Ella Kolkowska

dblp:93/10503 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0002-5270-1517ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 4 first-author · 5 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author
YearPublicationVenuePosition
2026 You get the answers you ask for: Experimental evidence on the influence of inconsistent variable definitions on non-/compliance research findings
abstract
The research literature on employee non-/compliance with information security policies (ISPs) suffers from inconsistent findings. The aim of this paper is to investigate a promising, yet largely unexplored cause of these inconsistencies, namely, differences in how key variables have been conceptualized and operationalized into questionnaire measurement items across this literature. Specifically, by means of a survey experiment with 215 participants from a Swedish university, we formally tested whether alternative operationalizations of two key variables from Protection Motivation Theory—Perceived vulnerability and Perceived severity of a threat—lead to statistically significant differences in mean values across responder groups. Regarding the former variable, we found significant differences between operationalizations focusing on the probability and vulnerability of the threat. Regarding the latter, we found significant differences between whether the target of the consequences of the threat was unclear or clear to respondents, but not between clearly stated targets in terms of individuals and organizations . Overall, therefore, this study contributes to the field by highlighting the importance of conceptual clarity and precision in measuring key variables. It also highlights the potential of survey experiments—an underutilized method in ISP compliance research—for exploring the empirical impact of the different variable operationalizations which currently characterize much of the extant literature.
Marcus Gerdin, Martin Karlsson, Ella Kolkowska, Åke Grönlund
Comput. Secur.3
2025 Conceptual inconsistencies in variable definitions and measurement items within ISP non-/compliance research: A systematic literature review
abstract
The rich stream of research focusing on employee non-/compliance with information security policies (ISPs) suffers from inconsistent results. Attempts to explain such inconsistencies have included investigation of possible contextual moderating factors. Another promising, yet not systematically investigated, explanation concerns conceptual inconsistencies in variable definitions and in questionnaire measurement items. Based on a systematic literature review covering 36 ISP non-/compliance articles using Protection Motivation Theory (PMT) and/or Theory of Planned Behavior (TPB), we found four major types of conceptual inconsistencies and unclarities within and across studies; (i) inconsistencies in variable definitions; (ii) inconsistencies between variable measurement items; (iii) inconsistencies between variable definitions and measurement items; and (iv) unclearly/vaguely worded measurement items. The review contributes to the field by demonstrating that the inconsistent results in the field may not only be due to unknown contextual moderators, but also to conceptual incongruences within and across studies.
Marcus Gerdin, Åke Grönlund, Ella Kolkowska
Comput. Secur.3
2025 Towards software for tailoring information security policies to organisations' different target groups
Elham Rostami, Fredrik Karlsson 0001, Ella Kolkowska, Shang Gao 0002
Comput. Secur.3
2024 What goes around comes around: an in-depth analysis of how respondents interpret ISP non-/compliance questionnaire items
abstract
Purpose Research on employee non-/compliance to information security policies suffers from inconsistent results and there is an ongoing discussion about the dominating survey research methodology and its potential effect on these results. This study aims to add to this discussion by investigating discrepancies between what the authors claim to measure (theoretical properties of variables) and what they actually measure (respondents’ interpretations of the operationalized variables). This study asks: How well do respondents’ interpretations of variables correspond to their theoretical definitions? What are the characteristics of any discrepancies between variable definitions and respondent interpretations? Design/methodology/approach This study is based on in-depth interviews with 17 respondents from the Swedish public sector to understand how they interpret questionnaire measurement items operationalizing the variables Perceived Severity from Protection Motivation Theory and Attitude from Theory of Planned Behavior. Findings The authors found that respondents’ interpretations in many cases differ substantially from the theoretical definitions. Overall, the authors found four principal ways in which respondents interpreted measurement items – referred to as property contextualization, extension, alteration and oscillation – each implying more or less (dis)alignment with the intended theoretical properties of the two variables examined. Originality/value The qualitative method used proved vital to better understand respondents’ interpretations which, in turn, is key for improving self-reporting measurement instruments. To the best of the authors’ knowledge, this study is a first step toward understanding how precise and uniform definitions of variables’ theoretical properties can be operationalized into effective measurement items.
Marcus Gerdin, Ella Kolkowska, Åke Grönlund
Inf. Comput. Secur.2
2022 Information security policy compliance-eliciting requirements for a computerized software to support value-based compliance analysis
abstract
When end users have to prioritize between different rationalities in organisations there is a risk of non-compliance with information security policies. Thus, in order for information security managers to align information security with the organisations’ core work practices, they need to understand the competing rationalities. The Value-based compliance (VBC) analysis method has been suggested to this end, however it has proven to be complex and time-consuming. Computerized software may aid this type of analysis and make it more efficient and executable. The purpose of this paper is to elicit a set of requirements for computerized software that support analysis of competing rationalities in relation to end users’ compliance and non-compliance with information security policies. We employed a design science research approach, drawing on design knowledge on VBC and elicited 17 user stories. These requirements can direct future research efforts to develop computerized software in this area.
Fredrik Karlsson 0001, Ella Kolkowska, Johan Petersson
Comput. Secur.2
2020 The hunt for computerized support in information security policy management
abstract
Purpose The purpose of this paper is to survey existing information security policy (ISP) management research to scrutinise the extent to which manual and computerised support has been suggested, and the way in which the suggested support has been brought about. Design/methodology/approach The results are based on a literature review of ISP management research published between 1990 and 2017. Findings Existing research has focused mostly on manual support for managing ISPs. Very few papers have considered computerised support. The entire complexity of the ISP management process has received little attention. Existing research has not focused much on the interaction between the different ISP management phases. Few research methods have been used extensively and intervention-oriented research is rare. Research limitations/implications Future research should to a larger extent address the interaction between the ISP management phases, apply more intervention research to develop computerised support for ISP management, investigate to what extent computerised support can enhance integration of ISP management phases and reduce the complexity of such a management process. Practical implications The limited focus on computerised support for ISP management affects the kind of advice and artefacts the research community can offer to practitioners. Originality/value Today, there are no literature reviews on to what extent computerised support the ISP management process. Findings on how the complexity of ISP management has been addressed and the research methods used extend beyond the existing knowledge base, allowing for a critical discussion of existing research and future research needs.
Elham Rostami, Fredrik Karlsson 0001, Ella Kolkowska
Inf. Comput. Secur.3
2018 Guest editorial
Fredrik Karlsson 0001, Ella Kolkowska, Marianne Törner
Inf. Comput. Secur.2
2017 Towards analysing the rationale of information security non-compliance: Devising a Value-Based Compliance analysis method
abstract
Employees’ poor compliance with information security policies is a perennial problem. Current information security analysis methods do not allow information security managers to capture the rationalities behind employees’ compliance and non-compliance. To address this shortcoming, this design science research paper suggests: (a) a Value-Based Compliance analysis method and (b) a set of design principles for methods that analyse different rationalities for information security. Our empirical demonstration shows that the method supports a systematic analysis of why employees comply/do not comply with policies. Thus we provide managers with a tool to make them more knowledgeable about employees’ information security behaviours.
Ella Kolkowska, Fredrik Karlsson 0001, Karin Hedström
J. Strateg. Inf. Syst.1
2016 Privacy by Design Principles in Design of New Generation Cognitive Assistive Technologies
Ella Kolkowska, Annica Kristoffersson
SEC1
2016 Inter-organisational information security: a systematic literature review
abstract
Purpose The purpose of this paper is to survey existing inter-organisational information security research to scrutinise the kind of knowledge that is currently available and the way in which this knowledge has been brought about. Design/methodology/approach The results are based on a literature review of inter-organisational information security research published between 1990 and 2014. Findings The authors conclude that existing research has focused on a limited set of research topics. A majority of the research has focused management issues, while employees’/non-staffs’ actual information security work in inter-organisational settings is an understudied area. In addition, the majority of the studies have used a subjective/argumentative method, and few studies combine theoretical work and empirical data. Research limitations/implications The findings suggest that future research should address a broader set of research topics, focusing especially on employees/non-staff and their use of processes and technology in inter-organisational settings, as well as on cultural aspects, which are lacking currently; focus more on theory generation or theory testing to increase the maturity of this sub-field; and use a broader set of research methods. Practical implications The authors conclude that existing research is to a large extent descriptive, philosophical or theoretical. Thus, it is difficult for practitioners to adopt existing research results, such as governance frameworks, which have not been empirically validated. Originality/value Few systematic reviews have assessed the maturity of existing inter-organisational information security research. Findings of authors on research topics, maturity and research methods extend beyond the existing knowledge base, which allow for a critical discussion about existing research in this sub-field of information security.
Fredrik Karlsson 0001, Ella Kolkowska, Frans Prenkert
Inf. Comput. Secur.2
2013 Organizational power and information security rule compliance
Ella Kolkowska, Gurpreet Dhillon
Comput. Secur.1
2013 Social action theory for understanding information security non-compliance in hospitals: The importance of user rationale
abstract
Purpose – Employees' compliance with information security policies is considered an essential component of information security management. The research aims to illustrate the usefulness of social action theory (SAT) for management of information security. Design/methodology/approach – This research was carried out as a longitudinal case study at a Swedish hospital. Data were collected using a combination of interviews, information security documents, and observations. Data were analysed using a combination of a value-based compliance model and the taxonomy laid out in SAT to determine user rationality. Findings – The paper argues that management of information security and design of countermeasures should be based on an understanding of users' rationale covering both intentional and unintentional non-compliance. The findings are presented in propositions with practical and theoretical implications: P1. Employees' non-compliance is predominantly based on means-end calculations and based on a practical rationality, P2. An information security investigation of employees' rationality should not be based on an a priori assumption about user intent, P3. Information security management and choice of countermeasures should be based on an understanding of the use rationale, and P4. Countermeasures should target intentional as well as unintentional non-compliance. Originality/value – This work is an extension of Hedström et al. arguing for the importance of addressing user rationale for successful management of information security. The presented propositions can form a basis for information security management, making the objectives underlying the study presented in Hedström et al. more clear.
Karin Hedström, Fredrik Karlsson 0001, Ella Kolkowska
Inf. Manag. Comput. Secur.3
2012 Analyzing Value Conflicts for a Work-Friendly ISS Policy Implementation
Ella Kolkowska, Bart De Decker
SEC1
2011 Organizational Power and Information Security Rule Compliance
Ella Kolkowska, Gurpreet Dhillon
SEC1
2011 Value conflicts for information security management
Karin Hedström, Ella Kolkowska, Fredrik Karlsson 0001, Jonathan P. Allen
J. Strateg. Inf. Syst.2