
Sign up to save your podcasts
Or


otes:
Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.
Her research focuses on understanding the human behind the keyboard through developmental history, motivation and lived experience.
Initial motivations among hackers often centre on curiosity, challenge seeking and belonging rather than financial gain.
Many participants reported early interest in technology, solitary online activity and experiences they described as destabilising events.
Melissa distinguishes between lawful and criminal pathways using indicators such as modifying games, low self-control and a history of property offending.
Her work highlights misunderstandings about intent, the role of gamification and the abstraction of harm when offending takes place online.
She argues that cybercrime is a societal problem requiring early education, parental and teacher capability building and partnerships with tech and gaming companies.
Diversion programs are essential to guide youth with technical interest toward prosocial cybersecurity roles rather than criminalisation.
About our guest:
Dr Melissa Martineau
https://www.linkedin.com/in/melissa-martineau-369bb5258/
https://www.captechu.edu/webinar-series-melissa-martineau
Papers or resources mentioned in this episode:
Martineau, M. (2023). The pathways of cyber dependent offenders. Journal of Cybercriminology, 3(3), 32.
https://www.mdpi.com/2673-6756/3/3/32
Martineau, M. (2024). Distinguishing lawful and criminal hacker trajectories. Journal of Cybercriminology, 4(4), 45.
https://www.mdpi.com/2673-6756/4/4/45
Other:
Dr Martineau wanted to share something called PRISMA (Preferred Reporting Items for Systematic reviews and Meta-Analyses) which is a helpful guideline designed to improve the reporting of systematic reviews. You can find out more about it here.
http://www.prisma-statement.org
Episode Notes:
Practical takeaway: Organizations should treat training (especially annually mandated modules) as only one part of a broader defence strategy, and design empirical measurement systems (including controls, realistic lures, and sustained engagement) before assuming large effect sizes.
About our Guest:
Dr Grant Ho Profile: https://cs.uchicago.edu/people/grant-ho/
Papers or resources mentioned in this episode:
Ho, G.; Mirian, A.; Luo, E.; Tong, K.; Lee, E.; Liu, L.; Longhurst, C.A.; Dameff, C.; Voelker, G.M. (2025). Understanding the Efficacy of Phishing Training in Practice: A Randomized Controlled Trial at a Large Health Organisation. Presented at the IEEE Symposium on Security & Privacy (May 2025). Full PDF: https://people.cs.uchicago.edu/~grantho/papers/oakland2025_phishing-training.pdf
Other:
I mentioned some figures about the spending on cybercsecurity education and training, You can find those here.
Canadian Survey of Cyber Security and Cybercrime (CSCSC)
https://www23.statcan.gc.ca/imdb/p2SV.pl?Function=getSurvey&SDDS=5244
Get convenient Excel Tables of the Statistics from 2017 and 2019.
https://www.serene-risc.ca/en/statistics-canada
Other Other:
Dr Ho was great to chat with and has a long history of researching phishing, Some of his older work that is more technical in nature, as so we didn't talk about in the episode, but in the case that it might be interesting to you, here are some links:
Ho, G., Sharma, A., Javed, M., Paxson, V., & Wagner, D. (2017). Detecting Credential Spearphishing Attacks in Enterprise Settings. In Proceedings of the 26th USENIX Security Symposium (USENIX Security ’17), Vancouver, BC, Canada, August 16-18, 2017. USENIX Association. ISBN 978-1-931971-40-9.
PDF: https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-ho.pdf USENIX+2USENIX+2
Presentation page: https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/hoUSENIX+1
Ho, G., Cidon, A., Gavish, L., Schweighauser, M., Paxson, V., Savage, S., Voelker, G. M., & Wagner, D. (2019). Detecting and Characterizing Lateral Phishing at Scale. In Proceedings of the 28th USENIX Security Symposium (USENIX Security ’19), Santa Clara, CA, USA, August 14-16, 2019. USENIX Association. ISBN 978-1-939133-06-9.
PDF: https://www.usenix.org/system/files/sec19-ho.pdf USENIX+1
Presentation page: https://www.usenix.org/conference/usenixsecurity19/presentation/ho USENIX
Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber.
Episode Notes
About our guest:
Dr. Deanna D. Caputo
MITRE Insider Threat Research & Solutions profile: https://insiderthreat.mitre.org/dr-caputo/
LinkedIn: https://www.linkedin.com/in/dr-deanna-d-caputo
Papers or resources mentioned in this episode:
Caputo, D. D. (2024). Employee risk recognition and reporting of malicious elicitations: Longitudinal improvement with new skills-based training. Frontiers in Psychology. https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2024.1410426/full
MITRE Insider Threat Research & Solutions. (2025). Suicide risk and insider-risk telemetry overview. https://insiderthreat.mitre.org/suicide-risk/
MITRE. (2024). Managing insider threats is a team sport. https://www.mitre.org/news-insights/impact-story/managing-insider-threats-team-sport
MITRE Insider Threat Research & Solutions. (2024). Capability overview two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-CapabilityTwoPager-24-0659_2024-02-01.pdf
MITRE Insider Threat Research & Solutions. (2024). Insider Threat Behavioural Risk Framework two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-InTFramework_TwoPager-24-0674_2024-03-18.pdf
Show Notes:
About our guest:
Danielle Stibbe
Papers or resources mentioned in this episode:
Other:
The open science framework https://osf.io
Dr. Francesco Carlo Campisi
PhD in Criminology, Université de Montréal
Researcher, International Centre for Comparative Criminology
🔗 https://www.cicc-iccc.org/fr/personnes/etudiants-supervises/carlo-campisi
🔗 https://www.linkedin.com/in/francesco-carlo-campisi-aa3576125/
Topics discussed in this episode:Other:
If you are curious about the video that was taken down, you should watch this video.
https://www.youtube.com/watch?v=PIyrzMThHq8
About our guest:
Dr. Iain Reid
Senior Lecturer in Cybercrime
University of Portsmouth
https://www.port.ac.uk/about-us/structure-and-governance/our-people/our-staff/iain-reid
Topics discussed in this episode:
Papers or resources mentioned:
Reid, I., Okeke-Ramos, A., & Serafin, M. (2024). Exploring the ethics of cyber deception technologies for defensive cyber deception. In P. Bednar, J. Kävrestad, E. Bergström, M. Rajanen, H. V. Hult, A. M. Braccini, A. S. Islind, & F. Zaghloul (Eds.), Proceedings of the 10th International Conference on Socio-Technical Perspectives in Information Systems (STPIS 2024) (pp. 140-148). (CEUR Workshop Proceedings). https://ceur-ws.org/Vol-3857
Whaley, B. (2007). Stratagem: deception and surprise in war. Artech.
Rowe, N.C., Rrushi, J. (2016). Measuring Deception. In: Introduction to Cyberdeception. Springer, Cham. https://doi.org/10.1007/978-3-319-41187-3_11
Ashenden, D., Ollis, G., & Reid, I. (2022, October). Dancing, not Wrestling: Moving from Compliance to Concordance for Secure Software Development. In Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering (pp. 1-9).
Paris Call for Trust and Security in Cyberspace
https://pariscall.international
Other
I would like to thank Dudley the French Bulldog for the invaluable (unavoidable) contribution to this episode.
Estelle Ruellan
Ruellan, E., Paquet-Clouston, M., & Garcia, S. (2024).Conti Inc.: understanding the internal discussions of a large ransomware-as-a-service operator with machine learning. Crime Science, 13, 16. https://doi.org/10.1186/s40163-024-00212-y
Flare Data Explorer – Explore cybercrime datasets visually:
https://flare.io/flare-data-explorer/
Other:Notes:
About our guests:
Dr. Sarah Elaine Eaton
https://profiles.ucalgary.ca/sarah-eaton
https://drsaraheaton.com/about/
Dr. Sabina Alam
https://www.taylorandfrancis.com/about/ethics-integrity/
https://www.csescienceeditor.org/article/dr-sabina-alam-shaping-critical-thinking-about-science/
Papers or resources mentioned in this episode:
United2Act initiative: https://united2act.org
Magazinov, Alexander. (2023). The Andrew Vickers Curse: secret revealed!, For Better Science
https://forbetterscience.com/2023/07/31/the-vickers-curse-secret-revealed/
Other:
Glossary of terms and acronyms:
A big thank you to the United2Act people for coming out of their comfort zone and chatting to me about this. This bravery is how science as an interdisciplinary pursuit driven by curiosity and collaboration happens.
Episode Notes:
About our guest:
Dr. Andrew Reeves
Papers or resources mentioned in this episode:
Reeves, A., Delfabbro, P., & Calic, D. (2021). Encouraging employee engagement with cybersecurity: How to tackle cyber fatigue. SAGE Open, 11(1).
https://doi.org/10.1177/21582440211000049
Reeves, A., Calic, D., & Delfabbro, P. (2023). Generic and unusable: Understanding employee perceptions of cybersecurity training and measuring advice fatigue. Computers & Security, 128, 103137.
https://doi.org/10.1016/j.cose.2023.103137
Reeves, A., & Ashenden, D. (2023). Understanding decision making in security operations centres: Building the case for cyber deception technology. Frontiers in Psychology, 14, 1165705.
https://doi.org/10.3389/fpsyg.2023.1165705
Other:
UNSW Institute for Cyber Security (IFCYBER)
https://www.unsw.edu.au/research/ifcyber
Dr. Susanne van ’t Hoff-de Goede
https://www.linkedin.com/in/susanne-van-t-hoff-de-goede/
https://www.thuas.com/research/centre-expertise/team-cyber-security
Resources and Research MentionedExamining Ransomware Payment Decision-making Among SMEs
Matthijsse, S. R., Moneva, A., van ’t Hoff-de Goede, M. S., & Leukfeldt, E. R.
European Journal of Criminology.
Explaining Cybercrime Victimization Using a Longitudinal Population-based Survey Experiment
van ’t Hoff-de Goede, M. S., van de Weijer, S., & Leukfeldt, R.
Journal of Crime and Justice, 47(4), 472-491 (2024).
How Safely Do We Behave Online? An Explanatory Study into the Cybersecurity Behaviors of Dutch Citizens
van der Kleij, R., van ’t Hoff-de Goede, S., van de Weijer, S., & Leukfeldt, R.
In: International Conference on Applied Human Factors and Ergonomics (2021), pp. 238-246.
The Online Behaviour and Victimization Study
van ’t Hoff-de Goede, M. S., Leukfeldt, E. R., van der Kleij, R., …
In:Cybercrime in Context: The human factor in victimization, offending, and … (2021).
OtherDutch Government Cybersecurity Resource
https://english.ncsc.nl
(English-language site for the Netherlands’ National Cyber Security Centre)
Secure Internetting (in Dutch)
https://veiliginternetten.nl/
From the publisher's feed