Framing Cybersecurity and AI Research

Location

Tampere University, City Centre Campus, Kanslerinrinne/Kalevantie 33100 TAMPERE

Room information (seminar is in two buildings in the city centre campus)
31.8.26 Pinni B Building, room B 0040 from 10am to 5pm
1.9.26 Main building (Päätalo) room A065 A07 from 9am to 4pm


Registration

Registration is open until August 20, 2026.

 

Speakers

Main speaker Professor and Dean Gurpreet Dhillon, University of Nebraska Omaha (UNO), USA 
NN, to be confirmed

 

Organizer

Professor Mikko Ruohonen, Tampere University, Finland.


Overview

Information systems security has evolved from a narrow concern with technical safeguards into a broader organizational and socio-technical field. Early approaches relied on checklists, risk analysis, access controls, and mechanistic methods designed to protect systems and information assets. Although these methods remain important, they often treat security as an addition to systems design rather than as an integral design principle. This separation creates a persistent duality in which systems are developed for functionality and security is addressed later, producing tension between how information is used and how it is protected.

From an information systems perspective, security concerns the integrity of the technical, formal, and informal dimensions of a system. The technical dimension includes hardware, software, networks, data, and security technologies. The formal dimension encompasses organizational structures, policies, standards, roles, and regulatory requirements. The informal dimension includes values, behaviors, relationships, power, and organizational culture. Information systems security therefore extends beyond technical infrastructure to the protection of information handling across all three dimensions.

The field now includes policy compliance, privacy, trust, risk management, secure systems design, vulnerability management, access control, insider threats, data breaches, phishing, malware, cloud security, mobile technologies, the Internet of Things, and critical infrastructure protection. Yet academic research has not always aligned with practitioner concerns. Scholars have focused heavily on compliance, individual behavior, and privacy, while practitioners continue to emphasize attacks, breaches, malware, hacking, infrastructure vulnerabilities, and weaknesses in systems design. This divergence raises important questions about the practical relevance of information systems security research.

A central premise of the seminar is that security failures rarely arise from a single cause. They emerge through interactions among people, organizational structures, tasks, and technologies. A phishing attack may compromise an employee account, bypass an organizational rule, exploit a system vulnerability, and lead to malware installation or a data breach. Similarly, access-control failures may result from technical flaws, unclear responsibilities, excessive privileges, poor implementation, or changing work practices. Security incidents must therefore be understood at the intersections of social and technical systems.

This two-day seminar examines the historical development of information systems security research and its movement from technical and functionalist approaches toward socio-organizational and socio-technical perspectives. It considers secure systems design, risk, compliance, privacy, organizational behavior, vulnerability management, and security governance. Particular attention will be given to duality in systems development, the limitations of standardized security methods, and the role of context in shaping security behavior and organizational responses.

The seminar will also address contemporary developments such as machine learning, user and entity behavior analytics, identity analytics, and sentiment analysis. These tools create new possibilities for identifying attacks, vulnerabilities, insider threats, and abnormal behavior, but they also raise questions concerning accountability, transparency, privacy, and organizational judgment. The growing use of artificial intelligence makes these issues especially important as security decisions become distributed across human and computational actors.

The aim of the seminar is to organize the major traditions of information systems security research into a coherent framework. Students will examine the assumptions underlying different approaches, assess the relationship between research and practice, and consider how technical and social countermeasures can be integrated. Drawing on the instructor’s engagement with the field over the past 30 years, the seminar will also consider where important gaps remain and how future research can respond to changing technologies, organizations, vulnerabilities, and forms of work.

The seminar is designed primarily for doctoral students in information systems and related disciplines (software engineering, business and management etc.).

 

Credit points

Doctoral students participating in the seminar can obtain 2 credit points. This requires active participating and completing assignments.

Registration fee

This seminar is free-of-charge for Inforte.fi member organization's staff and their PhD students. For others the participation fee is 400 €. The participation fee includes access to the event and the event materials. Lunch and dinner are not included.