Markus Schöps

dblp:323/0206 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0002-6804-3547ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Noise and Stress Don't Help With Learning: A Qualitative Study to Inform Design of Effective Cybersecurity Awareness in Manufacturing Environments
abstract
With Industry 4.0, cybersecurity risks in manufacturing contexts are increasing rapidly. Since mandatory cybersecurity awareness programs (CAP) are considered best practice, companies looking at adapting training for this group, and allowed us to conduct a study. We conducted semi-structured interviews with n=33 manufacturing workers in 6 locations, to determine what they knew about cybersecurity risks, to what extent they consider them relevant, and what their experiences with, and perceptions of cybersecurity measures and training were. The interviews were analyzed using qualitative content analysis. Most of our participants reported only occasional interaction with what they consider ''office'' information and communication technology (ICT) in the context of their daily work. For most, the only touchpoints were HR-related transactions (pay and vacation), conducted via shared digital shopfloor kiosk PCs, through which they also received corporate communications. Most participants did not consider cybersecurity their responsibility, associating it with ''office'' and ''management'' roles. Most ICT and cybersecurity as potential threats to ''smooth running'' of work processes and their productivity. At the same time, there was positive perception of safety measures and training, with a clear preference for face-to-face team-based training in situ, so they could ask questions and point out possible issues - very different from the company's idea of individual computer-based trained, which most would receive via shared kiosk PCs on a noisy shop floor. Our results suggest that successful CAP needs to tailor content not only according to relevant risks, but relating those to key values and work practices, and consider different ways of delivering it.
Lina Brunken, Markus Schöps, Annalina Buckmann, Florian Meißner, M. Angela Sasse
CCS2
2024 Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' Promises
abstract
Security awareness and training (SAT) vendors operate in a growing multi-billion dollar market. They publish various marketing promises on their websites to their customers -- organizations of all sizes. This paper investigates how these promises align with customers' needs, how they relate to human-centered security challenges highlighted in prior research, and what narrative is presented regarding the role of employees (as SAT recipients). We also investigate the level of transparency in vendor promises, as to whether it constitutes an information asymmetry. We gathered search terms from n=30 awareness professionals to perform an automated Google search and scraping of SAT vendors' websites. We then performed a thematic analysis of 2,476 statements on 156 websites from 59 vendors. We found that the messaging from SAT vendors precisely targets customers' need for easy-to-implement and compliance-fulfilling SAT products; how SAT products are offered also means that some of the impacts of SAT go unmentioned and are transferred to the customer, such as user support. In this vendor-customer relationship, employees are portrayed as a source of weaknesses, needing an indefinite amount of training to be incorporated into the organization's protection. We conclude with suggestions for SAT vendors and regulators, notably toward an SAT ecosystem that directly links SAT solutions to usable security technologies within the organization environment.
Jonas Hielscher, Markus Schöps, Jens Christian Opdenbusch, Felix Reichmann, Marco Gutfleisch, Karola Marky, Simon Edward Parkin
CCS2
2024 Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-Efficacy
Markus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela Sasse
USENIX Security Symposium1
2023 Lacking the Tools and Support to Fix Friction: Results from an Interview Study with Security Managers
Jonas Hielscher, Markus Schöps, Uta Menges, Marco Gutfleisch, Mirko Helbling, M. Angela Sasse
SOUPS2