Understanding user behavior is critical to achieving security objectives. People are repeatedly bombarded with messages about the dangers lurking on the Internet and are encouraged (or forced) to take numerous security-related actions, often without a clear understanding of why and to what end.
We conduct research to discover people’s security and privacy perceptions, attitudes, and behaviors with a goal of developing cybersecurity guidance that: 1) takes into account user needs, biases, and limitations and 2) helps people make sound security decisions.
Current/recent research projects:
Security and Privacy: authentication, behavior, general security & privacy, privacy, security programs & operations, usability
Technologies: email
Applications: cybersecurity education, cybersecurity workforce, Internet of Things