This study presents the benefits of employing a gesture-based natural user interface (NUI) for a scientifically grounded cyber-risk management collaborative game. Such a human-centered interface facilitates group-based training and enables board members to achieve better results collectively compared to operating individually. The main contribution of this tool is to enhance the group training leveraging on collective intelligence. To show that, the results and learning paths of single users and groups acquired from this game are compared. Moreover, the collaborative game provides executives and business leaders with insight into cyber-risk management issues, thereby improving their results through deeper learning. This work demonstrates that the interface is the key factor in the success of group cooperation. The idea, the design, and the improvement of the NUI are critical to make it possible to achieve these results.
Digital transformation embeds smart cities, e-health, and Industry 4.0 into critical infrastructures, thereby increasing reliance on digital systems and exposure to cyber threats and boosting complexity and dependency. Research involving over 200 executives reveals that under rising complexity, only 15% of cyber risk investments are effective, leaving most organizations misaligned or vulnerable. In this context, the role of artificial intelligence (AI) in cybersecurity requires systemic scrutiny. This study analyzes how AI reshapes systemic structures in cyber risk management through a multi-method approach: literature review, expert workshops with practitioners and policymakers, and a structured kill chain analysis of the Colonial Pipeline attack. The findings reveal three new feedback loops: (1) deceptive defense structures that misdirect adversaries while protecting assets, (2) two-step success-to-success attacks that disable defenses before targeting infrastructure, and (3) autonomous proliferation when AI applications go rogue. These dynamics shift cyber risk from linear patterns to adaptive, compounding interactions. The principal conclusion is that AI both amplifies and mitigates systemic risk. The core recommendation is to institutionalize deception in security standards and address drifting AI-powered systems. Deliverables include validated systemic structures, policy options, and a foundation for creating future simulation models to support strategic cyber risk management investment.
The growing system complexity from microservice architectures and the bilateral enhancement of artificial intelligence (AI) for both attackers and defenders presents increasing security challenges for cloud-native operations. In particular, cloud-native operators require a holistic view of the dynamic security posture for the cloud-native environment from a defense aspect. Additionally, both attackers and defenders can adopt advanced AI technologies. This makes the dynamic interaction and benchmark among different intelligent offense and defense strategies more crucial. Hence, following the multi-agent deep reinforcement learning (RL) paradigm, this research develops an agent-based intelligent security service framework (ISSF) for cloud-native operation. It includes a dynamic access graph model to represent the cloud-native environment and an action model to represent offense and defense actions. Then we develop an approach to enable the training, publishing, and evaluating of intelligent security services using diverse deep RL algorithms and training strategies, facilitating their systematic development and benchmark. The experiments demonstrate that our framework can sufficiently model the security posture of a cloud-native system for defenders, effectively develop and quantitatively benchmark different services for both attackers and defenders and guide further service optimization.
Organizations face an urgent need to bolster their cybersecurity defenses against the rising threat of ransomware. Implementing advanced antivirus and anti-malware tools is crucial for proactive identification and mitigation of malicious software. However, adversaries constantly refine malware to evade detection increasing the complexity of the threat. Hence, developing an effective strategy is nontrivial. To address this challenge, this study conducts various analyses on scan results of publicly shared malware samples. Utilizing metadata from 635K samples sourced from MalwareBazaar and scan results from VirusTotal, we assign family labels using AV Class. Additionally, we examine a 90-day longitudinal dataset alongside the main dataset. Our findings demonstrate that while over 60 % of scanner engines detect 67 % of samples, certain malware families consistently exhibit lower detection rates. Detection capability improves over time, particularly within the initial 30 days, but remains inadequate for specific families. Furthermore, we observe that some scanner engines demonstrate nearly flawless detection capability across all mal ware families, while the majority struggle with efficiently detecting certain types. Moreover, we performed Monte Carlo simulations and revealed that employing multiple scanner engines substantially enhances detection capability, with 3 to 7 scanners being optimal. Finally, simulation analysis in a case study highlights the significant impact of hard-to-detect malware on risk and performance, underscoring the importance of effective malware strategies.
Business enterprises have grappled in the last one and half decade with unavoidable risks of (major) cyber incidents. The market to manage such risks using cyber insurance (CI) has been growing steadily but is still skeptical of the economic and societal impact of systemic risk across networked supply chains in interdependent IT-driven enterprises. While systemic risk from traditional cyber loss events might lure more capacity to the CI market, such a risk from a catastrophic (CAT) cyber loss event can quite likely reverse this trend. The sustainability of the much viable risk diversification by cyber insurers in these environments depends on (a) the statistical nature of cyber risks that contribute to systemic cyber risk and (b) the interconnection topology between enterprises. We focus here on (a) and solve the theory challenge problem of proposing simulation-validated mathematical conditions on cyber risk distributions that make systemic risk VaR diversification-friendly for CI markets.
With the expanding cyber-risk terrain spanning business processes in digitally driven enterprises with critical infrastructure, it is inevitable in time that system process continuity (SPC) will be affected (e.g., via ransomware) for certain inter-dependent processes of such an enterprise, and hamper business continuity. We are interested in the question: how should managers of such enterprises optimize cyber-resilience (i.e., the ability to maintain SPC via absorbing and adapting to an adverse cyber-incident) for any complex networked critical infrastructure (CI) (sub-)system with multiple process functionality components (PFCs)? We prove via an algorithmic graph-theoretic approach that optimizing or approximately optimizing cyber-resilience within a pre-specified enterprise cyber-protection budget in any CI with networked and inter-dependent PFCs is NP-hard. Consequently, we propose a computationally tractable graph-based Monte-Carlo simulation framework to ‘optimize’ (boost) cyber-resilience within any PFC network by allocating a constrained cyber-protection budget among PFCs in accordance with their Katz centralities in the PFC network.
(Gen)AI is emerging as a powerful force transforming industrial control and business/enterprise productivity. This paper investigates the challenges and opportunities stemming from (Gen)AI on industrial control systems (ICSs) security within the framework of the Cyber Kill Chain (CKC). Leveraging the CKC framework, we examine how (Gen)AI enables attackers to automate each phase of the CKC - reconnaissance, weaponization, delivery, exploitation, installation, command and control, and action on objectives. Conversely, (Gen)AI also empowers defenders to employ advanced techniques such as AI-powered firewalls, anomaly detection, and automated incident response to thwart cyber threats effectively. We study how this defense dynamic using (Gen)AI operates within each phase of the Cyber Kill Chain for ICSs. We back up our attack-defense dynamics study with simulations on real-world ICS scenarios. To the best of our knowledge, this is the first cybersecurity study in the joint space of ICSs, the Cyber Kill Chain (CKC), and (Gen)AI.
The COVID-19 pandemic (e.g., especially the first and second COVID waves) had forced firms (organizations) to radically shift a considerable (if not all) proportion of their employees to serve in a work-from-home (WFH) mode. Industry statistics showcase that despite ushering in significant work-flexibility (and other) benefits, the WFH mode has also expanded an organization’s cyber-vulnerability space, and increased the number of cyber-breaches in IT and IT-OT systems (e.g., ICSs). This leads us to an important fundamental question: is the WFH paradigm detrimental to IT and IoT-driven ICS security in general? While vulnerability reasoning and empirical statistics might qualitatively support an affirmative answer to this question, a rigorous, practically motivated, and strategic cost-benefit analysis is yet to be conducted to establish in principle whether and to what degree WFH-induced cyber-security in an IT/ICS system is sub-optimal when compared to that in the non-WFH work mode. We propose a novel and rigorous strategic method to dynamically quantify the degree of sub-optimal cyber-security in an IT/ICS organization of employees, all of whom work in heterogeneous WFH “siloes”. We first derive as benchmark for a WFH setting - the centrally-planned socially optimal aggregate employee effort in cyber-security best practices at any given time instant. We then derive and compute (using Breton’s Nash equilibrium computation algorithm for stochastic dynamic games) for for the same setting - the distributed time-varying strategic Nash equilibrium amount of aggregate employee effort in cyber-security. The time-varying ratios of these centralized and distributed estimates quantify the free riding dynamics, i.e., a proxy concept for security sub-optimality, within an IT/ICS organization for the WFH setting. We finally compare the free-riding ratio between WFH and non-WFH work modes to gauge the (possible) extent of the increase (lower bound) in security sub-optimality when the organization operates in a WFH mode. We counter-intuitively observe through extensive real-world-trace-driven Monte Carlo simulations that the maximum of the time-dependent median increase in the related security sub-optimality ranges around 25% but decreases fast with time to near 0% (implying security sub-optimality in the WFH mode equals that in the non-WFH mode) if the impact of employee security effort is time-accumulative (sustainable) even for short time intervals.
In this research, we developed a novel approach to enable a dynamic cyber risk management strategy as the dynamic nature of cyber risk is rarely considered in current decision support tools. Our explorative case study shows that many management challenges such as investment decisions, priority setting, and "shelf time" analyses can be continuously analyzed. Our research using system thinking and modelling provides valuable insights about these challenges to support current strategic decision-making practices and improve managerial learning. These insights enable management to identify and analyze the effectiveness of future cyber risk management strategies before implementing them.
Cybersecurity is becoming an increasing hurdle for digital trade. The governance of cybersecurity in the global digital trade system is a bottom-up approach, where governments are implementing fragmental and inconsistent trade policies and forming different models of public-private co-governance. Based on network-governance theory, information security behavior theory, and international risk theory, we develop a conceptual model to investigate how various factors drive cybersecurity governance practices. Using Huawei's 5G as an example, this study explores how different governments-the United States, the United Kingdom, Germany, Australia, and India-act on the cybersecurity concerns from Huawei's 5G. The comparative analysis demonstrates how balancing different factors drive governments' actions and discuss what international corporations like Huawei can do to align their digital trade system strategies. This research guides international firms to participate in cybersecurity governance constructions within the digital trade system.
Cyberattacks targeting industrial control systems (ICS) pose a particularly serious threat due to their potential to cause not only physical damage but also cascading disruptions to the supply of critical services (such as water, electricity, or gas). One way to address these threats is through training in a cyber range. Such training can bolster defensive capabilities by increasing cross-domain knowledge between IT and OT teams about real-world industrial processes and equipment on the one hand and attacker tactics, techniques, and procedures (TTPs) and cyber defense tools on the other hand. To that end, this paper presents the development of a Cyber Range for ICS (CR-ICS) that is based on a real-time attacker-defender gameplay model in conjunction with dynamic simulation models of typical industrial systems. As a proof of concept, we present an industrial gas turbine as one use-case of an archetypal industrial system. In addition to the architecture of the range and the building of the simulation model, this paper also provides a demonstration of a sample training exercise.
There are considerable challenges that surround the security of cyber-physical systems. These challenges are compounded by the often heterogeneous nature of different IT and internet of things (IoT) systems that can be found in them. Some of the most onerous tasks around securing a cyber-physical system stem from operational security issues, like patch and update management. Many operational security tasks can be repetitive and prone to error. Managing the security of these systems requires a new approach, one designed to help reduce repetition and tackle common operational security tasks. The Security Automation through Blockchain Remediation and Execution (SABRE) agent was designed specifically to deal with these types of challenges. The SABRE agent aims to reduce complexity and increase the security within a fleet of devices in a cyber-physical system. The solution was built on top of the Etheruem network and designed to operate on large scale cyberphysical systems.
We developed a simulation game to study the effectiveness of decision-makers in overcoming two complexities in building cybersecurity capabilities: potential delays in capability development; and uncertainties in predicting cyber incidents. Analyzing 1,479 simulation runs, we compared the performances of a group of experienced professionals with those of an inexperienced control group. Experienced subjects did not understand the mechanisms of delays any better than inexperienced subjects; however, experienced subjects were better able to learn the need for proactive decision-making through an iterative process. Both groups exhibited similar errors when dealing with the uncertainty of cyber incidents. Our findings highlight the importance of training for decision-makers with a focus on systems thinking skills, and lay the groundwork for future research on uncovering mental biases about the complexities of cybersecurity.