{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:58:04Z","timestamp":1773511084375,"version":"3.50.1"},"reference-count":17,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2023,6,22]],"date-time":"2023-06-22T00:00:00Z","timestamp":1687392000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2023,7]]},"abstract":"<jats:p>The loss of potential gain from other alternatives when one alternative is chosen.<\/jats:p>","DOI":"10.1145\/3597464","type":"journal-article","created":{"date-parts":[[2023,6,22]],"date-time":"2023-06-22T22:47:22Z","timestamp":1687474042000},"page":"96-104","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Opportunity Cost and Missed Chances in Optimizing Cybersecurity"],"prefix":"10.1145","volume":"66","author":[{"given":"Kelly","family":"Shortridge","sequence":"first","affiliation":[{"name":"Fastly, New York, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Josiah","family":"Dykstra","sequence":"additional","affiliation":[{"name":"National Security Agency and the owner of Designer Security, LLC, Severn, MD, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,6,22]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1050.0440"},{"key":"e_1_2_1_2_1","volume-title":"Digital Service, and Federal Risk and Authorization Management Program. CISA cloud security technical reference architecture","author":"Cybersecurity and Infrastructure Security Agency","year":"2021","unstructured":"Cybersecurity and Infrastructure Security Agency, U.S. Digital Service, and Federal Risk and Authorization Management Program. CISA cloud security technical reference architecture, 2021; https:\/\/bit.ly\/3IXmNIt."},{"key":"e_1_2_1_3_1","volume-title":"Accelerate---The Science of Lean Software and DevOps: Building and scaling high-performing technology organizations","author":"Forsgren N.","year":"2018","unstructured":"Forsgren, N., Humble, J., and Kim, G. Accelerate---The Science of Lean Software and DevOps: Building and scaling high-performing technology organizations. IT Revolution Press, 2018."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3454122.3454124"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1515\/9781400883547-006"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1097\/CCM.0000000000000402"},{"key":"e_1_2_1_7_1","unstructured":"Kahneman D. Thinking Fast and Slow. Macmillan 2011."},{"key":"e_1_2_1_8_1","volume-title":"On the possible impact of security technology design on policy adherent user behavior---Results from a controlled empirical experiment","author":"Kurowski S.","year":"2018","unstructured":"Kurowski, S., F\u00e4hnrich, N., and Ro\u00dfnagel, H. On the possible impact of security technology design on policy adherent user behavior---Results from a controlled empirical experiment. SICHERHEIT. H. Langweg, M. Meier, B.C. Witt, and D. Reinhardt, eds. Gesellschaft f\u00fcr Informatik e.V., Bonn, Germany, 2018, 145--158; https:\/\/dl.gi.de\/handle\/20.500.12116\/16276."},{"key":"e_1_2_1_9_1","volume-title":"Phishing in organizations: Findings from a large-scale and long-term study","author":"Lain D.","year":"2021","unstructured":"Lain, D., Kostiainen, K., and Capkun, S. Phishing in organizations: Findings from a large-scale and long-term study, 2021; https:\/\/arxiv.org\/abs\/2112.07498."},{"key":"e_1_2_1_10_1","volume-title":"The role of affect in decision making. Handbook of Affective Science","author":"Loewenstein G.","unstructured":"Loewenstein, G. and Lerner, J.S. The role of affect in decision making. Handbook of Affective Science. R. Davidson, H. Goldsmith, and K. Scherer, eds. Oxford University Press, Oxford, U.K., 619--664; https:\/\/bit.ly\/3yh6X6s."},{"key":"e_1_2_1_11_1","volume-title":"Taking into account the strength of an alternative hypothesis. J. Experimental Psychology: Learning, Memory, and Cognition 24, 3","author":"McKenzie C.R.M.","year":"1998","unstructured":"McKenzie, C.R.M. Taking into account the strength of an alternative hypothesis. J. Experimental Psychology: Learning, Memory, and Cognition 24, 3 (1998), 771--792; https:\/\/bit.ly\/3ZAUENY."},{"key":"e_1_2_1_12_1","volume-title":"Glossary of statistical terms","author":"Organization for Economic Cooperation and Development. Externalities---OECD.","year":"2003","unstructured":"Organization for Economic Cooperation and Development. Externalities---OECD. Glossary of statistical terms, 2003; https:\/\/www.oecd.org\/regreform\/sectors\/2376087.pdf."},{"key":"e_1_2_1_13_1","volume-title":"ProPublica (Jan. 25","author":"Podkul C.","year":"2022","unstructured":"Podkul, C. Despite decades of hacking attacks, companies leave vast amounts of sensitive data unprotected. ProPublica (Jan. 25, 2022); http:\/\/bit.ly\/3JhmFot."},{"key":"e_1_2_1_14_1","volume-title":"Die softwareherkunft (software provenance): an opera in two acts. Why would anyone do that? (Jan. 14","author":"Poirier G.","year":"2022","unstructured":"Poirier, G. Die softwareherkunft (software provenance): an opera in two acts. Why would anyone do that? (Jan. 14, 2022); https:\/\/grepory.substack.com\/p\/der-softwareherkunft-software-provenance."},{"key":"e_1_2_1_15_1","first-page":"3","article-title":"Multiple-category decision making: review and synthesis","volume":"10","author":"Russell G.","year":"1999","unstructured":"Russell, G. et al. Multiple-category decision making: review and synthesis. Marketing Letters 10, 3 (1999), 319--332; https:\/\/link.springer.com\/article\/10.1023\/A:1008143526174#article-info.","journal-title":"Marketing Letters"},{"key":"e_1_2_1_16_1","volume-title":"Security Chaos Engineering: Sustaining Resilience in Software and Systems","author":"Shortridge K.","year":"2022","unstructured":"Shortridge, K. and Rinehart, A. Security Chaos Engineering: Sustaining Resilience in Software and Systems. O'Reilly Media, Sebastopol, CA, 2022."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1111\/1468-5973.12084"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597464","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597464","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:48:45Z","timestamp":1750182525000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597464"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,22]]},"references-count":17,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2023,7]]}},"alternative-id":["10.1145\/3597464"],"URL":"https:\/\/doi.org\/10.1145\/3597464","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,22]]},"assertion":[{"value":"2023-06-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}