EDBT 2026 Demo / reviewers in the wild / expert
Marcus A. Butavicius
dblp:37/2564 · also Marcus Antanas Butavicius
· DBLP profile ↗
24ranked-venue papers
6as first author
5since 2021 · last 2026
0000-0003-0722-3912ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forest or trees? Evidence for global processing via an information board study into cues utilised in phishing identificationabstractWe examined the patterns of cues people utilised as they attempted to classify emails as legitimate or phishing via a novel approach – an information board study. In this paradigm, participants had to click on email elements to examine them, revealing which cues are utilised in the decision-making process as well as viewing duration. An online email classification task (87 Ps) was presented, including a between-subjects’ manipulation of cognitive load. This revealed consistent patterns of behaviour associated with identification of legitimate emails such as more time spent looking at signoffs aiding in identification, whereas more time spent looking at logo and greetings was associated with worse performance. We also found no-load condition participants with lower intuitive decision-making style scores identified more phishing emails correctly suggesting elaborative processing as an important determinant of good decision-making. However, none of; cyber security experience, impulsivity, and checking the sender’s address corresponded to higher rates of phishing email identification. Furthermore, we found no behavioural, cue-based patterns associated with correct decisions for phishing emails. We speculate that this decision-making process may be based on a global, holistic interpretation of the stimuli. This has important implications for awareness campaigns suggesting a more holistic approach to email evaluation. Dan Conway, Kun Yu 0001, Marcus A. Butavicius, Fang Chen 0001, Anna Hepworth |
Behav. Inf. Technol. | 3 |
| 2025 | Hey "CSIRI", should I report this? Investigating the factors that influence employees to report cyber security incidents in the workplaceabstractPurpose Cyber security incidents pose a major threat to organisations. Reporting cyber security incidents and providing organisations with information about their true nature, type and volume, is crucial to inform risk-based decisions. Despite the importance of reporting cyber security incidents, little research has addressed employees’ motivations to do so. Therefore, the purpose of this study is to investigate the factors that influence employees to report cyber security incidents using the theory of planned behaviour as a theoretical framework. Design/methodology/approach Survey data were collected from a sample of 549 working Australian adults. Demographics were gathered, in addition to data using the Cyber Security Incident Reporting Inventory (CSIRI; pronounced, “Siri”). Findings Attitude towards reporting, subjective norms and perceived behavioural control each significantly predicted intention-to-report cyber security incidents. Perceived behavioural control also significantly predicted actual reporting behaviour. Research limitations/implications The results of this study validate the application of the theory of planned behaviour to the cyber security incident reporting context, also indicating that the relationship between intention to report a cyber security incident and actual reporting behaviour may be facilitated by perceived behavioural control. Practical implications These findings can be applied to inform the development of strategies that increase employees’ cyber security incident reporting behaviour. Originality/value This study outlines the development of a new tool to measure attitudes, subjective norms and perceived behavioural control in relation to the reporting of cyber security incidents. To the best of the authors’ knowledge, this is the first study of its kind to identify the relationship between these factors and intentions to report cyber security incidents. Kristiina Ahola, Marcus A. Butavicius, Agata McCormac, Daniel Sturman |
Inf. Comput. Secur. | 2 |
| 2024 | The sleepless sentinel: factors that predict burnout and sleep quality in cybersecurity professionalsabstractPurpose The purpose of this study is to investigate the extent to which a sample of the Australian cybersecurity industry is impacted by burnout. Design/methodology/approach Based on the review of the literature, this research investigates the following three hypotheses. Gender will significantly predict burnout scores. Those who identify as women will score higher on average than those who identify as men (because of being in a male-dominated industry). Self-reported burnout will differ across job roles. In addition, the authors expect these relationships to hold across the three dimensions of burnout, namely, emotional exhaustion, depersonalisation and professional efficacy. Sleep quality will be associated with burnout. Findings Gender and job role were significant predictors of emotional exhaustion, but not depersonalisation or professional efficacy. The interaction between gender and job role was also significant. Senior managers experienced poorer quality sleep, and poorer sleep quality was associated with greater reported emotional exhaustion at work. For emotional exhaustion, female respondents who worked in security consultant roles tended to score higher than their male counterparts. Practical implications Left unaddressed, the high level of workplace burnout may add to the well-being and retention problems developing within the cybersecurity community. These results indicate that organisations should look to measure the well-being of their own cyber workforce and implement meaningful changes if they wish to keep their cyber talent and enable them to thrive at work. Originality/value This research paper is an extension of a previous paper by the same authors which is titled “Is Your CISO Burnt Out Yet”. This paper examined the demographic differences in workplace burnout among cybersecurity professionals. Andrew Reeves, Malcolm Pattinson, Marcus A. Butavicius |
Inf. Comput. Secur. | 3 |
| 2024 | The prince of insiders: a multiple pathway approach to understanding IP theft insider attacksabstractPurpose Intellectual property (IP) theft is an increasing threat that can lead to large financial losses and reputational harm. These attacks are typically noticed only after the IP is stolen, which is usually too late. This paper aims to investigate the psychological profile and the socio-technical events that statistically predict the likelihood of an IP threat. Design/methodology/approach This paper analyses 86 IP theft cases found in court documents. Two novel analyses are conducted. The research uses LLMs to analyse the personality of these insiders, which is followed by an investigation of the pathways to the attack using behaviour sequence analysis (BSA). Findings These IP theft insiders scored significantly higher on measures of Machiavellianism compared to the normal population. Socio-technical variables, including IP theft via photographs, travelling overseas, approaching multiple organisations and delivering presentations, were identified. Contrary to previous assumptions that there is a single pathway to an attack, the authors found that multiple, complex pathways lead to an attack (sometimes multiple attacks). This work, therefore, provides a new framework for considering critical pathways to insider attacks. Practical implications These findings reveal that IP theft insiders may come across as charming, star employees rather than the stereotype of disgruntled employees. Moreover, organisations’ policies may need to consider that IP theft occurs via non-linear and multiple pathways. This means that sequences of events need to be considered in detecting these attacks instead of anomalies outright. The authors also argue that there may be a case for “continuous evaluation” to detect insider activity. Originality/value This paper offers a new framework for understanding and studying insider threats. Instead of a single critical pathway, this work demonstrates the need to consider multiple interconnected pathways. It elucidates the importance of a multidisciplinary approach and provides opportunities to reconsider current practices in detection and prevention. Monica T. Whitty, Christopher Ruddy, David A. Keatley, Marcus A. Butavicius, Marthie Grobler |
Inf. Comput. Secur. | 4 |
| 2022 | Why people keep falling for phishing scams: The effects of time pressure and deception cues on the detection of phishing emails
Marcus A. Butavicius, Ronnie Taib, Simon Jerome Han |
Comput. Secur. | 1 |
| 2020 | When believing in technology leads to poor cyber security: Development of a trust in technical controls scale
Marcus A. Butavicius, Kathryn Parsons, Meredith Lillie, Agata McCormac, Malcolm Robert Pattinson, Dragana Calic |
Comput. Secur. | 1 |
| 2020 | Matching training to individual learning styles improves information security awarenessabstractPurpose This paper aims to introduce the concept of a framework of cyber-security controls that are adaptable to different types of organisations and different types of employees. One of these adaptive controls, namely, the mode of training provided, is then empirically tested for its effectiveness. Design/methodology/approach In total, 1,048 working Australian adults completed the human aspects of the information security questionnaire (HAIS-Q) to determine their individual information security awareness (ISA). This included questions relating to the various modes of cyber-security training they had received and how often it was provided. Also, a set of questions called the cyber-security learning-styles inventory was used to identify their preferred learning styles for training. Findings The extent to which the training that an individual received matched their learning preferences was positively associated with their information security awareness (ISA) level. However, the frequency of such training did not directly predict ISA levels. Research limitations/implications Further research should examine the influence of matching cyber-security learning styles to training packages more directly by conducting a controlled trial where the training packages provided differ only in the mode of learning. Further research should also investigate how individual tailoring of aspects of an adaptive control framework (ACF), other than training, may improve ISA. Practical implications If cyber-security training is adapted to the preferred learning styles of individuals, their level of ISA will improve, and therefore, their non-malicious behaviour, whilst using a digital device to do their work, will be safer. Originality/value A review of the literature confirmed that ACFs for cyber-security does exist, but only in terms of hardware and software controls. There is no evidence of any literature on frameworks that include controls that are adaptable to human factors within the context of information security. In addition, this is the first study to show that ISA is improved when cyber-security training is provided in line with an individual’s preferred learning style. Similar improvement was not evident when the training frequency was increased suggesting real-world improvements in ISA may be possible without increasing training budgets but by simply matching individuals to their desired mode of training. Malcolm Robert Pattinson, Marcus A. Butavicius, Meredith Lillie, Beau Ciccarello, Kathryn Parsons, Dragana Calic, Agata McCormac |
Inf. Comput. Secur. | 2 |
| 2019 | Mouse Behavior as an Index of Phishing Awareness
Kun Yu 0001, Ronnie Taib, Marcus A. Butavicius, Kathryn Parsons, Fang Chen 0001 |
INTERACT (1) | 3 |
| 2019 | Using Semantic Context to Rank the Results of Keyword SearchabstractIn an empirical user study, we assessed two approaches to ranking the results from a keyword search using semantic contextual match based on Latent Semantic Analysis. These techniques involved searches initiated from words found in a seed document within a corpus. The first approach used the sentence around the search query in the document as context while the second used the entire document. With a corpus of 20,000 documents and a small proportion of relevant documents (<0.1%), both techniques outperformed a conventional keyword search on a recall-based information retrieval (IR) task. These context-based techniques were associated with a reduction in the number of searches conducted, an increase in users’ precision and, to a lesser extent, an increase in recall. This improvement was strongest when the ranking was based on document, rather than sentence, context. Individuals were more effective on the IR task when the lists returned by the techniques were ranked better. User performance on the task also correlated with achievement on a generalized IQ test but not on a linguistic ability test. Marcus A. Butavicius, Kathryn Parsons, Agata McCormac, Simon Dennis 0001, Aaron Ceglar, Derek Weber, Lael Ferguson, Kenneth Treharne, Richard Leibbrandt, David M. W. Powers |
Int. J. Hum. Comput. Interact. | 1 |
| 2019 | Predicting susceptibility to social influence in phishing emails
Kathryn Parsons, Marcus A. Butavicius, Paul H. Delfabbro, Meredith Lillie |
Int. J. Hum. Comput. Stud. | 2 |
| 2018 | The effect of resilience and job stress on information security awarenessabstractPurpose The purpose of this study was to investigate the relationship between resilience, job stress and information security awareness (ISA). The study examined the effect of resilience and job stress on the three components that comprise ISA, namely, knowledge, attitude and behaviour. Design/methodology/approach A total of 1,048 working Australians completed an online questionnaire. ISA was measured with the Human Aspects of Information Security Questionnaire. Participants also completed the Brief Resilience Scale and the Job Stress Scale. Findings It was found that participants with greater resilience also had higher ISA and experienced lower levels of job stress. More specifically, individuals who reported higher levels of resilience had significantly better knowledge, attitude and behaviour. Similarly, participants who reported lower levels of job stress also reported significantly better knowledge, attitude and behaviour. Resilience plays an important mediating role in the relationship between job stress and ISA. This means that even if people have high levels of job stress, if they are better able to cope with or adapt to stress (i.e. have higher resilience), they are less likely to have lower ISA. Results of this study add to the body of literature emphasising the positive effects of resilience and suggest that resilience is associated with improved ISA and therefore more secure behaviour. Research limitations/implications Future research should focus on assessing the influence of resilience training in the workplace. Originality/value Given the constructive findings, it may be valuable to focus on the effect of organisational culture, and organisational security culture, on resilience, job stress and ISA. Agata McCormac, Dragana Calic, Kathryn Parsons, Marcus A. Butavicius, Malcolm Robert Pattinson, Meredith Lillie |
Inf. Comput. Secur. | 4 |
| 2017 | The Human Aspects of Information Security Questionnaire (HAIS-Q): Two further validation studies
Kathryn Parsons, Dragana Calic, Malcolm Robert Pattinson, Marcus A. Butavicius, Agata McCormac, Tara Zwaans |
Comput. Secur. | 4 |
| 2017 | Managing information security awareness at an Australian bank: a comparative studyabstractPurpose The aim of this study was first to confirm that a specific bank’s employees were generally more information security-aware than employees in other Australian industries and second to identify the major factors that contributed to this bank’s high levels of information security awareness (ISA). Design/methodology/approach A Web-based questionnaire (the Human Aspects of Information Security Questionnaire – HAIS-Q) was used in two separate studies to assess the ISA of individuals who used computers at their workplace. The first study assessed 198 employees at an Australian bank and the second study assessed 500 working Australians from various industries. Both studies used a Qualtrics-based questionnaire that was distributed via an email link. Findings The results showed that the average level of ISA among bank employees was consistently 20 per cent higher than that among general workforce participants in all focus areas and overall. There were no significant differences between the ISA scores for those who received more frequent training compared to those who received less frequent training. This result suggests that the frequency of training is not a contributing factor to an employee’s level of ISA. Research limitations/implications This current research did not investigate the information security (InfoSec) culture that prevailed within the bank in question because the objective of the research was to compare a bank’s employees with general workforce employees rather than compare organisations. The Research did not include questions relating to the type of training participants had received at work. Originality/value This study provided the bank’s InfoSec management with evidence that their multi-channelled InfoSec training regime was responsible for a substantially higher-than-average ISA for their employees. Future research of this nature should examine the effectiveness of various ISA programmes in light of individual differences and learning styles. This would form the basis of an adaptive control framework that would complement many of the current international standards, such as ISO’s 27000 series, NIST’s SP800 series and ISACA’s COBIT5. Malcolm Robert Pattinson, Marcus A. Butavicius, Kathryn Parsons, Agata McCormac, Dragana Calic |
Inf. Comput. Secur. | 2 |
| 2016 | Assessing information security attitudes: a comparison of two studiesabstractPurpose The purpose of this paper is to report on the use of two studies that assessed the attitudes of typical computer users. The aim of the research was to compare a self-reporting online survey with a set of one-on-one repertory grid technique interviews. More specifically, this research focussed on participant attitudes toward naive and accidental information security behaviours. Design/methodology/approach In the first study, 23 university students responded to an online survey within a university laboratory setting that captured their attitudes toward behaviours in each of seven focus areas. In the second study, the same students participated in a one-on-one repertory grid technique interview that elicited their attitudes toward the same seven behaviours. Results were analysed using Spearman correlations. Findings There were significant correlations for three of the seven behaviours, although attitudes relating to password management, use of social networking sites, information handling and reporting of security incidents were not significantly correlated. Research limitations/implications The small sample size (n = 23) and the fact that participants were not necessarily representative of typical employees, may have impacted on the results. Practical implications This study contributes to the challenge of developing a reliable instrument that will assess individual InfoSec awareness. Senior management will be better placed to design intervention strategies, such as training and education of employees, if individual attitudes are known. This, in turn, will reduce risk-inclined behaviour and a more secure organisation. Originality/value The literature review indicates that this study addresses a genuine gap in the research. Malcolm Robert Pattinson, Kathryn Parsons, Marcus A. Butavicius, Agata McCormac, Dragana Calic |
Inf. Comput. Secur. | 3 |
| 2015 | The design of phishing studies: Challenges for researchers
Kathryn Parsons, Agata McCormac, Malcolm Robert Pattinson, Marcus A. Butavicius, Cate Jerram |
Comput. Secur. | 4 |
| 2014 | Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q)
Kathryn Parsons, Agata McCormac, Marcus A. Butavicius, Malcolm Robert Pattinson, Cate Jerram |
Comput. Secur. | 3 |
| 2014 | A study of information security awareness in Australian government organisationsabstractPurpose – The purpose of this paper is to investigate the human-based information security (InfoSec) vulnerabilities in three Australian government organisations. Design/methodology/approach – A Web-based survey was developed to test attitudes, knowledge and behaviour across eight policy-based focus areas. It was completed by 203 participants across the three organisations. This was complemented by interviews with senior management from these agencies. Findings – Overall, management and employees had reasonable levels of InfoSec awareness. However, weaknesses were identified in the use of wireless technology, the reporting of security incidents and the use of social networking sites. These weaknesses were identified in the survey data of the employees and corroborated in the management interviews. Research limitations/implications – As with all such surveys, responses to the questions on attitude and behaviour (but not knowledge) may have been influenced by the social desirability bias. Further research should establish more extensive baseline data for the survey and examine its effectiveness in assessing the impact of training and risk communication interventions. Originality/value – A new survey tool is presented and tested which is of interest to academics as well as management and IT systems (security) auditors. Kathryn Parsons, Agata McCormac, Malcolm Robert Pattinson, Marcus A. Butavicius, Cate Jerram |
Inf. Manag. Comput. Secur. | 4 |
| 2013 | Phishing for the Truth: A Scenario-Based Experiment of Users' Behavioural Response to Emails
Kathryn Parsons, Agata McCormac, Malcolm Robert Pattinson, Marcus A. Butavicius, Cate Jerram |
SEC | 4 |
| 2012 | How to Assess Human Visual Performance on an Operational Task
Katherine Hanton, Jadranka Sunde, Marcus A. Butavicius, Lakhmi C. Jain, Nicholas Burns |
KES-AMSTA | 3 |
| 2012 | An assessment of email and spontaneous dialog visualizations
Marcus A. Butavicius, Michael D. Lee 0001, Brandon M. Pincombe, Louise G. Mullen, Danielle J. Navarro, Kathryn Parsons, Agata McCormac |
Int. J. Hum. Comput. Stud. | 1 |
| 2012 | Why Do Some People Manage Phishing Emails Better Than Others?abstractPurpose The purpose of this paper is to investigate the behaviour response of computer users when either phishing e‐mails or genuine e‐mails arrive in their inbox. The paper describes how this research was conducted and presents and discusses the findings. Design/methodology/approach This study was a scenario‐based role‐play experiment that involved the development of a web‐based questionnaire that was only accessible by invited participants when they attended a one‐hour, facilitated session in a computer laboratory. Findings The findings indicate that overall, genuine e‐mails were managed better than phishing e‐mails. However, informed participants managed phishing e‐mails better than not‐informed participants. Other findings show how familiarity with computers, cognitive impulsivity and personality traits affect behavioural responses to both types of e‐mail. Research limitations/implications This study does not claim to evaluate actual susceptibility to phishing emails. The subjects were University students and therefore the conclusions are not necessarily representative of the general population of e‐mail users. Practical implications The outcomes of this research would assist management in their endeavours to improve computer user behaviour and, as a result, help to mitigate risks to their organisational information systems. Originality/value The literature review indicates that this paper addresses a genuine gap in the research. Malcolm Robert Pattinson, Cate Jerram, Kathryn Parsons, Agata McCormac, Marcus A. Butavicius |
Inf. Manag. Comput. Secur. | 5 |
| 2008 | An Experiment on Human Face Recognition Performance for Access Control
Marcus A. Butavicius, Chloë Mount, Veneta MacLeod, Robyn Vast, Ian Graves, Jadranka Sunde |
KES (1) | 1 |
| 2007 | An empirical evaluation of four data visualization techniques for displaying short news text similarities
Marcus A. Butavicius, Michael D. Lee 0001 |
Int. J. Hum. Comput. Stud. | 1 |
| 2003 | Visualizations of binary data: A comparative evaluation
Michael D. Lee 0001, Marcus A. Butavicius, Rachel E. Reilly |
Int. J. Hum. Comput. Stud. | 2 |