
Abstract Studies exploring cybersecurity risks on social media platforms (also known as online social networking sites—SNSs) often overlook those associated with parental disclosures of chid-centric information. Now increasingly described as ‘sharenting’, this practice involves sharing children’s sensitive details. Drawing on interviews with 30 parents based in the UK and inspired by a sociotechnical framework, this paper explores parental cyber awareness. The article examines their knowledge of how properties of SNSs can bypass their cybersecurity measures and foment security vulnerabilities. The features in question form part of the digital architecture driving the sites’ functionality. Beyond technological mediation, the properties invite and encourage both user engagement and content creation. Some are visible such as ‘tag’ and ‘share’ features operationalized by embedded technologies. Others are less visible content filtering and distribution algorithms. Findings revealed limited parental understanding of the risks posed by these properties. Privacy policies published by SNSs should provide relevant information but were deemed inaccessible. The paper situates these findings within systemic dynamics. It demonstrates how corporate priorities could be fuelling intersections of policy opacity and deficits in parental cyber awareness. Cybersecurity implications are discussed. In its conclusion, the paper proffers a sociotechnical approach to enhancing cyber awareness on SNSs. Insights from this work can inform cybersecurity policy, practice, and future research.
The revolutionary opportunities presented by eXtended Reality (XR) technologies will only materialize if modeling and analysis activities, undertaken during the engineering process of XR systems, are directed towards ensuring their social acceptance. By this, we mean integrating human and technical aspects during system development to ensure that the system guarantees communication security and data privacy, and is trusted by end users. One approach to achieve these guarantees is through rigorous, formal specification and verification during system modeling and analysis, explicitly considering the human factor. Accordingly, in this survey, we systematically investigate 6 mainstream formalisms for modeling and analyzing socio-technical security concerns, encompassing privacy and trust, in XR systems. We consider both desired concerns (e.g., requirements, properties) and undesired ones (e.g., threats, attacks). Our investigation incorporates 34 state-of-the-art approaches comprising languages, techniques, frameworks, and tools, leveraging these formalisms, which we compare against a diverse set of criteria: (1) expressivity, (2) modeling and analysis complexity, (3) modeling and analysis constructs, (4) power of inference, (5) user-friendliness, (6) applicability. Based on our findings, we identify the current gaps and considerable challenges and suggest an agenda for future research. To guide our investigation from a more practical perspective, we also present two real-world pilot studies that illustrate the potential application of formal methods in specific XR applications. This work thus aims to provide insights from a twofold perspective: for formal methods researchers seeking to learn more about socio-technical security in XR systems, and for security practitioners focused on socio-technical aspects in XR who are interested in formal approaches.
Social engineering (SE) attacks are among the most prevalent and persistent threats to organizations, carrying severe financial and legal consequences. Despite their severity and frequency, academic discourse addressing countermeasures that organizations can apply to minimize their occurrence remains fragmented, often relying on disparate conceptualizations that limit their practical uptake. In addition, widely recognized cybersecurity frameworks, such as NIST or ISO/IEC ones, broadly address diverse types of cyber threats, which may result in underrepresented specific SE countermeasures or limited consideration of the temporal dynamics of an SE attack. Therefore, our study aims to harmonize SE countermeasures identified in academic research by utilizing temporality as an analytical lens. Drawing on a systematic literature review, we first synthesize and categorize dispersed conceptualizations of SE countermeasures into six overarching either primary or cross-cutting themes, supported by knowledge-based tools. Second, we organize these harmonized SE countermeasures within a temporal framework that represents the lifecycle of SE attacks, emphasizing that distinct SE countermeasures serve different aims, such as anticipation, coping, or reflection, over time. Through this research, we contribute to scholarly discourse by demonstrating that temporality offers a unifying structure for reconciling fragmented SE countermeasure concepts and extends defense-in-depth thinking beyond static protection to a more dynamic, lifecycle-based perspective.
Online gaming platforms such as Fortnite, Roblox, and Minecraft have become central to children's digital lives. Concerns over child safety have intensified as these environments are increasingly exploited by offenders to facilitate grooming, exploitation, and other forms of child abuse. Preventing and responding to such harms is complicated by platform affordances such as anonymity, cross-border communication, and limited oversight. In response, gaming companies have introduced internal safety policies and tools aimed at reducing risk. Yet, systematic research examining how these measures operate and align with established prevention frameworks remains limited. This study applies a situational crime prevention (SCP) lens to analyse and compare the safety policies and mechanisms across Fortnite, Roblox, and Minecraft. Through a document analysis of platform guidelines and policies, we identify and categorize key safety features, examining how they map onto SCP techniques such as increasing effort, raising risk, reducing rewards, and removing excuses. The findings reveal both convergence and divergence in how platforms operationalize child protection online, where console-level controls and features supplement in-game measures. However, the analysis also indicates significant gaps where safeguards are unevenly applied or rely heavily on user or parental engagement rather than proactive, system-level design. This study demonstrates the utility of SCP as an analytical tool for auditing online safety interventions. We conclude that while platforms implicitly use SCP principles, a more intentional and proactive integration of this crime science framework is recommended for developing consistent and evidence-based safety architectures as gaming evolves towards immersive and metaverse-ready spaces.
In March of 2022, Network Battalion-65 (NB65), a hacktivist group affiliated with Anonymous, claimed responsibility for breaching a ROSCOSMOS ground segment in retaliation for Russia's invasion of Ukraine. NB65 released several primary sources to support its claims, alleging it had disabled ROSCOSMOS's vehicle monitoring system and exposed sensitive proprietary documents. Despite the significant implications of hacktivist activity in the space sector, the incident has received limited attention, partly due to the technical obscurity of the exploits and ROSCOSMOS's denial of the allegations. This paper analyzes the primary sources released by NB65 to present the likely kill chain that enabled the claimed intrusion of a ROSCOSMOS ground segment. The analysis is further supported with experimental reconstruction of the attack. Building on previously published findings, it proposes a space policy directive for securing space systems from cyberattacks, informed by the results of this analysis, with the aim of enhancing international technical standards for space system cybersecurity.
The maritime domain has relied on advanced technology that has been developing progressively, which increases the risk associated with new challenging threats regarding cybersecurity. Many researchers and technical reports mainly focus on the technical measures to prevent cyber-attacks; however, the human factor is still the crucial reason for cyber-attacks, similar to maritime accidents. This study aims to quantitatively assess human factors' role in cybersecurity by evaluating the seafarers' perception of cybersecurity risks and best practices in the maritime domain. The structured questionnaire was designed to measure the seafarers' cybersecurity awareness, perceptions, and knowledge, as well as their understanding of cybersecurity rules and protocols and their ability to identify and respond to potential cyber-attacks. The collected data was analysed using statistical methods to identify the relation between human factors and cybersecurity domain. The finding reveals that an organization's cybersecurity policies and guidelines influence an individual's security-related behaviours. Additionally, cybersecurity perception, knowledge, awareness, and behaviour of seafarers are positively associated. The study's results would have significant implications for maritime organizations, shipping companies, and training and education centres, which would be needed to develop effective policies, strategies, and tailored training programmes to address the specific needs of seafarers.
As cyber threats grow in complexity and impact, the limitations of traditional cybersecurity frameworks-focused primarily on prevention and control-have become increasingly evident. This paper introduces the Cyber Resilience Cube, a novel multidimensional framework that enables more comprehensive planning, assessment, and governance of cyber resilience as a holistic, organizational function. Drawing on interdisciplinary theory and extensive analysis of over 30 federal and international policy documents, the Cube organizes resilience capabilities across three axes: time (Plan, Absorb, Recover, and Adapt), system scale (Component to Ecosystem), and domain (Technical, Organizational, Human, and Institutional). The paper demonstrates how this structure exposes blind spots in current policy, highlights underdeveloped capabilities such as adaptation and cross-sector coordination, and offers a diagnostic tool for aligning investments, planning documents, and oversight mechanisms. Applications include recent incident analysis and alignment with global frameworks (e.g. NIST CSF 2.0 and ISO 27001). The Cube enables a shift from compliance-driven security to mission-driven resilience-advancing both conceptual clarity and operational utility in the evolving landscape of cyber risk.
A frequently asked question about government-funded research and development (R&D) projects is: What is the return on investment (ROI)? We initially addressed this question by conducting a benefit-cost-risk analysis (BCRA) and adapting it to 25 R&D projects funded by the Science and Technology Directorate (S&T) of the United States Department of Homeland Security (DHS). The net benefits and the associated benefit-to-cost ratios were mostly high for transitioned and used projects. Still, substantial uncertainty remained about the benefits of projects in transition that had not yet been implemented or put to use. Conducting BCRAs on cybersecurity R&D poses additional problems. First, many cybersecurity R&D projects are at a low technology readiness level (TRL). Second, the benefits of cybersecurity are the avoided risks and damages, which are very uncertain. Our objective is to provide a proof-of-concept demonstration of a novel BCRA methodology that accounts for uncertainties in the cybersecurity R&D domain. The innovative methodology described in this paper consists of conducting a BCRA, assuming that the cybersecurity R&D projects will be successfully transitioned and implemented, then discounting the net benefits by the probability of success. Both BCRAs employed a methodology that includes a decomposition of the projects' costs and benefits, characterization of uncertainty through subject-matter expert (SME) assessments, and Monte Carlo simulation via an Excel Add-In to account for uncertainty. We applied this methodology to two cybersecurity projects funded by the DHS. The primary benefit of the first project was automating malware detection, thereby saving time and labor costs. The benefits of the second project were to enhance early detection and removal of malware, thereby reducing the risks and costs of cyberattacks. The BCRA methodology provided estimates of the mean net benefit over 5 years and the benefit-cost ratio for each cybersecurity project. More importantly, the innovative BCRA methodology using Monte Carlo simulation yielded a distribution of net benefits for each project over its expected lifespan, as well as break-even analyses for both projects to achieve positive net benefits.
Cybersecurity and cyber defense have introduced a range of transformations in civil-military relations that remain underexplored as a distinct analytical domain. Existing scholarship often treats these dynamics in isolation, obscuring how they collectively reconfigure civil-military relations through interdependent and mutually reinforcing processes rather than as a series of discrete developments. This article addresses this gap through a three-step approach: first, it examines central debates in civil-military relations; second, it analyzes how cyber engages with its core analytical categories; and third, it synthesizes these insights to conceptualize cyber as a transformative force. In doing so, it shows how key dimensions-civilian control, nonstate actors, military-society relations, organizational dynamics, and processes of politicization and militarization-are reconfigured in tandem. This simultaneity reveals both the contours of cyber militarization and the persistence of civilian control, even as the military expands its operational footprint. Overall, these dynamics expose the limits of existing frameworks, which struggle to capture such distributed and interdependent effects.
One of the pressing issues in the regulation of digital communications services is how to ensure effective cryptographic protection of user communications. This issue is analysed in relation to the so-called "right to encryption" and the risks associated with using encrypted messengers to disseminate illegal content, including CSAM and extremist content. The response to this threat is various countries' adoption of a new category of regulations, which deliberately weaken certain traffic encryption techniques in order to enable service providers or public authorities to monitor the content of messages. This problem relates to end-to-end encryption (E2EE) in particular, which is widely used in leading communication services. The aim of this article is to discuss a ratio legis and present possible regulatory strategies for weakening E2EE that could be considered by EU legislature. Although the draft EU CSAM Regulation will serve as the backdrop for these considerations, the issue of regulating E2EE will be examined from multiple angles-starting with an explanation of its technical aspects, moving on to the reasons for the proposed regulation of its use, and ending with an analysis of the regulations that have been proposed or implemented in selected countries (Russia, the USA, and the UK). This paper outlines a proposal for the implementation of a horizontal EU act on the security of encrypted communications, applicable not only to one specific sector, but also affecting the entire EU digital market. It further argues that EU regulatory policy should be based on a hybrid regulatory approach, integrating normative obligations with technical design choices to adequately protect user transmissions without hindering the fight against serious crime.
As digital technologies become increasingly embedded in societal infrastructure, IT security and privacy (S&P) have become critical for protecting sensitive information and preserving trust. These domains have evolved from foundational security measures to address complex challenges introduced by artificial intelligence, regulatory frameworks, and decentralized technologies. This paper presents a longitudinal analysis of the evolution of IT S&P research from 1980 to 2023, analyzing over 13k papers from the most relevant venues. Employing the frameworks of established theories from social sciences, i.e. Latour's actor-network theory, and Bourdieu's forms of capital, along with Leydesdorff's key dimensions in scientometrics, we discuss the evolution of research topics and highlight research priorities in the past and today. We apply modern natural language processing techniques to build a taxonomy of research topics within the S&P community. Using this taxonomy, we analyze the community's thematic development, tracing its growth from 5 topics in the 1980s to 100 distinct research topics, reflecting the field's expanding scope and complexity. Analyzing 0.5M authors, we demonstrate strong collaboration networks in the IT S&P community. We also demonstrate that the proportion of female authors in this community has remained relatively constant over the decades, despite an increase in their research activity in recent years. Finally, we assess factors impacting paper citations, author networks, and the linguistic evolution of the community. This study enhances the understanding of the S&P research community, providing valuable insights into future directions. The data underlying this article, including the analysis code and data processing pipeline, are available in the repository at: https://pulse-of-cybersecurity.com/, which also provides an interactive webpage for exploring our results.
The paper explores the role and legal protection of vulnerability reporters, namely cybersecurity researchers within the evolving EU cybersecurity framework. It examines who these researchers are, the value of their work, and the growing legal risks they face across Europe, as demonstrated by high-profile cases in the Netherlands, Malta, and Germany. Drawing on international human rights frameworks including EU Charter of Fundamental Rights, the paper argues that security research should be protected under the right to science and the freedom to conduct research. The paper advocates for defining 'good-faith security research' as a legally recognized safe harbour in EU law. A comparative analysis of selected international and EU legal frameworks, such as the UN Convention Against Cybercrime, Budapest Convention, EU Directive on attacks against information systems, the Cybersecurity Act, the NIS2 Directive, the Cyber Resilience Act, and national policies of a selected group of EU Member States, including the Netherlands, Belgium, France, Germany, Italy, Spain, Poland, Czechia, Slovakia, Malta along with the UK and the USA, reveals fragmented and insufficient protection. To address this, the paper calls for a coherent EU-wide framework based on two interlinked pillars: (i) mandatory coordinated vulnerability disclosure (CVD) procedures, and (ii) substantive legal exemptions for ethical security research. While the recent NIS2 Commission Implementing Regulation (EU) 2024/2690 for entities from digital infrastructure is a step forward, it lacks explicit protection for researchers. Therefore, the paper concludes with a call for integrating legal and technical safe harbours into EU cybersecurity legislation to ensure that vulnerability disclosure policies are not only adopted by entities but are also legally accessible and safe for the researchers, who rely on them.
"Pig butchering" represents a sophisticated form of cyber-enabled social engineering that combines elements of romance and investment scams. Although existing literature focuses on victims' experiences, there is a lack of understanding regarding how scammers are trained to implement these strategies. To this end, we analysed a unique data source, scam manuals (i.e. documents guiding scam operations), to uncover the psychological and communication theories that inform their use. Our findings reveal that scammers systematically exploit interpersonal communication, relationship, and motivational tactics to gain victims' trust and commitment, and to manipulate their self-growth needs. We propose a unified stage model that maps and links psychological and communication theories across the scam stages. We discuss how our model contributes to the broader cybersecurity literature by informing the design of more targeted prevention and intervention strategies that address the human vulnerabilities exploited in advanced cyber-enabled crime.
Estonia, recognized for its robust e-services and cybersecurity, currently lacks a dedicated cybersecurity support service for laypeople to address private cybersecurity issues. Instead, citizens rely primarily on friends and family for assistance. This study explores the cybersecurity support needs of Estonian home users, analyzing the concept of "cybersecurity caregiving," where individuals offer voluntary, informal cybersecurity help. Using a mixed-methods approach, the study conducted seven interviews and surveyed 161 participants, broadly reflecting Estonia's demographic makeup. Key findings indicate that users seek support primarily in cyber incident handling and situational awareness, with desired support characterized by accuracy, speed, accessibility, understandability, and cost-free availability. However, informal support often lacks accuracy and promptness, highlighting a gap that a professional support service could address. Additional findings reveal demographic-based risk patterns, where younger users, high-frequency internet users, and men report higher anticipation of poor advice, while women report dependency on cybersecurity caregivers. The study underscores the need for (1) education on personal cybersecurity priorities and self-reliance in cybersecurity; (2) empowering cybersecurity caregivers with resources; and (3) establishing a professional cybersecurity support services. It makes recommendations to bolster Estonia's cyber resilience and proposes potential future research to address gaps for non-Estonian speakers and minors.
China's Great Firewall originally focused on restricting domestic access to resources on the global web. Today, however, efforts in China and beyond concentrate on restricting global access to information on the domestic internet. This article conceptualizes an emerging "Reverse Great Firewall": a set of practices through which Chinese government organs restrict foreign access to domestically hosted information. Geo-blocking is core in this development. It argues that geo-blocking emerges from decentralized responses to top-down cybersecurity pressures, shaped by cadre evaluation systems and local discretion. These cybersecurity concerns in China's context do not just target traditional risks like DDoS-attacks but especially foreign data aggregation, open-source intelligence, and politically sensitive information. Using HTTP/1.1 requests from residential proxies in 14 countries across the world, this study tests the availability of all 13 508 official government websites from China. The results show that >50% of government websites are inaccessible from abroad, with roughly 10% of websites exhibiting explicit and indiscriminate geo-blocking, primarily through either server-side or DNS blocking. The remaining 40% largely reflect network bottlenecks and fragmented infrastructure rather than coordinated policy. Bureaucratically, geo-blocking patterns resemble the fragmented nature of government websites in China, being concentrated in small batches of province and prefecture-level jurisdictions. While the Reverse Great Firewall remains uneven and opaque, it signals a shift in how states may leverage cybersecurity logics to reshape the digital information ecosystem.
AI-assisted technology is used to create synthetic voices that are highly naturalistic, making it difficult for listeners to distinguish between real and synthetic speech. While listeners often show a bias towards classifying these voices as human, this effect is even stronger when the voices use underrepresented regional or non-standard dialects – presumably because listeners are not used to such varieties being represented by speech technology. This MINDSET - Minority, Indigenous, Non-standard, and Dialect-Shaped Expectations of Technology – could leave some language communities more at risk of AI-voice based deception. To address this, the current study tested whether simple informational nudges could shift listeners’ default assumptions away from “Human” and increase their vigilance towards categorising voices as “AI”. Experiment 1 (N = 150) investigated whether nudges outlining AI’s ability to produce (Scottish) accents and dialects would affect human categorisation responses. The results demonstrated a significant reduction in “Human” responses for a nudge outlining AI’s capabilities at authentically producing these varieties. In Experiment 2 (N = 150), a vigilance-based nudge warning about the risks of AI deception was tested alone and in combination with the capability message. Only the capability-based nudge had a measurable effect, suggesting that updating expectations about what AI can convincingly reproduce is more effective than simply warning listeners to be cautious. As AI voice technology becomes more widespread, such nudges may offer a low-cost strategy for increasing vigilance - particularly in communities whose language varieties have been historically marginalised or excluded from speech technology systems.
The study investigates the effect of cyber resilience on cyber incidents outcomes. Though this relationship is intuitive, there is a lack of empirical evidence indicating that higher levels of organizational cyber resilience mitigate cyber incidents. We address this lack of evidence by collecting and analysing organizational data from 110 cyber practitioners using logistic regression, Kruskal-Wallis and Mann-Whitney tests. Our findings indicate that nonattacked organizations have higher levels of cyber resilience. More precisely, they have higher levels of prevention, education, strategy and planning, and accountability for cyber resilience. However, our findings do not support that a higher level of cyber resilience leads to a lower level of postincident outcomes. This study has implications for researchers by illustrating how cyber resilience may relate to cyber incidents-an area that can be further explored in future cyber resilience research.
The rapidly increasing field of industrial network security has led to the rapid growth of interconnecting devices, significantly enlarging attack surfaces and exposing flaws that older intrusion detection systems (IDS) cannot even handle due to scalability and privacy constraints. This work addresses the shortcomings by presenting an advanced federated framework for machine learning tailored toward intrusion detection in industrial networks. Using the detailed UNSW-NB15 dataset, known to represent realistic network traffic, we have analysed numerous machine learning methods in great detail to build a robust, adaptive, and privacy-preserving model for network protection. In a decentralized federated machine learning (FML) approach, the edge devices could train local models on their own and send aggregated parameters to a central server while keeping the data private. Our model, with differential privacy and secure aggregation, achieved an accuracy of 99.98% using the Random Forest Classifier and differentiated very well between benign and malicious traffic. Advanced feature engineering and interpretability tools, such as SHAP analysis, were used to identify critical detection features. The model was tested through iterative training and in-depth testing across distributed devices with remarkable resilience and efficiency in resource-limited environments. This research is therefore the shift in industrial cybersecurity toward the integration of federated learning with privacy-centric protocols in order to create a new effective, scalable, and resilient defense mechanism than the traditional IDS, which may offer a new standard for industrial network protection against evolving cyber threats.
The problem of maintaining organizational resilience in the face of ransomware attacks represents an important issue for modern organizations. Organizational networks and IT infrastructure have become increasingly complex, and it is often unclear how decisions about technology, policy, and recovery strategy will impact resilience. In this context, the paper focuses on two primary objectives. First, to offer security decision-makers a way of better understanding the impact of deploying different recovery solutions at organizational level by means of simulation modelling and comparative analysis of solutions. Second, to illustrate the suitability and benefits of using semantically justified, compositional system models together with a rigorously defined codesign model-construction methodology, in a complex scenario. Our choice of organizational recovery as modelling target is motivated through both form and complexity, allowing for illustrating the model conceptualization and construction methodology in a sufficiently rich context. We conceptualize the ransomware behaviour, organizational structure, IT infrastructure, and recovery choices and behaviour based on literature surveys and expert knowledge. Then, construct a modular, simulation model representing a generic target organization using our codesign approach. We execute the model over 9000 different parameter configurations, totalling an amount of 450 000 iterations. We analyse the results, both in three specific scenarios deemed organizationally relevant and at the general level-through sensitivity analysis-and, exemplify possible ways in which the model can help inform decision-makers about their possible recovery choices.
Despite the effectiveness and increasing proliferation of security controls designed to protect personal and sensitive information, there is increasing recognition that humans are susceptible to cyber exploitation and thus, individual users are deemed a causal element of personal cyber risk. Exposing personal perceptions and capabilities, such as cyber awareness and knowledge, is crucial to understanding personal cyber risks and allowing a holistic interpretation of an individual's cyber risk profile. This study uses a survey comprising n = 263 participants to explore to what extent awareness influences cyber knowledge and thereby impacts the level of personal cyber risk. We find that personal cyber awareness positively influences knowledge and personal cyber risk, whereas awareness independently fails to impact personal cyber risk, suggesting that knowledge acts as an influential mediator when determining an individual's personal cyber risk profile. Further, this paper acknowledges the importance of consistent definitions and addresses upfront a notable gap by defining personal cyberspace-a critical and foundational prerequisite to any research focused on the human cyber condition. The study contributes by proposing a unique definition of personal cyberspace, a conceptual model articulating an individual's personal cyber risk profile, and extending extant knowledge about relationships among personal cyber awareness, knowledge, and risk.