21 citations · 21 across the 4 of their papers we have counts for
5 papers
The best laid plans or lack thereof: Security decision-making of different stakeholder groups
Benjamin Shreeve, Joseph Hallett, Matthew Edwards +3
Cyber security requirements are influenced by the priorities and decisions of a range of stakeholders. Board members and CISOs determine strategic priorities. Managers have respons…
"Do this! Do that!, And nothing will happen" Do specifications lead to securely stored passwords?
Joseph Hallett, Nikhil Patnaik, Benjamin Shreeve +1
Does the act of writing a specification (how the code should behave) for a piece of security sensitive code lead to developers producing more secure code? We asked 138 developers t…
Technical Report: Gone in 20 Seconds -- Overview of a Password Vulnerability in Siemens HMIs
Joseph Gardiner, Awais Rashid
Siemens produce a range of industrial human machine interface (HMI) screens which allow operators to both view information about and control physical processes. For scenarios where…
Contextualising and Aligning Security Metrics and Business Objectives: a GQM-based Methodology
Eleni Philippou, Sylvain Frey, Awais Rashid
Pre-defined security metrics suffer from the problem of contextualisation, i.e. a lack of adaptability to particular organisational contexts - domain, technical infrastructure, sta…
Automatically Dismantling Online Dating Fraud
Guillermo Suarez-Tangil, Matthew Edwards, Claudia Peersman +3
Online romance scams are a prevalent form of mass-marketing fraud in the West, and yet few studies have addressed the technical or data-driven responses to this problem. In this ty…