{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T09:46:26Z","timestamp":1782380786358,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":71,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T00:00:00Z","timestamp":1776038400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"TheSEUS","award":["NWA.1215.18.006"],"award-info":[{"award-number":["NWA.1215.18.006"]}]},{"name":"Ministry of the Interior and Kingdom Relations of the Netherlands and Delft University of Technology","award":["M75B07"],"award-info":[{"award-number":["M75B07"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3772318.3790613","type":"proceedings-article","created":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T04:12:28Z","timestamp":1776053548000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["\u201cTell Them They Are a Responsible Entity, Not a Customer\u201d: Understanding Practitioner Challenges in Sector CSIRTs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-5738-7458","authenticated-orcid":false,"given":"Aksel","family":"Ethembabaoglu","sequence":"first","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8831-6744","authenticated-orcid":false,"given":"Natalia","family":"I. Kadenko","sequence":"additional","affiliation":[{"name":"National Cyber Security Center (NCSC), The Hague, Netherlands and Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-3068-8438","authenticated-orcid":false,"given":"Yana","family":"Angelova","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9116-0728","authenticated-orcid":false,"given":"Yury","family":"Zhauniarovich","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1491-9867","authenticated-orcid":false,"given":"Rolf","family":"van Wegberg","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6667-0440","authenticated-orcid":false,"given":"Simon","family":"Parkin","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0338-2812","authenticated-orcid":false,"given":"Michel","family":"van Eeten","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,13]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","unstructured":"Maziana Abd\u00a0Majid and Khairul\u00a0Akram Zainol\u00a0Ariffin. 2021. Model for successful development and implementation of Cyber Security Operations Centre (SOC). PloS One 16 11 (2021) e0260157. 10.1371\/journal.pone.0260157","DOI":"10.1371\/journal.pone.0260157"},{"key":"e_1_3_3_2_3_2","first-page":"319","volume-title":"Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)","author":"Alomar Noura","year":"2020","unstructured":"Noura Alomar, Primal Wijesekera, Edward Qiu, and Serge Egelman. 2020. \"You\u2019ve Got Your Nice List of Bugs, Now What?\" Vulnerability Discovery and Management Processes in the Wild. In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, Berkeley, CA, USA, 319\u2013339. https:\/\/www.usenix.org\/conference\/soups2020\/presentation\/alomar"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"crossref","unstructured":"Annika Andreasson Henrik Artman Joel Brynielsson and Ulrik Franke. 2024. Cybersecurity work at Swedish administrative authorities: taking action or waiting for approval. Cognition Technology & Work 26 4 (2024) 709\u2013731.","DOI":"10.1007\/s10111-024-00779-1"},{"key":"e_1_3_3_2_5_2","unstructured":"Atlas.Ti. 2023. ATLAS.ti | The #1 Software for Qualitative Data Analysis. https:\/\/atlasti.com"},{"key":"e_1_3_3_2_6_2","unstructured":"M Bada S Creese M Goldsmith C Mitchell and E Phillips. 2014. Improving the Effectiveness of CSIRTs Global Cyber Security Capacity Centre."},{"key":"e_1_3_3_2_7_2","first-page":"3313","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Badva Priyanka","year":"2024","unstructured":"Priyanka Badva, Kopo\u00a0M. Ramokapane, Eleonora Pantano, and Awais Rashid. 2024. Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber Defense. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 3313\u20133330. https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/badva"},{"key":"e_1_3_3_2_8_2","volume-title":"Community: The structure of belonging","author":"Block Peter","year":"2018","unstructured":"Peter Block. 2018. Community: The structure of belonging. Berrett-Koehler Publishers, Oakland, CA, USA."},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","unstructured":"Virginia Braun and Victoria Clarke. 2021. One size fits all? What counts as quality practice in (reflexive) thematic analysis? Qualitative Research in Psychology 18 3 (2021) 328\u2013352. arXiv:10.1080\/14780887.2020.176923810.1080\/14780887.2020.1769238","DOI":"10.1080\/14780887.2020.1769238"},{"key":"e_1_3_3_2_10_2","unstructured":"F. Cetin C. Ga\u00f1\u00e1n Maciej Korczy\u0144ski and M. van Eeten. 2017. Make Notifications Great Again: Learning How to Notify in the Age of Large-Scale Vulnerability Scanning. Workshop on the Economics of Information Security (WEIS). https:\/\/www.semanticscholar.org\/paper\/Make-notifications-great-again%3A-learning-how-to-in-Cetin-Ga%C3%B1%C3%A1n\/ed24ca9d63385392bbd6ac52288933b93444c43d Paper."},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","unstructured":"Tiffani\u00a0R. Chen Daniel\u00a0B. Shore Stephen\u00a0J. Zaccaro Reeshad\u00a0S. Dalal Lois\u00a0E. Tetrick and Aiva\u00a0K. Gorab. 2014. An Organizational Psychology Perspective to Examining Computer Security Incident Response Teams. IEEE Security & Privacy 12 5 (Sept. 2014) 61\u201367. 10.1109\/MSP.2014.85Conference Name: IEEE Security & Privacy.","DOI":"10.1109\/MSP.2014.85"},{"key":"e_1_3_3_2_12_2","unstructured":"Justin\u00a0Novak Christopher\u00a0Rodman Breanna\u00a0Kraus. 2024. SOC Service Areas: Identification Prioritization and Implementation. https:\/\/www.ndss-symposium.org\/ndss-paper\/auto-draft-521\/"},{"key":"e_1_3_3_2_13_2","unstructured":"European Commission. 2025. NIS2 Directive: new rules on cybersecurity of network and information systems | Shaping Europe\u2019s digital future. https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/nis2-directive"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78243-8_2"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_3_3_2_16_2","unstructured":"ENISA. 2019. Study on CSIRT landscape and IR capabilities in Europe 2025. https:\/\/www.enisa.europa.eu\/publications\/study-on-csirt-landscape-and-ir-capabilities-in-europe-2025"},{"key":"e_1_3_3_2_17_2","unstructured":"ENISA. 2022. CSIRT Maturity Framework. https:\/\/www.enisa.europa.eu\/topics\/incident-response\/csirt-capabilities\/csirt-maturity. Accessed December 18 2024."},{"key":"e_1_3_3_2_18_2","unstructured":"ENISA. 2024. How to set up CSIRT and SOC | ENISA. https:\/\/www.enisa.europa.eu\/publications\/how-to-set-up-csirt-and-soc"},{"key":"e_1_3_3_2_19_2","unstructured":"ENISA. 2024. NIS Directive and national CSIRTs | ENISA. https:\/\/www.enisa.europa.eu\/publications\/nis-directive-and-national-csirts"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSPP58763.2023.10404318"},{"key":"e_1_3_3_2_21_2","unstructured":"FIRST.ORG. 2019. FIRST CSIRT Services Framework. https:\/\/www.first.org\/standards\/frameworks\/csirts\/FIRST_CSIRT_Services_Framework_v2.1.0_bugfix1.pdf Accessed: 2024-Nov-23."},{"key":"e_1_3_3_2_22_2","unstructured":"FIRST.ORG. 2019. Team Types Within the Context of Services Frameworks. https:\/\/www.first.org\/standards\/frameworks\/csirts\/team-type_1-0 Accessed: 2024-Nov-23."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData55660.2022.10020736"},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICOIACT53268.2021.9563925"},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.57"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1184\/R1\/16416771.v1"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/2858036.2858503"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","unstructured":"Georgia Killcrece Klaus-Peter Kossakowski Robin\u00a0M. Ruefle and Mark Zajicek. 2018. Organizational Models for Computer Security Incident Response Teams (CSIRTs). 10.1184\/R1\/6575921.v1","DOI":"10.1184\/R1\/6575921.v1"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.14722\/usec.2014.23007"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"crossref","unstructured":"Laura Kocksch Matthias Korn Andreas Poller and Susann Wagenknecht. 2018. Caring for IT security: Accountabilities moralities and oscillations in IT security practices. Proceedings of the ACM on Human-Computer Interaction 2 CSCW (2018) 1\u201320.","DOI":"10.1145\/3274361"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354239"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-372-8-81"},{"key":"e_1_3_3_2_33_2","first-page":"1033","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Li Frank","year":"2016","unstructured":"Frank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael Bailey, Damon McCoy, Stefan Savage, and Vern Paxson. 2016. You\u2019ve Got Vulnerability: Exploring Effective Vulnerability Notifications. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 1033\u20131050. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/li"},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2872427.2883039"},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","unstructured":"Chanel Macabante Sherry Wei and David Schuster. 2019. Elements of Cyber-Cognitive Situation Awareness in Organizations. Proceedings of the Human Factors and Ergonomics Society Annual Meeting 63 1 (2019) 1624\u20131628. arXiv:10.1177\/107118131963148310.1177\/1071181319631483","DOI":"10.1177\/1071181319631483"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","unstructured":"Stuart Madnick Xitong Li and Nazli Choucri. 2009. Experiences and Challenges with Using CERT Data to Analyze International Cyber Security. 10.2139\/ssrn.1478206","DOI":"10.2139\/ssrn.1478206"},{"key":"e_1_3_3_2_37_2","first-page":"189","volume-title":"Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)","author":"Mare Shrirang","year":"2016","unstructured":"Shrirang Mare, Mary Baker, and Jeremy Gummeson. 2016. A Study of Authentication in Daily Life. In Twelfth Symposium on Usable Privacy and Security (SOUPS 2016). USENIX Association, Denver, CO, 189\u2013206. https:\/\/www.usenix.org\/conference\/soups2016\/technical-sessions\/presentation\/mare"},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","unstructured":"Nora McDonald Sarita Schoenebeck and Andrea Forte. 2019. Reliability and Inter-rater Reliability in Qualitative Research: Norms and Guidelines for CSCW and HCI Practice. Proceedings of the ACM on Human-Computer Interaction 3 CSCW (Nov. 2019) 1\u201323. 10.1145\/3359174","DOI":"10.1145\/3359174"},{"key":"e_1_3_3_2_39_2","first-page":"301","volume-title":"Proceedings of the Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)","author":"Michalec Ola\u00a0Aleksandra","year":"2020","unstructured":"Ola\u00a0Aleksandra Michalec, Dirk van\u00a0der Linden, Sveta Milyaeva, and Awais Rashid. 2020. Industry Responses to the European Directive on Security of Network and Information Systems (NIS): Understanding Policy Implementation Practices across Critical Infrastructures. In Proceedings of the Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, Berkeley, CA, USA, 301\u2013317. https:\/\/www.usenix.org\/conference\/soups2020\/presentation\/michalec"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","unstructured":"S.\u00a0R.\u00a0B. Mohd\u00a0Kassim S. Li and B. Arief. 2023. Understanding How National CSIRTs Evaluate Cyber Incident Response Tools and Data: Findings from Focus Group Discussions. Digital Threats: Research and Practice 4 3 (2023) 18\u00a0pages. 10.1145\/3609230","DOI":"10.1145\/3609230"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808134"},{"key":"e_1_3_3_2_42_2","unstructured":"Ali Naseri and Omid Azmoon. 2012. Proposition of model for CSIRT: Case study of telecommunication company in a province of Iran. International Journal of Computer Science Issues (IJCSI) 9 1 (2012) 156."},{"key":"e_1_3_3_2_43_2","unstructured":"Nationaal Cyber Security Centrum (NCSC-NL). n. d.. Over MijnNCSC. https:\/\/www.ncsc.nl\/aansluiten-en-samenwerken\/mijnncsc\/over-mijnncsc. Accessed September 11 2025."},{"key":"e_1_3_3_2_44_2","unstructured":"Nationaal Cybersecurity Centrum (NCSC). 2025. Ondersteuning bij cyberincidenten \u2013 Als sectoraal CSIRT. https:\/\/www.ncsc.nl\/documenten\/factsheets\/2025\/februari\/11\/ondersteuning-bij-cyberincidenten\u2014voor-nis2-organisaties. Accessed April 22 2025."},{"key":"e_1_3_3_2_45_2","doi-asserted-by":"publisher","unstructured":"Justin Novak Brittany Manley David McIntire Sharon Mudd Angel Hueca and Tracy Bills. 2021. The Sector CSIRT Framework: Developing Sector-Based Incident Response Capabilities. Carnegie Mellon University Software Engineering Institute\u2019s Digital Library. 10.1184\/R1\/13624148 Accessed: 2024-Sep-23.","DOI":"10.1184\/R1\/13624148"},{"key":"e_1_3_3_2_46_2","unstructured":"Justin Novak Brittany Manley David McIntire Sharon Mudd Angel Hueca and Tracy Bills. 2021. The Sector CSIRT Framework: Developing Sector-Based Incident Response Capabilities."},{"key":"e_1_3_3_2_47_2","unstructured":"The White House\u00a0Office of\u00a0the Press\u00a0Secretary. 2016. Presidential Policy Directive \u2013 United States Cyber Incident Coordination. https:\/\/obamawhitehouse.archives.gov\/the-press-office\/2016\/07\/26\/presidential-policy-directive-united-states-cyber-incident"},{"key":"e_1_3_3_2_48_2","doi-asserted-by":"publisher","unstructured":"Anthony\u00a0J. Onwuegbuzie Wendy\u00a0B. Dickinson Nancy\u00a0L. Leech and Annmarie\u00a0G. Zoran. 2009. A Qualitative Framework for Collecting and Analyzing Data in Focus Group Research. International Journal of Qualitative Methods 8 3 (2009) 1\u201321. arXiv:10.1177\/16094069090080030110.1177\/160940690900800301","DOI":"10.1177\/160940690900800301"},{"key":"e_1_3_3_2_49_2","doi-asserted-by":"publisher","unstructured":"Andreas Oster Eivor Wiking Gunnar\u00a0H. Nilsson and Christina\u00a0B. Olsson. 2024. Patients\u2019 expectations of primary health care from both patients\u2019 and physicians\u2019 perspectives: a questionnaire study with a qualitative approach. BMC Primary Care 25 1 (April 2024) 128. 10.1186\/s12875-024-02389-2","DOI":"10.1186\/s12875-024-02389-2"},{"key":"e_1_3_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3618257.3624810"},{"key":"e_1_3_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-61152-5_8"},{"key":"e_1_3_3_2_52_2","unstructured":"Kristin Repchick Stephen Zaccaro Lois Tetrick Julie Steinke Daniel Shore Carolyn Winslow Amber reecho Hargrove Balca Alaybek Jennifer Green Tracy McCausland and Alan Tomassetti. 2016. Improving social maturity of cybersecurity incident response teams."},{"key":"e_1_3_3_2_53_2","doi-asserted-by":"publisher","unstructured":"Thea Riebe Marc-Andr\u00e9 Kaufhold and Christian Reuter. 2021. The Impact of Organizational Structure and Technology Use on Collaborative Practices in Computer Emergency Response Teams: An Empirical Study. Proc. ACM Hum.-Comput. Interact. 5 CSCW2 Article 478 (Oct. 2021) 30\u00a0pages. 10.1145\/3479865","DOI":"10.1145\/3479865"},{"key":"e_1_3_3_2_54_2","doi-asserted-by":"publisher","unstructured":"Mario Saraiva and Nuno Mateus-Coelho. 2022. CyberSoc Framework a Systematic Review of the State-of-Art. Procedia Computer Science 204 (2022) 961\u2013972. 10.1016\/j.procs.2022.08.117Publisher Copyright: \u00a9 2022 Elsevier B.V.. All rights reserved.; 2022 International Conference on Industry Sciences and Computer Science Innovation iSCSi 2022 ; Conference date: 09-03-2022 Through 11-03-2022.","DOI":"10.1016\/j.procs.2022.08.117"},{"key":"e_1_3_3_2_55_2","unstructured":"Vilja Steffensen and Vahiny Gnanasekaran. 2024. Information Sharing between the Computer Security Incident Response Team and its Members: An Empirical Study. Norsk IKT-konferanse for forskning og utdanning 3 3 (Nov. 2024) n\/a\u00a0pages. https:\/\/www.ntnu.no\/ojs\/index.php\/nikt\/article\/view\/6250"},{"key":"e_1_3_3_2_56_2","doi-asserted-by":"publisher","unstructured":"Julie Steinke Balca Bolunmez Laura Fletcher Vicki Wang Alan\u00a0J. Tomassetti Kristin\u00a0M. Repchick Stephen\u00a0J. Zaccaro Reeshad\u00a0S. Dalal and Lois\u00a0E. Tetrick. 2015. Improving Cybersecurity Incident Response Team Effectiveness Using Teams-Based Research. IEEE Security and Privacy 13 4 (jul 2015) 20\u201329. 10.1109\/MSP.2015.71","DOI":"10.1109\/MSP.2015.71"},{"key":"e_1_3_3_2_57_2","unstructured":"Don Stikvoort. 2015. SIM3: Security Incident Management Maturity Model. https:\/\/cybilportal.org\/publications\/sim3-security-incident-management-maturity-model\/ Accessed: 2024-09-23."},{"key":"e_1_3_3_2_58_2","series-title":"(SEC\u201916)","first-page":"1015","volume-title":"Proceedings of the 25th USENIX Conference on Security Symposium","author":"Stock Ben","year":"2016","unstructured":"Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, and Michael Backes. 2016. Hey, you have a problem: on the feasibility of large-scaleweb vulnerability notification. In Proceedings of the 25th USENIX Conference on Security Symposium (Austin, TX, USA) (SEC\u201916). USENIX Association, USA, 1015\u20131032."},{"key":"e_1_3_3_2_59_2","doi-asserted-by":"publisher","unstructured":"Sathya\u00a0Chandran Sundaramurthy John McHugh Xinming\u00a0Simon Ou S.\u00a0Raj Rajagopalan and Michael Wesch. 2014. An Anthropological Approach to Studying CSIRTs. IEEE Security & Privacy 12 05 (Sept. 2014) 52\u201360. 10.1109\/MSP.2014.84","DOI":"10.1109\/MSP.2014.84"},{"key":"e_1_3_3_2_60_2","volume-title":"Handbook of Mixed Methods in Social & Behavioral Research","author":"Tashakkori Abbas","year":"2003","unstructured":"Abbas Tashakkori and Charles Teddlie. 2003. Handbook of Mixed Methods in Social & Behavioral Research. SAGE Publications, Thousand Oaks, CA, USA. https:\/\/books.google.nl\/books?id=F8BFOM8DCKoC"},{"key":"e_1_3_3_2_61_2","unstructured":"The Shadowserver Foundation. n. d.. The Shadowserver Foundation. https:\/\/www.shadowserver.org\/. Accessed April 28 2025."},{"key":"e_1_3_3_2_62_2","volume-title":"FY 2024 Annual Performance Report, Appendix D: Measure Descriptions, Data Collection Methodologies, and Completeness and Reliability Information","author":"Security U.S. Department of Homeland","year":"2024","unstructured":"U.S. Department of Homeland Security. 2024. FY 2024 Annual Performance Report, Appendix D: Measure Descriptions, Data Collection Methodologies, and Completeness and Reliability Information. Annual Performance Report. U.S. Department of Homeland Security. https:\/\/www.dhs.gov\/sites\/default\/files\/2025-01\/2025_0117_dhs_annual_performance_report_fy2024_appendixd.pdf Appendix D, p.\u00a025."},{"key":"e_1_3_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0076"},{"key":"e_1_3_3_2_64_2","doi-asserted-by":"publisher","unstructured":"Rick van\u00a0der Kleij Geert Kleinhuis and Heather Young. 2017. Computer Security Incident Response Team Effectiveness: A Needs Assessment. Frontiers in Psychology 8 (2017) 194. 10.3389\/fpsyg.2017.00194","DOI":"10.3389\/fpsyg.2017.00194"},{"key":"e_1_3_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706598.3713719"},{"key":"e_1_3_3_2_66_2","unstructured":"Koen van Hove Jeroen van der Ham-de Vos and Roland van Rijswijk-Deij. 2023. Your Vulnerability Disclosure Is Important To Us: An Analysis of Coordinated Vulnerability Disclosure Responses Using a Real Security Issue. arxiv:https:\/\/arXiv.org\/abs\/2312.07284\u00a0[cs.NI] https:\/\/arxiv.org\/abs\/2312.07284"},{"key":"e_1_3_3_2_67_2","unstructured":"YM Wara and D Singh. 2015. A guide to establishing computer security incident response team (CSIRT) for national research and education network (NREN). African Journal of Computing & ICT 8 2 (2015) 1\u20138."},{"key":"e_1_3_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.21236\/ADA358945"},{"key":"e_1_3_3_2_69_2","first-page":"67","volume-title":"Proceedings of the TF-CSIRT Meeting 2006","author":"Wiik Johannes","year":"2006","unstructured":"Johannes Wiik, Jose Gonzalez, and Klaus-Peter Kossakowski. 2006. Effectiveness of Proactive CSIRT Services. In Proceedings of the TF-CSIRT Meeting 2006. TERENA, Innsbruck, Austria, 67\u201381."},{"key":"e_1_3_3_2_70_2","doi-asserted-by":"publisher","unstructured":"Julia Wunder Alan Corona Andreas Hammer and Zinaida Benenson. 2024. On NVD Users\u2019 Attitudes Experiences Hopes and Hurdles. Digital Threats 5 3 Article 33 (Oct. 2024) 19\u00a0pages. 10.1145\/3688806","DOI":"10.1145\/3688806"},{"key":"e_1_3_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706598.3713652"},{"key":"e_1_3_3_2_72_2","doi-asserted-by":"publisher","unstructured":"Or\u00e7un \u00c7etin Mohammad Hanif\u00a0Jhaveri Carlos Ga\u00f1\u00e1n Michel van Eeten and Tyler Moore. 2016. Understanding the role of sender reputation in abuse reporting and cleanup. Journal of Cybersecurity 2 1 (12 2016) 83\u201398. arXiv:https:\/\/academic.oup.com\/cybersecurity\/article-pdf\/2\/1\/83\/10833175\/tyw005.pdf10.1093\/cybsec\/tyw005","DOI":"10.1093\/cybsec\/tyw005"}],"event":{"name":"CHI 2026: CHI Conference on Human Factors in Computing Systems","location":"Barcelona Spain","acronym":"CHI '26","sponsor":["SIGCHI ACM Special Interest Group on Computer-Human Interaction"]},"container-title":["Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3772318.3790613","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T08:51:59Z","timestamp":1782377519000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3772318.3790613"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,13]]},"references-count":71,"alternative-id":["10.1145\/3772318.3790613","10.1145\/3772318"],"URL":"https:\/\/doi.org\/10.1145\/3772318.3790613","relation":{},"subject":[],"published":{"date-parts":[[2026,4,13]]},"assertion":[{"value":"2026-04-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}