EDBT 2026 Demo / reviewers in the wild / expert
Karl van der Schyff
dblp:158/9288
· DBLP profile ↗
9ranked-venue papers
6as first author
7since 2021 · last 2024
0000-0002-2892-7954ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-author · 5 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Privacy policy analysis: A scoping review and research agendaabstractOnline users often neglect the importance of privacy policies - a critical aspect of digital privacy and data protection. This scoping review addresses this oversight by delving into privacy policy analysis, aiming to establish a comprehensive research agenda. The study's objective was to explore the analytic techniques employed in privacy policy analysis and to identify the associated challenges. Following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses for Scoping Reviews (PRISMA-ScR) checklist, the review selected n = 97 relevant studies. The findings reveal a diverse array of techniques used, encompassing automated machine learning and natural language processing, and manual content analysis. Notably, researchers grapple with challenges like linguistic nuances, ambiguity, and complex data harvesting methods. Additionally, the lack of privacy-centric theoretical frameworks and a dearth of user evaluations in many studies limit their real-world applicability. The review concludes by proposing a set of research recommendations to shape the future research agenda in privacy policy analysis. Karl van der Schyff, Suzanne Prior, Karen Renaud |
Comput. Secur. | 1 |
| 2024 | VISTA: An inclusive insider threat taxonomy, with mitigation strategiesabstractInsiders have the potential to do a great deal of damage, given their legitimate access to organisational assets and the trust they enjoy. Organisations can only mitigate insider threats if they understand what the different kinds of insider threats are, and what tailored measures can be used to mitigate the threat posed by each of them. Here, we derive VISTA (inclusiVe InSider Threat tAxonomy) based on an extensive literature review and a survey with C-suite executives to ensure that the VISTA taxonomy is not only scientifically grounded, but also meets the needs of organisations and their executives. To this end, we map each VISTA category of insider threat to tailored mitigations that can be deployed to reduce the threat. Karen Renaud, Merrill Warkentin, Ganna Pogrebna, Karl van der Schyff |
Inf. Manag. | 4 |
| 2024 | Optimism bias in susceptibility to phishing attacks: an empirical studyabstractPurpose Researchers looking for ways to change the insecure behaviour that results in phishing have considered multiple possible reasons for such behaviour. Therefore, the purpose of this paper is to understand the role of optimism bias (OB – defined as a cognitive bias), which characterises overly optimistic or unrealistic individuals, to ensure secure behaviour. Research that focused on issues such as personality traits, trust, attitude and Security, Education, Training and Awareness (SETA) was considered. Design/methodology/approach This study built on a recontextualized version of the theory of planned behaviour to evaluate the influence that optimism bias has on phishing susceptibility. To model the data, an analysis was performed on 226 survey responses from a South African financial services organisation using partial least squares (PLS) path modelling. Findings This study found that overly optimistic employees were inclined to behave insecurely, while factors such as attitude and trust significantly influenced the intention to behave securely. Practical implications Our contribution to practice seeks to enhance the effectiveness of SETA by identifying and addressing the optimism bias weakness to deliver a more successful training outcome. Originality/value Our study enriches the Information Systems literature by evaluating the effect of a cognitive bias on phishing susceptibility and offers a contextual explanation of the resultant behaviour. Morné Owen, Stephen Flowerday, Karl van der Schyff |
Inf. Comput. Secur. | 3 |
| 2023 | Would US citizens accept cybersecurity deresponsibilization? Perhaps notabstractResponsibilizing governments provide advice about how to manage a variety of risks. If citizens do not heed the advice and things go wrong, they are expected to accept the adverse consequences without complaint. However, in some cases, citizens are unable or unwilling to embrace these government-assigned responsibilities and to act on the advice, for a variety of valid reasons. It may be appropriate for governments to provide more direct support: in essence, deresponsibilizing citizens who struggle to embrace the responsibility. In this paper, we explore whether US citizens would be willing to accept more help from their government in the cyber realm. Using two studies, we find that perceptions related to the government's competence and benevolence are necessary pre-requisites for a willingness to be deresponsibilized, and also that many respondents did not have confidence that either of these were sufficient. This deficiency might well render governments’ well-intended deresponsibilization endeavours futile. We conclude by proposing deresponsibilization strategies that acknowledge and accommodate this. Karen Renaud, Karl van der Schyff, Stuart Macdonald |
Comput. Secur. | 2 |
| 2023 | The mediating role of perceived risks and benefits when self-disclosing: A study of social media trust and FoMO
Karl van der Schyff, Stephen Flowerday |
Comput. Secur. | 1 |
| 2022 | Intensity of Facebook use: a personality-based perspective on dependency formationabstractDespite recent privacy scandals, the intensity with which individuals use Facebook has not declined. This indicates that individuals still place significant value on the psychosocial development afforded by using Facebook. As such, the objective of this study was to develop a research model to evaluate the influence of specific individual differences (gender and personality traits) on the intensity of Facebook use. Data was collected from 576 United States Facebook users and subsequently analysed using partial least squares (PLS) path modelling including multi-group analysis. Results indicate the existence of a significant positive relationship between the intensity of Facebook use and extraversion as well as agreeableness. The results further indicate that males high in extraversion use Facebook more intensively than females making them particularly vulnerable to the development of a Facebook dependency. Karl van der Schyff, Stephen Flowerday, Hennie A. Kruger, Nikitha Patel |
Behav. Inf. Technol. | 1 |
| 2021 | Mediating effects of information security awareness
Karl van der Schyff, Stephen Flowerday |
Comput. Secur. | 1 |
| 2020 | Duplicitous social media and data surveillance: An evaluation of privacy risk
Karl van der Schyff, Stephen Flowerday, Steven Furnell |
Comput. Secur. | 1 |
| 2020 | Privacy risk and the use of Facebook Apps: A gender-focused vulnerability assessment
Karl van der Schyff, Stephen Flowerday, Steven Furnell |
Comput. Secur. | 1 |