EDBT 2026 Demo / reviewers in the wild / expert
Dragana Calic
dblp:165/6917
· DBLP profile ↗
10ranked-venue papers
0as first author
3since 2021 · last 2025
0000-0002-1314-5191ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | How to De-CyFa the actor-observer bias in cybersecurity fatigue: Building the CyFa measure of attribution styles and mitigation strategiesabstractCybersecurity fatigue and burnout, driven by an overload of security demands, are pressing concerns in the industry. Research increasingly shows that fatigued employees are more likely to engage in unsafe cyber behaviours, making it essential for cybersecurity leaders to implement targeted mitigation strategies. However, the extent to which these leaders understand the causes of cybersecurity fatigue and can identify effective solutions remains unclear. There is concern that cybersecurity professionals and non-cyber employees may view each other as distinct groups, potentially leading to biased decision-making, where each group recommends different interventions for themselves versus others. This actor-observer bias could have significant implications for leadership decisions, yet it remains underexplored in this context. This study examines what cybersecurity professionals believe are the causes of cybersecurity fatigue in their workplaces and the strategies they would adopt to mitigate it. It compares these views with those of non-cybersecurity managers and regular employees. Using attribution theory, we developed a novel measure, CyFa (pronounced “cipher”), to assess mitigation strategy preferences and attribution styles. Data from 506 participants across these groups were analysed. The findings suggest that actor-observer bias is present in all groups, with cybersecurity professionals and managers being no better at avoiding this bias than others. Differences between the groups often reflected a tendency to avoid responsibility rather than superior decision-making. Additionally, cybersecurity professionals were found to rely heavily on certain strategies, like employee awareness training, while neglecting others, such as organisational system changes. Andrew Reeves, Dragana Calic, Paul H. Delfabbro |
Comput. Secur. | 2 |
| 2023 | "Generic and unusable"1: Understanding employee perceptions of cybersecurity training and measuring advice fatigue
Andrew Reeves, Dragana Calic, Paul H. Delfabbro |
Comput. Secur. | 2 |
| 2021 | "Get a red-hot poker and open up my eyes, it's so boring"1: Employee perceptions of cybersecurity training
Andrew Reeves, Dragana Calic, Paul H. Delfabbro |
Comput. Secur. | 2 |
| 2020 | When believing in technology leads to poor cyber security: Development of a trust in technical controls scale
Marcus A. Butavicius, Kathryn Parsons, Meredith Lillie, Agata McCormac, Malcolm Robert Pattinson, Dragana Calic |
Comput. Secur. | 6 |
| 2020 | More than the individual: Examining the relationship between culture and Information Security Awareness
Ashleigh Wiley, Agata McCormac, Dragana Calic |
Comput. Secur. | 3 |
| 2020 | Matching training to individual learning styles improves information security awarenessabstractPurpose This paper aims to introduce the concept of a framework of cyber-security controls that are adaptable to different types of organisations and different types of employees. One of these adaptive controls, namely, the mode of training provided, is then empirically tested for its effectiveness. Design/methodology/approach In total, 1,048 working Australian adults completed the human aspects of the information security questionnaire (HAIS-Q) to determine their individual information security awareness (ISA). This included questions relating to the various modes of cyber-security training they had received and how often it was provided. Also, a set of questions called the cyber-security learning-styles inventory was used to identify their preferred learning styles for training. Findings The extent to which the training that an individual received matched their learning preferences was positively associated with their information security awareness (ISA) level. However, the frequency of such training did not directly predict ISA levels. Research limitations/implications Further research should examine the influence of matching cyber-security learning styles to training packages more directly by conducting a controlled trial where the training packages provided differ only in the mode of learning. Further research should also investigate how individual tailoring of aspects of an adaptive control framework (ACF), other than training, may improve ISA. Practical implications If cyber-security training is adapted to the preferred learning styles of individuals, their level of ISA will improve, and therefore, their non-malicious behaviour, whilst using a digital device to do their work, will be safer. Originality/value A review of the literature confirmed that ACFs for cyber-security does exist, but only in terms of hardware and software controls. There is no evidence of any literature on frameworks that include controls that are adaptable to human factors within the context of information security. In addition, this is the first study to show that ISA is improved when cyber-security training is provided in line with an individual’s preferred learning style. Similar improvement was not evident when the training frequency was increased suggesting real-world improvements in ISA may be possible without increasing training budgets but by simply matching individuals to their desired mode of training. Malcolm Robert Pattinson, Marcus A. Butavicius, Meredith Lillie, Beau Ciccarello, Kathryn Parsons, Dragana Calic, Agata McCormac |
Inf. Comput. Secur. | 6 |
| 2018 | The effect of resilience and job stress on information security awarenessabstractPurpose The purpose of this study was to investigate the relationship between resilience, job stress and information security awareness (ISA). The study examined the effect of resilience and job stress on the three components that comprise ISA, namely, knowledge, attitude and behaviour. Design/methodology/approach A total of 1,048 working Australians completed an online questionnaire. ISA was measured with the Human Aspects of Information Security Questionnaire. Participants also completed the Brief Resilience Scale and the Job Stress Scale. Findings It was found that participants with greater resilience also had higher ISA and experienced lower levels of job stress. More specifically, individuals who reported higher levels of resilience had significantly better knowledge, attitude and behaviour. Similarly, participants who reported lower levels of job stress also reported significantly better knowledge, attitude and behaviour. Resilience plays an important mediating role in the relationship between job stress and ISA. This means that even if people have high levels of job stress, if they are better able to cope with or adapt to stress (i.e. have higher resilience), they are less likely to have lower ISA. Results of this study add to the body of literature emphasising the positive effects of resilience and suggest that resilience is associated with improved ISA and therefore more secure behaviour. Research limitations/implications Future research should focus on assessing the influence of resilience training in the workplace. Originality/value Given the constructive findings, it may be valuable to focus on the effect of organisational culture, and organisational security culture, on resilience, job stress and ISA. Agata McCormac, Dragana Calic, Kathryn Parsons, Marcus A. Butavicius, Malcolm Robert Pattinson, Meredith Lillie |
Inf. Comput. Secur. | 2 |
| 2017 | The Human Aspects of Information Security Questionnaire (HAIS-Q): Two further validation studies
Kathryn Parsons, Dragana Calic, Malcolm Robert Pattinson, Marcus A. Butavicius, Agata McCormac, Tara Zwaans |
Comput. Secur. | 2 |
| 2017 | Managing information security awareness at an Australian bank: a comparative studyabstractPurpose The aim of this study was first to confirm that a specific bank’s employees were generally more information security-aware than employees in other Australian industries and second to identify the major factors that contributed to this bank’s high levels of information security awareness (ISA). Design/methodology/approach A Web-based questionnaire (the Human Aspects of Information Security Questionnaire – HAIS-Q) was used in two separate studies to assess the ISA of individuals who used computers at their workplace. The first study assessed 198 employees at an Australian bank and the second study assessed 500 working Australians from various industries. Both studies used a Qualtrics-based questionnaire that was distributed via an email link. Findings The results showed that the average level of ISA among bank employees was consistently 20 per cent higher than that among general workforce participants in all focus areas and overall. There were no significant differences between the ISA scores for those who received more frequent training compared to those who received less frequent training. This result suggests that the frequency of training is not a contributing factor to an employee’s level of ISA. Research limitations/implications This current research did not investigate the information security (InfoSec) culture that prevailed within the bank in question because the objective of the research was to compare a bank’s employees with general workforce employees rather than compare organisations. The Research did not include questions relating to the type of training participants had received at work. Originality/value This study provided the bank’s InfoSec management with evidence that their multi-channelled InfoSec training regime was responsible for a substantially higher-than-average ISA for their employees. Future research of this nature should examine the effectiveness of various ISA programmes in light of individual differences and learning styles. This would form the basis of an adaptive control framework that would complement many of the current international standards, such as ISO’s 27000 series, NIST’s SP800 series and ISACA’s COBIT5. Malcolm Robert Pattinson, Marcus A. Butavicius, Kathryn Parsons, Agata McCormac, Dragana Calic |
Inf. Comput. Secur. | 5 |
| 2016 | Assessing information security attitudes: a comparison of two studiesabstractPurpose The purpose of this paper is to report on the use of two studies that assessed the attitudes of typical computer users. The aim of the research was to compare a self-reporting online survey with a set of one-on-one repertory grid technique interviews. More specifically, this research focussed on participant attitudes toward naive and accidental information security behaviours. Design/methodology/approach In the first study, 23 university students responded to an online survey within a university laboratory setting that captured their attitudes toward behaviours in each of seven focus areas. In the second study, the same students participated in a one-on-one repertory grid technique interview that elicited their attitudes toward the same seven behaviours. Results were analysed using Spearman correlations. Findings There were significant correlations for three of the seven behaviours, although attitudes relating to password management, use of social networking sites, information handling and reporting of security incidents were not significantly correlated. Research limitations/implications The small sample size (n = 23) and the fact that participants were not necessarily representative of typical employees, may have impacted on the results. Practical implications This study contributes to the challenge of developing a reliable instrument that will assess individual InfoSec awareness. Senior management will be better placed to design intervention strategies, such as training and education of employees, if individual attitudes are known. This, in turn, will reduce risk-inclined behaviour and a more secure organisation. Originality/value The literature review indicates that this study addresses a genuine gap in the research. Malcolm Robert Pattinson, Kathryn Parsons, Marcus A. Butavicius, Agata McCormac, Dragana Calic |
Inf. Comput. Secur. | 5 |