The research group SECUSO (Security • Usability • Society) belongs to the Institute of Applied Informatics and Formal Description Methods (AIFB) of the Karlsruhe Institute of Technology (KIT). The group was founded in 2011 by Prof. Dr. Melanie Volkamer at the TU Darmstadt. SECUSO moved to the Karlsruhe Institute of Technology at the beginning of 2018. SECUSO is a member of Kastel, K-CIST and KD²Lab.
In May 2025, SECUSO was part of the evaluation of the Helmholtz Topic Engineering Secure System (ESS). Part of the evaluation was also the research of the research group Human and Societal Factors under the leadership of SECUSO. This also includes the development of the NoPhish concept and various measures respectively their evaluation in studies. For the Helmholtz evaluation, a short video was also created in which Dr. Benjamin Berens briefly explains the concept and the research behind it. In addition, it is discussed what influence the measures currently have on society, e.g. over 30,000 views on the videos on Youtube or over 70 organizations that use or recommend the measures.
Watch the videoWe are delighted to have gained a total of 13 new reference users of our NoPhish materials in 2025. New organizations include the Ostbayerische Technische Hochschule Amberg-Weiden, DNetz, podcast “Informatik für die moderne Hausfrau”, Hochschule Anhalt, Informatikzentrale.de, Rheinland-Pfälzische Technische Universität Kaiserslautern-Landau, Lehrerfreund.de, Pädagogische Hochschule Schwäbisch Gmünd, Berufliche Schulen Landshut-Schönbrunn, Universität Ulm, TU Freiburg, Polizeipräsidium Nordhessen, Bauhaus Universität Weimar. The NoPhish awareness, education and training concept on the subject of phishing and other fraudulent messages has been implemented in various measures. The concept includes, for example, information cards, challenge posters and online games.
NoPhishThe German Federal Office for Information Security (BSI) has examined e-mail programs for their security. The focus was on investigations into transport and content encryption, SPAM and tracking protection, as well as protection against phishing. To this end, phishing scenarios identified by Maxime Veit, Oliver Wiese, Fabian Ballreich, Melanie Volkamer, Douglas Engels and Peter Mayer as part of a literature search were recreated (“SoK: The past decade of user deception in emails and today's email clients' susceptibility to phishing techniques”). The BSI press release and the report can be found here.
Read the paperThere is a new demonstrator in the SECUSO showroom. It shows how multi-factor authentication in VR (virtual reality) works using EEG (electroencephalography) and a graphical password. The demonstrator was originally presented by Matin Fallahi as part of the ESS evaluation in May 2025. It was developed as a collaboration between SECUSO and the Chair of Privacy and Security, headed by Prof. Dr. Thorsten Strufe.
More information about our showroom