{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T17:28:54Z","timestamp":1754155734413,"version":"3.41.2"},"reference-count":58,"publisher":"Emerald","issue":"1","license":[{"start":{"date-parts":[[2023,10,10]],"date-time":"2023-10-10T00:00:00Z","timestamp":1696896000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ITP"],"published-print":{"date-parts":[[2025,1,8]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>This paper presents a qualitative study of penetration testing, the practice of attacking information systems to find security vulnerabilities and fixing them. The purpose of this paper is to understand whether and to what extent penetration testing can reveal various socio-organisational factors of information security in organisations. In doing so, the paper innovates theory by using Routine Activity Theory together with phenomenology of information systems concepts.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>The articulation of Routine Activity Theory and phenomenology emerged inductively from the data analysis. The data consists of 24 qualitative interviews conducted with penetration testers, analysed with thematic analysis.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>The starting assumption is that penetration testers are akin to offenders in a crime situation, dealing with targets and the absence of capable guardians. A key finding is that penetration testers described their targets as an installed base, highlighting how vulnerabilities, which make a target suitable, often emerge from properties of the existing built digital environments. This includes systems that are forgotten or lack ongoing maintenance. Moreover, penetration testers highlighted that although the testing is often predicated on planned methodologies, often they resort to serendipitous practices such as improvisation.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>This paper contributes to theory, showing how Routine Activity Theory and phenomenological concepts can work together in the study of socio-organisational factors of information security. This contribution stems from considering that much research on information security focuses on the internal actions of organisations. The study of penetration testing as a proxy of real attacks allows novel insights into socio-organisational factors of information security in organisations.<\/jats:p><\/jats:sec>","DOI":"10.1108\/itp-11-2021-0864","type":"journal-article","created":{"date-parts":[[2023,10,6]],"date-time":"2023-10-06T09:51:40Z","timestamp":1696585900000},"page":"380-398","source":"Crossref","is-referenced-by-count":0,"title":["A qualitative study of penetration testers and what they can tell us about information security in organisations"],"prefix":"10.1108","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1120-4773","authenticated-orcid":false,"given":"Stefano","family":"De Paoli","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1770-6849","authenticated-orcid":false,"given":"Jason","family":"Johnstone","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2023,10,10]]},"reference":[{"key":"key2025010610133940100_ref001","doi-asserted-by":"crossref","unstructured":"Aanestad, M., Grisot, M., Hanseth, O. and Vassilakopoulou, P. (2017), \u201cInformation infrastructures and the challenge of the installed base\u201d, in Aanestad, M., Grisot, M., Hanseth, O. and Vassilakopoulou, P. (Eds), Information Infrastructures within European Health Care, Springer, Cham, pp.\u00a025-33.","DOI":"10.1007\/978-3-319-51020-0_3"},{"issue":"4","key":"key2025010610133940100_ref002","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1016\/j.cose.2006.11.004","article-title":"A qualitative study of users' view on information security","volume":"26","year":"2007","journal-title":"Computers and Security"},{"issue":"sup1","key":"key2025010610133940100_ref003","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1080\/12460125.2018.1468177","article-title":"Decision support for selecting information security controls","volume":"27","year":"2018","journal-title":"Journal of Decision Systems"},{"issue":"2","key":"key2025010610133940100_ref004","doi-asserted-by":"publisher","first-page":"770","DOI":"10.1108\/ITP-06-2019-0269","article-title":"Information security awareness in a developing country context: insights from the government sector in Saudi Arabia","volume":"34","year":"2021","journal-title":"Information Technology and People"},{"key":"key2025010610133940100_ref005","doi-asserted-by":"publisher","first-page":"352","DOI":"10.1109\/ICITST.2016.7856729","article-title":"Information security policies: a review of challenges and influencing factors","year":"2016"},{"issue":"1","key":"key2025010610133940100_ref006","doi-asserted-by":"publisher","first-page":"250","DOI":"10.1108\/ITP-03-2019-0109","article-title":"Information system security policy noncompliance: the role of situation-specific ethical orientation","volume":"34","year":"2021","journal-title":"Information Technology and People"},{"issue":"1","key":"key2025010610133940100_ref007","doi-asserted-by":"publisher","first-page":"32","DOI":"10.17705\/1CAIS.01432","article-title":"Empirical test of a hacking model: an exploratory study","volume":"14","year":"2004","journal-title":"Communications of the Association for Information Systems"},{"issue":"5","key":"key2025010610133940100_ref009","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1080\/0735648X.2019.1692426","article-title":"Introduction: new directions in cybercrime research","volume":"42","year":"2019","journal-title":"Journal of Crime and Justice"},{"issue":"2","key":"key2025010610133940100_ref010","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1191\/1478088706qp063oa","article-title":"Using thematic analysis in psychology","volume":"3","year":"2006","journal-title":"Qualitative Research in Psychology"},{"key":"key2025010610133940100_ref011","unstructured":"Braun, V. and Clarke, V. (2012), \u201cThematic analysis\u201d, in Cooper, H., Camic, P.M., Long, D.L., Panter, A.T., Rindskopf, D. and Sher, K.J. (Eds), APA Handbook of Research Methods in Psychology, Vol. 2: Research Designs: Quantitative, Qualitative, Neuropsychological, and Biological, American Psychological Association, Washington, DC, pp.\u00a057-71."},{"issue":"4","key":"key2025010610133940100_ref012","doi-asserted-by":"publisher","first-page":"973","DOI":"10.1108\/ITP-12-2017-0421","article-title":"The effects of moral disengagement and organizational ethical climate on insiders' information security policy violation behavior","volume":"32","year":"2019","journal-title":"Information Technology and People"},{"issue":"3","key":"key2025010610133940100_ref013","first-page":"3389","article-title":"Ethical hacking techniques with penetration testing","volume":"5","year":"2014","journal-title":"International Journal of Computer Science and Information Technologies"},{"volume-title":"The Labyrinths of Information. Challenging the Wisdom of Systems","year":"2002","key":"key2025010610133940100_ref014"},{"issue":"4","key":"key2025010610133940100_ref015","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1108\/09593849810246129","article-title":"From tool to Gestell: agendas for managing the information infrastructure","volume":"11","year":"1998","journal-title":"Information Technology and People"},{"issue":"3","key":"key2025010610133940100_ref016","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1111\/jan.12163","article-title":"Data collection and sampling in qualitative research: does size matter?","volume":"70","year":"2014","journal-title":"Journal of Advanced Nursing"},{"key":"key2025010610133940100_ref017","doi-asserted-by":"publisher","first-page":"588","DOI":"10.2307\/2094589","article-title":"Social change and crime rate trends: a routine activity approach","volume":"44","year":"1979","journal-title":"American Sociological Review"},{"volume-title":"A Concise Introduction to Mixed Methods Research","year":"2014","key":"key2025010610133940100_ref018"},{"first-page":"352","volume-title":"XVI Simp\u00f3sio Brasileiro em Seguran\u00e7a da Informa\u00e7\u00e3o e de Sistemas Computacionais","year":"2016","key":"key2025010610133940100_ref008"},{"issue":"2","key":"key2025010610133940100_ref058","doi-asserted-by":"publisher","DOI":"10.1186\/s13173-017-0051-1","article-title":"Overview and open issues on penetration test","volume":"23","year":"2017","journal-title":"Journal of the Brazilian Computer Society"},{"issue":"1-2","key":"key2025010610133940100_ref019","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1080\/24701475.2018.1448498","article-title":"The engineer\u2013criminologist and \u201cthe novelty of cybercrime\u201d: a situated genealogical study of timesharing systems","volume":"2","year":"2018","journal-title":"Internet Histories"},{"issue":"4","key":"key2025010610133940100_ref020","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1111\/j.1365-2929.2006.02418.x","article-title":"The qualitative research interview","volume":"40","year":"2006","journal-title":"Medical Education"},{"first-page":"399","article-title":"Two methodologies for physical penetration testing using social engineering","year":"2010","key":"key2025010610133940100_ref021"},{"issue":"5","key":"key2025010610133940100_ref022","doi-asserted-by":"publisher","first-page":"1318","DOI":"10.1108\/ITP-05-2018-0252","article-title":"Cybersecurity economics \u2013 balancing operational security spending","volume":"32","year":"2019","journal-title":"Information Technology and People"},{"issue":"4","key":"key2025010610133940100_ref023","doi-asserted-by":"publisher","first-page":"389","DOI":"10.1007\/BF01561001","article-title":"Human ecology and crime: a routine activity approach","volume":"8","year":"1980","journal-title":"Human Ecology"},{"key":"key2025010610133940100_ref024","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1016\/j.procs.2021.01.103","article-title":"The role of employees' information security awareness on the intention to resist social engineering","volume":"181","year":"2021","journal-title":"Procedia Computer Science"},{"key":"key2025010610133940100_ref025","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1016\/j.cose.2019.02.012","article-title":"Virtuous human hacking: the ethics of social engineering in penetration-testing","volume":"83","year":"2019","journal-title":"Computers and Security"},{"issue":"6","key":"key2025010610133940100_ref026","doi-asserted-by":"publisher","first-page":"1135","DOI":"10.1108\/ITP-10-2017-0322","article-title":"Examining employee security violations: moral disengagement and its environmental influences","volume":"31","year":"2018","journal-title":"Information Technology and People"},{"issue":"4","key":"key2025010610133940100_ref027","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1177\/0093854819900322","article-title":"An examination of motivation and routine activity theory to account for cyberattacks against Dutch web sites","volume":"47","year":"2020","journal-title":"Criminal Justice and Behavior"},{"issue":"5","key":"key2025010610133940100_ref028","doi-asserted-by":"publisher","first-page":"536","DOI":"10.1080\/0735648X.2019.1691859","article-title":"Website defacement and routine activities: considering the importance of hackers' valuations of potential targets","volume":"42","year":"2019","journal-title":"Journal of Crime and Justice"},{"issue":"4","key":"key2025010610133940100_ref029","doi-asserted-by":"publisher","first-page":"615","DOI":"10.1111\/j.1540-5915.2012.00361.x","article-title":"Managing employee compliance with information security policies: the critical role of top management and organizational culture","volume":"43","year":"2012","journal-title":"Decision Sciences"},{"issue":"10","key":"key2025010610133940100_ref030","doi-asserted-by":"publisher","first-page":"1163","DOI":"10.1080\/01639625.2016.1169829","article-title":"Exploring the provision of online booter services","volume":"37","year":"2016","journal-title":"Deviant Behavior"},{"issue":"3","key":"key2025010610133940100_ref031","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1080\/01639625.2015.1012409","article-title":"Applying routine activity theory to cybercrime: a theoretical and empirical analysis","volume":"37","year":"2016","journal-title":"Deviant Behavior"},{"issue":"3","key":"key2025010610133940100_ref032","doi-asserted-by":"crossref","first-page":"1","DOI":"10.4018\/irmj.2011070101","article-title":"Social engineering: the neglected human factor for information security management","volume":"24","year":"2011","journal-title":"Information Resources Management Journal"},{"key":"key2025010610133940100_ref033","doi-asserted-by":"crossref","unstructured":"Monteiro, E. and Hanseth, O. (1996), \u201cSocial shaping of information infrastructure: on being specific about the technology\u201d, in Orlikowski, W.J., Walsham, G., Jones, M.R. and Degross, J.I. (Eds), Information Technology and Changes in Organizational Work, Springer, Boston, MA, pp.\u00a0325-343.","DOI":"10.1007\/978-0-387-34872-8_20"},{"key":"key2025010610133940100_ref034","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1016\/j.cose.2016.03.004","article-title":"Social engineering attack examples, templates and scenarios","volume":"59","year":"2016","journal-title":"Computers and Security"},{"issue":"2","key":"key2025010610133940100_ref035","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1108\/ICS-12-2016-0095","article-title":"Key elements of an information security culture in organisations","volume":"27","year":"2019","journal-title":"Information and Computer Security"},{"issue":"5","key":"key2025010610133940100_ref036","doi-asserted-by":"publisher","first-page":"1262","DOI":"10.1108\/ITP-06-2018-0261","article-title":"Organizational practices as antecedents of the information security management performance: an empirical investigation","volume":"32","year":"2019","journal-title":"Information Technology and People"},{"issue":"4","key":"key2025010610133940100_ref037","doi-asserted-by":"publisher","first-page":"757","DOI":"10.2307\/25750704","article-title":"Improving employees' compliance through information systems security training: an action research study","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"3","key":"key2025010610133940100_ref038","doi-asserted-by":"publisher","first-page":"358","DOI":"10.1177\/0022427810365904","article-title":"Guardians on guardianship: factors affecting the willingness to supervise, the ability to detect potential offenders, and the willingness to intervene","volume":"47","year":"2010","journal-title":"Journal of Research in Crime and Delinquency"},{"volume-title":"Information Security: The Complete Reference","year":"2013","key":"key2025010610133940100_ref039"},{"issue":"1","key":"key2025010610133940100_ref040","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1080\/14780887.2013.801543","article-title":"Sampling in interview-based qualitative research: a theoretical and practical guide","volume":"11","year":"2014","journal-title":"Qualitative Research in Psychology"},{"key":"key2025010610133940100_ref041","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1016\/j.cose.2015.05.012","article-title":"Information security conscious care behaviour formation in organizations","volume":"53","year":"2015","journal-title":"Computers and Security"},{"issue":"2","key":"key2025010610133940100_ref042","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1016\/S1361-3723(16)30017-3","article-title":"Human aspects of information security in organisations","volume":"2016","year":"2016","journal-title":"Computer Fraud and Security"},{"issue":"1","key":"key2025010610133940100_ref043","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/s11416-014-0231-x","article-title":"An overview of vulnerability assessment and penetration testing techniques","volume":"11","year":"2015","journal-title":"Journal of Computer Virology and Hacking Techniques"},{"issue":"5","key":"key2025010610133940100_ref044","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1016\/j.im.2008.12.007","article-title":"Information security management standards: problems and solutions","volume":"46","year":"2009","journal-title":"Information and Management"},{"issue":"3","key":"key2025010610133940100_ref045","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1177\/00027649921955326","article-title":"The ethnography of infrastructure","volume":"43","year":"1999","journal-title":"American Behavioral Scientist"},{"volume-title":"Human-machine Reconfigurations: Plans and Situated Actions","year":"2007","key":"key2025010610133940100_ref046"},{"key":"key2025010610133940100_ref047","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1145\/1059524.1059554","article-title":"Social engineering: \u2018the dark art","year":"2004"},{"volume-title":"The Ethical Hack: A Framework for Business Value Penetration Testing","year":"2005","key":"key2025010610133940100_ref048"},{"issue":"1","key":"key2025010610133940100_ref049","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1057\/ejis.2013.27","article-title":"Managing the introduction of information security awareness programmes in organisations","volume":"24","year":"2015","journal-title":"European Journal of Information Systems"},{"key":"key2025010610133940100_ref050","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102387","article-title":"Developing a cyber security culture: current practices and future needs","volume":"109","year":"2021","journal-title":"Computers and Security"},{"issue":"3","key":"key2025010610133940100_ref051","doi-asserted-by":"publisher","first-page":"578","DOI":"10.1093\/bjc\/azv009","article-title":"From cybercrime to cyborg crime: botnets as hybrid criminal actor-networks","volume":"55","year":"2015","journal-title":"British Journal of Criminology"},{"issue":"4","key":"key2025010610133940100_ref052","doi-asserted-by":"publisher","first-page":"476","DOI":"10.1016\/j.cose.2009.10.005","article-title":"Information security culture: a management perspective","volume":"29","year":"2010","journal-title":"Computers and Security"},{"key":"key2025010610133940100_ref053","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","article-title":"From information security to cyber security","volume":"38","year":"2013","journal-title":"Computers and Security"},{"issue":"1","key":"key2025010610133940100_ref054","doi-asserted-by":"publisher","DOI":"10.1108\/ITP-04-2020-0197","article-title":"Understanding employees' information security identities: an interpretive narrative approach","volume":"35","year":"2021","journal-title":"Information Technology and People"},{"issue":"4","key":"key2025010610133940100_ref055","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1016\/j.infoandorg.2006.08.001","article-title":"Understanding the perpetration of employee computer crime in the organisational context","volume":"16","year":"2006","journal-title":"Information and Organization"},{"volume-title":"Understanding Computers and Cognition","year":"1986","key":"key2025010610133940100_ref056"},{"issue":"4","key":"key2025010610133940100_ref057","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1016\/S1361-3723(13)70039-3","article-title":"Using penetration testing to enhance your company's security","volume":"2013","year":"2013","journal-title":"Computer Fraud and Security"}],"container-title":["Information Technology &amp; People"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-11-2021-0864\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-11-2021-0864\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:56:00Z","timestamp":1753394160000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/itp\/article\/38\/1\/380-398\/1241255"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,10]]},"references-count":58,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,10,10]]},"published-print":{"date-parts":[[2025,1,8]]}},"alternative-id":["10.1108\/ITP-11-2021-0864"],"URL":"https:\/\/doi.org\/10.1108\/itp-11-2021-0864","relation":{},"ISSN":["0959-3845"],"issn-type":[{"type":"print","value":"0959-3845"}],"subject":[],"published":{"date-parts":[[2023,10,10]]}}}