{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:21:23Z","timestamp":1778631683534,"version":"3.51.4"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031055621","type":"print"},{"value":"9783031055638","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-05563-8_10","type":"book-chapter","created":{"date-parts":[[2022,5,13]],"date-time":"2022-05-13T16:08:55Z","timestamp":1652458135000},"page":"135-153","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Lessons Learned and Suitability of Focus Groups in Security Information Workers Research"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6017-9693","authenticated-orcid":false,"given":"Julie M.","family":"Haney","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6433-884X","authenticated-orcid":false,"given":"Jody L.","family":"Jacobs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fernando","family":"Barrientos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7013-6603","authenticated-orcid":false,"given":"Susanne M.","family":"Furman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,6,16]]},"reference":[{"key":"10_CR1","unstructured":"7th Workshop on Security Information Workers. https:\/\/security-information-workers.org\/ (2021)"},{"key":"10_CR2","unstructured":"Acar, Y., Stransky, C., Wermke, D., Mazurek, M.L., Fahl, S.: Security developer studies with Github users: Exploring a convenience sample. In: Proceedings of the 13th Symposium on Usable Privacy and Security (SOUPS 2017). pp. 81\u201395 (2017)"},{"key":"10_CR3","unstructured":"Bada, M., Sasse, A.M., Nurse, J.R.: Cyber security awareness campaigns: Why do they fail to change behaviour? (2019). https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1901\/1901.02672.pdf"},{"key":"10_CR4","unstructured":"Bada, M., Solms, B.V., Agrafiotis, I.: Reviewing national cybersecurity awareness in Africa: An empirical study (2019)"},{"key":"10_CR5","unstructured":"Botta, D., Werlinger, R., Gagn\u00e9, A., Beznosov, K., Iverson, L., Fels, S., Fisher, B.: Studying IT security professionals: Research design and lessons learned (2007)"},{"key":"10_CR6","volume-title":"Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory","author":"J Corbin","year":"2015","unstructured":"Corbin, J., Strauss, A.: Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory, 4th edn. Sage Publications, Thousand Oaks (2015)","edition":"4"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"Cyr, J.: The unique utility of focus groups for mixed-methods research. Polit. Sci. Politics 50(4), 1038 (2017)","DOI":"10.1017\/S104909651700124X"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"David, D.P., Keupp, M.M., Mermoud, A.: Knowledge absorption for cyber-security: The role of human beliefs. Comput. Hum. Behav. 106, 106255 (2020)","DOI":"10.1016\/j.chb.2020.106255"},{"key":"10_CR9","unstructured":"Dykstra, J., Paul, C.L.: Cyber operations stress survey (COSS): Studying fatigue, frustration, and cognitive workload in cybersecurity operations. In: 11th USENIX Workshop on Cyber Security Experimentation and Test (CSET 18) (2018)"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Fujs, D., Mihelic\u0306, A., Vrhovec, S.L.: The power of interpretation: Qualitative methods in cybersecurity research. In: Proceedings of the 14th International Conference on Availability, Reliability and Security, pp. 1\u201310 (2019)","DOI":"10.1145\/3339252.3341479"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Galloway, K.L.: Focus groups in the virtual world: implications for the future of evaluation. New Dir. Eval. 131(2011), 47\u201351 (2011)","DOI":"10.1002\/ev.377"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Goodall, J.R., Lutters, W.G., Komlodi, A.: I know my network: collaboration and expertise in intrusion detection. In: Proceedings of the 2004 ACM Conference on Computer Supported Cooperative Work, pp. 342\u2013345 (2004)","DOI":"10.1145\/1031607.1031663"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Gorski, P., Leo, P., Acar, Y., Iacono, L.L., Fahl, S.: Listen to developers! A participatory design study on security warnings for cryptographic APIs. In: Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, pp. 1\u201313 (2020)","DOI":"10.1145\/3313831.3376142"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Guest, G., Namey, E., McKenna, K.: How many focus groups are enough? Building an evidence base for nonprobability sample sizes. Field Methods 29(1), 3\u201322, 106255 (2017)","DOI":"10.1177\/1525822X16639015"},{"key":"10_CR15","unstructured":"Krueger, R.A., Casey, M.A.: Focus Groups: A Practical Guide for Applied Research. Sage, Thousand Oaks (2015)"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Kumar, P.C., Chetty, M., Clegg, T.L., Vitak, J.: Privacy and security considerations for digital technology use in elementary schools. In: Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, pp. 1\u201313 (2019)","DOI":"10.1145\/3290605.3300537"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Malhotra, A., Majchrzak, A., Rosen, B.: Leading virtual teams. Acad. Manage. Perspect. 21(1), 60\u201370 (2007)","DOI":"10.5465\/amp.2007.24286164"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Mathew, A., Cheshire, C.: Risky business: Social trust and community in the practice of cybersecurity for internet infrastructure. In: Proceedings of the 50th Hawaii International Conference on System Sciences, pp. 2341\u20132350 (2017)","DOI":"10.24251\/HICSS.2017.283"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Mermoud, A., Keupp, M.M., Huguenin, K., Palmi\u00e9, M., David, D.P.: To share or not to share: A behavioral perspective on human participation in security information sharing. J. Cybersecurity 5(1) (2019)","DOI":"10.1093\/cybsec\/tyz006"},{"key":"10_CR20","unstructured":"Nassar-McMillan, S.C., Borders, L.D.: Use of focus groups in survey item development. Qual. Rep. 7(1), 1\u201312, 106255 (2002)"},{"key":"10_CR21","unstructured":"National Institute of Standards and Technology: FISSEA - Federal Information Security Educators (2021). https:\/\/csrc.nist.gov\/projects\/fissea"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"O\u2019Brien, K.: Using focus groups to develop health surveys: An example from research on social relationships and AIDS-preventive behavior. Health Educ. Q. 20(3), 361\u2013372, 106255 (1993)","DOI":"10.1177\/109019819302000307"},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Paul, C.L.: Human-centered study of a network operations center: Experience report and lessons learned. In: Proceedings of the 2014 ACM Workshop on Security Information Workers, pp. 39\u201342 (2014)","DOI":"10.1145\/2663887.2663899"},{"key":"10_CR24","unstructured":"Petersen, R., Santos, D., Smith, M.C., Wetzel, K.A., Witte, G.: NIST Special Publication 800\u2013181 Revision 1: Workforce Framework for Cybersecurity (NICE Framework) (2020). https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-181r1.pdf"},{"key":"10_CR25","unstructured":"SANS: 2021 SANS security awareness report: Managing human cyber risk (2021). https:\/\/www.sans.org\/security-awareness-training\/resources\/reports\/sareport-2021\/"},{"key":"10_CR26","unstructured":"Schneier, B.: The security mindset (2008). https:\/\/www.schneier.com\/blog\/archives\/2008\/03\/the_security_mi_1.html"},{"key":"10_CR27","doi-asserted-by":"crossref","unstructured":"Sim, J.: Collecting and analysing qualitative data: Issues raised by the focus group. J. Adv. Nurs. 28(2), 345\u2013352, 106255 (1998)","DOI":"10.1046\/j.1365-2648.1998.00692.x"},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"Smith, E., Loftin, R., Murphy-Hill, E., Bird, C., Zimmermann, T.: Improving developer participation rates in surveys. In: Proceedings of the 6th International Workshop on Cooperative and Human Aspects of Software Engineering (CHASE), pp. 89\u201392 (2013)","DOI":"10.1109\/CHASE.2013.6614738"},{"key":"10_CR29","unstructured":"Stewart, D.W., Shamdasani, P.N.: Focus Groups: Theory and Practice, vol. 20. Sage, Thousand Oaks (2014)"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Sundaramurthy, S.C., McHugh, J., Ou, X.S., Rajagopalan, S.R., Wesch, M.: An anthropological approach to studying CSIRTs. IEEE Secur. Priv. 12(5), 52\u201360, 106255 (2014)","DOI":"10.1109\/MSP.2014.84"},{"key":"10_CR31","unstructured":"The State of Security: The security mindset: the key to success in the security field, November 2015. https:\/\/www.tripwire.com\/state-of-security\/off-topic\/the-security-mindset-the-key-to-success-in-the-security-field\/"},{"key":"10_CR32","unstructured":"U.S. Bureau of Labor Statistics: Information security analysts (2021). https:\/\/www.bls.gov\/ooh\/computer-and-information-technology\/information-security-analysts.htm"},{"key":"10_CR33","unstructured":"U.S. Bureau of Labor Statistics: Software developers, quality assurance analysts, and testers (2021). https:\/\/www.bls.gov\/ooh\/computer-and-information-technology\/software-developers.htm"},{"key":"10_CR34","unstructured":"UX Alliance: Conducting remote online focus groups in times of COVID-19, April 2020. https:\/\/medium.com\/@UXalliance\/conducting-remote-online-focus-groups-in-times-of-covid-19-ee1c66644fdb"},{"key":"10_CR35","doi-asserted-by":"crossref","unstructured":"Wilson, M., Hash, J.: NIST Special Publication 800\u201350 - Building an information technology security awareness program (2003). https:\/\/nvlpubs.nist.gov\/nistpubs\/Legacy\/SP\/nistspecialpublication800-50.pdf","DOI":"10.6028\/NIST.SP.800-50"},{"key":"10_CR36","doi-asserted-by":"crossref","unstructured":"Witschey, J., Murphy-Hill, E., Xiao, S.: Conducting interview studies: Challenges, lessons learned, and open questions. In: Proceedings of the 1st International Workshop on Conducting Empirical Studies in Industry (CESI), pp. 51\u201354 (2013)","DOI":"10.1109\/CESI.2013.6618471"},{"key":"10_CR37","unstructured":"Woelk, B.: The successful security awareness professional: Foundational skills and continuing education strategies (2015). https:\/\/library.educause.edu\/~\/media\/files\/library\/2016\/8\/erb1608.pdf"}],"container-title":["Lecture Notes in Computer Science","HCI for Cybersecurity, Privacy and Trust"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-05563-8_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:04:12Z","timestamp":1778630652000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-05563-8_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031055621","9783031055638"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-05563-8_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"16 June 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"HCII","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Human-Computer Interaction","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 July 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"hcii2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2022.hci.international\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}