C. Hernandez Ganan
Please Note
11 records found
1
Vulnerability Disclosure Programs
A Multiple Case Study on the Factors Influencing Vendors’ Decision on Adopting Coordinated Vulnerability Disclosure Programs
Using a multiple case study approach and guided by the Technology-Organization-Environment (TOE) framework and Stakeholder Theory, this study examines how technological readiness, organizational culture, and environmental pressures affect the adoption of CVD programs. The analysis is based on 15 semi-structured interviews with security professionals from vendors with and without CVD programs.
The findings reveal that successful CVD adoption is often driven by strong internal capabilities, openness to transparency, support from leadership, and external regulatory pressure. In contrast, barriers include resource limitations, reputational concerns, and unclear internal processes. The study highlights the importance of third-party platforms, legal guidance, and a tailored approach that aligns with the organization's risk profile and industry context.
This research contributes to the academic literature by shifting attention from post-adoption practices to the decision-making processes leading to adoption. It provides actionable recommendations for vendors and stakeholders to improve vulnerability management and increase preparedness in an increasingly complex digital environment. ...
Using a multiple case study approach and guided by the Technology-Organization-Environment (TOE) framework and Stakeholder Theory, this study examines how technological readiness, organizational culture, and environmental pressures affect the adoption of CVD programs. The analysis is based on 15 semi-structured interviews with security professionals from vendors with and without CVD programs.
The findings reveal that successful CVD adoption is often driven by strong internal capabilities, openness to transparency, support from leadership, and external regulatory pressure. In contrast, barriers include resource limitations, reputational concerns, and unclear internal processes. The study highlights the importance of third-party platforms, legal guidance, and a tailored approach that aligns with the organization's risk profile and industry context.
This research contributes to the academic literature by shifting attention from post-adoption practices to the decision-making processes leading to adoption. It provides actionable recommendations for vendors and stakeholders to improve vulnerability management and increase preparedness in an increasingly complex digital environment.
Hourly Certificate Framework
Framework for Integrating Hourly Certificates into the Guarantees of Origin Scheme within the AIB
This thesis develops a comprehensive framework for the integration of hourly certificates within the AIB infrastructure, combining regulatory, technical, and cybersecurity perspectives. Adopting a Design Science Research approach, the study maps the alignment between existing EU legislation (RED II/III, EN 16325, Commission Implementing Regulation 2023/1162) and emerging standards such as EnergyTag, PJM GATS, and Flexidao granular certificate architecture. It then proposes a revised data-attribute model and process flow compatible with the EECS lifecycle, covering issuance, transfer, cancellation, and storage events, and introduces a STRIDE-based threat model to assess data integrity, authentication, and scalability risks across six trust boundaries. The proposed framework was validated through semi-structured interviews with four domain experts representing registry operators, market innovators, and regulatory bodies.
This research was conducted in collaboration with Flexidao, a software-as-a-service company that offers advanced data, software and advisory solutions to manage, trade and report on renewable energy portfolios, and it is also an accredited issuer of granular certificates.
The results demonstrate that hourly certificates are technically feasible within the current EECS structure, provided that registries implement timestamp granularity to the hourly level and adopt cryptographic mechanisms (digital signatures, append-only logs, Merkle-tree chaining) to ensure traceability and non-repudiation. Expert feedback confirmed strong consensus (3 of 4) on the necessity of hourly matching to restore transparency and public trust in energy disclosure, though all participants highlighted significant implementation costs, data-scalability challenges, and limited current market demand. The analysis further identifies storage event linkage as a pivotal extension to guarantee accurate tracking of renewable energy use and to enable 24/7 matching of stored electricity.
By bridging regulatory requirements and digital infrastructure design, this thesis contributes a novel, technically grounded roadmap for operationalising hourly GOs within the European context. It advances both policy and academic understanding by connecting energy governance with trustworthy data systems and by outlining practical measures for secure, interoperable, and scalable deployment of hourly certificates across Europe.
Keywords: Guarantees of Origin (GOs); Granular Certificates (GCs); 24/7 Carbon-Free Energy (CFE); AIB; EECS; EnergyTag; Flexidao; RED II/III; STRIDE.
...
This thesis develops a comprehensive framework for the integration of hourly certificates within the AIB infrastructure, combining regulatory, technical, and cybersecurity perspectives. Adopting a Design Science Research approach, the study maps the alignment between existing EU legislation (RED II/III, EN 16325, Commission Implementing Regulation 2023/1162) and emerging standards such as EnergyTag, PJM GATS, and Flexidao granular certificate architecture. It then proposes a revised data-attribute model and process flow compatible with the EECS lifecycle, covering issuance, transfer, cancellation, and storage events, and introduces a STRIDE-based threat model to assess data integrity, authentication, and scalability risks across six trust boundaries. The proposed framework was validated through semi-structured interviews with four domain experts representing registry operators, market innovators, and regulatory bodies.
This research was conducted in collaboration with Flexidao, a software-as-a-service company that offers advanced data, software and advisory solutions to manage, trade and report on renewable energy portfolios, and it is also an accredited issuer of granular certificates.
The results demonstrate that hourly certificates are technically feasible within the current EECS structure, provided that registries implement timestamp granularity to the hourly level and adopt cryptographic mechanisms (digital signatures, append-only logs, Merkle-tree chaining) to ensure traceability and non-repudiation. Expert feedback confirmed strong consensus (3 of 4) on the necessity of hourly matching to restore transparency and public trust in energy disclosure, though all participants highlighted significant implementation costs, data-scalability challenges, and limited current market demand. The analysis further identifies storage event linkage as a pivotal extension to guarantee accurate tracking of renewable energy use and to enable 24/7 matching of stored electricity.
By bridging regulatory requirements and digital infrastructure design, this thesis contributes a novel, technically grounded roadmap for operationalising hourly GOs within the European context. It advances both policy and academic understanding by connecting energy governance with trustworthy data systems and by outlining practical measures for secure, interoperable, and scalable deployment of hourly certificates across Europe.
Keywords: Guarantees of Origin (GOs); Granular Certificates (GCs); 24/7 Carbon-Free Energy (CFE); AIB; EECS; EnergyTag; Flexidao; RED II/III; STRIDE.
Bridging the Gap: A Socio-Technical Framework for Enhancing Application Interoperability in the AEC Industry
A design research exploring digital innovation through technical and organizational strategies
The framework proposed in this research aims to bridge these gaps by combining ontology development and semantic web technologies with middleware integration, which should enhance data exchange and improve standardization. On the non-technical side, the framework emphasizes the importance of collaboration across organizations through coalition-building, the development of standardized contracts, and ensuring strategic alignment.
Ultimately, this research not only presents a practical solution to the interoperability challenges in the AEC industry, but it also contributes to the larger conversation on digital transformation within the sector. By aligning technical innovations with organizational strategies, the proposed framework has the potential to improve productivity by encourage innovation. The study highlights the importance of integrating both technical and organizational perspectives in order to create scalable and effective solutions. ...
The framework proposed in this research aims to bridge these gaps by combining ontology development and semantic web technologies with middleware integration, which should enhance data exchange and improve standardization. On the non-technical side, the framework emphasizes the importance of collaboration across organizations through coalition-building, the development of standardized contracts, and ensuring strategic alignment.
Ultimately, this research not only presents a practical solution to the interoperability challenges in the AEC industry, but it also contributes to the larger conversation on digital transformation within the sector. By aligning technical innovations with organizational strategies, the proposed framework has the potential to improve productivity by encourage innovation. The study highlights the importance of integrating both technical and organizational perspectives in order to create scalable and effective solutions.
Exploring the Autonomous System Number Ecosystem
A Qualitative Exploration of Policies Governing Internet Number Resources
The research highlights regional differences in ASN policies and the effects on stakeholders. It also explores the broader consequences of these policies for the global internet infrastructure. Based on the findings, several recommendations are proposed to harmonize policies, improve transparency, and ensure that the governance of ASNs remains responsive to the evolving needs of the Internet. The study concludes by addressing the critical balance between financial sustainability for RIRs and the accessibility of resources for diverse stakeholders. ...
The research highlights regional differences in ASN policies and the effects on stakeholders. It also explores the broader consequences of these policies for the global internet infrastructure. Based on the findings, several recommendations are proposed to harmonize policies, improve transparency, and ensure that the governance of ASNs remains responsive to the evolving needs of the Internet. The study concludes by addressing the critical balance between financial sustainability for RIRs and the accessibility of resources for diverse stakeholders.
Improving financial services organisations their information security
Improving the implementation of the right access controls in IAM systems of organisations within the financial services sector
Enabling Data Marketplaces with Multi-Party Computation (MPC)
An Exploratory Study investigating the Implication of the Maturation of Multi-Party Computation (MPC) technology to the Architecture and the Threat Landscape of the Data Marketplaces
Targeting financial organisations with DDoS: a multi-sided perspective
Comparing patterns in AmpPot data to experts view on target selection in the financial sector
reputation, media attention, patching, having capable employees, and mitigation parties. Finally, this paper reflects on the implications of these findings for the financial sector and related sectors. ...
reputation, media attention, patching, having capable employees, and mitigation parties. Finally, this paper reflects on the implications of these findings for the financial sector and related sectors.