CH

C. Hernandez Ganan

info

Please Note

11 records found

A Multiple Case Study on the Factors Influencing Vendors’ Decision on Adopting Coordinated Vulnerability Disclosure Programs

As cybersecurity threats continue to evolve, organizations face increasing pressure to proactively identify and manage vulnerabilities. Coordinated Vulnerability Disclosure (CVD) programs offer a structured approach to receiving and responding to vulnerability reports. While prior research has largely focused on the operational aspects of CVD implementation, this thesis investigates the upstream decision-making factors influencing vendors' adoption of such programs.

Using a multiple case study approach and guided by the Technology-Organization-Environment (TOE) framework and Stakeholder Theory, this study examines how technological readiness, organizational culture, and environmental pressures affect the adoption of CVD programs. The analysis is based on 15 semi-structured interviews with security professionals from vendors with and without CVD programs.

The findings reveal that successful CVD adoption is often driven by strong internal capabilities, openness to transparency, support from leadership, and external regulatory pressure. In contrast, barriers include resource limitations, reputational concerns, and unclear internal processes. The study highlights the importance of third-party platforms, legal guidance, and a tailored approach that aligns with the organization's risk profile and industry context.

This research contributes to the academic literature by shifting attention from post-adoption practices to the decision-making processes leading to adoption. It provides actionable recommendations for vendors and stakeholders to improve vulnerability management and increase preparedness in an increasingly complex digital environment. ...

Framework for Integrating Hourly Certificates into the Guarantees of Origin Scheme within the AIB

The transition towards 24/7 CFE has intensified attention on temporal granularity in energy certification. Within the Guarantees of Origin (GO) system, certificates are matched with consumption annually, failing to capture the real-time relationship between generation and consumption. This temporal disconnect weakens the credibility of corporate Scope 2 accounting and limits the policy effectiveness of the Renewable Energy Directive (RED II/III). In response, a new class of “granular” or hourly certificates has emerged to enable verifiable matching between consumption and renewable production. Yet, the integration of such certificates into the Association of Issuing Bodies’ (AIB) European Energy Certificate System (EECS) remains unaddressed from both technical and institutional standpoints.
This thesis develops a comprehensive framework for the integration of hourly certificates within the AIB infrastructure, combining regulatory, technical, and cybersecurity perspectives. Adopting a Design Science Research approach, the study maps the alignment between existing EU legislation (RED II/III, EN 16325, Commission Implementing Regulation 2023/1162) and emerging standards such as EnergyTag, PJM GATS, and Flexidao granular certificate architecture. It then proposes a revised data-attribute model and process flow compatible with the EECS lifecycle, covering issuance, transfer, cancellation, and storage events, and introduces a STRIDE-based threat model to assess data integrity, authentication, and scalability risks across six trust boundaries. The proposed framework was validated through semi-structured interviews with four domain experts representing registry operators, market innovators, and regulatory bodies.
This research was conducted in collaboration with Flexidao, a software-as-a-service company that offers advanced data, software and advisory solutions to manage, trade and report on renewable energy portfolios, and it is also an accredited issuer of granular certificates.
The results demonstrate that hourly certificates are technically feasible within the current EECS structure, provided that registries implement timestamp granularity to the hourly level and adopt cryptographic mechanisms (digital signatures, append-only logs, Merkle-tree chaining) to ensure traceability and non-repudiation. Expert feedback confirmed strong consensus (3 of 4) on the necessity of hourly matching to restore transparency and public trust in energy disclosure, though all participants highlighted significant implementation costs, data-scalability challenges, and limited current market demand. The analysis further identifies storage event linkage as a pivotal extension to guarantee accurate tracking of renewable energy use and to enable 24/7 matching of stored electricity.
By bridging regulatory requirements and digital infrastructure design, this thesis contributes a novel, technically grounded roadmap for operationalising hourly GOs within the European context. It advances both policy and academic understanding by connecting energy governance with trustworthy data systems and by outlining practical measures for secure, interoperable, and scalable deployment of hourly certificates across Europe.

Keywords: Guarantees of Origin (GOs); Granular Certificates (GCs); 24/7 Carbon-Free Energy (CFE); AIB; EECS; EnergyTag; Flexidao; RED II/III; STRIDE.
...

A design research exploring digital innovation through technical and organizational strategies

The Architecture, Engineering, and Construction (AEC) industry is grappling with the growing challenge of improving communication and collaboration. As projects become more intricate, the need for seamless interoperability—where systems and teams can easily exchange and understand information—becomes even more critical. This research delves into a socio-technical approach designed to address both the technical and non-technical obstacles that hinder seamless integration and interaction across various systems and stakeholders. By conducting an in-depth review of existing literature and engaging with industry professionals, the study identifies key challenges such as fragmented information sources, misaligned organizational strategies, and complex contractual relationships.

The framework proposed in this research aims to bridge these gaps by combining ontology development and semantic web technologies with middleware integration, which should enhance data exchange and improve standardization. On the non-technical side, the framework emphasizes the importance of collaboration across organizations through coalition-building, the development of standardized contracts, and ensuring strategic alignment.
Ultimately, this research not only presents a practical solution to the interoperability challenges in the AEC industry, but it also contributes to the larger conversation on digital transformation within the sector. By aligning technical innovations with organizational strategies, the proposed framework has the potential to improve productivity by encourage innovation. The study highlights the importance of integrating both technical and organizational perspectives in order to create scalable and effective solutions. ...
Master thesis (2024) - A.P. Siregar, C. Hernandez Ganan, N. Pachos-Fokialis, Paulina Nalivaikaité
This thesis investigates the impact of market-specific factors on user acquisition for the HomeID app across various international markets. Utilising a qualitative approach, the study integrates primary data from semi-structured interviews with stakeholders and secondary data from internal company documents. Key findings reveal that cultural relevance, technological readiness, economic conditions, and administrative regulations significantly influence user acquisition. The research underscores the importance of tailored strategies for different markets, highlighting the need for localised marketing efforts, community engagement features, and adaptive pricing models. These insights provide a strategic framework for enhancing user acquisition and sustaining growth in diverse international contexts. ...

A Qualitative Exploration of Policies Governing Internet Number Resources

The internet's infrastructure relies heavily on Autonomous System Numbers (ASNs) for efficient and reliable data routing across complex networks. This thesis investigates the policies governing the allocation and management of ASNs across the five Regional Internet Registries by employing a mixed-method approach, including content analysis, surveys, and interviews. The study examines the potential impacts of recent policy changes, particularly the introduction of maintenance fees at RIPE NCC and APNIC as these fees could disproportionately affect smaller stakeholders.

The research highlights regional differences in ASN policies and the effects on stakeholders. It also explores the broader consequences of these policies for the global internet infrastructure. Based on the findings, several recommendations are proposed to harmonize policies, improve transparency, and ensure that the governance of ASNs remains responsive to the evolving needs of the Internet. The study concludes by addressing the critical balance between financial sustainability for RIRs and the accessibility of resources for diverse stakeholders. ...

Improving the implementation of the right access controls in IAM systems of organisations within the financial services sector

Master thesis (2022) - T.H.C.M. van de Weijer, P.H.A.J.M. van Gelder, C. Hernandez Ganan, Y. Ding, Nicole Daal Tweeboom

An Exploratory Study investigating the Implication of the Maturation of Multi-Party Computation (MPC) technology to the Architecture and the Threat Landscape of the Data Marketplaces

Master thesis (2019) - Jeevan Kumar, Mark de Reuver, Tobias Fiebig, Carlos Hernandez Ganan
The emergence of the Data Marketplaces is the latest iteration in the phenomenon of data-driven transformation of the world. Data marketplaces have emerged as a new form of data-driven business models which enable trading of data between the data owners/providers and data consumers by providing the necessary technological and non-technological infrastructure. These features present an alternative to the cumbersome logistics currently involved in searching, buying and selling data; thus, simplify the data supply chains between the data-driven business entities. However, they suffer to take off into mainstream success because of a myriad of reasons. Of all the reasons, 2 of them are focused in this thesis. Firstly, the difficulty involved in architecturally enabling a data marketplace platform as the prospective enabling technologies are still immature. Secondly, the uncertainty associated with the commodification of data which comprises of the intellectual property enforcement of data (data ownership), privacy and confidentiality breach (threats), regulatory ignorance (implication of GDPR), reluctance of businesses from participating because of the previous reasons et cetera. This reason is collectively referred as due to the uncertainty around the threat landscape of the data marketplaces. Multi-Party Computation (MPC) technology provide a solution to these problems. Through its capabilities to preserve the confidentiality of data architecturally and thereby securing the interests of the data actors with respect to the uncertainty of the threat landscape around data, MPC can enable safe and secure data sharing between data actors. This characteristic of MPC can help data marketplaces to overcome their challenges and foster their realisation. However, since MPC cannot handle the scale of real-life application, it is not mature enough yet to be incorporated into real-life data marketplaces. An EU funded project called SafeDEED: Safe Data-Enabled Economic Development, proposes to overcome the scalability issue and intends to achieve the maturation of MPC for real-life application. Building upon this forecast, a research was conducted to investigate the implication of the maturation of MPC technology towards the 2 problems faced by data marketplaces, architectural and threat landscape; and the same is documented in this thesis. ...
Master thesis (2019) - Altynay Orynbayeva, Marijn Janssen, Carlos Hernandez Ganan
Companies today are continually looking for new ways to digitize and automate their processes in order to maximize productivity and efficiency. Existing academic research has shown the efficiency and benefits of process automation using Robotics Process Automation (RPA). Through preliminary research, we observed that most of the companies have stagnated in a pilot or proof of concept of implementing RPA phase which implies that they are still learning how to manage RPA. The success of scaling up RPA lies in proper governance that may establish guidance, processes and mechanisms to manage and control the RPA activities in order to realize the expected benefits from technology. It is vital to assure that RPA robots are efficiently used, running as expected and following the security controls within the organization. There is a void in the academic literature which means that the current study does not provide a sufficient understanding of RPA governance, and there is no existing proper governance model for managing RPA. Therefore, the main goal of this master research is to develop a governance model for Robotics Process Automation using design science methodology from a management and operational perspective. The developed RPA governance model is based on the synthesis of the literature on RPA, IT and BPM governance and the findings from the case study analysis. ...
Malicious software such as botnets are a threat to society and increasingly so through Internet of Things (IoT) devices. The large volume, pervasiveness and high vulnerability of IoT devices make them low hanging fruit for malicious actors. Currently, the biggest threat for insecure IoT devices is Mirai, a botnet which is deployed for DDoS attacks. Home users often fail to detect and resolve Mirai on their IoT devices. For this reason, Internet Service Providers (ISP) increasingly take efforts to increase remediation. Sending their infected customers a notifications containing cleanup instructions is currently the most feasible measure on a large scale. However, previous studies point out that it is not clear how people process these notifications, if they comply with it and how this effects the remediation rate and speed. The central research question of this study is ‘What is the role of IoT device end users in Mirailike bot remediation?’. We have conducted an eight-week experiment at the KPN Abuse Desk that notifies customers about abuse incidents. 177 Mirai-infected consumers have been randomly assigned to a walled garden notification (i.e., a quarantined environment), an e-mail notification, or control group. All subjects within the experiment have been tracked for two weeks to estimate the infection time and are contacted afterward for interview purposes. Male consumers and consumers younger than 54 years possess relatively more often a Miraiinfected device compared to other consumers. Both e-mail and walled garden notifications are effective in reaching consumers, informing them and encouraging them to take action. The majority of consumers do not follow the recommendations provided by the notification. In contrast, the number of actions that are performed while not mentioned in the notifications is remarkably high. Since many consumers asked for additional help, we conclude that consumers appear don’t have a full understanding of how to tackle the problem. In the control group, several consumers remediated Mirai unintentionally. However, these cases do not explain all observed remediation. Using two survival analysis modeling techniques, we find that consumers placed in a walled garden have a 29% to 85% shorter infection time than other consumers. We conclude that there is a discrepancy between stated behavior and the actual behavior of consumers. Although we cannot observe all cleanup efforts of consumers, we observed that awareness of the Mirai-infection and the intention to comply with the recommended actions influence that unobserved behavior. Gender also influences the unobserved behavior. Women clean up their device quicker than men while their statements during the interviews contradict this. One explanation is that women may unintentionally clean up their device. We conclude that age, consumer market, device type and customer satisfaction have no significant influence on remediation. We believe that it is unlikely that all unexplained remediation can be attributed to the unobserved behavior. We thus cannot explain all observed remediation from the user perspective. Therefore, we argue that future work must also focus on the attacker perspective. Since we only observed Mirai-infections, we cannot exclude the possibility that competing malware confiscated infected devices within our experiment. In addition, novel Mirai variants may have evolved scanning behavior which obstructed proper detection of infected bots. ...
Master thesis (2018) - Samuel Natalius, Michel van Eeten, Carlos Hernandez Ganan, Mark de Reuver, Samaneh Tajalizadehkhoob
Understanding target selection is a step before making a suitable proactive measure to address the complex issue of banking malware in online banking landscape. Despite several previous studies, gaps in the research of target selection are still present like the lack of attention to the non-targeted entities, the presence of other potential factors and the change in the landscape itself. Seeking to address the gaps, this research is conducted to find out what characteristics related to online banking services can affect the likelihood of the malware attack to them. The research starts with literature review to identify characteristics which can potentially explain the target selection, in accordance to aspects of Routine Activity Theory (RAT). Next, data about malware attack and the list of banks as well as several external data like language and authentication factor of online banking were collected and processed for quantitative analysis. Several metrics to approach the actual attack count were proposed and other metrics were extracted from the data. Some interesting findings were captured, like, within the period February 2014 – November 2017, from 5,039 banks in the EU, 1,188 banks were without any online banking services and from 3,851 banks with an online banking service, 1,802 banks were found targeted and 2,049 not targeted. Some malware variants were also seen performing targeted attacks. Meanwhile, it is found from explanatory analysis that some characteristics maintain their significance in explaining the likelihood of attack, like the presence of English and two-factor authentication. Services offering English language were seen to be more attacked. Contrarily, services which implemented 2-factor authentication were found to receive fewer attacks, although more entities with such authentication were targeted. Meanwhile, some other variables were getting less significant when more controlling factors are taken into account, indicating that some variables were relatively more or less important than others. Future work is needed in order to enhance the model so that more plausible conclusion can be obtained, such as improving and adding more data as well as including more factors, especially those that are financial and market related. ...

Comparing patterns in AmpPot data to experts view on target selection in the financial sector

Master thesis (2017) - Ryan Cheung, Michel van Eeten, Carlos Hernandez Ganan, André Herdeiro Teixeira, Vincent Waart
Currently, DDoS attacks have become inevitable for financial services and their threat keeps rising. Numerous researches have focused on the technical since the rise of DDoS amplification attacks. However, there is less understanding regarding their target selection on financial services. This research uses a mixed method approach to capture factors that influence cybercriminals in their selection of victims. Via data from amplification DDoS honeypots, various factors are identified and explanatory models are provided. In addition, financial cyber security experts are consulted to assess their perspective on target selection. The analysis demonstrates that certain countries have significantly higher or lower victims, which can partially be explained through country level factors such as the ICT development and Normal GDP Per capita. In addition, the ICT development influences the duration of the attack significantly. The findings also indicate that organizational size, as measured by market value, showed a limited effect on the number of attacks. Contrary, experts regarded the size as a highly influential factor. The analyses furthermore demonstrate that financial organisations incur significantly more attacks on Friday than on any other day. Moreover, the experts mention additional target selection factors such as,
reputation, media attention, patching, having capable employees, and mitigation parties. Finally, this paper reflects on the implications of these findings for the financial sector and related sectors. ...