Prof. Dr. Nico Ebert
Prof. Dr. Nico Ebert
ZHAW
School of Management and Law
Institute of Information Systems
Theaterstrasse 17
8400 Winterthur
Work at ZHAW
Position
- Professor of Information Systems, Head of Human-Centered Cybersecurity Group
- Head of CAS Cyber Risk Awareness
- Head of CAS Business Analysis & Methods
Focus
Teaching
Experience
- IT-Consultant
McKinsey, Namics and others.
01 / 2010 - 07 / 2016 - Founder / Managing Director
LearningCulture GmbH
01 / 2013 - 12 / 2014
Education and Continuing education
Education
- Research semester (SNSF) / Information Systems
Tsinghua University, Beijing
08 / 2009 - 12 / 2009 - PhD / Information Systems
University of St.Gallen
08 / 2005 - 07 / 2009 - Master of Science / Information Systems
University of Paderborn
10 / 2000 - 07 / 2005
Network
Membership of networks
- DSI (Digital Society Initiative)
- Association for Computing Machinery (ACM)
- Cyber Resilience Network for the Canton of Zurich
- DIZH Fellows
- Cybersecurity @ ZHAW
ORCID digital identifier
Awards
CHI 2020 Honourable Mentions
ACM
11 / 2020
Social media
Media presence
- SRF Rundschau - Tracking with Location Data
- SRF Podcast - Die Cookie-Falle
- SRF News - TikTok & Data Privacy
Projects
- Cyber Resilience Network For The Canton Of Zurich / Co-project leader / ongoing
- The effect of fear appeals on online privacy protection behavior / Project leader / ongoing
- Cybersecurity Awareness-Measurement @ ZHAW / Team member / completed
- TikTok privacy behaviour of Swiss young people / Project leader / completed
- Confidential Data Analytics based on Trusted Execution Environments / Project leader / completed
- Usable Privacy: Contextual privacy notices for app users / Project leader / completed
- Privacy-preserving confidential computing with trusted execution environments / Project leader / completed
- Acceptance of an app for contact-tracing of SARS-CoV-2 in the Swiss population / Project leader / completed
- User-Centric Privacy Policy: A GDPR-Compliant Policy Which Users Understand / Project leader / completed
- Component-based Tendering / Team member / completed
Publications
Articles in scientific journal, peer-reviewed
- Ebert, N., Fischer-Hübner, S., Human, S., Kitkowska, A., Kollnig, K., Mitrović, J., Pan, S., Schaltegger, T., Schaub, F., Smullen, D., & Xian, L. (2026). From procedures to peril : towards risk transparency in information privacy for users. Telecommunications Policy, 50(5), 103195. https://doi.org/10.1016/j.telpol.2026.103195
- Geppert, T., Dudas, T., Frei, P., Knieps, M., Ambuehl, B., Schaltegger, T., Rennhard, M., & Ebert, N. (2026). CYRENZH Cybersecurity Clinic : Konzept und Erkenntnisse. HMD Praxis der Wirtschaftsinformatik. https://doi.org/10.1365/s40702-026-01250-7
- Ebert, N., Schaltegger, T., Ambuehl, B., Geppert, T., Trammell, A., Knieps, M., & Zimmermann, V. (2025). Learning from safety science : designing incident reporting systems in cybersecurity. Journal of Cybersecurity, 11(1), tyaf019. https://doi.org/10.1093/cybsec/tyaf019
- Schaltegger, T., Ambuehl, B., Bosshart, N., Bearth, A., & Ebert, N. (2025). Human behavior in cybersecurity : an opportunity for risk research. Journal of Risk Research, 28(8), 843–854. https://doi.org/10.1080/13669877.2025.2539109
- Zimmermann, V., Schöni, L., Schaltegger, T., Ambuehl, B., Knieps, M., & Ebert, N. (2024). Human-centered cybersecurity revisited : from enemies to partners. Communications of the ACM, 67(11), 72–81. https://doi.org/10.1145/3665665
- Ebert, N., Schaltegger, T., Ambühl, B., Schöni, L., Zimmermann, V., & Knieps, M. (2023). Learning from safety science : a way forward for studying cybersecurity incidents in organizations. Computers & Security, 134(103435). https://doi.org/10.1016/j.cose.2023.103435
- Geppert, T., Deml, S., Sturzenegger, D., & Ebert, N. (2022). Trusted execution environments : applications and organizational challenges. Frontiers in Computer Science, 4(930741). https://doi.org/10.3389/fcomp.2022.930741
- Ebert, N., Ackermann, K. A., & Bearth, A. (2022). When information security depends on font size : how the saliency of warnings affects protection behavior. Journal of Risk Research, 26(3), 233–255. https://doi.org/10.1080/13669877.2022.2142952
- Kägi, P., & Ebert, N. (2019). Die Rolle des Business-Analysten : Kompetenz- und Qualifikationsanforderungen aus Stellenanzeigen. Zeitschrift Führung + Organisation, 88(2), 76–82.
- Ebert, N., Schmid, M., & Böni, Y. (2019). Verbreitung von App-Tracking in der Schweiz. Digma: Zeitschrift für Datenrecht und Informationssicherheit, 2019(4), 222–223.
- Ebert, N., Zenklusen, P., Kaeser, B. F., & Brucker-Kley, E. (2018). Die Business-Analyse in deutschsprachigen Unternehmen. HMD Praxis der Wirtschaftsinformatik, 55(4), 866–882. https://doi.org/10.1365/s40702-018-0416-8
- Ebert, N., Weber, K., & Koruna, S. (2017). Integration platform as a service. Business & Information Systems Engineering, 59(5), 375–379. https://doi.org/10.1007/s12599-017-0486-0
- Ebert, N., & Schlatter, U. (2017). Cloud-basierte Integration. Informatik Spektrum, 40(3), 278–282. https://doi.org/10.1007/s00287-017-1035-4
- Christ, O., & Ebert, N. (2016). Predictive Analytics im Human Capital Management : Status Quo und Potentiale. HMD Praxis der Wirtschaftsinformatik, 53(3), 298–309. https://doi.org/10.1365/s40702-015-0193-6
- Ebert, N., & Weber, K. (2015). Cloud-basierte Plattformen zur Anwendungsintegration : Angebote und Praxisbeispiel. HMD Praxis der Wirtschaftsinformatik, 52(6), 931–944. https://doi.org/10.1365/s40702-015-0186-5
Book chapters, peer-reviewed
Keller, T., Brucker-Kley, E., & Ebert, N. (2020). The use of virtual reality at lower secondary schools. In P. Isaias, D. G. Sampson, & D. Ifenthaler (Eds.), Technology Supported Innovations in School Education (pp. 15–32). Springer. https://doi.org/10.1007/978-3-030-48194-0_2
Written conference contributions, peer-reviewed
- Schaltegger, T., Ambuehl, B., Geppert, T., & Ebert, N. (2025). Understanding the critical role of expert intuition in cyber incident response [Conference paper]. ICIS 2025 Proceedings, 5. https://aisel.aisnet.org/icis2025/cyb_security/cyb_security/5
- Fischer-Hübner, S., Chang, K.-W., Ebert, N., Kitkowska, A., & Pan, S. (2025). Usable and useful notice & consent [Conference paper]. In F. Schaub, C. Utz, S. Wilson, & L. Xian (Eds.), Dagstuhl Reports (Vol. 15, Issue 1, pp. 17–23). Schloss Dagstuhl – Leibniz-Zentrum für Informatik. https://doi.org/10.4230/DagRep.15.1.1
- Geppert, T., Fuoco, A. D., Leikert-Böhm, N., Deml, S., Sturzenegger, D., & Ebert, N. (2025). The data collaboration canvas : a visual framework for systematically identifying and evaluating organizational data collaboration opportunities [Conference paper]. In D. Beverungen, C. Lehrer, & M. Trier (Eds.), Solutions and Technologies for Responsible Digitalization (pp. 49–64). Springer. https://doi.org/10.1007/978-3-031-80122-8_4
- Geppert, T., Dudas, T., Zimmermann, S., Sutter, T., & Ebert, N. (2025). How to successfully implement phishing awareness training in organizations : a technology adoption perspective [Conference paper]. In T. X. Bui (Ed.), Proceedings of the 58th Hawaii International Conference on System Sciences (p. 6156). University of Hawaiʻi at Mānoa. https://doi.org/10.24251/hicss.2025.737
- Ebert, N., Geppert, T., Knieps, M., Zarouali, B., Schaltegger, T., Wiedemann, A., & Ambuehl, B. (2024, May 3). Reflective data sharing on TikTok : encouraging adolescents to engage with privacy settings. ECIS 2024 Proceedings. https://aisel.aisnet.org/ecis2024/track24_socialmedia/track24_socialmedia/5/
- Schaltegger, T., Ambuehl, B., Ackermann, K. A., & Ebert, N. (2024). Re-thinking decision-making in cybersecurity : leveraging cognitive heuristics in situations of uncertainty [Conference paper]. Proceedings of the 57th Hawaii International Conference on System Sciences, 4734–4743. https://doi.org/10.21256/zhaw-30548
- Ebert, N., Geppert, T., Strycharz, J., Knieps, M., Hönig, M., & Brucker-Kley, E. (2023). Creative beyond TikToks : investigating adolescents’ social privacy management on TikTok [Conference paper]. Proceedings on Privacy Enhancing Technologies Symposium, 2023(2), 221–235. https://doi.org/10.56553/popets-2023-0049
- Geppert, T., Dal Fuoco, A., Leikert-Boehm, N., Deml, S., Sturzenegger, D., & Ebert, N. (2023). The data collaboration canvas : a visual framework for systematically identifying and evaluating organizational data collaboration opportunities [Conference paper]. Wirtschaftsinformatik 2023 Proceedings, 103. https://aisel.aisnet.org/wi2023/1/
- Ebert, N., Scheppler, B., Ackermann, K. A., & Geppert, T. (2023). QButterfly : lightweight survey extension for online user interaction studies for non-tech-savvy researchers [Conference paper]. CHI ’23: Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems, 161. https://doi.org/10.1145/3544548.3580780
- Geppert, T., Anderegg, J., Frei, L., Moeller, S., Deml, S., Sturzenegger, D., & Ebert, N. (2022). Overcoming cloud concerns with trusted execution environments? : exploring the organizational perception of a novel security technology in regulated Swiss companies [Conference paper]. Proceedings of the 55th Hawaii International Conference on System Sciences, 6822–6829. https://doi.org/10.24251/HICSS.2022.824
- Ebert, N., Ackermann, K. A., & Scheppler, B. (2021). Bolder is better : raising user awareness through salient and concise privacy notices [Conference paper]. CHI ’21: Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems, 67. https://doi.org/10.1145/3411764.3445516
- Ebert, N., Ackermann, K. A., & Heinrich, P. (2020). Does context in privacy communication really matter? : a survey on consumer concerns and preferences [Conference paper]. CHI ’20: Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, 448. https://doi.org/10.1145/3313831.3376575
- Casutt, N., & Ebert, N. (2020). Data protection officers : figureheads of privacy or merely decoration? [Conference paper]. Proceedings of the 16th European Conference on Management Leadership and Governance, 39–48. https://doi.org/10.34190/ELG.20.021
- Keller, T., Glauser, P., Ebert, N., & Brucker-Kley, E. (2018). Virtual reality at secondary school : first results [Conference paper]. In D. G. Sampson, D. Ifenthaler, & P. Isaias (Eds.), Proceedings of the 15th International Conference on Cognition and Exploratory Learning in the Digital Age (CELDA 2018) (pp. 53–60). International Association for Development of the Information Society (IADIS).
- Ebert, N., & Weber, K. (2016). Integration platform as a service in der Praxis : eine Bestandsaufnahme [Conference paper]. In N. Volker, D. Stelzer, S. Strassburger, & D. Fischer (eds.), Multikonferenz Wirtschaftsinformatik (MKWI) 2016 : Band III (pp. 1675–1685). Universitätsverlag Ilmenau. https://www.db-thueringen.de/servlets/MCRFileNodeServlet/dbt_derivate_00033065/ilm1-2016100035.pdf
- Ebert, N., & Ruf, C. (2015). Documentation is dead : why requirements Engineering should further develop from formalization to effective collaboration. Fachgruppentreffen RE 2015, Windisch, 18. November 2015.
Other publications
- Nüesch Erismann, R., Ebert, N., & Geppert, T. (2023). Cyberangriffe und IT-Sicherheitsmassnahmen in der Schweizer Speditions- und Logistikindustrie : Standortbestimmung im Q1/2023. ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-2489
- Ebert, N., Dal Fuoco, A., & Geppert, T. (2021). Data collaboration canvas : facilitating data innovation between organizations. ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-2421
- Knuchel, C., & Ebert, N. (2020). DSGVO-konformes Löschen. Datenschutz und Datensicherheit, 44(2), 126–127. https://doi.org/10.1007/s11623-020-1235-y
- Ebert, N., & Widmer, M. (2020). Akzeptanz einer App zur Kontaktnachverfolgung von SARS-CoV-2 in der Schweizer Bevölkerung. ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-19987
- Ebert, N., & Widmer, M. (2018). Datenschutz in Schweizer Unternehmen 2018 : eine Studie des Instituts für Wirtschaftsinformatik und des Zentrums für Sozialrecht. ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-4001
- Ebert, N., Bärtschi, C. N., Kaeser, B. F., & Zenklusen, P. (2017). Business Analyse 2017 : eine empirische Untersuchung im deutschsprachigen Raum und Fallbeispiele aus Unternehmen (S. T. Näpflin & N. Ebert, eds.). ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-3460
- Ebert, N., Keller, T., Cuche, S., & Gasser, P. (2017). Integration Platform as a Service - Fallbeispiele aus der Praxis (N. Ebert & T. Keller, eds.). ZHAW Zürcher Hochschule für Angewandte Wissenschaften. https://doi.org/10.21256/zhaw-1360
- Uhl, A., & Ebert, N. (2016). Die Befreiung von der Arbeit und ihr Preis. Personalwirtschaft: Magazin für Human Resources, 2016(11), 12–14. https://www.wiso-net.de/document/PWI__442B8CA12B4E7C78AEB463CA4125AA61
- Ebert, N., & Weber, K. (2015). Sicherheit von Cloud-basierten Plattformen zur Anwendungsintegration : eine Bewertung aktueller Angebote. FHWS Science Journal, 3(2), 10–23. https://doi.org/10.21256/zhaw-4678
- Christ, O., & Ebert, N. (2015). Predictive Analytics im Human Capital Management : wie datengetriebene Unternehmen Personaldaten nutzen. IM+io - Magazin für Innovation, Organisation und Management, 2015(4), 62–67.
Publications before appointment at the ZHAW
- Ebert, N., Uebernickel, F., Hochstein, A., & Brenner, W. (2007). A service model for the development of management systems for IT-enabled services. In Proceedings of the 13th Americas Conference on Information Systems (AMCIS 2007).
- Brenner, W., Hochstein, A., Übernickel, F., & Ebert, N. (2007). IT-Industrialisierung: Was ist das? Computerwoche, (15), 5.
- Hau, T., Ebert, N., Hochstein, A., & Brenner, W. (2008). Where to start with SOA: Criteria for selecting SOA projects. In Proceedings of the 41st Annual Hawaii International Conference on System Sciences (HICSS 2008).
- Ebert, N., Vogedes, A., Uebernickel, F., Brenner, W., & Heinz, M. (2008). Production planning for IT-service providers: An ERP-based concept. In Proceedings of the 19th Australasian Conference on Information Systems (ACIS 2008). Christchurch, New Zealand
- Ebert, N., Vogedes, A., Hau, T., Uebernickel, F., & Brenner, W. (2008). Potenziale der Produktionsplanung und steuerung bei IT-Dienstleistern. In Proceedings der 10. Paderborner Frühjahrstagung. Universität Paderborn.
- Ebert, N., & Vogedes, A. (2008). Dynamic Services for SAP Solutions der T Systems Enterprise Services GmbH. St. Gallen: Institut für Wirtschaftsinformatik, Universität St. Gallen.
- Ebert, N. (2009). Produktionsplanung und steuerung bei IT-Dienstleistern (Dissertation, Universität St. Gallen).
- Ebert, N., & Brenner, W. (2010). PPS im IT-Servicemanagement: Möglichkeiten und Grenzen für die Provisionierung standardisierter Services. HMD, 47(4), 103–111.
Research data
Ebert, Nico; Widmer, Michael, 2021. SARS-CoV-2 contact-tracing app survey Switzerland. OSF. Available from: https://doi.org/10.17605/OSF.IO/F8CUK