BZ
B.C.P. Zuurbier
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
2 records found
1
As cybercrimes rise, companies increasingly invest in security awareness training to protect themselves, but the effectiveness of the training is being called into question by researchers. Vendors sell one-size-fits-all training, yet these programmes fail to take the routines and needs of employees into account. This results in low engagement, wasted resources and, most importantly, little change in actual behaviour. Research has explored the relation between training and behaviour, identifying several factors that influence behaviour change. The resulting advice however often remains highly abstract. As such, this research explores how security awareness training can be made more effective by involving employees and designing or modifying it to align with their primary work tasks. It offers a structured approach and practical examples for practitioners to learn from.
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change. ...
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change. ...
As cybercrimes rise, companies increasingly invest in security awareness training to protect themselves, but the effectiveness of the training is being called into question by researchers. Vendors sell one-size-fits-all training, yet these programmes fail to take the routines and needs of employees into account. This results in low engagement, wasted resources and, most importantly, little change in actual behaviour. Research has explored the relation between training and behaviour, identifying several factors that influence behaviour change. The resulting advice however often remains highly abstract. As such, this research explores how security awareness training can be made more effective by involving employees and designing or modifying it to align with their primary work tasks. It offers a structured approach and practical examples for practitioners to learn from.
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change.
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change.
Using Large Language Models to Detect Deliberative Elements in Public Discourse
Detecting Subjective Emotions in Public Discourse
Bachelor thesis
(2024)
-
B.C.P. Zuurbier, L. Cavalcante Siebert, A. Homayounirad, E. Liscio, J. Yang
In order to tackle topics such as climate change together with the population, public discourse should be scaled up. This discourse should be mediated as it makes it more likely that people understand each other and change their point of view. To help the mediator with this task, emotion detection can greatly help. Positive emotions can improve communications, while negative emotions cause people to be irrational and irritated. However, since emotions are highly subjective, it can make both predictions and evaluation more difficult.
Still, Large Language Models (LLMs) could be used to detect these subjective emotions using different prompting strategies and labels. The experiment included zero-, one-, fewshot and Chain of Thought (CoT) strategies. The precision was better for the one- and fewshot method compared to zeroshot. The CoT methods also showed an increase in precision, but a decrease in recall. The different labels were hard majority labels, soft labels and hard per annotator labels. In conclusion, providing examples improved the performance of the LLM. The CoT strategies were more precise, but gave a worse general prediction. The hard majority labels allow for more general predictions, where per annotator hard labels capture the perspective of different annotators. Soft labels reflect the subjective nature of the labels by providing probabilities instead of binary classification.
The experiment was done on a small data sample, so it is recommended to try the strategies on a larger data sample. Looking into appropriate evaluations for subjective predictions is also recommended in order to reflect the actual performance better. ...
Still, Large Language Models (LLMs) could be used to detect these subjective emotions using different prompting strategies and labels. The experiment included zero-, one-, fewshot and Chain of Thought (CoT) strategies. The precision was better for the one- and fewshot method compared to zeroshot. The CoT methods also showed an increase in precision, but a decrease in recall. The different labels were hard majority labels, soft labels and hard per annotator labels. In conclusion, providing examples improved the performance of the LLM. The CoT strategies were more precise, but gave a worse general prediction. The hard majority labels allow for more general predictions, where per annotator hard labels capture the perspective of different annotators. Soft labels reflect the subjective nature of the labels by providing probabilities instead of binary classification.
The experiment was done on a small data sample, so it is recommended to try the strategies on a larger data sample. Looking into appropriate evaluations for subjective predictions is also recommended in order to reflect the actual performance better. ...
In order to tackle topics such as climate change together with the population, public discourse should be scaled up. This discourse should be mediated as it makes it more likely that people understand each other and change their point of view. To help the mediator with this task, emotion detection can greatly help. Positive emotions can improve communications, while negative emotions cause people to be irrational and irritated. However, since emotions are highly subjective, it can make both predictions and evaluation more difficult.
Still, Large Language Models (LLMs) could be used to detect these subjective emotions using different prompting strategies and labels. The experiment included zero-, one-, fewshot and Chain of Thought (CoT) strategies. The precision was better for the one- and fewshot method compared to zeroshot. The CoT methods also showed an increase in precision, but a decrease in recall. The different labels were hard majority labels, soft labels and hard per annotator labels. In conclusion, providing examples improved the performance of the LLM. The CoT strategies were more precise, but gave a worse general prediction. The hard majority labels allow for more general predictions, where per annotator hard labels capture the perspective of different annotators. Soft labels reflect the subjective nature of the labels by providing probabilities instead of binary classification.
The experiment was done on a small data sample, so it is recommended to try the strategies on a larger data sample. Looking into appropriate evaluations for subjective predictions is also recommended in order to reflect the actual performance better.
Still, Large Language Models (LLMs) could be used to detect these subjective emotions using different prompting strategies and labels. The experiment included zero-, one-, fewshot and Chain of Thought (CoT) strategies. The precision was better for the one- and fewshot method compared to zeroshot. The CoT methods also showed an increase in precision, but a decrease in recall. The different labels were hard majority labels, soft labels and hard per annotator labels. In conclusion, providing examples improved the performance of the LLM. The CoT strategies were more precise, but gave a worse general prediction. The hard majority labels allow for more general predictions, where per annotator hard labels capture the perspective of different annotators. Soft labels reflect the subjective nature of the labels by providing probabilities instead of binary classification.
The experiment was done on a small data sample, so it is recommended to try the strategies on a larger data sample. Looking into appropriate evaluations for subjective predictions is also recommended in order to reflect the actual performance better.