Framing Cybersecurity and AI Research
Location
Tampere University, City Centre Campus, Kanslerinrinne/Kalevantie 33100 TAMPERE
Room information (seminar is in two buildings in the city centre campus)
31.8.26 Pinni B Building, room B 0040 from 10am to 5pm
1.9.26 Main building (Päätalo) room A069 A07 from 9am to 4pm
Registration
Registration is open until August 20, 2026.
Speakers
Main speaker Professor and Dean Gurpreet Dhillon, University of Nebraska Omaha (UNO), USA
Organizer
Professor Mikko Ruohonen, Tampere University, Finland.
Overview
Cybersecurity and artificial intelligence are creating phenomena that challenge many of the assumptions underlying established theories of organizations, technology, human behavior, privacy, identity, trust, and governance.
This doctoral seminar approaches cybersecurity and AI not simply as topics to be studied, but as research settings in which important theoretical puzzles become visible.
Phenomenon → Tension → Puzzle → Theory → Evidence → Contribution
The seminar is organized as a doctoral research laboratory. Short conceptual discussions are combined with research provocations, theory exercises, collaborative problem solving, critique, and intensive work on participants’ own research ideas.
Participants should leave the seminar with:
• A clearer understanding of what makes cybersecurity and AI research theoretically interesting
• An improved ability to distinguish a topic, problem, puzzle, and research question
• A stronger understanding of how theoretical lenses shape what researchers see
• New perspectives on AI, cybersecurity, privacy, identity, trust, and governance
• A substantially revised framing of their own doctoral research
• A set of potentially important research questions for the next decade
Information systems security has evolved from a narrow concern with technical safeguards into a broader organizational and socio-technical field. Early approaches relied on checklists, risk analysis, access controls, and mechanistic methods designed to protect systems and information assets. Although these methods remain important, they often treat security as an addition to systems design rather than as an integral design principle. This separation creates a persistent duality in which systems are developed for functionality and security is addressed later, producing tension between how information is used and how it is protected.
From an information systems perspective, security concerns the integrity of the technical, formal, and informal dimensions of a system. The technical dimension includes hardware, software, networks, data, and security technologies. The formal dimension encompasses organizational structures, policies, standards, roles, and regulatory requirements. The informal dimension includes values, behaviors, relationships, power, and organizational culture. Information systems security therefore extends beyond technical infrastructure to the protection of information handling across all three dimensions.
The field now includes policy compliance, privacy, trust, risk management, secure systems design, vulnerability management, access control, insider threats, data breaches, phishing, malware, cloud security, mobile technologies, the Internet of Things, and critical infrastructure protection. Yet academic research has not always aligned with practitioner concerns. Scholars have focused heavily on compliance, individual behavior, and privacy, while practitioners continue to emphasize attacks, breaches, malware, hacking, infrastructure vulnerabilities, and weaknesses in systems design. This divergence raises important questions about the practical relevance of information systems security research.
A central premise of the seminar is that security failures rarely arise from a single cause. They emerge through interactions among people, organizational structures, tasks, and technologies. A phishing attack may compromise an employee account, bypass an organizational rule, exploit a system vulnerability, and lead to malware installation or a data breach. Similarly, access-control failures may result from technical flaws, unclear responsibilities, excessive privileges, poor implementation, or changing work practices. Security incidents must therefore be understood at the intersections of social and technical systems.
This two-day seminar examines the historical development of information systems security research and its movement from technical and functionalist approaches toward socio-organizational and socio-technical perspectives. It considers secure systems design, risk, compliance, privacy, organizational behavior, vulnerability management, and security governance. Particular attention will be given to duality in systems development, the limitations of standardized security methods, and the role of context in shaping security behavior and organizational responses.
The seminar will also address contemporary developments such as machine learning, user and entity behavior analytics, identity analytics, and sentiment analysis. These tools create new possibilities for identifying attacks, vulnerabilities, insider threats, and abnormal behavior, but they also raise questions concerning accountability, transparency, privacy, and organizational judgment. The growing use of artificial intelligence makes these issues especially important as security decisions become distributed across human and computational actors.
The aim of the seminar is to organize the major traditions of information systems security research into a coherent framework. Students will examine the assumptions underlying different approaches, assess the relationship between research and practice, and consider how technical and social countermeasures can be integrated. Drawing on the instructor’s engagement with the field over the past 30 years, the seminar will also consider where important gaps remain and how future research can respond to changing technologies, organizations, vulnerabilities, and forms of work.
The seminar is designed primarily for doctoral students in information systems and related disciplines (software engineering, business and management etc.).
Program
Day 1 — Learning to See Differently
Building the Intellectual Foundations of Cybersecurity Research
Monday, 31 August 2026 | 10:00 AM – 5:00 PM | Pinni B Building, Room B0040
10:00 – 10:30
Opening — What Don’t We Understand About Cybersecurity?
The seminar begins not with definitions but with unanswered questions. Participants introduce themselves through the phenomenon they are studying and the question they are struggling to answer. These questions form a Wall of Puzzles that evolves throughout the seminar.
Topics
· What constitutes a cybersecurity phenomenon?
· Cybersecurity as technical, behavioral, organizational, and societal inquiry
· From research topics to research puzzles
· Cybersecurity and AI as settings for theory development
· Seminar framework: See → Question → Theorize → Investigate → Challenge → Contribute
Participant Activity
Each participant completes two statements: “My phenomenon is…” and “The thing I cannot adequately explain is…”
10:30 – 11:30
Session 1 — Cybersecurity Is Not What You Think It Is: Seeing the Phenomenon
Cybersecurity research has evolved from a predominantly technical orientation toward increasingly socio-technical, organizational, behavioral, institutional, and societal perspectives. This session examines how different intellectual lenses can produce fundamentally different explanations of the same cybersecurity event.
Topics
· Evolution from information security to cybersecurity
· Socio-organizational perspectives
· Technology versus organizational explanations
· Levels and units of analysis
· Cybersecurity as a multidisciplinary research setting
· Grand challenges in cybersecurity research
Research Laboratory — Six Explanations, One Incident
Participants analyze the same cybersecurity incident as a technology failure, human behavior failure, organizational failure, governance failure, economic/incentive failure, and societal/institutional failure. Central question: If the phenomenon remains the same but the explanation changes, what exactly is the researcher studying? Access the case here
Selected Readings
Dhillon, G., & Backhouse, J. (2000). Technical opinion: Information system security management in the new millennium. Communications of the ACM, 43(7), 125-128.
Dhillon, G., & Backhouse, J. (2001). Current directions in IS security research: Towards socio-organizational perspectives. Information Systems Journal, 11(2), 127–153.
Von Solms, R., & Van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97–102.
11:30 – 11:45 | Coffee Break
11:45 – 12:45
Session 2 — Kill Your Research Question: From Topic to Theoretical Puzzle
Cybersecurity and AI research is especially vulnerable to being driven by fashionable technologies, emerging threats, and rapidly changing practical concerns. Doctoral projects can therefore begin with a topic—generative AI, ransomware, deepfakes, zero trust, AI governance, human–AI collaboration—or with a claimed “gap” in the literature rather than an intellectually consequential problem.
Topics
· Topic versus phenomenon
· Practical problem versus research problem
· Literature gaps versus theoretical puzzles
· Problematization
· What makes a research question interesting?
· Context-specific theorizing
· From puzzle to contribution
Research Laboratory — Research Question Stress Test
Participants test their own research questions: Is this a topic disguised as a question? Is the answer predictable? Is it simply another X-affects-Y study? Why don’t we already know the answer? Would answering it change how we understand something? Why should anyone outside this narrow literature care? They then rewrite the question and submit it to peer challenge.
Selected Readings
Hong, W., Chan, F. K. Y., Thong, J. Y. L., Chasalow, L. C., & Dhillon, G. (2014). A framework and guidelines for context-specific theorizing in information systems research. Information Systems Research, 25(1), 111–136.
Alvesson, M., & Sandberg, J. (2011). Generating research questions through problematization. Academy of Management Review, 36(2), 247–271.
Whetten, D. A. (1989). What constitutes a theoretical contribution? Academy of Management Review, 14(4), 490–495.
12:45 – 1:45 | Lunch
1:45 – 3:00
Session 3 — Theory Is a Flashlight: What Becomes Visible—and What Disappears?
Theory is not decoration added to empirical findings. Theories shape what researchers notice, what they ignore, and what they are capable of explaining. This session uses human cybersecurity behavior to explore how competing theoretical lenses construct different explanations of the same phenomenon.
Topics
· What theory does
· Theory versus framework versus model
· Human-centered cybersecurity
· Compliance and non-compliance
· Deterrence
· Psychological empowerment
· Organizational justice
· Trust and control
· Socio-technical explanations
· The limits of theoretical lenses
Research Laboratory — One Phenomenon, Multiple Theories
Participants analyze a common paradox: See Appendix for the case details. Groups explain the behavior using different theoretical perspectives, then ask: What did your theory allow you to see? What did it prevent you from seeing?
Selected Readings
Dhillon, G., Abdul Talib, Y. Y., & Picoto, W. N. (2021). The mediating role of psychological empowerment in information security compliance intentions. Journal of the Association for Information Systems, 22(5), 1292–1315.
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance. MIS Quarterly, 34(3), 523–548.
Gregor, S. (2006). The nature of theory in information systems. MIS Quarterly, 30(3), 611–642.
3:00 – 3:15 | Coffee Break
3:15 – 4:15
Session 4 — The Cybersecurity Paradox Factory: Finding Research in Contradictions
Some of the most interesting research problems arise not from gaps in literature but from competing values and objectives. Participants use contradictions as engines for theory development.
Topics
· Security ↔ Usability
· Security ↔ Productivity
· Security ↔ Privacy
· Control ↔ Trust
· Transparency ↔ Security
· Personalization ↔ Privacy
· Automation ↔ Human Agency
· AI Autonomy ↔ Accountability
· Compliance ↔ Innovation
· Resilience ↔ Efficiency
Research Laboratory — The Paradox Factory
Each group selects one contradiction and develops the phenomenon, competing values, tension, anomaly, and three potential research puzzles.
Selected Readings
Dhillon, G., & Torkzadeh, G. (2006). Value-focused assessment of information system security in organizations. Information Systems Journal, 16(3), 293–314.
Dhillon, G., Oliveira, T., Susarapu, S., & Caldeira, M. (2016). Deciding between information security and usability: Developing value based objectives. Computers in Human Behavior, 61, 656-666.
Keeney, R. L. (1992). Value-Focused Thinking. Harvard University Press.
4:15 – 5:00
Doctoral Research Clinic I — Research Surgery: Reconstructing Your Research DNA
Participants apply the day’s ideas directly to their doctoral research and critique one another’s research architecture.
Topics
· Phenomenon — What is happening?
· Anomaly — What is surprising?
· Tension — What competing forces are present?
· Puzzle — What can’t we adequately explain?
· Theory — What lens might help us see it differently?
· Evidence — What would convince a skeptical scholar?
· Contribution — What changes if the explanation is correct?
Day 1 Closing Question
What do you see in your research now that you did not see this morning?
Day 2 — Researching What Doesn’t Exist Yet
AI, Identity and the Future of Cybersecurity Research
Tuesday, 1 September 2026 | 9:00 AM – 4:00 PM | Main Building (Päätalo), Room A065 (A07)
9:00 – 9:30
Opening Provocation — It Is September 1, 2035
Participants enter a hypothetical world in which AI agents negotiate with AI agents, synthetic humans participate in organizations, autonomous systems make consequential decisions, digital identity has become probabilistic, and machines increasingly attack and defend against other machines.
Research Challenge
What research paper do you wish someone had written in 2026? Groups identify problems that today’s doctoral researchers may need to investigate before they become obvious.
Selected Readings
Ozuna, X., Dhillon, G., & Kaur, J. (2026). Reflexive Ethnography of Digital Legitimacy: Promissory Governance in Decentralized Organizations. AMCIS.
9:30 – 10:30
Session 5 — AI Breaks Our Theories
Much AI research asks how established theories can explain AI-related phenomena. This session reverses the question: What happens when AI makes the assumptions underlying our theories untenable?
Topics
· Human-AI collaboration
· Algorithm delegation
· Machine agency
· Autonomous cybersecurity
· Responsibility and accountability
· AI-enabled cyber threats
· AI governance
· Human control
· Theoretical assumptions in an AI-enabled world
Research Laboratory — Break the Theory
Participants examine assumptions embedded in familiar concepts: Deterrence assumes whom we deter; accountability assumes a responsible actor; trust assumes a trustee; agency assumes intention; identity assumes a person; compliance assumes an actor capable of choosing. The challenge is to determine whether AI merely provides a new context for old theories or requires new theorizing.
Selected Readings
Dhillon, G. (2023). Cybersecurity Challenges in an AI Enabled World. Journal of Information Systems Security, 19(3), 165-168.
Dhillon, G. (2023). The intellectual core of information systems security. Journal of Information System Security. 19(2), 91.
Wagner, R., Costa Pinto, D., Hildebrand, D., Pacheco, N. A., Dhillon, G., & Herter, M. M. (2025). Algorithm delegation: How embedded AI facilitates agency transference in medical services. Psychology & Marketing.
10:30 – 10:45 | Coffee Break
10:45 – 11:45
Session 6 — The Identity Crisis: Privacy and Trust in a Synthetic World
Begin with an apparently simple challenge: “Prove that you are you.” As AI-generated identities, synthetic media, algorithmic personalization, autonomous agents, and sophisticated cybercrime blur distinctions between authentic and artificial actors, fundamental assumptions about identity and trust become problematic,
Topics
· Digital identity
· Synthetic identity
· Authentication
· Privacy and disclosure
· Personalization versus intrusion
· Digital trust
· Human versus machine identity
· Security versus privacy
· Trust in AI-mediated environments
Research Laboratory — Four Lenses
Students examine one phenomenon through privacy, cybersecurity, identity, and trust, then ask: How did changing the theoretical lens change the research question?
Selected Readings
Kolotylo-Kulkarni, M., Xia, W., & Dhillon, G. (2021). Information disclosure in e-commerce: A systematic review and agenda for future research. Journal of Business Research, 126, 221–238.
Bélanger, F., & Crossler, R. E. (2011). Privacy in the digital age. MIS Quarterly, 35(4), 1017–1041.
Acquisti, A., Brandimarte, L., & Loewenstein, G. (2015). Privacy and human behavior in the age of information. Science, 347(6221), 509–514.
11:45 – 12:45 | Lunch
12:45 – 1:45
Session 7 — The Research Frontier Auction: What Should We Be Studying Now?
Participants receive an imaginary €10 million research budget and invest it across emerging research domains. Every investment must be defended on intellectual rather than fashionable grounds.
Topics
· Autonomous cyber defense
· Synthetic identities
· AI-enabled deception
· Human-AI trust
· Cyber resilience
· Digital sovereignty
· Privacy in agentic systems
· AI governance
· Cybercrime ecosystems
· Post-quantum organizational security
Research Laboratory — The Auction
Participants bid on the domains they believe will matter most over the next decade. The class then examines which topics attracted little or no investment and whether neglected problems may contain the most interesting opportunities. The exercise begins a collective Tampere Research Agenda 2026–2036.
1:45 – 2:30
Session 8 — Reviewer #2 Is an AI: Scholarship in the Age of Generative AI
Generative AI can increasingly summarize literature, identify relationships, formulate hypotheses, critique manuscripts, and produce competent scholarly prose. What, then, remains distinctively scholarly?
Topics
· AI-assisted research
· The changing role of literature reviews
· AI and theory development
· Identifying novelty
· Research judgment
· Reviewing research
· Scholarly creativity
· Responsible AI use in doctoral research
· What makes research interesting rather than merely correct?
Research Laboratory — Human Reviewer versus Machine Reviewer
Participants critique a research abstract and consider what a scholar should ask of it. Every paper must survive four questions: What’s new? So what? Why should I believe you? What changes because we now know this?
Selected Readings
Dhillon, G. (2022). A bad review is as much of a labor to write as a good one: The four principles for reviewing research manuscripts. Journal of Information System Security. 18(3)
Alvesson, M., & Sandberg, J. (2011). Generating research questions through problematization. Academy of Management Review, 36(2), 247–271.
Sutton, R. I., & Staw, B. M. (1995). What theory is not. Administrative Science Quarterly, 40(3), 371–384.
2:30 – 2:45 | Coffee Break
2:45 – 3:35
Doctoral Research Clinic II — The Dissertation Defense Before the Dissertation
Each participant has three minutes to defend the intellectual architecture of their research. They must convince the group that something important is happening, we do not adequately understand it, existing explanations are insufficient, there is a credible way to investigate it, and knowing the answer would change something.
Topics
· Importance
· Novelty
· Theory
· Evidence
· Contribution
Peer Challenge
Questions focus only on the five dimensions above. Participants then revise the Research DNA Canvas developed on Day 1.
3:35 – 4:00
Closing Laboratory — The Tampere 20: Cybersecurity & AI Research Questions for 2026–2036
The seminar returns to the Wall of Puzzles created at the beginning of Day 1. Participants reconsider the original questions: some are discarded, some rewritten, and new questions added. The group identifies a preliminary set of twenty research questions for the next decade.
Topics
· AI agency and accountability
· Synthetic identity
· Human-AI trust
· Autonomous cybersecurity
· Digital sovereignty
· Privacy in agentic environments
· Cybercrime ecosystems
· Organizational resilience
· Security and human values
· Responsible innovation
Final Question
What do you see now that you didn’t see yesterday?
Essential readings
Baskerville, R. (1993). Information systems security design methods: implications for information systems development. ACM Computing Surveys, 25(4), 375-414.
Dhillon, G., & Backhouse, J. (2001). Current directions in IS security research: towards socio‐organizational perspectives. Information Systems Journal, 11(2), 127-153.
Siponen, M. T. (2005). An analysis of the traditional IS security approaches: implications for research and practice. European Journal of Information Systems, 14(3), 303-315.
Moody, G. D., Siponen, M., & Pahnila, S. (2018). Toward a unified model of information security policy compliance1. MIS Quarterly, 42(1), 285-311.
Dhillon, G., Smith, K., & Dissanayaka, I. (2021). Information systems security research agenda: Exploring the gap between research and practice. The Journal of Strategic Information Systems, 30(4), 101693.
Credit points
Doctoral students participating in the seminar can obtain 2 credit points. This requires active participating and completing assignments.
Registration fee
This seminar is free-of-charge for Inforte.fi member organization's staff and their PhD students. For others the participation fee is 400 €. The participation fee includes access to the event and the event materials. Lunch and dinner are not included.





