Decision Making and Biases in Cybersecurity Capability Development: Evidence from a Simulation Game Experiment

نویسندگان

  • Mohammad S. Jalali
  • Michael D. Siegel
  • Stuart E. Madnick
چکیده

Despite the rise in the frequency and intensity of cyber-attacks, many organizations are still negligent in their management of cybersecurity practices. To address this shortcoming, we developed a simulation game to understand and improve how managers make investment decisions in building cybersecurity capabilities. The simulation game focuses on how managers’ decisions may impact the profits of their business, considering the costs of cybersecurity capability development, the unpredictability of cyber-attacks, and potential delays in building capabilities. In an experiment with 67 individuals, we recorded and analyzed 1,479 simulation runs. We compared the performances of a group of experienced cybersecurity professionals with diverse industry backgrounds to an inexperienced control group. Both groups exhibited similar systematic errors in decision-making, indicative of erroneous heuristics when dealing with uncertainty. Experienced subjects did not understand the mechanisms of delays any better than inexperienced subjects, and in fact, performed worse in a less uncertain environment, suggesting more developed heuristics. Our findings highlight the importance of training and education for decision-makers and professionals in cybersecurity, and lay the groundwork for future research in uncovering mental biases about the complexities of cybersecurity capability development.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Mitigating Evidentiary Bias in Planning and Policy-Making; Comment on “Reflective Practice: How the World Bank Explored Its Own Biases?”

The field of cognitive psychology has increasingly provided scientific insights to explore how humans are subject to unconscious sources of evidentiary bias, leading to errors that can affect judgement and decision-making. Increasingly these insights are being applied outside the realm of individual decision-making to the collective arena of policy-making as well. A recent editorial in this jou...

متن کامل

Effect of Cognitive Biases on Rationality of Economic Decision Making under Risk among Students of Shahid Beheshti University

The purpose of this study is to determine the quality of individual economic decision making under risk and uncertainty. The research method is a quasi-experiment with single group and a post-test. The total population of the students of Shahid Beheshti University in 97 was 8.700 and due to non-normal distribution, we should use non-parametric Wilcoxon test, with sample of 180. The tool used to...

متن کامل

Risk management in urban tunnels using methods of game theory and multi-criteria decision-making

In general, underground spaces are associated with high risks because of their high uncertainty in geotechnical environments. Since most accidents and incidents in these structures are often associated with uncertainty, the development of risk analysis and management methods and prevention of accidents are essential. A deeper recognition of the factors affecting the implementation process can p...

متن کامل

The Effects of the CEO’s Perceptual Bias in Economic Decision-Making and Judgment on the Capabilities of the Financial Reporting Quality

The current research sets out to identify and scrutinize the impact of the CEO’s perceptual biases in judgment and economic decision-making on the reporting quality of the firms listed on the Tehran Stock Exchange. Adopting a mixed method, the present study first seeks to detect the components and indices of CEO’s perceptual biases via critical appraisal and with the special participation of 10...

متن کامل

Evidence for Informing Health Policy Development in Low- Income Countries (LICS): Perspectives of Policy Actors in Uganda

Background Although there is a general agreement on the benefits of evidence informed health policy development given resource constraints especially in Low-Income Countries (LICs), the definition of what evidence is, and what evidence is suitable to guide decision-making is still unclear. Our study is contributing to filling this knowledge gap. We aimed to explore health policy actors’ views r...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1707.01031  شماره 

صفحات  -

تاریخ انتشار 2017