{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T11:22:20Z","timestamp":1783423340690,"version":"3.54.6"},"reference-count":77,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000269","name":"Economic and Social Research Council","doi-asserted-by":"publisher","award":["ES\/ V 003666\/1"],"award-info":[{"award-number":["ES\/ V 003666\/1"]}],"id":[{"id":"10.13039\/501100000269","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Inf Syst Front"],"published-print":{"date-parts":[[2026,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Cybersecurity is now critically important in an increasingly digitized and connected world. In addition to required digital security, individuals and organisations pursue multiple other objectives under binding resource constraints. Understanding how they make decisions in the face of these trade-offs is important for both research and teaching purposes. Games can create effective and exciting learning environments and also provide an immersive and experiment-based research setting to understand decision-making. We present a novel tabletop board game which sets cybersecurity in a broader organisational context and emulates real life business decisions. It can be used as a powerful research tool to understand decision-making about cybersecurity in a resource-constrained and uncertain environment. It is also a useful interdisciplinary educational tool, integrating concepts from cybersecurity, business development, and innovation management in gameplay.<\/jats:p>","DOI":"10.1007\/s10796-025-10604-3","type":"journal-article","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T17:55:28Z","timestamp":1745344528000},"page":"471-492","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Threats &amp; Trade-offs: A Start-up Simulation Game for Cybersecurity and Innovation Decision-Making"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3798-0551","authenticated-orcid":false,"given":"Kseniya","family":"Stsiampkouskaya","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9731-2972","authenticated-orcid":false,"given":"Oishee","family":"Kundu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9908-6710","authenticated-orcid":false,"given":"Joanna","family":"Syrda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7019-7038","authenticated-orcid":false,"given":"Adam","family":"Joinson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"issue":"1","key":"10604_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1093\/cybsec\/tyy006","volume":"4","author":"I Agrafiotis","year":"2018","unstructured":"Agrafiotis, I., Nurse, J. R., Goldsmith, M., Creese, S., & Upton, D. (2018). A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate. Journal of Cybersecurity, 4(1), 1\u201315. https:\/\/doi.org\/10.1093\/cybsec\/tyy006","journal-title":"Journal of Cybersecurity"},{"issue":"6","key":"10604_CR2","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1007\/s10796-016-9649-7","volume":"18","author":"O Allal-Ch\u00e9rif","year":"2016","unstructured":"Allal-Ch\u00e9rif, O., Bidan, M., & Makhlouf, M. (2016). Using serious games to manage knowledge and competencies: The seven-step development process. Information Systems Frontiers, 18(6), 1153\u20131163. https:\/\/doi.org\/10.1007\/s10796-016-9649-7","journal-title":"Information Systems Frontiers"},{"issue":"4","key":"10604_CR3","doi-asserted-by":"publisher","first-page":"1055","DOI":"10.1007\/s10796-022-10353-7","volume":"24","author":"N Ameen","year":"2022","unstructured":"Ameen, N., Choudrie, J., Jones, P., & Anand, A. (2022). Innovative Technologies and Small-Medium Sized Enterprises in Times of Crisis. Information Systems Frontiers, 24(4), 1055\u20131060. https:\/\/doi.org\/10.1007\/s10796-022-10353-7","journal-title":"Information Systems Frontiers"},{"issue":"3\u20134","key":"10604_CR4","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1362\/026725706776861217","volume":"22","author":"L Ang","year":"2006","unstructured":"Ang, L., & Buttle, F. (2006). Managing for successful customer acquisition: An exploration. Journal of Marketing Management, 22(3\u20134), 295\u2013317.","journal-title":"Journal of Marketing Management"},{"key":"10604_CR5","doi-asserted-by":"publisher","unstructured":"Angafor, G. N., Yevseyeva, I., spsampsps He, Y. (2020). Bridging the cyber security skills gap: Using tabletop exercises to solve the CSSG crisis. In Joint International Conference on Serious Games (pp. 117\u2013131). Cham: Springer International Publishing. https:\/\/doi.org\/10.1007\/978-3-030-61814-8_10","DOI":"10.1007\/978-3-030-61814-8_10"},{"key":"10604_CR6","doi-asserted-by":"publisher","unstructured":"Anvik, J., Cote, V., & Riehl, J. (2019). Program Wars: A Card Game for Learning Programming and Cybersecurity Concepts. Proceedings of the 50th ACM Technical Symposium on Computer Science Education, 393\u2013399. https:\/\/doi.org\/10.1145\/3287324.3287496","DOI":"10.1145\/3287324.3287496"},{"key":"10604_CR7","doi-asserted-by":"publisher","unstructured":"Bahuguna, A., Bisht, R. K., & Pande, J. (2019). Don\u2019t wanna cry: A cyber crisis table top exercise for assessing the preparedness against eminent threats. International Journal of Engineering and Advanced Technology, 9(1), 3705-3710. . https:\/\/doi.org\/10.35940\/ijeat.A9893.109119","DOI":"10.35940\/ijeat.A9893.109119"},{"issue":"1","key":"10604_CR8","first-page":"15","volume":"44","author":"JS Bain","year":"1954","unstructured":"Bain, J. S. (1954). Economies of scale, concentration, and the condition of entry in twenty manufacturing industries. The American Economic Review, 44(1), 15\u201339.","journal-title":"The American Economic Review"},{"key":"10604_CR9","unstructured":"British Business Bank. (n.d.) Start Up Loans. British Business Bank. https:\/\/www.startuploans.co.uk\/"},{"key":"10604_CR10","doi-asserted-by":"publisher","unstructured":"Beautement, A., Sasse, M. A., & Wonham, M. (2008). The compliance budget: Managing security behaviour in organisations. Proceedings of the 2008 New Security Paradigms Workshop, 47\u201358. https:\/\/doi.org\/10.1145\/1595676.1595684","DOI":"10.1145\/1595676.1595684"},{"key":"10604_CR11","unstructured":"Bone, J., Allen, O., & Haley, C. (2017). Business incubators and accelerators: the national picture (BEIS Research Paper No. 7). Gov.uk. Retrieved July 13, 2024, from https:\/\/www.gov.uk\/government\/publications\/business-incubators-and-accelerators-the-national-picture"},{"key":"10604_CR12","unstructured":"Boxall, C. (2023). Sewing the seeds for ABC: A funding guide for startups. Legislate. Retrieved July 13, 2024, from https:\/\/www.legislate.ai\/blog\/sewing-the-seeds-for-abc-a-funding-guide-for-startups"},{"key":"10604_CR13","unstructured":"British Business Bank. (2018). The UK business angels market report. British business bank. Retrieved July 13, 2024, from https:\/\/www.british-business-bank.co.uk\/sites\/g\/files\/sovrnj166\/files\/2022-11\/Business-Angel-Reportweb.pdf"},{"issue":"2","key":"10604_CR14","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/s10796-019-09951-9","volume":"23","author":"AJ Burns","year":"2021","unstructured":"Burns, A. J., Posey, C., & Roberts, T. L. (2021). Insiders\u2019 Adaptations to Security-Based Demands in the Workplace: An Examination of Security Behavioral Complexity. Information Systems Frontiers, 23(2), 343\u2013360. https:\/\/doi.org\/10.1007\/s10796-019-09951-9","journal-title":"Information Systems Frontiers"},{"key":"10604_CR15","unstructured":"Center for Internet Security. (2021). CIS Community defense model 2.0. Center for internet security. Retrieved March 11, 2025, from https:\/\/www.cisecurity.org\/insights\/white-papers\/cis-community-defense-model-2-0"},{"issue":"1","key":"10604_CR16","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1108\/ITP-11-2017-0390","volume":"32","author":"A Ceric","year":"2019","unstructured":"Ceric, A., & Holland, P. (2019). The role of cognitive biases in anticipating and responding to cyberattacks. Information Technology & People, 32(1), 171\u2013188. https:\/\/doi.org\/10.1108\/ITP-11-2017-0390","journal-title":"Information Technology & People"},{"key":"10604_CR17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.chbr.2022.100167","volume":"5","author":"S Chng","year":"2022","unstructured":"Chng, S., Lu, H. Y., Kumar, A., & Yau, D. (2022). Hacker types, motivations and strategies: A comprehensive framework. Computers in Human Behavior Reports, 5, 1\u20138. https:\/\/doi.org\/10.1016\/j.chbr.2022.100167","journal-title":"Computers in Human Behavior Reports"},{"key":"10604_CR18","doi-asserted-by":"publisher","unstructured":"Conklin, A., & White, G. B. (2006, January). E-government and cyber security: the role of cyber security exercises. In Proceedings of the 39th Annual Hawaii International Conference on System Sciences (HICSS'06) 4,79b-79b. IEEE. https:\/\/doi.org\/10.1109\/HICSS.2006.133","DOI":"10.1109\/HICSS.2006.133"},{"issue":"2","key":"10604_CR19","doi-asserted-by":"publisher","first-page":"661","DOI":"10.1016\/j.compedu.2012.03.004","volume":"59","author":"TM Connolly","year":"2012","unstructured":"Connolly, T. M., Boyle, E. A., MacArthur, E., Hainey, T., & Boyle, J. M. (2012). A systematic literature review of empirical evidence on computer games and serious games. Computers & Education, 59(2), 661\u2013686. https:\/\/doi.org\/10.1016\/j.compedu.2012.03.004","journal-title":"Computers & Education"},{"key":"10604_CR20","doi-asserted-by":"publisher","unstructured":"Cornel, C. J., Rowe, D. C., & Cornel, C. M. (2017). Starships and Cybersecurity: Teaching Security Concepts through Immersive Gaming Experiences. Proceedings of the 18th Annual Conference on Information Technology Education, 27\u201332. https:\/\/doi.org\/10.1145\/3125659.3125696","DOI":"10.1145\/3125659.3125696"},{"key":"10604_CR21","unstructured":"Cremades, A. (2019). 8 Types of investors for startups. Forbes. Retrieved July 10, 2024, from https:\/\/www.forbes.com\/sites\/alejandrocremades\/2019\/01\/02\/8-types-of-investors-for-startups\/?sh=c790e9b4a3e8"},{"key":"10604_CR22","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.cose.2012.09.010","volume":"32","author":"RE Crossler","year":"2013","unstructured":"Crossler, R. E., Johnston, A. C., Lowry, P. B., Hu, Q., Warkentin, M., & Baskerville, R. (2013). Future directions for behavioral information security research. Computers & Security, 32, 90\u2013101. https:\/\/doi.org\/10.1016\/j.cose.2012.09.010","journal-title":"Computers & Security"},{"issue":"2","key":"10604_CR23","doi-asserted-by":"publisher","first-page":"431","DOI":"10.1007\/s10796-022-10332-y","volume":"25","author":"C Daniel","year":"2023","unstructured":"Daniel, C., Mullarkey, M., & Agrawal, M. (2023). RQ Labs: A Cybersecurity Workforce Skills Development Framework. Information Systems Frontiers, 25(2), 431\u2013450. https:\/\/doi.org\/10.1007\/s10796-022-10332-y","journal-title":"Information Systems Frontiers"},{"key":"10604_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3389\/fpsyg.2018.00744","volume":"9","author":"J Dawson","year":"2018","unstructured":"Dawson, J., & Thomson, R. (2018). The future cybersecurity workforce: Going beyond technical skills for successful cyber performance. Frontiers in Psychology, 9, 1\u201312. https:\/\/doi.org\/10.3389\/fpsyg.2018.00744","journal-title":"Frontiers in Psychology"},{"issue":"2","key":"10604_CR25","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1057\/s41288-018-0082-7","volume":"43","author":"G de Smidt","year":"2018","unstructured":"de Smidt, G., & Botzen, W. (2018). Perceptions of Corporate Cyber Risks and Insurance Decision-Making. The Geneva Papers on Risk and Insurance - Issues and Practice, 43(2), 239\u2013274. https:\/\/doi.org\/10.1057\/s41288-018-0082-7","journal-title":"The Geneva Papers on Risk and Insurance - Issues and Practice"},{"key":"10604_CR26","doi-asserted-by":"publisher","unstructured":"Denning, T., Lerner, A., Shostack, A., & Kohno, T. (2013). Control-Alt-Hack: The design and evaluation of a card game for computer security awareness and education. Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, 915\u2013928. https:\/\/doi.org\/10.1145\/2508859.2516753","DOI":"10.1145\/2508859.2516753"},{"key":"10604_CR27","volume-title":"Management: Tasks, responsibilities, practices","author":"PF Drucker","year":"1973","unstructured":"Drucker, P. F. (1973). Management: Tasks, responsibilities, practices. Harper and Row."},{"key":"10604_CR28","unstructured":"DSIT. (2023). Cyber security breaches survey 2023 [Official statistics]. Department for science, innovation & technology. Retrieved July 10, 2024, from https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2023\/cyber-security-breaches-survey-2023#summary"},{"issue":"1","key":"10604_CR29","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/s10796-018-9845-8","volume":"22","author":"M Ezhei","year":"2020","unstructured":"Ezhei, M., & Tork Ladani, B. (2020). Interdependency Analysis in Security Investment against Strategic Attacks. Information Systems Frontiers, 22(1), 187\u2013201. https:\/\/doi.org\/10.1007\/s10796-018-9845-8","journal-title":"Information Systems Frontiers"},{"issue":"1","key":"10604_CR30","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1111\/joes.12456","volume":"36","author":"A Fedele","year":"2022","unstructured":"Fedele, A., & Roner, C. (2022). Dangerous games: A literature review on cybersecurity investments. Journal of Economic Surveys, 36(1), 157\u2013187. https:\/\/doi.org\/10.1111\/joes.12456","journal-title":"Journal of Economic Surveys"},{"key":"10604_CR31","doi-asserted-by":"crossref","unstructured":"Foreman, C., Turner, M., & Perusich, K. (2015). Educational Modules in Industrial Control Systems for Critical Infrastructure Cyber Security. 26.573.1\u201326.573.10. https:\/\/peer.asee.org\/educational-modules-in-industrial-control-systems-for-critical-infrastructure-cyber-security","DOI":"10.18260\/p.23911"},{"issue":"5","key":"10604_CR32","doi-asserted-by":"publisher","first-page":"521","DOI":"10.1109\/TSE.2017.2782813","volume":"45","author":"S Frey","year":"2019","unstructured":"Frey, S., Rashid, A., Anthonysamy, P., Pinto-Albuquerque, M., & Naqvi, S. A. (2019). The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game. IEEE Transactions on Software Engineering, 45(5), 521\u2013536. https:\/\/doi.org\/10.1109\/TSE.2017.2782813","journal-title":"IEEE Transactions on Software Engineering"},{"key":"10604_CR33","volume-title":"Game design workshop: Designing, prototyping, & playtesting games","author":"T Fullerton","year":"2004","unstructured":"Fullerton, T., Swain, C., & Hoffman, S. (2004). Game design workshop: Designing, prototyping, & playtesting games. CRC Press."},{"key":"10604_CR34","unstructured":"FundersClub. (n.d.) Chapter 2: Understanding venture capital. FundersClub. Retrieved July 9, 2024, from https:\/\/fundersclub.com\/learn\/guides\/vc-101\/understanding-venture-capital\/"},{"key":"10604_CR35","unstructured":"Gondree, M., & Peterson, Z. N. J. (2013). Valuing security by getting {[d0x3d!]}: Experiences with a network security board game. 6th Workshop on cyber security experimentation and test (CSET 13). Retrieved July 10, 2024, from https:\/\/www.usenix.org\/conference\/cset13\/workshop-program\/presentation\/gondree"},{"key":"10604_CR36","doi-asserted-by":"crossref","unstructured":"Gov.uk. (2022). The cyber security breaches survey 2022. Gov.uk. Retrieved July 8, 2024, from https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2022\/cyber-security-breaches-survey-2022","DOI":"10.12968\/S1361-3723(22)70568-4"},{"key":"10604_CR37","doi-asserted-by":"publisher","first-page":"101827","DOI":"10.1016\/j.cose.2020.101827","volume":"95","author":"S Hart","year":"2020","unstructured":"Hart, S., Margheri, A., Paci, F., & Sassone, V. (2020). Riskio: A Serious Game for Cyber Security Awareness and Education. Computers & Security, 95, 101827. https:\/\/doi.org\/10.1016\/j.cose.2020.101827","journal-title":"Computers & Security"},{"issue":"6","key":"10604_CR38","doi-asserted-by":"publisher","first-page":"1285","DOI":"10.1007\/s10796-019-09959-1","volume":"21","author":"M Heidt","year":"2019","unstructured":"Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the Security Divide between SME and Large Companies: How SME Characteristics Influence Organizational IT Security Investments. Information Systems Frontiers, 21(6), 1285\u20131305. https:\/\/doi.org\/10.1007\/s10796-019-09959-1","journal-title":"Information Systems Frontiers"},{"issue":"1","key":"10604_CR39","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1016\/j.jsis.2018.09.003","volume":"28","author":"MS Jalali","year":"2019","unstructured":"Jalali, M. S., Siegel, M., & Madnick, S. (2019). Decision-making and biases in cybersecurity capability development: Evidence from a simulation game experiment. The Journal of Strategic Information Systems, 28(1), 66\u201382. https:\/\/doi.org\/10.1016\/j.jsis.2018.09.003","journal-title":"The Journal of Strategic Information Systems"},{"key":"10604_CR40","doi-asserted-by":"publisher","unstructured":"Karagiannis, S., spsampsps Magkos, E. (2021). Engaging Students in Basic Cybersecurity Concepts Using Digital Game-Based Learning: Computer Games as Virtual Learning Environments. Advances in Core Computer Science-Based Technologies: Papers in Honor of Professor Nikolaos Alexandris, 55\u201381. https:\/\/doi.org\/10.1007\/978-3-030-41196-1_4","DOI":"10.1007\/978-3-030-41196-1_4"},{"issue":"2","key":"10604_CR41","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/s10796-019-09977-z","volume":"23","author":"E Kweon","year":"2021","unstructured":"Kweon, E., Lee, H., Chai, S., & Yoo, K. (2021). The Utility of Information Security Training and Education on Cybersecurity Incidents: An empirical evidence. Information Systems Frontiers, 23(2), 361\u2013373. https:\/\/doi.org\/10.1007\/s10796-019-09977-z","journal-title":"Information Systems Frontiers"},{"key":"10604_CR42","unstructured":"Levitt, T. (1965). Exploit the product life cycle. Harvard Business Review. Retrieved July 7, 2024, from https:\/\/hbr.org\/1965\/11\/exploit-the-product-life-cycle"},{"key":"10604_CR43","doi-asserted-by":"publisher","first-page":"j3179","DOI":"10.1136\/bmj.j3179","volume":"358","author":"G Martin","year":"2017","unstructured":"Martin, G., Martin, P., Hankin, C., Darzi, A., & Kinross, J. (2017). Cybersecurity and healthcare: How safe are we? BMJ, 358, j3179. https:\/\/doi.org\/10.1136\/bmj.j3179","journal-title":"BMJ"},{"key":"10604_CR44","doi-asserted-by":"publisher","unstructured":"McAlaney, J., & Benson, V. (2020). Chapter 1\u2014Cybersecurity as a social phenomenon. In V. Benson & J. Mcalaney (Eds.), Cyber Influence and Cognitive Threats (pp. 1\u20138). Academic Press. https:\/\/doi.org\/10.1016\/B978-0-12-819204-7.00001-4","DOI":"10.1016\/B978-0-12-819204-7.00001-4"},{"key":"10604_CR45","unstructured":"Microsoft. (2009). The STRIDE Threat Model. Microsoft. Retrieved March 10, 2025, from https:\/\/learn.microsoft.com\/en-us\/previous-versions\/commerce-server\/ee823878(v=cs.20)?redirectedfrom=MSDN"},{"key":"10604_CR46","unstructured":"MITRE ATT&CK\u00ae. (n.d.) ATT&CK matrix for enterprise. MITRE ATT&CK\u00ae. Retrieved July 6, 2024, from https:\/\/attack.mitre.org\/"},{"key":"10604_CR47","doi-asserted-by":"publisher","unstructured":"Neag, A. (2019). Board Games as Interview Tools: Creating a Safe Space for Unaccompanied Refugee Children. Media and Communication, 7(2), 254\u2013263. https:\/\/doi.org\/10.17645\/mac.v7i2.1817","DOI":"10.17645\/mac.v7i2.1817"},{"issue":"4","key":"10604_CR48","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1515\/jhsem-2014-0031","volume":"11","author":"R Ottis","year":"2014","unstructured":"Ottis, R. (2014). Light weight tabletop exercise for cybersecurity education. Journal of Homeland Security and Emergency Management, 11(4), 579\u2013592. https:\/\/doi.org\/10.1515\/jhsem-2014-0031","journal-title":"Journal of Homeland Security and Emergency Management"},{"issue":"4","key":"10604_CR49","doi-asserted-by":"publisher","first-page":"1189","DOI":"10.25300\/MISQ\/2013\/37.4.09","volume":"37","author":"C Posey","year":"2013","unstructured":"Posey, C., Roberts, T. L., Lowry, P. B., Bennett, R. J., & Courtney, J. F. (2013). Insiders\u2019 protection of organizational information assets: Development of a systematics-based taxonomy and theory of diversity for protection-motivated behaviors. MIS Quarterly, 37(4), 1189\u20131210.","journal-title":"MIS Quarterly"},{"key":"10604_CR50","doi-asserted-by":"publisher","unstructured":"Rindell, K., Bernsmed, K., & Jaatun, M. G. (2019). Managing Security in Software: Or: How I Learned to Stop Worrying and Manage the Security Technical Debt. Proceedings of the 14th International Conference on Availability, Reliability and Security, 1\u20138. https:\/\/doi.org\/10.1145\/3339252.3340338","DOI":"10.1145\/3339252.3340338"},{"key":"10604_CR51","volume-title":"Diffusion of Innovations","author":"EM Rogers","year":"2003","unstructured":"Rogers, E. M. (2003). Diffusion of Innovations (5th ed.). Simon and Schuster.","edition":"5"},{"key":"10604_CR52","unstructured":"Rutan, R. (2023). Series A, B, C, D, and E Funding: How It Works. Retrieved July 10, 2024, from https:\/\/www.startups.com\/library\/expert-advice\/series-funding-a-b-c-d-e"},{"issue":"3","key":"10604_CR53","doi-asserted-by":"publisher","first-page":"1277","DOI":"10.1007\/s10796-022-10274-5","volume":"25","author":"R Safi","year":"2023","unstructured":"Safi, R., & Browne, G. J. (2023). Detecting Cybersecurity Threats: The Role of the Recency and Risk Compensating Effects. Information Systems Frontiers, 25(3), 1277\u20131292. https:\/\/doi.org\/10.1007\/s10796-022-10274-5","journal-title":"Information Systems Frontiers"},{"key":"10604_CR54","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1109\/ICOCO56118.2022.10031900","volume":"2022","author":"A Selamat","year":"2022","unstructured":"Selamat, A., Marican, M. N. Y., Othman, S. H., & Razak, S. A. (2022). An End-To-End Cyber Security Maturity Model For Technology Startups. IEEE International Conference on Computing (ICOCO), 2022, 185\u2013190. https:\/\/doi.org\/10.1109\/ICOCO56118.2022.10031900","journal-title":"IEEE International Conference on Computing (ICOCO)"},{"key":"10604_CR55","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-023-10404-7","author":"FA Shaikh","year":"2023","unstructured":"Shaikh, F. A., & Siponen, M. (2023). Organizational Learning from Cybersecurity Performance: Effects on Cybersecurity Investment Decisions. Information Systems Frontiers. https:\/\/doi.org\/10.1007\/s10796-023-10404-7","journal-title":"Information Systems Frontiers"},{"issue":"5","key":"10604_CR56","doi-asserted-by":"publisher","first-page":"1515","DOI":"10.1109\/TSE.2020.3023735","volume":"48","author":"B Shreeve","year":"2022","unstructured":"Shreeve, B., Hallett, J., Edwards, M., Ramokapane, K. M., Atkins, R., & Rashid, A. (2022). The Best Laid Plans or Lack Thereof: Security Decision-Making of Different Stakeholder Groups. IEEE Transactions on Software Engineering, 48(5), 1515\u20131528. https:\/\/doi.org\/10.1109\/TSE.2020.3023735","journal-title":"IEEE Transactions on Software Engineering"},{"key":"10604_CR57","doi-asserted-by":"publisher","unstructured":"Shreeve, B., Hallett, J., Edwards, M., Anthonysamy, P., Frey, S., & Rashid, A. (2020). \u201cSo if Mr Blue Head here clicks the link...\u201d Risk Thinking in Cyber Security Decision Making. ACM Transactions on Privacy and Security, 24(1), 5:1\u20135:29. https:\/\/doi.org\/10.1145\/3419101","DOI":"10.1145\/3419101"},{"key":"10604_CR58","doi-asserted-by":"publisher","unstructured":"Shreeve, B., Gralha, C., Rashid, A., Ara\u00fajo, J., & Goul\u00e3o, M. (2023). Making Sense of the Unknown How Managers Make Cyber Security Decisions. ACM Transactions on Software Engineering and Methodology, 32(4), 83:1\u201383:33. https:\/\/doi.org\/10.1145\/3548682","DOI":"10.1145\/3548682"},{"key":"10604_CR59","unstructured":"Smith, J. (2021). Biotech startups face a growing wave of cyberattacks. Labiotech.Eu. Retrieved July 5, 2024, from https:\/\/www.labiotech.eu\/in-depth\/cyberattack-biotech-startups-covid\/"},{"key":"10604_CR60","doi-asserted-by":"publisher","unstructured":"Stites, J., Siraj, A., & Brown, E. L. (2013). Smart Grid Security Educational Training with ThunderCloud: A Virtual Security Test Bed. Proceedings of the 2013 on InfoSecCD \u201913: Information Security Curriculum Development Conference, 105\u2013110. https:\/\/doi.org\/10.1145\/2528908.2528927","DOI":"10.1145\/2528908.2528927"},{"key":"10604_CR61","unstructured":"The Federal Emergency Management Agency. (2025). Exercise and preparedness tools. Retrieved July 10, 2024, from https:\/\/www.fema.gov\/emergency-managers\/national-preparedness\/exercises\/tools"},{"key":"10604_CR62","unstructured":"The National Institute of Standards and Technology. (n.d.) Cybersecurity framework. The national institute of standards and technology. Retrieved July 4, 2024, from https:\/\/www.nist.gov\/cyberframework"},{"key":"10604_CR63","doi-asserted-by":"crossref","unstructured":"Thompson, M., & Irvine, C. (2011). Active learning with the {CyberCIEGE} video game. In 4th workshop on cyber security experimentation and test (CSET 11). Retrieved March 9, 2025, from https:\/\/www.usenix.org\/legacy\/events\/cset11\/tech\/final_files\/Thompson.pdf","DOI":"10.21236\/ADA547670"},{"key":"10604_CR64","doi-asserted-by":"publisher","unstructured":"Tseng, S.-S., Yang, T.-Y., Shih, W.-C., & Shan, B.-Y. (2022). Building a self-evolving iMonsters board game for cyber-security education. Interactive Learning Environments, 0(0), 1\u201319. Retrieved July 2, 2024, from https:\/\/doi.org\/10.1080\/10494820.2022.2120015","DOI":"10.1080\/10494820.2022.2120015"},{"key":"10604_CR65","unstructured":"U.S. Food & Drug Administration. (2017). FDA approves pill with sensor that digitally tracks if patients have ingested their medication. U.S. Food & Drug Administration. Retrieved March 8, 2025, fromhttps:\/\/www.fda.gov\/news-events\/press-announcements\/fda-approves-pill-sensor-digitally-tracks-if-patients-have-ingested-their-medication"},{"key":"10604_CR66","doi-asserted-by":"publisher","DOI":"10.1002\/9781118988374","volume-title":"Risk Centric Threat Modeling: Process for attack simulation and threat analysis","author":"T UcedaVelez","year":"2015","unstructured":"UcedaVelez, T., & Morana, M. M. (2015). Risk Centric Threat Modeling: Process for attack simulation and threat analysis. John Wiley & Sons."},{"key":"10604_CR67","unstructured":"Vasquez, C. (2024). CISA leads first tabletop exercise for AI cybersecurity. Cyberscoop. Retrieved July 10, 2024, fromhttps:\/\/cyberscoop.com\/cisa-ai-tabletop-exercise-playbook\/"},{"key":"10604_CR68","unstructured":"Verizon. (2023). 2023 Data breach investigations report. Retrieved July 1, 2024, from https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/"},{"key":"10604_CR69","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/SP.2015.9","volume":"2015","author":"RNM Watson","year":"2015","unstructured":"Watson, R. N. M., Woodruff, J., Neumann, P. G., Moore, S. W., Anderson, J., Chisnall, D., Dave, N., Davis, B., Gudka, K., Laurie, B., Murdoch, S. J., Norton, R., Roe, M., Son, S., & Vadera, M. (2015). CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. IEEE Symposium on Security and Privacy, 2015, 20\u201337. https:\/\/doi.org\/10.1109\/SP.2015.9","journal-title":"IEEE Symposium on Security and Privacy"},{"key":"10604_CR70","doi-asserted-by":"publisher","first-page":"807","DOI":"10.1016\/j.cose.2018.02.001","volume":"77","author":"E Weish\u00e4upl","year":"2018","unstructured":"Weish\u00e4upl, E., Yasasin, E., & Schryen, G. (2018). Information security investments: An exploratory multiple case study on decision-making, evaluation and learning. Computers & Security, 77, 807\u2013823. https:\/\/doi.org\/10.1016\/j.cose.2018.02.001","journal-title":"Computers & Security"},{"issue":"4","key":"10604_CR71","doi-asserted-by":"publisher","first-page":"1061","DOI":"10.1007\/s10796-021-10210-z","volume":"24","author":"C Wendt","year":"2022","unstructured":"Wendt, C., Adam, M., Benlian, A., & Kraus, S. (2022). Let\u2019s Connect to Keep the Distance: How SMEs Leverage Information and Communication Technologies to Address the COVID-19 Crisis. Information Systems Frontiers, 24(4), 1061\u20131079. https:\/\/doi.org\/10.1007\/s10796-021-10210-z","journal-title":"Information Systems Frontiers"},{"key":"10604_CR72","doi-asserted-by":"publisher","unstructured":"White, G. B., Dietrich, G., & Goles, T. (2004, January). Cyber security exercises: testing an organization's ability to prevent, detect, and respond to cyber security events. In 37th Annual Hawaii International Conference on System Sciences, 2004. Proceedings of the (pp. 10-pp). IEEE. https:\/\/doi.org\/10.1109\/HICSS.2004.1265411","DOI":"10.1109\/HICSS.2004.1265411"},{"key":"10604_CR73","doi-asserted-by":"publisher","unstructured":"Yardley, T., Uludag, S., Nahrstedt, K., & Sauer, P. (2014). Developing a Smart Grid cybersecurity education platform and a preliminary assessment of its first application. 2014 IEEE Frontiers in Education Conference (FIE) Proceedings, 1\u20139. https:\/\/doi.org\/10.1109\/FIE.2014.7044273","DOI":"10.1109\/FIE.2014.7044273"},{"key":"10604_CR74","unstructured":"Young, J., & Farshadkhah, S. (2021). Backdoors & breaches: Using a tabletop exercise game to teach cybersecurity incident response. In Proceedings of the EDSIG Conference ISSN 2473, 4901)."},{"key":"10604_CR75","doi-asserted-by":"publisher","unstructured":"Younis, Y. A., & Alghamdi, M. Y. (2021). The use of computer games for teaching and learning cybersecurity in higher education institutions. Journal of Engineering Research, 9(3A), Article 3A. https:\/\/doi.org\/10.36909\/jer.v9i3A.10943","DOI":"10.36909\/jer.v9i3A.10943"},{"key":"10604_CR76","doi-asserted-by":"publisher","unstructured":"Zahir, S., Pak, J., Singh, J., Pawlick, J., & Zhu, Q. (2015). Protection and Deception: Discovering Game Theory and Cyber Literacy through a Novel Board Game Experience (arXiv:1505.05570). arXiv. https:\/\/doi.org\/10.48550\/arXiv.1505.05570","DOI":"10.48550\/arXiv.1505.05570"},{"issue":"2","key":"10604_CR77","doi-asserted-by":"publisher","first-page":"49","DOI":"10.3390\/systems10020049","volume":"10","author":"S Zeijlemaker","year":"2022","unstructured":"Zeijlemaker, S., Rouwette, E. A., Cunico, G., Armenia, S., & von Kutzschenbach, M. (2022). Decision-Makers\u2019 Understanding of Cyber-Security\u2019s Systemic and Dynamic Complexity: Insights from a Board Game for Bank Managers. Systems, 10(2), 49. https:\/\/doi.org\/10.3390\/systems10020049","journal-title":"Systems"}],"container-title":["Information Systems Frontiers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-025-10604-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10796-025-10604-3","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-025-10604-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T06:37:44Z","timestamp":1779691064000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10796-025-10604-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":77,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["10604"],"URL":"https:\/\/doi.org\/10.1007\/s10796-025-10604-3","relation":{},"ISSN":["1387-3326","1572-9419"],"issn-type":[{"value":"1387-3326","type":"print"},{"value":"1572-9419","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,22]]},"assertion":[{"value":"7 April 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 April 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"A favourable opinion has been given for this study by the Social Science Research Ethics Committee of the University of Bath (S22 -\u2009152). Informed consent to participate was obtained from all participants following the guidelines of the Social Science Research Ethics Committee of the University of Bath.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval and Consent to Participate"}},{"value":"Informed consent for publication was obtained from all participants following the guidelines of the Social Science Research Ethics Committee of the University of Bath.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for Publication"}},{"value":"We have no known competing interests to disclose.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}