ARC@ORU: When Information Security Policies Don’t Work: Are We Using the Right (or Wrong) words?

05 maj 2026 10:15 – 11:30 Visual Lab, ARC

ARC@ORU.

En paneldiskussion om kvaliteten på informationssäkerhetsriktlinjer som organisationer använder för att vägleda sina anställda i hur de ska agera säkert när de använder informationstillgångar. Paneldeltagarna kommer att diskutera frågor som hur tillgängliga riktlinjerna är för anställda, hur man mäter deras kvalitet och vilka konsekvenser dålig kvalitet har.

ARC@ORU Research Seminar Series

When Information Security Policies Don’t Work: Are We Using the Right (or Wrong) words?

 

Panel Discussion

During this panel, the panelists will discuss the quality of information security policies that organisations use to guide their employees on how to act securely when using information assets. The panellists will discuss issues such as how accessible the guidelines are to employees, how to measure their quality, and what the consequences of poor quality are.

Panelists

Mattias Sjödin, Chief Information Security Officer, Kommuninvest i Sverige AB

Sara Rungård, Information Security Management Consultant, XEEDA AB

Alexander Wedlund, Chief Information Security Officer, Statistics Sweden (SCB)

Fredrik Karlsson, Professor in Informatics, Örebro University

Moderator

Shang Gao, Associate Professor in Informatics, Örebro University


For remote participation

Use this Zoom Link

Registration for ARC@ORU: When Information Security Policies Don’t Work

I am participating:

GDPR

By submitting, I consent to Örebro University processing the personal data I have entered in the registration form, for the purpose of event administration and for as long as the event is being administered. You may request that any data provided be changed or deleted by contacting carolina.wittenfelt@oru.se.

More information on how Örebro University handles personal data can be found on the Processing of personal data page at Örebro University.

I understand and give my consent to Örebro University processing my personal data in line with the purpose of the event and in accordance with the data protection legislation in force.