Top of Page
Skip main navigation

Levy CyLab

The research by our group focuses on addressing the following three key research areas and their interconnections: Cybersecurity Threat Mitigation, Social-Engineering/Human Factor in Cybersecurity, and User-Authentication.



Figure 1: Cybersecurity LandscapeCybersecurity threats and vulnerabilities are causing substantial financial losses for individuals, organizations, and government agencies all over the world. Such cybersecurity landscape can be classified under three major pillars: (a) technology/system, (b) human-computer, and (c) socio-political-organizational (See Figure 1). One of the weakest links in the cybersecurity chain has to do with the individuals who are using and protecting such systems. The focus of our Levy CyLab research group is to work on diverse projects related to the human-centric lens (also known as "Human Factor in Cybersecurity") of all three cybersecurity landscape pillars. In the technology/systems pillar, user-authentication has long been a challenge due to the overuse of passwords and the ease at which they can be guessed or cracked along with increased password entropy that impacts employee productivity. In the human-computer pillar, employees’ mistakes, human error, falling to social engineering and phishing attacks due to low cybersecurity awareness, knowledge, competencies, skills, and what is known by the 2002 Nobel Prize Laureate, Princeton University's Professor Daniel Kahneman as “System 1” thinking (or what we call “oh shoot syndrome”) represent the majority of cybersecurity threats to organizations. Moreover, non-IT employees have a low awareness of the magnitude of cybersecurity threats and their impact on organizations, government, and society. On the other hand, increasing complexity for computer systems due to demands for heightened security can cause frustration, resistance, and lower productivity. In the socio-political-organizational pillar, identity theft, social engineering, phishing, and insider threats are on the rise, which poses imminent threats to the reputation as well as the financial stability of individuals, organizations, governments, and societies. Our research focuses on all three cybersecurity pillars by (a) the development of novel approaches to improve user authentication including their role in reducing organizational cyber risk; (b) the development of innovative tools to measure cybersecurity skills and reduction of human errors related to cybersecurity; as well as (c) development of state-of-the-art tools to identify insider-threats, programs to help mitigation of social engineering, phishing attacks, and other cyber threats, along with the protection of privacy and corporate intellectual property, threat mitigation and cybersecurity risk management analysis. Over the last 16 years, the Levy CyLab research group has published over 52 papers in refereed publications, one patent application, four grants awarded (one internal grant awarded by NSU's Presidents' Research, four external DoD awarded since 2019), six external gifts, and over 30 doctoral students have completed their dissertation research in these areas of cybersecurity.

Current Research 

Our current work continues to focus on the human-centric lens (human factor) of all three cybersecurity pillars with increased emphasis on the development of state-of-the-art tools and prototype applications to assist in the measurement of cybersecurity skills, human errors, identify insider threats, cybersecurity hygiene, along with experimental studies to assist organizations with Business E-mail Compromise (BEC), social engineering and phishing, cyber threat mitigation, improve business continuity plans, resilience, and general cybersecurity risk management.

Cybersecurity Threat Mitigations and Prevention:

  • Supply chain cybersecurity
  • Assessment of cybersecurity skills, competencies, and awareness among employees/individuals 
  • Detecting identity theft and privacy threat vectors
  • Cyber risk management and resilience
  • Increasing collaboration with Federal Law Enforcement agencies on cyber incidents 

- Social Engineering/Human Factor in Cybersecurity:

  • Social engineering/human factor in cybersecurity (phishing, vishing, SMiShing) 
  • Cybersecurity hygiene
  • Cybersecurity human error reduction 
  • Detection and prevention of Business E-mail Compromise (BEC) 
  • Security, Education, Training, and Awareness (SETA) programs
  • Organizational and employee resilience to social engineering

- User Authentication:

  • User authentication (Via Web/mobile or physical at work/home) 
  • Resistance to biometric and multi-factor authentication 
  • Reduced employee productivity due to increased user authentication measures


For contributions to our efforts, please: 
Visit the Nova Southeastern University Gift and Donations page
1. Under "Gift Area" - select "College of Computing and Engineering"
2. Under "Gift Donation" - select "Other"
3. Please specify by typing - "For Levy CyLab"

Thank you for the generous contribution!



Principal Investigator (PI)

Dr. Yair Levy

Yair Levy, Ph.D., Professor of IS and Cybersecurity
College of Computing and Engineering 

levyy AT

Current Ph.D. Students and Projects:

Brian Bisceglia Brian Bisceglia, Ph.D. Candidate 
Dissertation title: "An Empirical Assessment on the Role of Persuasion Principles and Cybersecurity Skills Training on Senior Citizens' SMiShing Susceptibility"
bb1704 AT

Christopher P. Collins Christopher Collins, Ph.D. Student 
Dissertation title: "Development of a Phishing Risk Exposure Taxonomy on Mobile Devices in the Healthcare Industry"
cc2409 AT
John Del Vecchio John Del Vecchio, Ph.D. Candidate 
Dissertation title: "Development of Cybersecurity Footprint Index for Manufacturing Companies to Assess Organizational Cyber Posture" 
(NSA Funded)
jd2940 AT
Juan Madrid Juan Madrid, Ph.D. Candidate 
Dissertation title: "Development of the Password Alleviating Abstraction, Remembering and Strength (PALAbRas) Method"
jm2249 AT
Luke Nabozny Luke Nabozny, Ph.D. Student 
Dissertation title: "Identification and Quantification of the Cybersecurity Footprint in Defense Industrial Base Organizations"
ln604 AT
Dariusz Witko

Dariusz Witko, Ph.D. Student 
Dissertation title: "Empirical Assessment of Cybersecurity Competencies Through Human-Guided Generative Artificial Intelligence (GenAI)"
dw1272 AT


Past Interns/Undergraduate Students/Graduate and Projects:

emilyafrick.jpeg Emily Africk, Undergraduate Intern (2018-2021)
Project title: "An examination of historic data breach incidents: What cybersecurity big data visualization and analytics can tell us?"
Oriana Ricci Oriana Ricci, Graduate Assistant & Student - MS in Cybersecurity Management (2021-2023)
Project title: "CyberSecurity, Professional training, And Research in Computing (CyberSPARC) at NSU" (DoD Funded)

Alumni and Past Projects

AmyAntonucci Amy Antonucci, Ph.D. - Western Governors University
Dissertation title (2021): "Pause for a Cybersecurity Cause: Assessing the Influence of a Waiting Period on User Habituation in Mitigation of Phishing Attacks"
2016_aviv_pic_small.jpg Shahar (Sean) Aviv, Ph.D. - 
Dissertation title (2019): "An Examination of User Detection of Business Email Compromise Amongst Corporate Professionals"
2020_Backer_Pic_Small Patricia Baker, Ph.D. 
Dissertation title: "A Universal Cybersecurity Competency Framework for Organizational Users"
20150810_batie_pic_small.jpg Robert R. Batie, Ph.D. - Modern Technology Solutions, Inc. (MTSI)
Dissertation title (2016): "Assessing the Effectiveness of a Fingerprint Biometric and a Biometric Personal Identification Number (BIO-PIN) as a Multi-Factor Authentication Mechanism"
20150827_beaudin_pic_small.jpg Shauna Beaudin, Ph.D. - Southern New Hampshire University
Dissertation title (2017): "An empirical study of authentication methods to secure e-learning system activities against impersonation fraud"
2016_blackwoodbrown_pic_small.jpg Carlene Blackwood-Brown, Ph.D. - Seneca College of Applied Arts and Technology & Sheridan College
Dissertation title (2018): "An empirical assessment of senior citizens’ cybersecurity awareness, motivation to pursue training, and perceived risk of identity theft"
2016_blanke_pic_small.png Sandra J. Blanke, Ph.D. - Associate Professor, University of Dallas
Dissertation title (2008): "A study of the contributions of attitude, computer security policy awareness, and computer self-efficacy to the employees' computer abuse intention in business environments"
2016_brown_pic_small.png Shonda D. Brown, Ph.D. - CIGNA Healthcare 
Dissertation title (2015): "An information privacy examination of the practices of pharmaceutical companies regarding use of information collected through their Websites"
20150805_carlton_pic_small.jpg Melissa Carlton, Ph.D. - Associate Professor, Lindsey Wilson College
Dissertation title (2016): "Development of a cybersecurity skills index: A scenarios-based, hands-on measure of non-IT professionals’ cybersecurity skills"
No Headshot Picture MinSuk Choi, Ph.D.
Dissertation title (2013): "Assessing the role of user computer self-efficacy, cybersecurity countermeasures awareness, and cybersecurity skills toward computer misuse intention at government agencies"

Karla Clarke, Ph.D. - KPMG Cybersecurity Consulting - Middle Georgia State University 
Dissertation title (2018): "Novel alert visualization: The development of a visual analytics prototype for mitigation of malicious insiders cyber threat"

2016_clarke_pic_small.jpg Marlon Clarke, Ph.D. - Director of IT Security - MagicLeap
Dissertation title (2010): "The role of self-efficacy in computer security behavior: Developing the construct of computer security self-efficacy (CSSE)"
mollycooper.jpg Molly Cooper, Ph.D. - Associate Professor - Ferris State University 
Dissertation title (2021): "Assessment of Audio and Visual Warnings to Mitigate Risk of Phishing Attacks"
Javier Coto Javier Coto, Ph.D. (Posthumous Degree, RIP) - Miami-Dade College
Dissertation title (2022): "An Empirical Investigation of Static and Polymorphic Tactile Stimuli’s Effect on Habituation to Mitigate Malware Attack Vector" 
2017_cornejo_pic_small.jpg Gabriel Cornejo, Ph.D. - DoD 
Dissertation title (2021): "Human Errors in Data Breaches: An Exploratory Configurational Analysis"
No Headshot Picture Theon Danet, Ph.D. - SRA International
Dissertation title (2006): "A study of the impact of users' involvement, resistance, and computer self-efficacy on the success of a centralized identification system implementation"
20150831_davis_pic_small.jpg Keiona Davis, Ph.D. 
Dissertation title (2020): "The Role of Cybersecurity Responsibility in Small to Medium Enterprises (SMEs) on Risk of Point-of-Sale (POS) Data Breach"
darrelleilts.jpg Darrell Eilts, Ph.D. - Hancock Whitney and Loyola University New Orleans
Dissertation title (2020): "An Empirical Assessment of Cybersecurity Readiness and Resilience in Small Businesses"
2016_forman_pic_small.jpg Abbe E. Forman, Ph.D. - ECPI University
Dissertation title (2009): "An exploratory study on the factors associated with ethical intention of digital piracy"
Munther Ghazawneh Munther Ghazawneh, Ph.D. - Deloitte
Dissertation title (2024): "Assessing Organizational Investments in Cybersecurity and Financial Performance Before and After Data Breach Incidents of Cloud SaaS Platforms"
20150812_goode_pic_small.png Jodi Goode, Ph.D. - Howard Payne University - CIO
Dissertation title (2018): "Comparing training methodologies on employee’s cybersecurity awareness and skills in traditional and socio-technical programs" 
2016_hambly_pic_small.jpg Robert J. Hambly, Ph.D. - Defense Media Activity (DMA)
Dissertation title (2016): "An empirical investigation of the willingness of US intelligence community analysts to contribute knowledge to a Knowledge Management System (KMS) in a highly classified and sensitive environment"
2016_hernandez_pic_small.jpg Wilnelia Hernandez, Ph.D. - Independent Consultant, Puerto Rico
Dissertation title (2016): "An empirical assessment of employees cyberslacking in the public sector"
20150810_hueca_pic_small.jpg Angel Hueca, Ph.D. - CERT US and Northeastern University
Dissertation title (2018): "Development and validation of a proof-of-concept for malicious cybersecurity insider threats alerting system utilizing analytics-based visualization in real-time"
2016_hylton_pic_small.jpg Kenrie Hylton, Ph.D. - Northern Caribbean University
Dissertation title (2012): "An experiment using Webcam-based surveillance to deter information systems misuse"
No Headshot Picture Okay Igbonagwam, Ph.D. - Saint Leo University and Lockheed Martin
Dissertation title (2008): "The contribution of security clearance, users’ involvement, and computer self-efficacy in the efficiency of requirements-gathering process: An information-systems case study in the U.S. military"
2018_jigo_pic_small.jpg Emmanuel Jigo, Ph.D.
Dissertation title (2020): "Development of Criteria for Mobile Device Cybersecurity Threat Classification and Communication Standard using Labels, Pictogram, as well as Safety Data Sheets"
No Headshot Picture Gerald D. Johnson, Ph.D. 
Dissertation title (2012): "Development of an audit classification index (ACI) for federal e-learning systems security vulnerabilities"
Ariel Luna Ariel Luna, Ph.D. - Microsoft 
Dissertation title (2024): "Empirical Assessment of Remote Workers’ Cyberslacking and Computer Security Posture to Assess Organizational Cybersecurity Risks"
20150831_marnell_pic_small.jpg Joseph Marnell, Ph.D. - Wayland Baptist University
Dissertation title (2016): "An empirical investigation of factors effecting resistance to use multi-factor authentication systems in public-access environments"
2016_mattord_pic_small.jpg Herb J. Mattord, Ph.D. - Kennesaw State University
Dissertation title (2012): "Assessment of Web-based authentication methods in the U.S.: Comparing e-learning systems to Internet healthcare information systems"
20150810_mujeye_pic_small.png Stephen Mujeye, Ph.D. - Illinois State University
Dissertation title (2016): "An experimental study on the role of password strength and cognitive load on employee productivity"
2015_nilsen_pic_small.jpg Richard Nilsen, Ph.D. - DoD and Middle Georgia State University 
Dissertation title (2017): "Measuring cybersecurity competency: An exploratory investigation of the cybersecurity knowledge, skills, and abilities necessary for organizational network access privileges"
2016_perez_pic_small.jpg Guillermo (Will) Perez, Ph.D. - Royal Caribbean Cruises 
Dissertation title (2019): "Cyber situational awareness and cyber curiosity taxonomy for understanding susceptibility of social engineering attacks in the maritime industry"
Tommy Pollock Tommy Pollock, Ph.D. - National Defense University (NDU)
Dissertation title (2022): "Experimental Study to Assess the Role of Environment and Device Type on the Success of Social Engineering Attacks: The Case of Judgment Errors"
MichaelRooney Michael Rooney, Ph.D. - DoD 
Dissertation title (2023): "An empirical assessment of the use of password workarounds and the cybersecurity risk of data breaches"
Chris Scott Jackie (Chris) Scott, Ph.D. -  AirSculpt Technologies
Dissertation title (2023): "Comparing social engineering prevention methods and their tole on successful malicious emails in corporations"
2016_smiley_pic_small.jpg Garrett Smiley, Ph.D. - Serco and Northcentral University
Dissertation title (2013): "Investigating the role of multibiometric authentication on professional certification e-examination"
2016_stalker_pic_small.png Joshua D. Stalker, Ph.D. - ASRC Federal 
Dissertation title (2012): "A reading preference and risk taxonomy for printed proprietary information compromise in the aerospace and defense industry"
2016_wells_pic_small.jpg Raymond Wells, Ph.D. - The College of The Bahamas and Bahamas National Insurance Board
Dissertation title (2012): "An empirical assessment of factors contributing to individuals’ propensity to commit software piracy in The Bahamas"
2016_wilkerson_pic_small.jpg William Shawn Wilkerson, Ph.D.  
Dissertation title (2021): "Development of a Social Engineering Exposure Index using Open Source Personal Information"


Updated: April 29, 2024

Return to top of page