Program

Pale Blue Dot
Earth, as seen by Voyager 1
from 6 billion km away (1990).
Day 1

Wednesday, 2 September 2026

8:30 – 9:00
Participants gathering & registration
9:00 – 9:15
Opening — Chairs' greetings
9:15 – 10:15
Invited Talk Usable, Human-Centred, Socio-Technical Security: What Is the Difference? M. Angela Sasse
Speaker page →

This talk will provide a personal review of 30 years of researching how human behaviour in security, and our community’s efforts to develop effective solutions to protect individuals, organisations and societies from increasing numbers of attacks. Usable security focused on functionality and aesthetics of expert-designed solutions, human-centred security put human needs and preferences at the centre of design. The STS perspective offers a different perspective of the processes involved in security — and I will argue that re-conceptualising security in terms of care, maintenance and tinkering can help organisations.

10:15 – 10:35
Coffee Break
10:35 – 11:40
Session 1 Cognitive Biases and Decision-Making in Security
1.
"Something else to worry about": An Exploratory Study of Deliberate Ignorance Towards Online Security Jan Magnus Nold, Markus Schöps and Martina Angela Sasse
2.
Cybersecurity Decision-Making: Ensnared by the Bias Trap Karl Van der Schyff, Stephen Flowerday and Karen Renaud
3.
Studying Personality and Attacker Behavior in a Deceptive Multi-Stage Capture-the-Flag Environment Khalid Alasiri and Rakibul Hasan
4.
Beyond the Binder: Investigating the Potential of Diagram-based Incident Response Plans in Critical Infrastructure Vahiny Gnanasekaran and Magdalena Glas
11:40 – 11:45
Technical Break
11:45 – 12:50
Session 2 Human Factors in Authentication and Verification
5.
Verifying the Fraud: German Users' Proficiency in (Not) Identifying Online Banking Manipulations Franziska Bumiller, Rolf Lehnert, Julia Wunder, Freya Gassmann and Zinaida Benenson
6.
Formal Modeling and Analysis of Human Memory Lapses in Security Ceremonies Ioana Sandu, Rishabh Kar, Megha Quamara, Antonio Balordi and Luca Viganò
7.
The (Un)suitability of Passwords and Password Managers in Virtual Reality Emiram Kablo, Yorick Last, Patricia Arias Cabarcos and Melanie Volkamer
8.
PGP and S/MIME in the Age of Multi-Device Email Usage: "Admittedly, an outrageously confusing system." Katharina Schiller, Andreas Herrmannsdörfer, Zinaida Benenson and Florian Adamsky
12:50 – 14:20
Lunch
14:20 – 15:05
Session 3 Security and Privacy for Diverse and Vulnerable Users
9.
"The System Will Choose Security Over Humanity Every Time": Understanding Security and Privacy for U.S. Incarcerated Users Yael Eiger, Nino Migineishvili, Emi Yoshikawa, Liza Nadtochiy, Kentrell Owens and Franziska Roesner
10.
Understanding the Perception of Transliterated Offensive Social Media Posts Among Banglish and Hinglish Users Dhiman Goswami, Zhicong Lu and Sanchari Das
11.
"Please Listen to Us and Respect": Understanding Privacy Perspectives and Experiences of FemHealth App Users Through a Qualitative Analysis of User Reviews Chenkai Ma, Shijing He, Calum Inverarity, Mohammad Tahaei, Ina Kaleva, Mark Warner and Ruba Abu-Salma
15:05 – 15:25
Coffee Break
15:25 – 16:30
Session 4 Organizational Security Governance and Practices
12.
Validating CRIB as a Board-Level Cyber Risk Governance Maturity Framework Robert Bose and Tristan Caulfield
13.
Default but Fragmented: How Security Practitioners Use Social Media for Cyber Threat Intelligence Shota Fujii, Goki Hanawa, Takayuki Sato and Nobutaka Kawaguchi
14.
Does My Code Leak Secrets? Developers' View on Security Testing Tool Reports in Timing Side-Channel Analysis Michael Kloos, Stephan Wiefling and Luigi Lo Iacono
15.
Investigating Shadow IT Use and Adoption in Educational Institutions and their Privacy Implications Easton Kelso, Ananta Soneji, Yan Shoshitaishvili, Sazzadur Rahaman and Rakibul Hasan
17:00 – 19:00
Visit to Haut Fourneaux Belval Free for all participants
19:00
Gala Dinner
Day 2

Thursday, 3 September 2026

9:00 – 9:30
Registration
9:30 – 10:35
Session 5 Privacy in Everyday Apps and Platforms
16.
Privacy in the Generative AI Context: Exploring Users' Privacy Perceptions and Professional Use Intentions Grace Fox, Aneka Williams, Mary Jean Amon, Tangila Islam Tanni and Yan Solihin
17.
What Dating Apps Show About Us: A Sociotechnical Measurement Study of Security and Privacy Weaknesses in Android Dating Applications Ayush Daga, Laraib Asif and Sanchari Das
18.
There's a (pot)hole in your privacy policy: Privacy Concerns in Canadian Problem-Reporting Websites Indrani Ray, Maria Wolters and Kami Vaniea
19.
Preventing Privacy Dark Patterns: A Pre-Release Review Framework Mahe Chen
10:35 – 11:00
Coffee Break
11:00 – 12:00
Invited Talk Simulating Personality-Driven News Judgement with Large Language Models Marinella Petrocchi
Speaker page →

Large language models are increasingly used to simulate human decision-making. In this talk, I examine whether personality-aligned LLM “agents”, endowed with Big-Five profiles, can reproduce human differences in news judgement — the ability to rate true news as accurate and false news as inaccurate. Using existing datasets where human participants with known personality traits evaluated political headlines, we create matching LLM agents and compare their responses with human patterns. I will present where trait effects (e.g., Agreeableness, Conscientiousness, Open-Mindedness) are echoed by LLMs, where they diverge, and how personality conditioning changes overall accuracy ratings across different prompt formats and model settings. This offers a cautious view of what current LLMs can and cannot tell us about personality-driven susceptibility to misinformation.

12:00 – 13:30
Lunch
13:30 – 14:35
Session 6 From Awareness to Behavior Change in Security
20.
Applying Behaviour Change Knowledge to Foster Secure Employee Behaviour: An Exploratory Study with Security and Security Awareness Practitioners Rebecca Panskus, Martina Angela Sasse and Karola Marky
21.
Evaluating the Learning Efficiency of a Ransomware Awareness Video Mrudula Arunkumar, Christian Schunck, Matthias Winterstetter, Daniel Sonnensperger-Kann and Heiko Roßnagel
22.
Even the Cybersecurity-Adept Avoid Planning for Post-Mortem Digital Account Dissolution Raha Asadi, Oksana Kulyk and Karen Renaud
23.
The Cost of Compliance: An Empirical Research of Cognitive Cost and System Usability for Cybersecurity in SMEs Laura van Rooij, Maud Modders, Minou van der Werf and Bastian Küppers
14:35 – 15:00
Closing Remarks
15:00 – 15:30
Final Coffee Break