At first glance, Pieters has a noteworthy position at Radboud University. He completed his computing science and philosophy of technology studies at the University of Twente in 2003 and received his PhD for research into the use of electronic voting machines at the faculty of sciences at Radboud University. He also conducted research into risk management for cyber security at Delft University of Technology. Yet this apparent “exact scientist” will now be working as a professor at the Faculty of Social Sciences. According to Pieters, this is characteristic of the interdisciplinary research at Radboud University.
“For my PhD, I conducted research into the security of voice computers and voting over the internet. It quickly became clear how important communication and trust are in the acceptance of technology,” says Pieters in his recent inaugural lecture. “However, I specifically do not want to be the technician in the world of social sciences. I mainly want to demonstrate how the design sciences — conceptual, technical, and communicative — can enrich the behavioural sciences, especially by not only assigning responsibility to individuals, but also by distributing it among all technical and human actors in an organisation.”
Hassle factor
Technology is an obstacle for people sometimes, and vice versa. Pieters notes that business ICT can be very complex at times, just to comply with certain security standards. The consequence of this is that people will start using workarounds. Is complex multi-factor authentication required to communicate with colleagues? If so, then there is a good chance that those colleagues will start a WhatsApp group and bypass a lot of security in doing so. Does someone’s work inbox not work well or at all on a mobile phone? In that case, people will suddenly start sending business documents to their personal e-mail. It is a choice that is made even at the highest levels of Dutch government.
Pieters describes it as the “hassle factor”. Technologists and security staff can continue to upgrade the standards in the hope that people will start to listen, but it does not necessarily help in practice. This is why he preaches the importance of finding the right balance between standards and practical feasibility. “Many awareness initiatives are too focused on knowledge transfer. This has a limited and often short-lived effect on behaviour. Furthermore, it can also have the opposite effect if you scare people or make them feel ashamed.”
Interventions
“Instead, let us look at interventions to permanently change people’s attitude towards safety and cyber security. That starts with repetition. If you start every meeting by explaining where the emergency exit is, then the importance of safety will automatically become clear to those present, for example. If people have heard something about security recently, or have done something related to security, then they are more likely to include it in their considerations. We want to create an organisational climate in which security plays an important role, and where people are not afraid to hold each other accountable and report matters that they think may pose a risk, such as workarounds that are not secure. It should also include regular discussions about security, if only to keep focus on the topic.”
On the other hand, there are matters that are better resolved by technology than people, in Pieters’ opinion. “The removal of sensitive information related to applications, for example. If you expect staff members to take the initiative for the removal, you may be disappointed as it is never really a priority. You will have to organise this differently, by assigning an expiration date to data, for example. If you want people to stop being fooled by phishing e-mails so quickly, would it not be prudent to put in a cooldown period for links/attachments after people open the e-mail? That means: people will be forced to wait a bit before they can take action, and will hopefully think about it a little more.”
However, technology cannot resolve everything as you will quickly encounter the hassle factor again. “If you want to ensure a better work-life balance, as an employer you can organise that e-mails that are sent in the evening will only be delivered in the morning. At the same time, this will increase the risk that people will use their personal e-mail address for important e-mails outside of working hours, or use WhatsApp to exchange documents, and you do not want that either.”
Research
These are the challenges that appeal to the new professor and which he will be researching in the coming period. The research is structured along three main lines. First, Pieters will look at how staff members and organisations deal with warning signals at work and how the response to them can be improved. This not only includes signals about cyber threats, but also signals related to social safety. He will also work on the abovementioned workarounds: staff members who think of a different method to circumvent a “secure” but complicated procedure implemented by the employer, for example. How can security be ensured, knowing that the temptation of workarounds is strong?
There is also the gap between digital technology and responsibility. Increasingly, we, as people, will make choices based on the advice of a computer or other intelligent system. What if the advice is not right? “I want to examine what exactly happens to the perceptions of responsibility and the associated behaviour such as when people should really go against the advice of a computer but maybe do not do so because of possible consequences.” He will do this together with iHub, Radboud’s Interdisciplinary Hub for Security, Privacy and Data Governance among others. Pieters feels that interdisciplinarity, such as that between technicians and social scientists, is indispensable for the technology of today and tomorrow.
Image source: Pexels