Individual preferences in security risk decision making

an exploratory study under security professionals

Conference Paper (2021)
Author(s)

J.J. de Wit (TU Delft - Safety and Security Science)

W Pieters (Radboud Universiteit Nijmegen)

P.H.A.J.M. van Gelder (TU Delft - Safety and Security Science)

Safety and Security Science
Copyright
© 2021 J.J. de Wit, W. Pieters, P.H.A.J.M. van Gelder
DOI related publication
https://doi.org/10.2495/SAFE210161
More Info
expand_more
Publication Year
2021
Language
English
Copyright
© 2021 J.J. de Wit, W. Pieters, P.H.A.J.M. van Gelder
Safety and Security Science
Volume number
206
Pages (from-to)
187-199
ISBN (electronic)
978-178466443-5
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Risk assessments in the (cyber) security domain are often, if not always, based on subjective expert judgement. For the first time, to the best of our knowledge, the individual preferences of professionals from the security domain are studied. In on online survey they are asked to mention, rate and rank their preferences when assessing a security risk. The survey setup allows to differentiate between easily accessible or “on top of mind” attributes and guided or stimulated attributes. The security professionals are also challenged to both non-compensatory and compensatory decision making on the relevance of the attributes. The results of this explorative study indicate a clear difference and shift in the individual perceived relevance of attributes in these different settings. Another remarkable finding of this study is the predominant focus on impact attributes by the respondents and the less significant position of likelihood or probability. The majority of professionals seem to ignore likelihood in their security risk assessment. This might be due to so called probability neglect as introduced by other scholars. the security in organisations and society is depending on the assessment and judgement of these professionals, understanding their preferences and the influence of cognitive biases is paramount. This study contributes to this body of knowledge and might raise attention to this important topic in both the academic and professional security domain.

Files

SAFE21016FU1.pdf
(pdf | 0.872 Mb)
License info not available