Note: When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher.
Some full text articles may not yet be available without a charge during the embargo (administrative interval).
What is a DOI Number?
Some links on this page may take you to non-federal websites. Their policies may differ from this site.
-
We study how firms adjust their cybersecurity postures after experiencing a cyber attack. We combine publicly disclosed ransomware cyber incidents with detailed data on security products and vendor deployments from the Spiceworks Ziff Davis (SWZD) Company Intelligence Database (CIDB) over multiple years. Our empirical approach compares attacked firms to similar non-attacked firms using econometrics and employing a difference-in-difference (DID) framework. Controlling for common changes made by all firms over time, we find that “attacked” firms increased the breadth of their security posture relative to non-attacked firms. They adopted more National Institute of Standards and Technology (NIST) functions and had broader “category coverage” than non-attacked firms in the “post attack” period. Attacked firms also increased the usage of security products from large and “platform” vendors relative to non-attacked firms in the “post attack” period.more » « lessFree, publicly-accessible full text available June 2, 2027
-
PurposeAll US defense contractors were required to have fully implemented the 110 security requirements included in NIST Special Publication 800-171 entitled “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” by 1 January 2018 whenever a system owned or operated by or for a contractor processes, stores or transmits controlled unclassified information. Despite the mandate, adoption has been minimal, mostly because the requirement is so costly and time consuming that medium and small firms cannot afford to comply. Because the adoption of security precautions is costly and time consuming, the purpose of this paper is to propose a constrained optimization methodology to examine this issue. Design/methodology/approachIn this paper, the authors introduce a method to significantly reduce the number of required precautions by soliciting expert opinion as to the perceived benefits and costs of all precautions. The authors defined the difference between benefits and costs as value. FindingsIn the key constrained optimization exercise conducted, the authors show that including only the top 50 security precautions (out of the 110 security precautions) led to just a very small decline in value. Originality/valueThis paper makes an important contribution to information security research. To the best of the authors’ knowledge, no one has conducted similar analysis on the 110 proposed precautions.more » « lessFree, publicly-accessible full text available September 22, 2026
-
Multifactor authentication (MFA) is one of the most important security controls, topping most lists of cyber hygiene activities advocated by experts. While the security benefits may be substantial, less attention has been paid to the impact on users by the added friction introduced by the more stringent precautions. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on opportunity costs experienced by users: (1) log-in failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a deny/approve mobile notification to a more cumbersome two-digit code mobile notification confirmation, we show that there are significant increases in the number of log-in failures and in time spent away following failures when using mobile MFA. We also briefly examine which which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.more » « less
-
Multifactor authentication (MFA) is one of the most important security controls, topping most lists of cyber hygiene activities advocated by experts. While the security benefits may be substantial, less attention has been paid to the impact on users by the added friction introduced by the more stringent precautions. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on opportunity costs experienced by users: (1) log-in failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a deny/approve mobile notification to a more cumbersome two-digit code mobile notification confirmation, we show that there are significant increases in the number of log-in failures and in time spent away following failures when using mobile MFA. We also briefly examine which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.more » « less
An official website of the United States government

Full Text Available