kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The use of simulations in economic cybersecurity decision-making
Norwegian Univ Sci & Technol, Dept Informat Secur & Commun Technol, Hgsk Ringen 1, N-7034 Trondheim, Norway.;RISE Res Inst Sweden, POB 1263, SE-16429 Kista, Sweden..
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID. RISE Res Inst Sweden, POB 1263, SE-16429 Kista, Sweden.;Swedish Def Univ, POB 27805, SE-11593 Stockholm, Sweden..ORCID iD: 0000-0003-2017-7914
2025 (English)In: Journal of Cybersecurity, ISSN 2057-2085, Vol. 11, no 1, article id tyaf003Article in journal (Refereed) Published
Abstract [en]

This paper presents an in-depth examination of the use of simulations in economic cybersecurity decision-making, highlighting the dual nature of their potential and the challenges they present. Drawing on examples from existing studies, we explore the role of simulations in generating new knowledge about probabilities and consequences in the cybersecurity domain, which is essential in understanding and managing risk and uncertainty. Additionally, we introduce the concepts of "bookkeeping" and "abstraction" within the context of simulations, discussing how they can sometimes fail and exploring the underlying reasons for their failures. This discussion leads us to suggest a framework of considerations for effectively utilizing simulations in cybersecurity. This framework is designed not as a rigid checklist but as a guide for critical thinking and evaluation, aiding users in assessing the suitability and reliability of a simulation model for a particular decision-making context. Future work should focus on applying this framework in real-world settings, continuously refining the use of simulations to ensure they remain effective and relevant in the dynamic field of cybersecurity.

Place, publisher, year, edition, pages
Oxford University Press (OUP) , 2025. Vol. 11, no 1, article id tyaf003
Keywords [en]
simulations, economics, decision-making under risk, decision-making under uncertainty, bias
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:kth:diva-360444DOI: 10.1093/cybsec/tyaf003ISI: 001419613000001Scopus ID: 2-s2.0-85218089039OAI: oai:DiVA.org:kth-360444DiVA, id: diva2:1940367
Note

QC 20250303

Available from: 2025-02-26 Created: 2025-02-26 Last updated: 2025-03-03Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Franke, Ulrik

Search in DiVA

By author/editor
Franke, Ulrik
By organisation
Media Technology and Interaction Design, MID
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 84 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf