Towards Understanding Cognitive Biases in Cybersecurity Governance

Avtorji

Gulet Barre
Odprta univerza Nizozemske, Fakulteta za naravoslovje
https://orcid.org/0000-0002-9826-8624
Tim Huygh
Odprta univerza Nizozemske, Fakulteta za naravoslovje
https://orcid.org/0000-0003-4564-7994
Dinh Khoi Nguyen
Odprta univerza Nizozemske, Fakulteta za naravoslovje
Arno Nuijten
Odprta univerza Nizozemske, Fakulteta za naravoslovje
https://orcid.org/0000-0002-6701-8040

Kratka vsebina

Cognitive biases can influence the decision-making of board members and CISOs responsible for managing cyber risks. However, limited attention has been given to understanding how these biases affect cybersecurity governance, specifically in the communication of risks between CISOs and boards.  This paper aims to address this gap by identifying cognitive biases and proposing how these biases influence communication and strategic decision-making in cybersecurity governance. By further examining their impact, we strive to uncover the mechanisms that contribute to underestimations or distortions in risk perception, which can compromise an organization’s ability to respond effectively to cyber threats. This short paper provides three exemplary biases expected to influence communication and decision-making in cybersecurity governance. Following the initial results, we propose a series of interviews with CISOs to reveal the challenges they face when communicating cyber risks to boards, focusing on how biases influence the decisions regarding cybersecurity risks.

Biografije avtorja

Gulet Barre, Odprta univerza Nizozemske, Fakulteta za naravoslovje

Limburg, Nizozemska. E-mail: gulet.barre@ou.nl

Tim Huygh, Odprta univerza Nizozemske, Fakulteta za naravoslovje

Limburg, Nizozemska. E-mail: tim.huygh@ou.nl

Dinh Khoi Nguyen, Odprta univerza Nizozemske, Fakulteta za naravoslovje

Limburg, Nizozemska. E-mail: khoi.nguyen@ou.nl

Arno Nuijten, Odprta univerza Nizozemske, Fakulteta za naravoslovje

Limburg, Nizozemska. E.mail: arno.nuijten@ou.nl

Prenosi

Izdano

09.06.2025

Kako citirati

Barre, G., Huygh, T., Nguyen, D. K., & Nuijten, A. (2025). Towards Understanding Cognitive Biases in Cybersecurity Governance. In A. Pucihar, M. Kljajić Borštnar, S. Blatnik, M. Marolt, R. W. H. Bons, K. Smit, & M. Glowatz (Eds.), & (Ed.), 38th Bled eConference: Empowering Transformation: Shaping Digital Futures for All: Conference Proceedings (pp. 737-744). Univerzitetna založba Univerze v Mariboru. https://press.um.si/index.php/ump/catalog/book/947/chapter/631