Open Access. Powered by Scholars. Published by Universities.®

Cybersecurity Commons

Open Access. Powered by Scholars. Published by Universities.®

Business

Institution
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 23 of 23

Full-Text Articles in Cybersecurity

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap Jul 2026

Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap

Journal of Cybersecurity Education, Research and Practice

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …


Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca May 2026

Meeting The Moment With Ai-Employer Informed Education, Brent Terwilliger, John Faraca

Publications

As artificial intelligence transforms aviation, aerospace, and autonomy-related sectors, higher education must adapt to meet evolving workforce demands. This session shares emerging findings from a nationwide study led by Embry-Riddle Aeronautical University, focused on employer perceptions of AI adoption, responsible use, and workforce preparedness in domains including uncrewed systems, space systems, robotics, and advanced air mobility. Based on a structured survey and follow-up interviews, the presentation explores how organizations are using AI tools, from generative platforms to enterprise systems, and defining effective and inappropriate use in operational contexts. Participants will gain insight into critical concerns (e.g., data privacy, compliance, security, …


Exploring The U.S. Public Service Employees’ Experiences With Gamified Cybersecurity Awareness Training, Bisola Adepoju Apr 2026

Exploring The U.S. Public Service Employees’ Experiences With Gamified Cybersecurity Awareness Training, Bisola Adepoju

Human Resource Development Theses and Dissertations

The purpose of this qualitative study was to explore the U.S. public service employees' experiences with gamified cybersecurity awareness training. The primary research question guiding this inquiry was: How do U.S. public service employees make sense of their lived experiences with gamified cybersecurity awareness training? Two secondary questions examined what aspects of the training employees perceive as meaningful or disengaging, and how they interpret their motivation, engagement, and cybersecurity awareness during training. I chose an interpretive qualitative research design grounded in a constructivist paradigm and purposefully selected 11 U.S. public service employees who had participated in gamified cybersecurity awareness training. …


Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn Feb 2026

Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn

Journal of Cybersecurity Education, Research and Practice

The digital transformation of higher education institutions (HEIs) has introduced unprecedented connectivity and operational efficiency, but it has also heightened their exposure to cyber threats. South African HEIs, in particular, face increasing vulnerability due to their reliance on technology, openness, and diverse user communities. This study examines the influence of the institutional cybersecurity environment on employee cybersecurity-compliant behaviour (CCB), emphasising the critical roles of awareness, policy engagement, and experience. Drawing on Protection Motivation Theory and the Theory of Planned Behaviour, a conceptual model was developed to explore how cybersecurity awareness, policy familiarity, and prior experience shape employees’ attitudes, subjective norms, …


Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom Jan 2026

Proof Of Recovery: A Model To Enhance Data Integrity In Data Management Systems, Gustaf Barkstrom

Theses and Dissertations

Businesses lose millions of dollars every year when they can’t restore data from backups. Research shows that Disaster Recovery Plan (DRP) testing is not conducted frequently enough, nor are records maintained that demonstrate full data recovery from backups. This work introduces a design science artifact called PRTOK that aims to increase DRP testing. The design science artifact is a software solution that integrates with Data Management Systems (DMS)

such as iRODS and DSpace, and can work with formats such as HDF5 and BagIt. Proof-of- recovery records, or tokens, are recorded in a replicated, resilient, and indelible proof-of- authority blockchain data …


Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han Jan 2026

Lost In The Language: Data Breaches And The Strategic Fog Of Risk Disclosures, Ling Tuo, Shipeng Han

Accounting Faculty Publications

This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm-year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post-breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for …


Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney Dec 2025

Sme Cyber Resilience State Of The Sector 2025, Hazel Murray, Gillian O'Carroll, Aoibheann Brangan, Jason Holland, Stephanie Chevanne Wallace, Miriam Curtain, Glenda Deveney

Department of Computer Science Publications

Ireland's small and medium enterprises (SMEs) face a critical cyber resilience gap. SMEs account for 99.8% of all enterprises in Ireland and employ over 2.29 million people, representing 67.9% of total employment (based on the latest CSO 2022 figures). This cyber resilience assessment reveals that the majority of SMEs remain underprepared for modern cyber threats.


Systematic Review Of Elementary Cybersecurity Education: Curriculum, Pedagogy, And Barriers, Na Liu, Siyu Long, Florence Martin Nov 2025

Systematic Review Of Elementary Cybersecurity Education: Curriculum, Pedagogy, And Barriers, Na Liu, Siyu Long, Florence Martin

Journal of Cybersecurity Education, Research and Practice

Abstract -As children increasingly engage with digital platforms, the need for effective cybersecurity education has become urgent. This systematic review synthesizes 81 studies published between 2017 and 2024 to examine global curricula research focus and topics, pedagogical approaches and assessment methods, and key challenges in elementary cybersecurity education. The findings reveal six major thematic categories: student awareness, parental mediation, teacher engagement, curriculum design, community and policy support, and pedagogical innovation. Among instructional strategies, game-based learning and narrative storytelling emerge as the most frequently explored. Despite this growth, major gaps remain in curriculum consistency, teacher preparation, assessment rigor, and stakeholder coordination. …


Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green May 2025

Deepfakes On Trial: Developing A High-Accuracy, Court-Admissible Ai Pipeline For Deepfake Detection In Corporate Fraud Litigation, Aiden J. Green

Honors College Theses

As deepfake technology advances, cybercriminals are increasingly using AI-generated videos and audios to impersonate executives and carry out sophisticated CEO fraud schemes. These synthetic forgeries target human trust and corporate communication systems, creating an urgent need for forensic tools capable of authenticating digital evidence with legal accuracy. This thesis presents a forensic-grade AI deepfake detection pipeline designed for this purpose, emphasizing courtroom admissibility, reproducibility, and evidentiary integrity. Built entirely with free, opensource tools, the framework combines metadata analysis, AI-powered spectrogram analysis, neural artifact detection, and facial manipulation recognition into a transparent workflow that accurately identifies synthetic media. It was trained …


Network-Based Attacks In Cloud Computing In 2020-2024, Yaswanth Sai Manikanta Anguluri May 2025

Network-Based Attacks In Cloud Computing In 2020-2024, Yaswanth Sai Manikanta Anguluri

Electronic Theses, Projects, and Dissertations

As the use of cloud technologies has increased in the past five years, the number of network attacks is also increasing. During 2020 to 2024, there are lot of changes in cloud technologies which led to various network attacks in the cloud computing environments from 2020 to 2024. This study investigates the evolution of network-based attacks in cloud environments from 2020 to 2024. Data was collected from Kaggle website to analyze the trends of the evolution of network-based attacks. The research questions are: (Q1) How do the trends change in network-based attack from 2020 to 2024 and why? (Q2) Which …


Advancing Devsecops In Smes: Challenges And Best Practices For Secure Ci/Cd Pipelines, Jayaprakashreddy Cheenepalli, John Hastings, Khandaker Mamun Ahmed, Chad Fenner Apr 2025

Advancing Devsecops In Smes: Challenges And Best Practices For Secure Ci/Cd Pipelines, Jayaprakashreddy Cheenepalli, John Hastings, Khandaker Mamun Ahmed, Chad Fenner

Research & Publications

This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit. Our findings highlight a growing integration of security tools, particularly API security …


A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings Jan 2025

A Survey-Based Quantitative Analysis Of Stress Factors And Their Impacts Among Cybersecurity Professionals, Sunil Arora, John D. Hastings

Research & Publications

This study investigates the prevalence and underlying causes of work-related stress and burnout among cybersecurity professionals using a quantitative survey approach guided by the Job Demands-Resources model. Analysis of responses from 50 cybersecurity practitioners reveals an alarming reality: 44% report experiencing severe work-related stress and burnout, while an additional 28% are uncertain about their condition. The demanding nature of cybersecurity roles, unrealistic expectations, and unsupportive organizational cultures emerge as primary factors fueling this crisis. Notably, 66% of respondents perceive cybersecurity jobs as more stressful than other IT positions, with 84% facing additional challenges due to the pandemic and recent high-profile …


Cybersecurity And Business Analytics: Strengthening Financial And Governmental Digital Defenses, Bushra F. Malik, Ravindar Reddy Gopireddy Jan 2025

Cybersecurity And Business Analytics: Strengthening Financial And Governmental Digital Defenses, Bushra F. Malik, Ravindar Reddy Gopireddy

Accounting, Business Analytics, Economics, and Finance Department Faculty Articles

The rapid digitization of financial services and federal operations has significantly increased cybersecurity risks. Cybercriminals are continuously evolving their attack methodologies, targeting financial institutions and government agencies to exploit vulnerabilities in digital infrastructures. Business analytics has emerged as a powerful tool in combating these threats by leveraging artificial intelligence (AI), machine learning (ML), and big data analytics to detect, analyze, and prevent cyber threats in real time. This paper explores the convergence of cybersecurity and business analytics, emphasizing their combined role in strengthening threat intelligence, fraud detection, incident response, and regulatory compliance. The research provides insights into emerging security trends, …


A Spoofing Speech Detection Method Combining Multi-Scale Features And Cross-Layer Identification, Hongyan Yuan, Linjuan Zhang, Baoning Niu, Xianrong Zheng Jan 2025

A Spoofing Speech Detection Method Combining Multi-Scale Features And Cross-Layer Identification, Hongyan Yuan, Linjuan Zhang, Baoning Niu, Xianrong Zheng

Information Technology & Decision Sciences Faculty Publications

Pre-trained self-supervised speech models can extract general acoustic features, providing feature inputs for various speech downstream tasks. Spoofing speech detection, which is a pressing issue in the age of generative AI, requires both global information and local features of speech. The multi-layer transformer structure in pre-trained speech models can effectively capture temporal information and global context in speech, but there is still room for improvement in handling local features. To address this issue, a speech spoofing detection method that integrates multi-scale features and cross-layer information is proposed. The method introduces a multi-scale feature adapter (MSFA), which enhances the model’s ability …


Watchdogs Or Lapdogs: How Audit Committees Influence Financial Reporting Quality And Cybersecurity, Yanru Yang Jan 2025

Watchdogs Or Lapdogs: How Audit Committees Influence Financial Reporting Quality And Cybersecurity, Yanru Yang

2025

With the increasing complexity of the business environment, the role of corporate governance and oversight is expanding continuously. Grounded in archival research, my dissertation consists of three studies that explore the features of audit committees in monitoring both financial reporting and broader areas, such as cybersecurity.

The first paper, co-authored with Gopal Krishnan and Wei Yu, examines the implications of audit committee (AC) director departure for financial reporting quality and audit risk. We find that the departures in the firms with most concerning AC departures are associated with a higher likelihood of a future “Big R” restatement announcement and auditor …


Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang Jan 2025

Safeguard Cyberspace In Ransomware Era: Risk Analysis & Cyber Insurance, Li Huang

Electronic Theses & Dissertations (2024 - present)

The increasing frequency and severity of ransomware attacks pose significant challenges for organizational cybersecurity. Fragmentation across disciplines in cyber defense has created practical gaps in the development of the necessary capabilities needed to address rapidly evolving cyber threats. This study explores the impact of ransomware attacks and the evolving role of cyber insurance as a proactive cybersecurity partner. Bridging the gap between actuarial science and cyber risk management, it proposes an interdisciplinary framework that quantifies the impact of ransomware and integrates cyber insurance into cybersecurity strategies.

The primary contribution of this study is methodology. We present a framework that remains …


Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu Jan 2025

Cyberattacks On Port Infrastructures: A Decade Of Trends, Incidents, And Mitigation Strategies (2011-2024), Minodora Badea, Olga Bucovetchi, Adrian V. Gheorghe, Gabriel Raicu

Engineering Management & Systems Engineering Faculty Publications

Port infrastructures are critical to global trade, handling over 80% of the world's cargo by volume. However, their increasing reliance on digital technologies has exposed them to a wide range of cyber threats. This paper provides a comprehensive analysis of cyberattacks targeting port infrastructures from 2011 to the present. We examine the types of attacks, geographical distribution, notable incidents, and underlying vulnerabilities. Additionally, we discuss mitigation strategies and future directions for enhancing cybersecurity in the maritime sector. Our findings highlight the urgent need for robust regulatory frameworks, advanced technological solutions, and collaborative efforts to safeguard critical port operations.


Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang Dec 2024

Safeguarding Virtual Healthcare: A Novel Attacker-Centric Model For Data Security And Privacy, Suvineetha Herath, Haywood Gelman, John Hastings, Yong Wang

Research & Publications

The rapid growth of remote healthcare delivery has introduced significant security and privacy risks to protected health information (PHI). Analysis of a comprehensive healthcare security breach dataset covering 2009-2023 reveals their significant prevalence and impact. This study investigates the root causes of such security incidents and introduces the Attacker-Centric Approach (ACA), a novel threat model tailored to protect PHI. ACA addresses limitations in existing threat models and regulatory frameworks by adopting a holistic attacker-focused perspective, examining threats from the viewpoint of cyber adversaries, their motivations, tactics, and potential attack vectors. Leveraging established risk management frameworks, ACA provides a multi-layered approach …


Organizational Readiness Assessment For Fraud Detection And Prevention: Case Of Airlines Sector And Electronic Payment, Sultan Ayed Alghamdi Jan 2023

Organizational Readiness Assessment For Fraud Detection And Prevention: Case Of Airlines Sector And Electronic Payment, Sultan Ayed Alghamdi

Dissertations and Theses

Payment processing systems have advanced significantly in the airline business. Because e-payments are easy, they have captured the attention of many companies in the aviation industry and are quickly becoming the dominant means of payment. However, as technology advances, fraud grows at a comparable rate. Over the years, there has been a surge in payment fraud incidents in the airline sector, reducing the platform's trustworthiness. Despite attempts to eliminate e-payment fraud, decision-makers lack the technical expertise required to use the finest fraud detection and prevention assessments; this research recognizes the lack of an established decision model as a hurdle and …


Retention Of Qualified Cybersecurity Professionals: A Qualitative Study, Andrew Ishmael, Leila Halawi Apr 2022

Retention Of Qualified Cybersecurity Professionals: A Qualitative Study, Andrew Ishmael, Leila Halawi

Publications

The current endeavors to retain cybersecurity professionals are not enough to sustain the needs of the U.S. workforce. The researchers aim to explore retention strategies for qualified cybersecurity professionals supporting U.S. government contracts at a leading global security company. The researchers interviewed a sample of qualified cybersecurity professionals supporting U.S. government contracts to get essential information on retention in the cybersecurity profession. The researchers proposed four distinct pillars to make up the strategic framework for retaining qualified cybersecurity professionals.


Adapting Financial Technology Standards To Blockchain Platforms, Gabriel Bello Jan 2019

Adapting Financial Technology Standards To Blockchain Platforms, Gabriel Bello

Theses and Dissertations

Traditional payment systems have standards designed to keep transaction data secure, but blockchain systems are not in scope for such security standards. We compare the Payment Application Data Security Standard’s (PA-DSS) applicability towards transaction-supported blockchain platforms to test the standard’s applicability. By highlighting the differences in implementation on traditional and decentralized transaction platforms, we critique and adapt the standards to fit the decentralized model. In two case studies, we analyze the QTUM and Ethereum blockchain platforms’ industry compliance, as their payment platforms support transactions equivalent to that of applications governed by the PA-DSS. We determine QTUM’s and Ethereum’s capabilities to …


Ua8 It Security Bulletins, Wku Information Technology Jan 2018

Ua8 It Security Bulletins, Wku Information Technology

WKU Administration Documents

IT Security Bulletins issued in 2018 to faculty and staff via email.

  • Ciampa, Mark. Protecting Your Critical Email Password
  • Alteryx Data Breach
  • Securing the Human
  • New to WKU?
  • Spam
  • University Policy
  • Personnel Changes
  • Password Extortion
  • Facebook Messenger Scam
  • Privacy
  • Phishing


Ua8 It Security Bulletin, Wku Information Technology Aug 2017

Ua8 It Security Bulletin, Wku Information Technology

WKU Administration Documents

WKU Information Technology security bulletin issued to faculty & staff via email.

  • Ciampa, Mark. Ransomware
  • Securing the Human
  • New to WKU?
  • Phone Scams
  • Phishing
  • SMiShing
  • Handling Sensitive Data
  • University Policy