Research Profile
Cyber security researcher · software-engineering educator · Oslo
In cyber security, the non-technical professional is usually framed as the weak point. My work is on strengthening them.
That work centres on the human side of cyber security: how non-technical professionals learn to recognise risk, and why most awareness training doesn't shift behaviour in practice. My approach is game-based learning, treating game design as the method of teaching rather than as decoration around a lesson. I would like to take this further as doctoral research.
I hold a Master's in IT and seven peer-reviewed publications across cyber security awareness, game design, and computing education. I started as a backend developer and have spent more than a decade across industry and teaching since, which keeps the work practical rather than purely academic.
How awareness in the non-technical workplace feeds into the broader resilience of society.
Using game design as the method for teaching, not as decoration around a lesson.
Teaching non-specialists to recognise and act on risk, and shifting behaviour beyond one-off compliance training.
Pairing practical design with rigorous, iterative evaluation in real workplace settings.
I am taking this research further into a full PhD. I have an interested supervisor at a Russell Group university and am drafting a formal proposal aimed at two outcomes: a practical intervention that builds cyber security awareness among non-technical professionals, and a reusable framework for developing further awareness tools, both validated through iterative, real-world evaluation.
To ground the work in practice, I am looking for an industrial partner that can connect the research to real non-technical workplaces. That might be a single organisation strengthening its own people, or a consultancy, industry body, or service provider with reach across many. Either works well; broader reach simply helps the resulting framework travel further across varied settings.
Access to real non-technical workplaces to design in and test against, whether their own people or those reached through clients and networks, across iterative cycles.
An awareness intervention and a reusable framework to apply in their own workplace or take to their clients, delivered in English and Norwegian and backed by evidence of what genuinely shifts behaviour, not off-the-shelf compliance training.
Through Norway's Industrial PhD scheme, where the partner hosts the candidate and the Research Council co-funds the post. I am open to other cooperative arrangements too.
A four-year plan spanning Norwegian and UK workplaces. Proposal in draft now; conversations welcome at any stage.
If this could fit your organisation, I would welcome a conversation. Reach me by email or on LinkedIn.
The Balance Between Surveillance and Privacy: Adjusting to a Changing Threat LandscapePDF ↗
Offline-First Design for Fault Tolerant ApplicationsPDF ↗
Towards a Technical Skills Curriculum to Supplement Traditional Computer Science TeachingDOI ↗
Problem-Solving Ability of First Year CS Students: A Case Study and InterventionPDF ↗
Incorporating a Game Design Document into Game Development Project DeliverablesPDF ↗
Are you human? A framework to prevent automated web-form submissions
Fostering Content Relevant Information Security Awareness through Browser ExtensionsDOI ↗
Guidelines for the Use of the Indie Approach in Game Development Projects in the Context of a Capstone ExperienceWorldCat ↗