three models—representational model, which identifies subsystems within an organization; state-tracking model, which ensures that different states trace IS security in the real world;nd the decomposition model, which defines specific external events that are a stimuli to changes in internal events. In a final synthesis, the paper presents a deep structure-based conceptual clarity that manifests the meaning of dynamic, custom-fit and flexible IS security solutions.
Manoj A. Thomas, Gurpreet Dhillon
Comput. J.2
2011 Organizational Power and Information Security Rule Compliance
Ella Kolkowska, Gurpreet Dhillon
SEC2
2011 Intentionality and power interplay in IS implementation: The case of an asset management firm
Gurpreet Dhillon, Mário M. Caldeira, Mitchell R. Wenger
J. Strateg. Inf. Syst.1
2010 Using Actor Network Theory to Understand Information Security Management
Karin Hedström, Gurpreet Dhillon, Fredrik Karlsson 0001
SEC2
2008 Organizational competence for harnessing IT: A case study
Gurpreet Dhillon
Inf. Manag.1
2007 Editorial: JSIS Security and Privacy Special Issue
Gurpreet Dhillon, James Backhouse, Amy W. Ray
J. Strateg. Inf. Syst.1
2004 Re-examining the measurement models of success for Internet commerce
Jerry Cha-Jan Chang, Gholamreza Torkzadeh, Gurpreet Dhillon
Inf. Manag.3
2004 Dimensions of power and IS implementation
Gurpreet Dhillon
Inf. Manag.1
2003 Applying double loop learning to interpret implications for information systems security design
abstract
The security of information systems (IS) continues to be one of the most serious issues of the twenty-first century. Past research indicates human factors to be the prime reason for IS security breaches. Human factors are repertoires of behavior that evolve from the reasoning and actions that individuals follow. These actions become the 'theories of action' individuals espouse and their 'theories-in-use', which are the actions they actually use. We argue that IS security problems occur when an organization's 'espoused theory' and their 'theory-in-use' (what they actually do) are contradictory. It is important, therefore, that human factors be addressed in (IS) security. The current focus on technological methods alone is an incomplete solution. The purpose of this paper is to present double loop learning as a strategy for designing and implementing security actions that bring an organization's 'espoused theory' and their 'theory-in-use' (what they actually do) into congruence . Indeed, by doing so double loop learning is a proactive security method that never becomes outdated.
Angela Mattia, Gurpreet Dhillon
SMC2
2003 Integrating Digital Signatures with Relational Databases: Issues and Organizational Implications
abstract
This paper explores the nature and scope of integration of digital signatures with relational databases, such as integration is essential if Internet commerce is to succeed. While evaluating the pros and cons of the integration and the related technologies, this paper identifies challenges, both technological and organizational. The paper proposes that any implementation needs to consider the organizational policies and the related rules. Careful consideration of these aspects will ensure a successful integration and implementation.
Randal Reid, Gurpreet Dhillon
J. Database Manag.2
2001 Violation of Safeguards by Trusted Personnel and Understanding Related Information Security Concerns
Gurpreet Dhillon
Comput. Secur.1
2001 Computer crimes: theorizing about the enemy within
Gurpreet Dhillon
Comput. Secur.1
2001 The Emergence of Networked Organizations in India: A Misalignment of Interests?
abstract
We present a potential misalignment that many emerging economies may face with respect to the advent of networked organisations. We argue that although it may seem that networked organisations appear to offer a viable option for the progress of a nation, a deeper analysis suggests otherwise. This will be exemplified through the case of The Engineering Corporation and its presence in India. While The Engineering Corporation does indeed provide employment to the local economy, the host country must determine the right mix of the aspects involved in the collaborative venture. If this care is not taken, there will be little benefit for the host country, thus resulting in a skewed orientation in the relationship.
Gurpreet Dhillon, Trevor T. Moores, Ray Hackney
J. Glob. Inf. Manag.1
2000 Interpreting the adoption and use of EDI in the Portuguese clothing and textile industry
abstract
The aim of this paper is to develop an understanding of the adoption and use of EDI in the Portuguese clothing and textile industry. The inherent argument is that although such inter‐organizational systems in small and medium‐sized enterprises facilitate competitiveness through collaboration, the successful deployment of such systems is not solely a function of transaction costs and the resource base of an organization, as has been argued in the literature. In fact the values and attitudes of senior management play a critical role in the adoption of inter‐organizational systems. Various issues are analyzed by critically reviewing the literature, which has traditionally focused either on reducing transaction costs or managing the resource base. The argument of this paper is conducted by evaluating managers’ beliefs and attitudes towards the use of EDI within the Portuguese clothing and textile industry.
Gurpreet Dhillon, Mário M. Caldeira
Inf. Manag. Comput. Secur.1
2000 Ethics and information technology use: a survey of US based SMEs
abstract
The purpose of this paper is to study the beliefs and attitudes of small‐ and medium‐sized enterprises (SMEs) toward the ethical use of information technology (IT). This research in progress paper presents findings from an “ethics survey” conducted in the USA. The initial data presented here suggest that even though IT has become an integral part of the US SMEs, there is a clear lack of awareness of basic ethical issues. The participants on this survey did not seem to understand the importance of their moral and ethical responsibilities in the use of IT. In a follow‐up of this study, we hope to extend and use the initial findings to conduct focused in‐depth interviews with some of the survey participants. In a subsequent stage we wish to conduct a similar research for large enterprises, so as to compare and contrast the extent of IT related ethical practices in businesses.
Sanjeev Phukan, Gurpreet Dhillon
Inf. Manag. Comput. Secur.2
1999 Managing and controlling computer misuse
abstract
This paper argues that many of the losses owing to computer‐related fraud could be avoided if organizations adopt a more pragmatic approach in dealing with such incidents. The paper suggests that in implementing controls, both within organizations and computer systems, a balanced approach be adopted. Such an approach should place equal emphasis on technical, formal and informal interventions. The argument is conducted by reviewing the nature of security breaches that have taken place in different parts of the world.
Gurpreet Dhillon
Inf. Manag. Comput. Secur.1
1995 Managing computer crime: a research outlook
James Backhouse, Gurpreet Dhillon
Comput. Secur.2