We explore the effect of information about the pro-sociality of group members on public good contributions. We first provide a theoretical framework, based on psychological game theory, to model the influence of information about pro-sociality on first and second-order beliefs and thereby contributions. We subsequently report the results of three experiments in which we use social value orientation (SVO) as a measure of pro-sociality. We compare: (i) four networks of information: complete, star, pair and empty, and (ii) two information framings: identifying pro-socials versus pro-selfs. Our findings indicate that SVO information significantly boosts contributions, with enhancements ranging from 50% to 70% based on the group’s information structure. Regarding framing effects, we find evidence that emphasizing pro-social traits leads to higher contributions than emphasizing pro-self traits, though this effect emerges primarily after repeated interactions.
This paper investigates the interplay between income inequality, growth, and redistribution in a dynamic public good game. Redistribution, as expected, leads to lower inequality but it does not necessarily reduce growth. Especially in settings characterized by high initial inequality, a high tax rate can produce similar wealth levels as without taxation while reducing inequality. On average, we find that people tend to favor more redistribution over time, but there is substantial heterogeneity in this trend. We also find that individuals who are more favourable to redistribution contribute more to the public good.
There is widely recognized challenge to improve cybersecurity awareness and understanding in the workforce. In this paper we assess the impact of cybersecurity training in the workplace on an individual's awareness of basic cybersecurity best practice. We report the results of a survey (n = 965) of individuals resident in the UK, who's cybersecurity knowledge was assessed on two key dimensions: secure passwords and use of public Wi-Fi. Despite using a forgiving definition of best practice we find that only 8.6% of participants correctly identified best practice. Around a half of participants had received cybersecurity training through their current employer with a mix of online training, in-person training and training outside the workplace. We find that those who received online training were significantly less likely to identify best practice than those with no training. Those who received in-person training and training outside the workplace were no more likely to identify best practice than those with no training. We also measured participants self-assessed familiarity with cybersecurity and confidence in spotting a phishing attack. We find a positive relationship between training and self-assessed familiarity and confidence. Our results, therefore, suggest that training typical training in use increases confidence without improving awareness or end-user behavior.
The increasing frequency of cyber threats poses substantial challenges for organizations in both the private and public sectors. This systematic literature review evaluates and categorizes current cyber risk assessment methodologies and frameworks, supporting the selection of suitable approaches for practical and academic applications. Utilizing the PRISMA framework, 712 relevant studies were filtered from an initial pool of 1900 academic publications and subsequently analyzed and organized into a structured database, providing an overview of the advantages and limitations of widely cited approaches in this domain. The findings indicate a strong preference for established risk management frameworks, including the ISO 27000 family, OCTAVE, and NIST Special Publications, as well as mathematical approaches such as Bayesian networks, fuzzy logic, and multi-criteria decision-making techniques. The 217 approaches identified were grouped into two primary categories: Standards, Frameworks, and Guidelines and Risk Assessment Methods, with further classification by the application sectors addressed in the literature. Analysis suggests that no single approach offers universal applicability. The choice of methodology should therefore be informed by an organization’s specific resources, size, and sectoral requirements. A cross-analysis of methods and sectors reveals gaps in sector-specific coverage, particularly for healthcare, finance, and small and medium-sized enterprises. The review identifies a trend toward hybrid approaches that combine organizational frameworks with quantitative methods and documents persistent barriers to adoption, including cost, data scarcity, and insufficient management engagement. Based on these findings, a conceptual framework is developed to evaluate approaches across five dimensions and to derive a typology of governance-oriented, quantitative, and hybrid methods. Implications for practitioners, regulators, and researchers are discussed in relation to current regulatory frameworks, including the NIS-2 Directive and the Digital Operational Resilience Act (DORA).
We explore whether information on one's own social value orientation (SVO) impacts contributions in a public good game with leadership by example. In doing so, we compare the predictions of a model of belief-based preferences, where payoffs depend on first- and second-order beliefs on the contributions of others, and a model of internalized descriptive norms, where payoffs depend on deviation from an empirical norm. We argue that if pro-social behavior is driven by belief-based preferences, then private information on SVO should not impact contributions, but if the behavior is driven by internalized descriptive norms, then information on its own SVO should impact contributions. We report an experiment with three treatments: no information on SVO, binary information whether pro-self or pro-social, and SVO indicated on a scale from very pro-social to very pro-self. We observe no effect of information on contributions. This finding is inconsistent with internalized descriptive norms. We find that contributions are highest with a pro-social leader.
Ransomware is a fast-evolving form of cybercrime in which a ransom is demanded to restore access to a victim’s encrypted files. The business model of the criminals relies on victims being willing to pay the ransom demand. In this paper we use insights from behavioural economics to see how the framing of a ransom demand may influence willingness to pay the ransom. We then report the results of an experiment in which subjects (n=93) were shown eight different ransom demand splash screens, based on well-known examples of ransomware. The subjects were asked to rate and rank the ransom demands on six criteria that included willingness to pay and willingness to trust the criminals. This allows a within-subject comparison of different ransom demand frames. We find that trust is the main determinant of willingness to pay. We also find that positive framing is likely to increase willingness to pay compared to negative framing.
Many businesses, particularly small businesses, are underinvesting in cyber security. This exposes them to the risk of costly cyber attack. To address the challenge of cyber security in small businesses a greater understanding is needed of why businesses are underinvesting. To address this challenge, we propose a novel framework to distinguish five behavioral types and quantify the proportion of businesses fitting each type. The types are overconfident, procrastinator, risk accepting, defer responsibility, and optimal. We apply our framework using data from the UK Government's Cyber Security Breaches Survey from 2018-2024. We find that procrastination and overconfidence are the main reasons for underinvestment in cyber security in small businesses. We also find that small businesses with cyber insurance and/or cyber outsourcing are more likely to be classified as optimal. These results can inform policy interventions that better target the root cause of underinvestment in cyber security.
Two consistent findings from the experimental literature on public good games are that cooperation declinesover time and cooperation is lower in countries with weak institutions. These findings, however, are primarilybased on experiments in Europe, North America, and Asia. There is little evidence from South and CentralAmerica. In an experiment conducted in Guyana, we found consistent, indeed rising, levels of cooperationover time. The robustness of this result was checked across three different treatments and has high power(a total of 176 subjects). Our results indicate that more experimental work is needed to fully understandwillingness to cooperate in public good games. Guyana has relatively weak institutions and yet cooperationremained high.
Ransomware attacks have evolved with criminals using double extortion schemes, where they signal data exfiltration to inflate ransom demands. This development is further complicated by information asymmetry, where victims are compelled to respond to ambiguous and often deceptive signals from attackers. This study explores the complex interactions between criminals and victims during ransomware attacks, especially focusing on how data exfiltration is communicated. We use a signaling game to understand the strategies both parties use when dealing with uncertain information. We identify five distinct equilibria, each characterized by the criminals' varied approaches to signaling data exfiltration, influenced by the strategic parameters inherent in each attack scenario. Calibrating the game parameters with real-world like values, we identify the most probable equilibrium, offering insights into anticipated ransom amounts and corresponding payoffs for both victims and criminals. Our findings suggest criminals are likely to claim data exfiltration, true or not, highlighting a strategic advantage for intensifying attack efforts. The study underscores the need for victims' caution towards criminals' claims and highlights the unintended consequences of policies making false claims costlier for criminals.
Economics has long shunned qualitative research methods, such as interviews, focus groups and observational studies, in preference for quantitative methods, such as empirical analysis of secondary data and field experiments. Moreover, recent years, with advances in econometric theory, have seen a notable increase in the size and quality of data sets that are needed to publish quantitative research in leading journals. This has the effect of significantly increasing the ‘entry costs’ for researchers interested in studying economic development. Crucially, it also limits the topics that can be studied. In particular, it focuses attention on issues and countries where large data sets exist or can be collected. In this paper, we argue that by putting too much weight on internal validity, economics has adopted a too narrow definition of ‘rigour’ and would benefit from embracing qualitative and mixed methods research. To illustrate our point, we pay particular attention to the informal economy. The informal economy is understudied by economists because of the lack of available quantitative data. We show that this fundamentally impacts our understanding of the wider economy. Qualitative research can enrich our understanding by providing a more complete and nuanced view of the economy.
This study examines the relative effectiveness of the UK government’s public health messages used during the first wave of the COVID-19 pandemic. We focus on the use of a loss versus gain frame. We look at the effect of framing on behavioural inclination to follow COVID-19 guidance, as well as affective mechanisms and individual characteristic moderators that might explain said willingness. We ran two studies with a voluntary sample of the UK adult population (total n = 300). Across both studies, we only find a significant impact of message framing on the level of negative affect triggered, with the loss frame triggering a higher negative affect. Instead, attitude to public health communication had a direct and indirect effect on behavioural inclination. Our results suggest that threat minimisation and satisfaction with authorities handling a health crisis might be key to consider when developing effective public health communications.
We study the impact of framing on leading-by-example. Our 2 x 2 design consists of group level frames (Wall Street vs. Community) and individual level frames (First/Second Movers vs. Leader/Followers). We report on two studies where we elicit participants' beliefs allowing us to evaluate whether framing effects are driven by beliefs or preferences. Across both studies, average contributions are significantly lower in the Community-First Mover frame. This is primarily because leaders contribute less, pulling down followers' contributions. We find that contributions are strongly related to first order and second order beliefs but framing effects remain once we control for beliefs.
In this article, the authors analyze data accumulated over 10+ years of teaching market interaction using a simple classroom experiment. The experiment is designed to teach first-year undergraduate students the basics of supply and demand and market efficiency. In total, they analyze data from 85 teaching sessions and 243 individual markets. They find that traded prices typically (90% of the time) move in accordance with market equilibrium comparative statics. They also find that average traded prices are rarely (5% of the time) consistent with market equilibrium but typically (70% of the time) "close" to the equilibrium. The traded quantity is often (60% of the time) more than equilibrium, which results in a loss of efficiency. The law of one price is strongly rejected.
This paper demonstrates how the innovative application of a Collective Intelligence approach enhanced Local Skills Improvement Planning information for employers, education and skills training organisations and regional economic policy organisations. This took place within a Knowledge Transfer Partnership between a Chamber of Commerce and a University. This aimed to develop and deploy regional business intelligence for enhanced policy and decision-making in enterprise and economic development. The project converged knowledge from several research centres including economics, entrepreneurship and innovation, data science, and Artificial Intelligence. The paper presents a project case study which provides two contributions to applied knowledge. Firstly, it demonstrates how a Collective Intelligence (CI) approach can be applied to achieve rapid results in resolving the real-world problem of local skills information availability. Useful real-time data was gathered from employers in three sectors on skills requirements, supply and training. This was analysed using Artificial Intelligence tools, then shared publicly via an automated Internet portal, providing a scalable model for wider use. Secondly, it explores and evaluates how the knowledge exchange (KE) process can function effectively and quickly in applying CI-based innovation in practical ways which create new value, within a Knowledge Transfer Partnership between a University and Chamber of Commerce.environment.
Previous studies have shown that pro-social leaders cooperate, on average, more than pro-self leaders in social dilemmas. It can, thus, be beneficial for the group to have a pro-social leader. In this paper we analyze the consequences of a leader informing followers that they are pro-social (or pro-self). In doing so, we compare a setting in which the leader's type is truthfully revealed to settings where the leader can 'hide' or 'lie' about their pro-sociality. We find that a leader saying they are pro-social boosts efficiency, even if the signal is not fully credible. Cooperation is highest in a truth setting with a pro-social leader. We demonstrate that these results are consistent with a belief-based model of social preference in which the stated type of the leader changes the frame of reference for followers.
The dictator game has become a celebrated workhorse of experimental economics and social psychology. In the standard version of the game an individual is given a sum of money and must choose how to split this money between themselves and some other individual. In a variant of the game the individual must split the money between themselves and a charitable cause. This charity version of the dictator game has now been used in well over fifty studies and has provided critical insight on the motives behind giving. It also provides a simple tool that policy makers and practitioners can use to test the effect of interventions. In this paper we explain the different ways in which charity dictator games can and have been used. We also look at the external validity of charity dictator games and discuss the research questions that can be appropriately studied using them.
Consensus algorithms facilitate agreement on and resolution of blockchain functions, such as smart contracts and transactions. Ethereum uses a Proof-of-Stake (PoS) consensus mechanism, which depends on financial incentives to ensure that validators perform certain duties and do not act maliciously. Should a validator attempt to defraud the system, legitimate validators will identify this and then staked cryptocurrency is ‘burned’ through a process of slashing. In this paper, we show that an attacker who has compromised a set of validators could threaten to perform malicious actions that would result in slashing and thus, hold those validators to ransom. We use game theory to study how an attacker can coerce payment from a victim, for example by deploying a smart contract to provide a root of trust shared between attacker and victim during the extortion process. Our game theoretic model finds that it is in the interests of the validators to fully pay the ransom due to a lack of systemic protections for validators. Financial risk is solely placed on the victim during such an attack, with no mitigations available to them aside from capitulation (payment of ransom) in many scenarios. Such attacks could be disruptive to Ethereum and, likely, to many other PoS networks, if public trust in the validator system is eroded. We also discuss and evaluate potential mitigation measures arising from our analysis of the game theoretic model.
Micro and small businesses are increasingly reliant on digital and online technology. They have, though, very limited resources and expertise to devote to cyber security. There is, thus, a pressing economic and social challenge of how to improve cyber security in small businesses. We look at the potential role of IT companies as a conduit through which to cascade information on best practice, focusing on the United Kingdom. We first present an analysis of the UK’s Cyber Security Breaches Survey (2018–2021) distinguishing different channels through which micro and small businesses access information on cyber security. We find that the main channel, by far, is through IT companies. Very few businesses directly access information from the government or law enforcement. To further explore the role of IT companies we conducted a series of focus groups and interviews with experts in IT and cyber security for small businesses in the UK. One theme to emerge is that IT companies, while they can be part of the solution, can also be part of the problem and so a number of interventions are needed if IT companies are to effectively disseminate best practice. These include advice and guidance for micro and small businesses on how to distinguish ‘good’ IT companies, as well as appropriate support for IT companies, who themselves are typically micro and small businesses that lack expertise on cyber security.