Human-Centered Cybersecurity Revisited: From Enemies to Partners

Verena Zimmermann,Lorin Schöni,Thierry Schaltegger,Benjamin Ambuehl,Melanie Knieps,Nico Ebert
DOI: https://doi.org/10.1145/3665665
IF: 22.7
2024-10-26
Communications of the ACM
Abstract:Humans, especially in their role as end users in organizations, have long been considered the weakest link—even enemies—in cybersecurity. This image stems from the perception that, essentially, it is the users who behave insecurely by creating weak passwords, clicking on phishing links, or providing data in insecure networks. Thus, "enemies" here concerns insecure behaviors and policy violations attributed to seemingly thoughtless, careless, or uninformed user actions, not necessarily malicious activities from attackers or hostile insiders.
computer science, theory & methods, software engineering, hardware & architecture
What problem does this paper attempt to address?