EDBT 2026 Demo / reviewers in the wild / expert
Mikko Siponen
dblp:80/6493 · also Mikko T. Siponen
· DBLP profile ↗
14ranked-venue papers in the field
6as first author
4since 2021 · last 2024
0000-0001-7041-1313ORCID · verified
Domains — venue-derived; a paper can count in several
Knowledge Engineering, Semantic Web & Information Systems · 14 (6 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Towards a cybercontextual transmission model for online scammingabstractThis study focuses on advance fee fraud (AFF) scamming, a specific form of online deception in which scammers rely on social engineering techniques to deceive individuals into making advance payments to them. Several industry and law enforcement reports have emphasised that AFF scamming is among the most pervasive forms of online social engineering attacks against consumers, organisations, and online users. Although AFF scamming has received significant attention worldwide, it remains an under-researched and poorly understood crime, and little work has focused on offenders. Although studies on online scammers have inferred that digital environment attributes influence online deception, few studies have empirically clarified how such contexts explain online scammers’ motivations. The present study was designed to explore the motivations and deceptive practices of modern-day AFF scammers by using data from scammers. The empirical results urge the adoption of a model for AFF scamming that conceptually builds on social learning theory (SLT)’s core concepts but functions differently from it, warranting a new IT-based conceptual model. Accordingly, our contributions identify and explain cybercontextual social learning attributes that influence AFF scamming and underscore how traditional criminological theories, such as SLT, cannot sufficiently account for online offences, such as AFF scamming. Consequently, we propose cybercontextual transmission model (CTM) as a reformulation of SLT. Additional theory and practice implications are discussed. Alain Claude Tambe Ebot, Mikko Siponen, Volkan Topalli |
Eur. J. Inf. Syst. | 2 |
| 2024 | Splitting versus lumping: narrowing a theory's scope may increase its valueabstractSpecialisation, by seeking theoretically deeper explanations or more accurate predictions, is common in the sciences. It typically involves splitting, where one model is further divided into several or even hundreds of narrow-scope models. The Information Systems (IS) literature does not discuss such splitting. On the contrary, many seminal IS studies report that a narrow scope is less strong, less interesting, or less useful than a wider scope. In this commentary, we want to raise the awareness of the IS community that in modern scientific progress, specialisation – an activity that generally narrows the scope and decreases the generalisability of a hypothesis – is important. The philosophy of science discusses such positive developments as splitting and trading off a wide scope in favour of accuracy. Narrowing the scope may increase value, especially in sciences where practical applicability is valued. If the IS community generally prefers a wider scope, then we run the risk of not having the information necessary to understand IS phenomena in detail. IS research must understand splitting, how it results in narrowing the scope, and why it is performed for exploratory or predictive reasons in variance, process, and stage models. Mikko Siponen, Tuula Klaavuniemi, Quan Xiao |
Eur. J. Inf. Syst. | 1 |
| 2023 | Personal use of technology at work: a literature review and a theoretical model for understanding how it affects employee job performanceabstractEmployee personal use of technology at work (PUTW) – defined as employees’ activities using organisational or personal IT resources for non-work-related purposes while at work – is increasingly common. Our review of existing PUTW studies (n = 137) suggests that previous studies widely discussed PUTW outcomes, antecedents, and policies. The literature review also indicates that previous studies proposed opposing viewpoints regarding the effect of PUTW on employee job performance, but few studies offered empirical evidence. Consequently, the conditions under which PUTW can increase or decrease employee job performance have not been discussed. We develop a theoretical model for increasing the understanding of this issue. Our model suggests that executive attention is an important underlying mechanism through which PUTW affects employee job performance. We further suggest the effect of PUTW on executive attention (and job performance) depends on PUTW behavioural characteristics in terms of four dimensions: PUTW cognitive load, PUTW arousal level, PUTW timing, and PUTW frequency/duration. The model can advance researchers’ understanding of the possible conditions under which PUTW may increase or decrease employee job performance. The model also offers new insights into existing studies on PUTW antecedents and policies. As a result, our proposed model provides new theoretical guidance for future studies on PUTW. Hemin Jiang, Mikko Siponen, Aggeliki Tsohou |
Eur. J. Inf. Syst. | 2 |
| 2022 | Discovering the interplay between defensive avoidance and continued use intention of anti-malware software among experienced home users: A moderated mediation model
Yitian Xie, Mikko Siponen, Greg D. Moody, Xiaosong Zheng |
Inf. Manag. | 2 |
| 2020 | Effects of sanctions, moral beliefs, and neutralization on information security policy violations across cultures
Anthony Vance, Mikko Siponen, Detmar W. Straub |
Inf. Manag. | 2 |
| 2017 | How Do Mobile ICTs Enable Organizational Fluidity: Toward a Theoretical Framework
Sutirtha Chatterjee, Suprateek Sarker, Mikko Siponen |
Inf. Manag. | 3 |
| 2014 | Guidelines for improving the contextual relevance of field surveys: the case of information security policy violationsabstractThe information systems (IS) field continues to debate the relative importance of rigor and relevance in its research. While the pursuit of rigor in research is important, we argue that further effort is needed to improve practical relevance, not only in terms of topics, but also by ensuring contextual relevance. While content validity is often performed rigorously, validated survey instruments may still lack contextual relevance and be out of touch with practice. We argue that IS behavioral research can improve its practical relevance without loss of rigor by carefully addressing a number of contextual issues in instrumentation design. In this opinion article, we outline five guidelines – relating to both rigor and relevance – designed to increase the contextual relevance of field survey research, using case examples from the area of IS security. They are: (1) inform study respondents that a behavior is an ISP violation, (2) measure specific examples of ISP violations, (3) ensure that ISP violations are important ISP problems in practice, (4) ensure the applicability of IS security violations to the organizational context, and (5) consider the appropriate level of specificity and generalizability for instrumentation. We review previous behavioral research on IS security and show that no existing study meets more than three of these five guidelines. By applying these guidelines where applicable, IS scholars can increase the contextual relevance of their instrumentation, yielding results more likely to address important problems in practice. Mikko Siponen, Anthony Vance |
Eur. J. Inf. Syst. | 1 |
| 2014 | Employees' adherence to information security policies: An exploratory field study
Mikko Siponen, Mo Adam Mahmood, Seppo Pahnila |
Inf. Manag. | 1 |
| 2013 | Using the theory of interpersonal behavior to explain non-work-related personal use of the Internet at work
Greg D. Moody, Mikko Siponen |
Inf. Manag. | 2 |
| 2012 | New insights into the problem of software piracy: The effects of neutralization, shame, and moral beliefs
Mikko Siponen, Anthony Vance, Robert Willison |
Inf. Manag. | 1 |
| 2012 | Motivating IS security compliance: Insights from Habit and Protection Motivation Theory
Anthony Vance, Mikko Siponen, Seppo Pahnila |
Inf. Manag. | 2 |
| 2009 | What levels of moral reasoning and values explain adherence to information security rules? An empirical studyabstractIt is widely agreed that employee non-adherence to information security policies poses a major problem for organizations. Previous research has pointed to the potential of theories of moral reasoning to better understand this problem. However, we find no empirical studies that examine the influence of moral reasoning on compliance with information security policies. We address this research gap by proposing a theoretical model that explains non-compliance in terms of moral reasoning and values. The model integrates two well-known psychological theories: the Theory of Cognitive Moral Development by Kohlberg and the Theory of Motivational Types of Values by Schwartz. Our empirical findings largely support the proposed model and suggest implications for practice and research on how to improve information security policy compliance. Liisa Myyry, Mikko Siponen, Seppo Pahnila, Tero Vartiainen, Anthony Vance |
Eur. J. Inf. Syst. | 2 |
| 2009 | Information security management standards: Problems and solutions
Mikko Siponen, Robert Willison |
Inf. Manag. | 1 |
| 2005 | An analysis of the traditional IS security approaches: implications for research and practiceabstractScholars have developed several modern information systems security (ISS) methods. Yet the traditional ISS methods – ISS checklists, ISS standards, ISS maturity criteria, risk management (RM) and formal methods (FM) – are still among the most used ISS methods. This study makes sense of these traditional ISS methods by comparing their underlying key assumptions. The main finding is that the traditional ISS methods regurgitate several features and assumptions that are required to be dealt with by traditional ISS methods developers and practitioners. Mikko Siponen |
Eur. J. Inf. Syst. | 1 |