M.J.G. van Eeten
Please Note
24 records found
1
AI in the Middle
A sociomaterial study of a GenAI chatbot in product-to-sales knowledge communication
The findings show that the chatbot reorganises rather than simply replaces the existing knowledge channel. First, product documentation increasingly becomes a machine-readable organisational resource, although this transition is uneven and constrained by fragmented and outdated source material. Second, accountability for AI-generated answers becomes distributed across customer-facing users, documentation owners, the platform team and the vendor. Third, routine factual questions increasingly move to the chatbot, while judgement, customer-specific interpretation and commercial nuance continue to depend on people.
The central finding is a broken correction circuit: problems are often encountered on the customer-facing side, while the actor able to address them may sit elsewhere, yet no consistently used process connects detection to correction. The study concludes that reliable AI-mediated knowledge exchange depends not only on producing answers at scale, but also on maintaining source knowledge, preserving human escalation paths and building mechanisms through which errors, feedback and field signals can travel back to the people able to act on them. ...
The findings show that the chatbot reorganises rather than simply replaces the existing knowledge channel. First, product documentation increasingly becomes a machine-readable organisational resource, although this transition is uneven and constrained by fragmented and outdated source material. Second, accountability for AI-generated answers becomes distributed across customer-facing users, documentation owners, the platform team and the vendor. Third, routine factual questions increasingly move to the chatbot, while judgement, customer-specific interpretation and commercial nuance continue to depend on people.
The central finding is a broken correction circuit: problems are often encountered on the customer-facing side, while the actor able to address them may sit elsewhere, yet no consistently used process connects detection to correction. The study concludes that reliable AI-mediated knowledge exchange depends not only on producing answers at scale, but also on maintaining source knowledge, preserving human escalation paths and building mechanisms through which errors, feedback and field signals can travel back to the people able to act on them.
How IT Auditors and Cybersecurity Consultants Operationalize EU Digital Legislation in the Netherlands
A comparative study of how GDPR, NIS2, DORA and the AI Act are operationalized into compliance practices
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change. ...
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change.
Beyond AI Adoption
A Comparative Analysis of Perceived AI Value Realization across Organizational Levels in a Construction Company
This study addresses the research question: How is AI value realization perceived across organizational levels within a construction company? A qualitative single-case study was conducted within a large Dutch construction and infrastructure organization through 29 semi-structured interviews with managers (n = 14) and employees (n = 15). Using a Gioia-inspired methodology, the data were analysed through both cross-group and within-group comparisons across five aggregate dimensions: adoption, AI use practices, perceptions, value realization, and enabling dynamics. The findings demonstrate that AI adoption is widespread but unevenly experienced. AI use is predominantly assistive across both organizational groups, while automation-oriented and transformational applications remain comparatively limited. Across both managers and employees, bounded use emerged as the dominant AI use pattern, reflecting deliberate restrictions on AI authority in favour of continued human judgement, accountability, and professional expertise.
The study identifies a structural asymmetry in perceived AI value realization. Managers predominantly describe realized benefits, including efficiency gains, improved decision support, and enhanced work experience. Employees also perceive positive value but report substantially more constrained value, including verification burden, operational inefficiencies, job-related concerns, and unrealized collaborative benefits. The collaboration gap emerged as the clearest illustration of this asymmetry, as employees uniquely anticipated AI-enabled collaboration and uniquely experienced its absence, whereas managers were largely absent from both sides of this discussion.
A second key finding concerns the enabling dynamics underpinning perceived AI value realization. Human capability emerged as the primary enabling dynamic, followed by organizational coordination, while technical capability, although necessary, proved comparatively less decisive. The findings indicate that the principal barriers to AI value realization are not technological limitations, but the organizational and human conditions required to translate existing AI capabilities into sustained practice.
The study makes three theoretical contributions. First, it extends socio-technical theory by demonstrating that perceived AI value is distributed asymmetrically across organizational levels rather than uniformly across organizations. Second, it introduces bounded use and bounded acceptance as complementary concepts explaining how professionals simultaneously adopt AI while deliberately limiting its authority. Third, it develops a dynamic perspective on AI value realization by conceptualizing human, organizational, and technical factors as interacting enabling dynamics rather than static conditions.
To support practice, two complementary frameworks were developed. Framework 1 provides a comparative diagnosis of managers' and employees' current AI experiences, while Framework 2 translates these findings into a differentiated managerial pathway for strengthening human capability, organizational coordination, and technical support. Together, the findings suggest that improving AI value realization depends less on acquiring more advanced technologies than on creating the organizational conditions through which AI-generated value can be more evenly perceived and realized across organizational levels.
...
This study addresses the research question: How is AI value realization perceived across organizational levels within a construction company? A qualitative single-case study was conducted within a large Dutch construction and infrastructure organization through 29 semi-structured interviews with managers (n = 14) and employees (n = 15). Using a Gioia-inspired methodology, the data were analysed through both cross-group and within-group comparisons across five aggregate dimensions: adoption, AI use practices, perceptions, value realization, and enabling dynamics. The findings demonstrate that AI adoption is widespread but unevenly experienced. AI use is predominantly assistive across both organizational groups, while automation-oriented and transformational applications remain comparatively limited. Across both managers and employees, bounded use emerged as the dominant AI use pattern, reflecting deliberate restrictions on AI authority in favour of continued human judgement, accountability, and professional expertise.
The study identifies a structural asymmetry in perceived AI value realization. Managers predominantly describe realized benefits, including efficiency gains, improved decision support, and enhanced work experience. Employees also perceive positive value but report substantially more constrained value, including verification burden, operational inefficiencies, job-related concerns, and unrealized collaborative benefits. The collaboration gap emerged as the clearest illustration of this asymmetry, as employees uniquely anticipated AI-enabled collaboration and uniquely experienced its absence, whereas managers were largely absent from both sides of this discussion.
A second key finding concerns the enabling dynamics underpinning perceived AI value realization. Human capability emerged as the primary enabling dynamic, followed by organizational coordination, while technical capability, although necessary, proved comparatively less decisive. The findings indicate that the principal barriers to AI value realization are not technological limitations, but the organizational and human conditions required to translate existing AI capabilities into sustained practice.
The study makes three theoretical contributions. First, it extends socio-technical theory by demonstrating that perceived AI value is distributed asymmetrically across organizational levels rather than uniformly across organizations. Second, it introduces bounded use and bounded acceptance as complementary concepts explaining how professionals simultaneously adopt AI while deliberately limiting its authority. Third, it develops a dynamic perspective on AI value realization by conceptualizing human, organizational, and technical factors as interacting enabling dynamics rather than static conditions.
To support practice, two complementary frameworks were developed. Framework 1 provides a comparative diagnosis of managers' and employees' current AI experiences, while Framework 2 translates these findings into a differentiated managerial pathway for strengthening human capability, organizational coordination, and technical support. Together, the findings suggest that improving AI value realization depends less on acquiring more advanced technologies than on creating the organizational conditions through which AI-generated value can be more evenly perceived and realized across organizational levels.
Beyond Accuracy: A Mixed-Method Exploration of Hash Database Verification
Focusing on the Detection of Child Sexual Abuse Material and Terrorist Content Online
This thesis investigates the characteristics of verification processes in CSAM and TCO hash databases, with a particular focus on triple verification. Using a multiphase mixed-methods design, the study integrates qualitative insights from stakeholder interviews, an annotation experiment, and a follow-up focus group with annotators.
The interviews with experts highlighted variations in verification workflows, ranging from single-rater decisions to triple verification models. While triple verification is seen as a standard for increasing trust and minimizing false positives, its feasibility in terms of emotional toll and volume has been questioned. Thematic insights centered around benefits (e.g., legal considerations), challenges (e.g., emotional toll, inconsistent thresholds), necessity (e.g., utility and impact), future opportunities (e.g., automation), and differences between CSAM and TCO workflows.
In the experiment, two raters from the Dutch National Police classified 2,031 real potentially illegal items under two different conditions. In the blind phase, raters voted independently, whereas in the non-blind phase, prior votes were visible. Overall inter-rater agreement rose from 89.4% in the blind condition to 97.1% in the non-blind condition. A statistically significant association was found between voting order and agreement rates, suggesting that seeing one or two prior votes can subtly influence rater alignment.
The focus group offered further insight into the found disagreements. A key theme was the importance of recognizing image series: individual images were often reclassified as illegal when identified as part of a known CSAM series. Age estimation was also a recurring source of ambiguity, particularly when visual quality was poor or when victims’ physical development and ethnicity made assessment difficult. Raters relied on indicators such as skin texture, body proportions, and dental features, though these cues were often interpreted differently.
The findings emphasize the need for verification systems that are both flexible and context-sensitive. Not all cases require the same level of scrutiny: while baseline CSAM could be classified with fewer checks, ambiguous cases require more checks. Rather than enforcing uniformity, organizations should accommodate interpretive differences while safeguarding consistency and accountability.
...
This thesis investigates the characteristics of verification processes in CSAM and TCO hash databases, with a particular focus on triple verification. Using a multiphase mixed-methods design, the study integrates qualitative insights from stakeholder interviews, an annotation experiment, and a follow-up focus group with annotators.
The interviews with experts highlighted variations in verification workflows, ranging from single-rater decisions to triple verification models. While triple verification is seen as a standard for increasing trust and minimizing false positives, its feasibility in terms of emotional toll and volume has been questioned. Thematic insights centered around benefits (e.g., legal considerations), challenges (e.g., emotional toll, inconsistent thresholds), necessity (e.g., utility and impact), future opportunities (e.g., automation), and differences between CSAM and TCO workflows.
In the experiment, two raters from the Dutch National Police classified 2,031 real potentially illegal items under two different conditions. In the blind phase, raters voted independently, whereas in the non-blind phase, prior votes were visible. Overall inter-rater agreement rose from 89.4% in the blind condition to 97.1% in the non-blind condition. A statistically significant association was found between voting order and agreement rates, suggesting that seeing one or two prior votes can subtly influence rater alignment.
The focus group offered further insight into the found disagreements. A key theme was the importance of recognizing image series: individual images were often reclassified as illegal when identified as part of a known CSAM series. Age estimation was also a recurring source of ambiguity, particularly when visual quality was poor or when victims’ physical development and ethnicity made assessment difficult. Raters relied on indicators such as skin texture, body proportions, and dental features, though these cues were often interpreted differently.
The findings emphasize the need for verification systems that are both flexible and context-sensitive. Not all cases require the same level of scrutiny: while baseline CSAM could be classified with fewer checks, ambiguous cases require more checks. Rather than enforcing uniformity, organizations should accommodate interpretive differences while safeguarding consistency and accountability.
“How effective is an LLM in lowering the workload of the Dutch court clerks?”
The research employs a mixed research approach. The literature and desk review examines the tasks of the clerks, information about the available LLMs and prompt engineering technique. In addition to this, semi-structured interviews have been held to explore the different tasks of the clerks. Since the scope of this research is only big enough for one task, The task selection process utilized the elimination by aspects technique. After this, a targeted experiment has been conducted to analyse and evaluate the possible LLMs and select the most suitable model for this research. The effectiveness of the LLM-based prompt support have been evaluated using a mixed-methods approach, combining quantitative and qualitative data analysis, which are a within-subject experiment, semi-structured interviews, DeepEval Evaluation, expert evaluation, and a statistical analysis.
The results and the conclusion of this research are still under embargo.
...
“How effective is an LLM in lowering the workload of the Dutch court clerks?”
The research employs a mixed research approach. The literature and desk review examines the tasks of the clerks, information about the available LLMs and prompt engineering technique. In addition to this, semi-structured interviews have been held to explore the different tasks of the clerks. Since the scope of this research is only big enough for one task, The task selection process utilized the elimination by aspects technique. After this, a targeted experiment has been conducted to analyse and evaluate the possible LLMs and select the most suitable model for this research. The effectiveness of the LLM-based prompt support have been evaluated using a mixed-methods approach, combining quantitative and qualitative data analysis, which are a within-subject experiment, semi-structured interviews, DeepEval Evaluation, expert evaluation, and a statistical analysis.
The results and the conclusion of this research are still under embargo.
Trust at First Sight
A User Study of Developers’ Practices and Perception in VS Code Extension Ecosystem
Despite growing attention to these technical threats, little is known about how such risks are perceived and managed within organizational settings, where developer autonomy intersects with organizational governance and policy. Using a qualitative approach, interviews were conducted with 21 professionals from 19 companies across five countries to explore how developers perceive and manage the security of VS Code extensions in organizational contexts.
The findings reveal that extension management practices are largely convenience-driven, with developers relying on surface-level Marketplace signals, such as publisher verification, ratings, and download counts, that can easily be manipulated, as shown in prior research. These cues provide reassurance but not assurance, leading developers to conflate popularity or verified status with safety. In most organizations, extension governance is minimal or informal, resulting in fragmented practices where developers must independently assess security risks despite operating in managed environments.
The study concludes that secure extension use in VS Code is not merely a technical issue but a socio-technical and governance challenge that requires coordination across multiple levels. At the marketplace level, clearer communication of verification criteria, greater visibility of permissions or a modified permission model, and stronger mechanisms for signaling risk are needed. At the organizational level, structured allowlist policies, internal vetting workflows, and targeted awareness programs can bridge the gap between platform safeguards and developer behavior. At the developer level, improved understanding and interpretation of trust cues should be supported, not assumed, through organizational policy and education. Together, these measures align platform design, organizational governance, and developer practice toward a shared framework of accountability and safer extension use within professional environments.
...
Despite growing attention to these technical threats, little is known about how such risks are perceived and managed within organizational settings, where developer autonomy intersects with organizational governance and policy. Using a qualitative approach, interviews were conducted with 21 professionals from 19 companies across five countries to explore how developers perceive and manage the security of VS Code extensions in organizational contexts.
The findings reveal that extension management practices are largely convenience-driven, with developers relying on surface-level Marketplace signals, such as publisher verification, ratings, and download counts, that can easily be manipulated, as shown in prior research. These cues provide reassurance but not assurance, leading developers to conflate popularity or verified status with safety. In most organizations, extension governance is minimal or informal, resulting in fragmented practices where developers must independently assess security risks despite operating in managed environments.
The study concludes that secure extension use in VS Code is not merely a technical issue but a socio-technical and governance challenge that requires coordination across multiple levels. At the marketplace level, clearer communication of verification criteria, greater visibility of permissions or a modified permission model, and stronger mechanisms for signaling risk are needed. At the organizational level, structured allowlist policies, internal vetting workflows, and targeted awareness programs can bridge the gap between platform safeguards and developer behavior. At the developer level, improved understanding and interpretation of trust cues should be supported, not assumed, through organizational policy and education. Together, these measures align platform design, organizational governance, and developer practice toward a shared framework of accountability and safer extension use within professional environments.
Adoption of AI in Cybersecurity
Bridging the Gap Between Innovation and Application
Despite the increased importance, not all organisations have the same resources and knowledge when it comes to securing their networks against cyber adversaries.
This research tries to examine the vulnerability posture of Dutch municipal ICT networks.
To accomplish this a network ranges dataset was curated using open source intelligence techniques.
These networks, related to current and previous Dutch municipalities, have been used to collect network data scans and observe the changes in software products and versions.
Based on the data collected we can observe the software update moments for different organisations and analyse how often software products are kept up to date.
Using this network scan data and a subset of open-source products, we were able to construct a case study analysis about the general trends of vulnerability management and the influencing factors thereof.
This was done through timeline analysis, involving also software update releases, security advisories, and publicly disclosed vulnerability exploits.
Our findings show uncoordinated strategies within the different organisations and rare proactive security behaviour.
Another contribution of this study is in the sphere of reconnaissance and open source intelligence gathering, showing that publicly available information alone is a time-consuming procedure that renders very few useful data points.
These later findings have implications for both adversaries as well as security organisations, as reliable data could only be obtained through direct contact with the underlying municipality.
...
Despite the increased importance, not all organisations have the same resources and knowledge when it comes to securing their networks against cyber adversaries.
This research tries to examine the vulnerability posture of Dutch municipal ICT networks.
To accomplish this a network ranges dataset was curated using open source intelligence techniques.
These networks, related to current and previous Dutch municipalities, have been used to collect network data scans and observe the changes in software products and versions.
Based on the data collected we can observe the software update moments for different organisations and analyse how often software products are kept up to date.
Using this network scan data and a subset of open-source products, we were able to construct a case study analysis about the general trends of vulnerability management and the influencing factors thereof.
This was done through timeline analysis, involving also software update releases, security advisories, and publicly disclosed vulnerability exploits.
Our findings show uncoordinated strategies within the different organisations and rare proactive security behaviour.
Another contribution of this study is in the sphere of reconnaissance and open source intelligence gathering, showing that publicly available information alone is a time-consuming procedure that renders very few useful data points.
These later findings have implications for both adversaries as well as security organisations, as reliable data could only be obtained through direct contact with the underlying municipality.
This research aims to investigate possibilities for the creation of a free space in the cultural sphere for digital education technology to protect from intervention by intellectual (near-) monopolies. Intellectual monopolies are companies that build their wealth by excessive monopolising access to knowledge and converting it into intellectual rents, a type of intangible assets.
The thesis are examined against the background of an overarching perspective on society as consisting of three spheres. Legal-political sphere is to develop laws and regulations; Economic sphere is about production, distribution (trading) and consumption of goods; Cultural sphere is to generate idea and knowledge. In each sphere, there also are three aspects belonging to legal-politics, economics, and culture.
The thesis consists of two parts and adopts a macro-to-micro research framework. In the first part, the research focuses on the macro-socialistic level first and then zooms in to business level (education technology) by analysing existing literature. This part investigates how intellectual monopolies emerge, first in general and then more specifically in digital education technology, and how they reduce freedom of education. More specifically, the thesis identifies economic, legal-political and cultural factors that promote intellectual monopoly in the digital industry, and explains how intellectual (near-)monopoly in digital education (e.g. in online-learning platforms, LMSs or video-conferencing software) arises as a consequence of particular relationships between the economic, legal-political and cultural sphere, where governments and international organisations give laws and regulation (e.g. IP law, education laws and regulation, the standardisation of education) that support the concentration of R&D in a few giant digital high-tech companies and the growth of (near-)monopoly positions in the digital education technology market, enabling high-tech giants to extract what in this study is called ‘learning-related rent’ (tangible and intangible assets formed by controlling learning tools and learning content), and reducing freedom of education (the core component of the cultural sphere).
In the second part, the thesis zoom in further to the university level and examines the possibilities decision-makers at universities have to expand freedom of choice in digital education technology for professors and students through a case study of a Dutch university. An interview is conducted as the main method of the case study to collect data. From the interview results, legal-political, economic and cultural hurdles in establishing free space in choosing education technology in the cultural sphere have been identified. ...
This research aims to investigate possibilities for the creation of a free space in the cultural sphere for digital education technology to protect from intervention by intellectual (near-) monopolies. Intellectual monopolies are companies that build their wealth by excessive monopolising access to knowledge and converting it into intellectual rents, a type of intangible assets.
The thesis are examined against the background of an overarching perspective on society as consisting of three spheres. Legal-political sphere is to develop laws and regulations; Economic sphere is about production, distribution (trading) and consumption of goods; Cultural sphere is to generate idea and knowledge. In each sphere, there also are three aspects belonging to legal-politics, economics, and culture.
The thesis consists of two parts and adopts a macro-to-micro research framework. In the first part, the research focuses on the macro-socialistic level first and then zooms in to business level (education technology) by analysing existing literature. This part investigates how intellectual monopolies emerge, first in general and then more specifically in digital education technology, and how they reduce freedom of education. More specifically, the thesis identifies economic, legal-political and cultural factors that promote intellectual monopoly in the digital industry, and explains how intellectual (near-)monopoly in digital education (e.g. in online-learning platforms, LMSs or video-conferencing software) arises as a consequence of particular relationships between the economic, legal-political and cultural sphere, where governments and international organisations give laws and regulation (e.g. IP law, education laws and regulation, the standardisation of education) that support the concentration of R&D in a few giant digital high-tech companies and the growth of (near-)monopoly positions in the digital education technology market, enabling high-tech giants to extract what in this study is called ‘learning-related rent’ (tangible and intangible assets formed by controlling learning tools and learning content), and reducing freedom of education (the core component of the cultural sphere).
In the second part, the thesis zoom in further to the university level and examines the possibilities decision-makers at universities have to expand freedom of choice in digital education technology for professors and students through a case study of a Dutch university. An interview is conducted as the main method of the case study to collect data. From the interview results, legal-political, economic and cultural hurdles in establishing free space in choosing education technology in the cultural sphere have been identified.
The Risks and Regulation of Decentralized Finance
A Recommendation to Policy Makers
Thus, this research offers an evaluation of the MiCA framework by adopting World Economic Forum’s DeFi white paper risk framework and interviews with the industry experts to generate both qualitative and quantitative data that is used to construct policy considerations for future amendments. By conducting interviews with 8 legal experts, the study provides insights into the strengths and weaknesses of the MiCA framework, while the interviews with 2 respondents from crypto-asset issuer entities, 6 from crypto-asset service providers entities and 3 from institutional investors entities provided further insights into the perceptions of the industry participants on the EU crypto regulation. Moreover, the study presents the risk perceptions of each respondent groups as during the interview rounds the participants were presented 18 risks of DeFi and were asked to select the most 5 critical risks perceived by them. This information is used to reveal what risks are perceived by each group. Lastly, the study presents a content analysis to assess the extent to which the 18 risks ranked by the interviewees are addressed in the MiCA framework. In summary, the results of the study suggest many points of improvement to the MiCA framework with respect to definitions, scoping, classifications and the regulatory approach. Moreover, the results suggest that the policy makers should focus on the unaddressed risks in the future amendments and policies, most importantly on technical and operational risks that have been left out from the framework. ...
Thus, this research offers an evaluation of the MiCA framework by adopting World Economic Forum’s DeFi white paper risk framework and interviews with the industry experts to generate both qualitative and quantitative data that is used to construct policy considerations for future amendments. By conducting interviews with 8 legal experts, the study provides insights into the strengths and weaknesses of the MiCA framework, while the interviews with 2 respondents from crypto-asset issuer entities, 6 from crypto-asset service providers entities and 3 from institutional investors entities provided further insights into the perceptions of the industry participants on the EU crypto regulation. Moreover, the study presents the risk perceptions of each respondent groups as during the interview rounds the participants were presented 18 risks of DeFi and were asked to select the most 5 critical risks perceived by them. This information is used to reveal what risks are perceived by each group. Lastly, the study presents a content analysis to assess the extent to which the 18 risks ranked by the interviewees are addressed in the MiCA framework. In summary, the results of the study suggest many points of improvement to the MiCA framework with respect to definitions, scoping, classifications and the regulatory approach. Moreover, the results suggest that the policy makers should focus on the unaddressed risks in the future amendments and policies, most importantly on technical and operational risks that have been left out from the framework.
Exploring the practice of organisational Security Patch Management from a socio-technical perspective
Using a Mixed Methods Approach to investigate IT-practitioners’ decision-making and patch activity
Behind the Botnet
Evaluating Avalanche's security controls using a reconstruction of its anatomy from forensic evidence
In this work, we answer this question by analyzing Avalanche’s security controls and its business model based on longitudinal ground truth data from its criminal investigation by German law enforcement. We first analyzed previous botnet research and identified five research challenges: (1) the botnet phenomenon keeps evolving, so continuous research is required, (2) there is not yet a framework to categorize or interpret botnet evasion techniques, (3) botnet research is challenging due to the lack of large real-world datasets, (4) botnet takedowns are challenging and costly, so other avenues for intervening in botnets should be explored, and (5) more research is being done into botnet economics, but it is mostly based on case studies methodologies without access to ground truth data.
We defined the adversarial context of botnets and showed how their responses – evasion techniques – can be interpreted as security controls according to deviant security theory. We created a framework for categorizing these security controls, based on security control types and the type of threat. Turning to our data, we performed an exploratory analysis in which we processed, validated and interpreted the available data based on their different types: server images, network data and databases. Based on the insights from this analysis, we applied the business model canvas and described Avalanche’s business model. We describe how Avalanche provides it customers with proxying and domain registration services, generating on aver- age $7,500 of revenue per month from 59 customers. We identified seven security controls, three technical controls and four administrative controls, that were applied to evade detection, to increase resilience against takedowns and to conceal the ownership by the botnet operators.
Our findings show that Avalanche configured itself to adequately respond to the threats in its adversarial context. Its business model – through using different key partners and many replaceable resources – and its application of security controls – such as backups, bot monitoring and proxy architecture – created redun- dancy in Avalanche’s operation, allowing it to detect and resolve threats quickly. ...
In this work, we answer this question by analyzing Avalanche’s security controls and its business model based on longitudinal ground truth data from its criminal investigation by German law enforcement. We first analyzed previous botnet research and identified five research challenges: (1) the botnet phenomenon keeps evolving, so continuous research is required, (2) there is not yet a framework to categorize or interpret botnet evasion techniques, (3) botnet research is challenging due to the lack of large real-world datasets, (4) botnet takedowns are challenging and costly, so other avenues for intervening in botnets should be explored, and (5) more research is being done into botnet economics, but it is mostly based on case studies methodologies without access to ground truth data.
We defined the adversarial context of botnets and showed how their responses – evasion techniques – can be interpreted as security controls according to deviant security theory. We created a framework for categorizing these security controls, based on security control types and the type of threat. Turning to our data, we performed an exploratory analysis in which we processed, validated and interpreted the available data based on their different types: server images, network data and databases. Based on the insights from this analysis, we applied the business model canvas and described Avalanche’s business model. We describe how Avalanche provides it customers with proxying and domain registration services, generating on aver- age $7,500 of revenue per month from 59 customers. We identified seven security controls, three technical controls and four administrative controls, that were applied to evade detection, to increase resilience against takedowns and to conceal the ownership by the botnet operators.
Our findings show that Avalanche configured itself to adequately respond to the threats in its adversarial context. Its business model – through using different key partners and many replaceable resources – and its application of security controls – such as backups, bot monitoring and proxy architecture – created redun- dancy in Avalanche’s operation, allowing it to detect and resolve threats quickly.
People ignore design that ignores people
Understanding the impact of security training on the security behaviour of employees within an organisational context
Have you updated your lightbulb?
Solving IoT vulnerabilities through governance
Using a literature study to define IoT concepts and the governance of IoT and current governance examples, background information is provided for the rest of this research. The database of 1649 IP addresses of network scan data from the area of The Hague is then used to find what vulnerabilities are present and what stakeholders are identifiable from this data. Exploring this network scan data showed only 191 devices are fully identifiable from the total number of IP addresses. These devices all carry vulnerabilities for the user of these devices, and being visible is by itself a vulnerability. No device owners could be directly identified, only the providers of the networks these devices are found in. This results in the identifiable stakeholders from the dataset: ISPs and device manufacturers.
Governance options are defined for these stakeholders (e.g. security-by-design, informing users etc.). These options are assessed on viability and validity through semi-structured interviews with three ISPs and the municipality.
The conclusion found is that the most viable action to take is informing device users since secure configuration and usage of a device would take away vulnerabilities while waiting for European legislation to be implemented. This legislation will force more security-by-design. The recommendation for the municipality is to take the role of leading actor, provide a better problematization with the data available, and use this to generate more urgency with other stakeholders. Starting public-private partnerships (with ISPs, device vendors, universities, other municipalities: different perspectives to progress the problem) and starting information campaigns and therefore try to reach as many people as possible. Even though ISPs can not provide in reaching vulnerable users directly, they can help in general information campaigns. Increasing security practices on the user side while waiting for legislation on the manufacturer's side.
...
Using a literature study to define IoT concepts and the governance of IoT and current governance examples, background information is provided for the rest of this research. The database of 1649 IP addresses of network scan data from the area of The Hague is then used to find what vulnerabilities are present and what stakeholders are identifiable from this data. Exploring this network scan data showed only 191 devices are fully identifiable from the total number of IP addresses. These devices all carry vulnerabilities for the user of these devices, and being visible is by itself a vulnerability. No device owners could be directly identified, only the providers of the networks these devices are found in. This results in the identifiable stakeholders from the dataset: ISPs and device manufacturers.
Governance options are defined for these stakeholders (e.g. security-by-design, informing users etc.). These options are assessed on viability and validity through semi-structured interviews with three ISPs and the municipality.
The conclusion found is that the most viable action to take is informing device users since secure configuration and usage of a device would take away vulnerabilities while waiting for European legislation to be implemented. This legislation will force more security-by-design. The recommendation for the municipality is to take the role of leading actor, provide a better problematization with the data available, and use this to generate more urgency with other stakeholders. Starting public-private partnerships (with ISPs, device vendors, universities, other municipalities: different perspectives to progress the problem) and starting information campaigns and therefore try to reach as many people as possible. Even though ISPs can not provide in reaching vulnerable users directly, they can help in general information campaigns. Increasing security practices on the user side while waiting for legislation on the manufacturer's side.
Looking under the Streetlights
Evaluating Cyber Threat Intelligence Feeds Using Quantitative Metrics and User Appreciation Scores
This mystery surrounding Threat Intelligence, caused by its prohibitively high pricing, shows in the limited amount of research that has been conducted on the topic. Bouwman et al. lifted a tip of the veil, interviewing professionals regarding their use of Threat Intelligence and presenting descriptive statistics of its contents. They found very limited overlap between Threat Intelligence sources and that acquisition is largely based on gut-feeling. However, it is still largely unknown if these findings generalize to the whole field of Threat Intelligence and if these findings on macro level translate to more granular levels, it is our goal to find this out. ...
This mystery surrounding Threat Intelligence, caused by its prohibitively high pricing, shows in the limited amount of research that has been conducted on the topic. Bouwman et al. lifted a tip of the veil, interviewing professionals regarding their use of Threat Intelligence and presenting descriptive statistics of its contents. They found very limited overlap between Threat Intelligence sources and that acquisition is largely based on gut-feeling. However, it is still largely unknown if these findings generalize to the whole field of Threat Intelligence and if these findings on macro level translate to more granular levels, it is our goal to find this out.