{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:20:38Z","timestamp":1773670838954,"version":"3.50.1"},"reference-count":75,"publisher":"Association for Computing Machinery (ACM)","issue":"1","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,3,31]]},"abstract":"<jats:p>Security conferences are important venues for information sharing, where academics and practitioners share knowledge about new attacks and state-of-the-art defenses. Despite their importance, researchers have not systematically examined who shares information and which security topics are discussed. To address this gap, our article characterizes the speakers, sponsors, and topics presented at prestigious academic and industry security conferences. We compile a longitudinal dataset containing 9,728 abstracts and 1,686 sponsors across 4 academic and 6 industry conferences. Our findings show limited information sharing between industry and academia. Conferences vary significantly in how equitably talks and authorship are distributed across individuals. The topics of academic and industry abstracts display consistent coverage of techniques within the MITRE ATT&amp;CK framework. Top-tier academic conferences, as well as DEFCON and Black Hat, address the governance, response, and recovery functions of the NIST Cybersecurity Framework inconsistently. Commercial information security and insurance conferences (RSA, Gartner, Advisen, and NetDiligence) more consistently cover the framework. Prevention and detection were the most common topics in the sample period, with no clear temporal trends.<\/jats:p>","DOI":"10.1145\/3788676","type":"journal-article","created":{"date-parts":[[2026,1,19]],"date-time":"2026-01-19T10:05:08Z","timestamp":1768817108000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Who Shares What? An Empirical Analysis of Security Conference Content across Academia and Industry"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-1128-1712","authenticated-orcid":false,"given":"Lukas","family":"Walter","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-9464-5080","authenticated-orcid":false,"given":"Clemens","family":"Sauerwein","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Innsbruck, Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8569-1917","authenticated-orcid":false,"given":"Daniel W.","family":"Woods","sequence":"additional","affiliation":[{"name":"School of Informatics, University of Edinburgh, Edinburgh, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,16]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.04.003"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3124398"},{"key":"e_1_3_2_4_2","doi-asserted-by":"crossref","first-page":"103352","DOI":"10.1016\/j.cose.2023.103352","article-title":"Cyber-threat intelligence for security decision-making: A review and research agenda for practice","author":"Ainslie Scott","year":"2023","unstructured":"Scott Ainslie, Dean Thompson, Sean Maynard, and Atif Ahmad. 2023. Cyber-threat intelligence for security decision-making: A review and research agenda for practice. Computers & Security 132 (2023), 103352.","journal-title":"Computers & Security"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11192-019-03279-6"},{"key":"e_1_3_2_6_2","unstructured":"Davide Balzarotti. 2022. System Security Circus 2022. Retrieved October 10 2025 from https:\/\/www.s3.eurecom.fr\/\u223cbalzarot\/security-circus\/circus_stats.html"},{"key":"e_1_3_2_7_2","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1145\/2898375.2898380","volume-title":"Proceedings of the Symposium and Bootcamp on the Science of Security","author":"Carver Jeffrey C.","year":"2016","unstructured":"Jeffrey C. Carver, Morgan Burcham, Sedef Akinli Kocak, Ayse Bener, Michael Felderer, Matthias Gander, Jason King, Jouni Markkula, Markku Oivo, Clemens Sauerwein, et al. 2016. Establishing a baseline for measuring advancement in the science of security: An analysis of the 2015 IEEE security & privacy proceedings. In Proceedings of the Symposium and Bootcamp on the Science of Security, 38\u201351."},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1145\/3055305.3055307","volume-title":"Proceedings of the Hot Topics in Science of Security: Symposium and Bootcamp","author":"Burcham Morgan","year":"2017","unstructured":"Morgan Burcham, Mahran Al-Zyoud, Jeffrey C. Carver, Mohammed Alsaleh, Hongying Du, Fida Gilani, Jun Jiang, Akond Rahman, \u00d6zg\u00fcr Kafal\u0131, Ehab Al-Shaer, et al. 2017. Characterizing scientific reporting in security literature: An analysis of ACM CCS and IEEE S&P papers. In Proceedings of the Hot Topics in Science of Security: Symposium and Bootcamp, 13\u201323."},{"key":"e_1_3_2_9_2","unstructured":"Lukas Walter Clemens Sauerwein and Daniel Woods. 2024. InfoSec.pptx: A longitudinal dataset of talks and sponsors at academic and industry security conferences. Retrieved April 2024 from https:\/\/doi.org\/10.5281\/zenodo.15989593"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.04.005"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102122"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.99"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1108\/IMDS-10-2019-0536"},{"issue":"1","key":"e_1_3_2_14_2","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1353\/tech.2020.0036","article-title":"Trusting infrastructure: The emergence of computer security incident response, 1989\u20132005","volume":"61","author":"Slayton Rebecca","year":"2020","unstructured":"Rebecca Slayton and Brian Clarke. 2020. Trusting infrastructure: The emergence of computer security incident response, 1989\u20132005. Technology and Culture 61, 1 (2020), 173\u2013206.","journal-title":"Technology and Culture"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101589"},{"key":"e_1_3_2_16_2","unstructured":"Clemens Sauerwein Christian Sillaber Andrea Mussmann and Ruth Breu. 2017. Threat intelligence sharing platforms: An exploratory study of software vendors and research perspectives. In Proceedings of the Wirtschaftsinformatik."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808133"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.12.011"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3465481.3470048"},{"key":"e_1_3_2_20_2","first-page":"1","volume-title":"Proceedings of the 2013 5th International Conference on Cyber Conflict (CYCON \u201913)","author":"Dandurand Luc","year":"2013","unstructured":"Luc Dandurand and Oscar Serrano Serrano. 2013. Towards improved cyber security information sharing. In Proceedings of the 2013 5th International Conference on Cyber Conflict (CYCON \u201913). IEEE, 1\u201316."},{"key":"e_1_3_2_21_2","first-page":"36","volume-title":"Threat Intelligence: Collecting, Analysing, Evaluating","author":"Chismon David","year":"2015","unstructured":"David Chismon and Martyn Ruks. 2015. Threat Intelligence: Collecting, Analysing, Evaluating, Vol. 3. MWR InfoSecurity Ltd, 36\u201342."},{"key":"e_1_3_2_22_2","first-page":"851","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"Li Vector Guo","year":"2019","unstructured":"Vector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy, Geoffrey M. Voelker, and Stefan Savage. 2019. Reading the tea leaves: A comparative analysis of threat intelligence. In Proceedings of the 28th USENIX Security Symposium, 851\u2013867."},{"key":"e_1_3_2_23_2","first-page":"143","volume-title":"Proceedings of the 19th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201916)","author":"Thomas Kurt","year":"2016","unstructured":"Kurt Thomas, Rony Amira, Adi Ben-Yoash, Ori Folger, Amir Hardon, Ari Berger, Elie Bursztein, and Michael Bailey. 2016. The abuse sharing economy: Understanding the limits of threat exchanges. In Proceedings of the 19th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID \u201916). Springer, 143\u2013164."},{"key":"e_1_3_2_24_2","first-page":"1149","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Bouwman Xander","year":"2022","unstructured":"Xander Bouwman, Victor Le Pochat, Pawel Foremski, Tom Van Goethem, Carlos H. Ga\u00f1\u00e1n, Giovane Moura, Samaneh Tajalizadehkhoob, Wouter Joosen, and Michel van Eeten. 2022. Helping hands: Measuring the impact of a large threat intelligence sharing community. In Proceedings of the 31st USENIX Security Symposium, 1149\u20131165."},{"key":"e_1_3_2_25_2","first-page":"433","volume-title":"Proceedings of the 30th USENIX Security Symposium","author":"Bouwman Xander","year":"2020","unstructured":"Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, and Michel van Eeten. 2020. A different cup of TI? The added value of commercial threat intelligence. In Proceedings of the 30th USENIX Security Symposium, 433\u2013450."},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3484202"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.5325\/jinfopoli.7.2017.0372"},{"issue":"1","key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"tyab007","DOI":"10.1093\/cybsec\/tyab007","article-title":"Hacking for good: Leveraging HackerOne data to develop an economic model of bug bounties","volume":"7","author":"Sridhar Kiran","year":"2021","unstructured":"Kiran Sridhar and Ming Ng. 2021. Hacking for good: Leveraging HackerOne data to develop an economic model of bug bounties. Journal of Cybersecurity 7, 1 (2021), tyab007.","journal-title":"Journal of Cybersecurity"},{"key":"e_1_3_2_29_2","first-page":"273","volume-title":"Proceedings of the Presented as Part of the 22nd USENIX Security Symposium","author":"Finifter Matthew","year":"2013","unstructured":"Matthew Finifter, Devdatta Akhawe, and David Wagner. 2013. An empirical study of vulnerability rewards programs. In Proceedings of the Presented as Part of the 22nd USENIX Security Symposium. USENIX, 273\u2013288."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813704"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00003"},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1109\/SP61157.2025.00020","volume-title":"Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP)","author":"Piao Yangheran","year":"2025","unstructured":"Yangheran Piao, Temima Hrle, Daniel W. Woods, and Ross Anderson. 2025. Study club, labor union or start-up? Characterizing teams and collaboration in the bug bounty ecosystem. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP). IEEE, 539\u2013558."},{"key":"e_1_3_2_33_2","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1145\/1162666.1162671","volume-title":"Proceedings of the SIGCOMM Workshop on Large-Scale Attack Defense","author":"Frei Stefan","year":"2006","unstructured":"Stefan Frei, Martin May, Ulrich Fiedler, and Bernhard Plattner. 2006. Large-scale vulnerability analysis. In Proceedings of the SIGCOMM Workshop on Large-Scale Attack Defense, 131\u2013138."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_35_2","first-page":"273","volume-title":"Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS \u201919)","author":"Li Frank","year":"2019","unstructured":"Frank Li, Lisa Rogers, Arunesh Mathur, Nathan Malkin, and Marshini Chetty. 2019. Keepers of the machines: Examining how system administrators manage software updates for multiple machines. In Proceedings of the 15th Symposium on Usable Privacy and Security (SOUPS \u201919), 273\u2013288."},{"key":"e_1_3_2_36_2","first-page":"43","volume-title":"Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS \u201916)","author":"Mathur Arunesh","year":"2016","unstructured":"Arunesh Mathur, Josefine Engel, Sonam Sobti, Victoria Chang, and Marshini Chetty. 2016. \u201cThey keep coming back like zombies\u201d: Improving software updating interfaces. In Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS \u201916), 43\u201358."},{"key":"e_1_3_2_37_2","first-page":"1015","volume-title":"Proceedings of the USENIX Security Symposium","author":"Stock Ben","year":"2016","unstructured":"Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, and Michael Backes. 2016. Hey, you have a problem: On the feasibility of large-scale web vulnerability notification. In Proceedings of the USENIX Security Symposium. USENIX, 1015\u20131032."},{"key":"e_1_3_2_38_2","first-page":"1033","volume-title":"Proceedings of the USENIX Security Symposium","author":"Li Frank","year":"2016","unstructured":"Frank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael Bailey, Damon McCoy, Stefan Savage, and Vern Paxson. 2016. You\u2019ve got vulnerability: Exploring effective vulnerability notifications. In Proceedings of the USENIX Security Symposium. USENIX, 1033\u20131050."},{"key":"e_1_3_2_39_2","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1109\/EuroSP.2019.00032","volume-title":"Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"\u00c7etin Or\u00e7un","year":"2019","unstructured":"Or\u00e7un \u00c7etin, Carlos Ga\u00f1\u00e1n, Lisette Altena, Samaneh Tajalizadehkhoob, and Michel Van Eeten. 2019. Tell me you fixed it: Evaluating vulnerability notifications via quarantine networks. In Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 326\u2013339."},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyaa015"},{"key":"e_1_3_2_41_2","volume-title":"Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP)","author":"de Smale Stephanie","year":"2023","unstructured":"Stephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham, and Michel van Eeten. 2023. No one drinks from the firehose: How organizations filter and prioritize vulnerability information. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_42_2","first-page":"380","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP)","author":"Li Jingjie","year":"2023","unstructured":"Jingjie Li, Kaiwen Sun, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim, Florian Schaub, and Kassem Fawaz. 2023. \u201cIt\u2019s up to the consumer to be smart\u201d: Understanding the security and privacy attitudes of smart home users on reddit. In Proceedings of the IEEE Symposium on Security and Privacy (SP). IEEE, 380\u2013396."},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376768"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1109\/SP.2017.31","volume-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP)","author":"Fischer Felix","year":"2017","unstructured":"Felix Fischer, Konstantin B\u00f6ttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, and Sascha Fahl. 2017. Stack overflow considered harmful? The impact of copy&paste on android application security. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 121\u2013136."},{"key":"e_1_3_2_46_2","first-page":"339","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security 19)","author":"Fischer Felix","year":"2019","unstructured":"Felix Fischer, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin B\u00f6ttinger, Paul Muntean, et al. 2019. Stack overflow considered helpful! Deep learning security nudges towards stronger cryptography. In Proceedings of the 28th USENIX Security Symposium (USENIX Security 19), 339\u2013356."},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","first-page":"272","DOI":"10.1109\/SP.2016.24","volume-title":"Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP)","author":"Redmiles Elissa M.","year":"2016","unstructured":"Elissa M. Redmiles, Amelia R. Malone, and Michelle L. Mazurek. 2016. I think they\u2019re trying to tell me something: Advice sources and selection for digital security. In Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 272\u2013288."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489218"},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"1845","DOI":"10.1109\/SP46214.2022.9833581","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP)","author":"Soneji Ananta","year":"2022","unstructured":"Ananta Soneji, Faris Bugra Kokulu, Carlos Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, and Adam Doup\u00e9. 2022. \u201cFlawed, but like democracy we don\u2019t have a better system\u201d: The experts\u2019 insights on the peer review process of evaluating security papers. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP). IEEE, 1845\u20131862."},{"key":"e_1_3_2_50_2","first-page":"293","volume-title":"Proceedings of the Symposium on Security and Privacy","author":"Dambra Savino","year":"2020","unstructured":"Savino Dambra, Leyla Bilge, and Davide Balzarotti. 2020. SoK: Cyber insurance\u2014Technical challenges and a system security roadmap. In Proceedings of the Symposium on Security and Privacy. IEEE, 293\u2013309."},{"key":"e_1_3_2_51_2","unstructured":"National Association of Insurance Commissioners Staff. 2021. Report on the Cybersecurity Insurance Market. Retrieved October 10 2025 from https:\/\/content.naic.org\/sites\/default\/files\/cmte-c-cyber-supplement-report-2022-for-data-year-2021.pdf"},{"key":"e_1_3_2_52_2","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Woods Daniel W.","year":"2023","unstructured":"Daniel W. Woods, Rainer B\u00f6hme, Josephine Wolff, and Daniel Schwarcz. 2023. Lessons lost: Incident response in the age of cyber insurance and breach attorneys. In Proceedings of the 32nd USENIX Security Symposium."},{"key":"e_1_3_2_53_2","volume-title":"Proceedings of the 34th USENIX Security Symposium (USENIX Security \u201925)","author":"Kaur Harjot","year":"2025","unstructured":"Harjot Kaur, Carson Powers, Ronald E. Thompson, III, Sascha Fahl, and Daniel Votipka. 2025. \u201cThreat modeling is very formal, it\u2019s very technical, and also very hard to do correctly\u201d: Investigating threat modeling practices in open-source software projects. In Proceedings of the 34th USENIX Security Symposium (USENIX Security \u201925)."},{"key":"e_1_3_2_54_2","doi-asserted-by":"crossref","first-page":"2697","DOI":"10.1109\/SP61157.2025.00033","volume-title":"Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP)","author":"Usman Warda","year":"2025","unstructured":"Warda Usman and Daniel Zappala. 2025. SoK: A framework and guide for human-centered threat modeling in security and privacy research. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP). IEEE, 2697\u20132715."},{"key":"e_1_3_2_55_2","doi-asserted-by":"crossref","first-page":"440","DOI":"10.1109\/EuroSP51992.2021.00037","volume-title":"Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"Vermeer Mathew","year":"2021","unstructured":"Mathew Vermeer, Jonathan West, Alejandro Cuevas, Shuonan Niu, Nicolas Christin, Michel Van Eeten, Tobias Fiebig, Carlos Gan\u00e1n, and Tyler Moore. 2021. SoK: A framework for asset discovery: Systematizing advances in network measurements for protecting organizations. In Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 440\u2013456."},{"key":"e_1_3_2_56_2","first-page":"1009","volume-title":"Proceedings of the USENIX Security Symposium","author":"Liu Yang","year":"2015","unstructured":"Yang Liu, Armin Sarabi, Jing Zhang, Parinaz Naghizadeh, Manish Karir, Michael Bailey, and Mingyan Liu. 2015. Cloudy with a chance of breach: Forecasting cyber security incidents. In Proceedings of the USENIX Security Symposium. USENIX, 1009\u20131024."},{"key":"e_1_3_2_57_2","first-page":"1299","volume-title":"Proceedings. of the Conference on Computer and Communications Security","author":"Bilge Leyla","year":"2017","unstructured":"Leyla Bilge, Yufei Han, and Matteo Dell\u2019Amico. 2017. Riskteller: Predicting the risk of cyber incidents. In Proceedings. of the Conference on Computer and Communications Security. ACM, 1299\u20131311."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359172"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_60_2","first-page":"37","volume-title":"Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP)","author":"Ho Grant","year":"2025","unstructured":"Grant Ho, Ariana Mirian, Elisa Luo, Khang Tong, Euyhyun Lee, Lin Liu, Christopher A. Longhurst, Christian Dameff, Stefan Savage, and Geoffrey M. Voelker. 2025. Understanding the efficacy of phishing training in practice. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP). IEEE, 37\u201354."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-02343-9"},{"key":"e_1_3_2_62_2","volume-title":"Proceedings of the Workshop on the Economics of Information Security","author":"Collier Benjamin","year":"2020","unstructured":"Benjamin Collier, Richard Clayton, Alice Hutchings, and Daniel Thomas. 2020. Cybercrime is (often) boring: Maintaining the infrastructure of cybercrime economies. In Proceedings of the Workshop on the Economics of Information Security."},{"key":"e_1_3_2_63_2","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Vu Anh V.","year":"2025","unstructured":"Anh V. Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings. 2025. Assessing the aftermath: The effects of a global takedown against DDoS-for-hire services. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_64_2","volume-title":"Learning from Cyber Incidents: Adapting Aviation Safety Models to Cybersecurity","author":"Knake Rob","year":"2021","unstructured":"Rob Knake, Adam Shostack, and Tarah Wheeler. 2021. Learning from Cyber Incidents: Adapting Aviation Safety Models to Cybersecurity. Harvard Belfer Center."},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2010.05.009"},{"key":"e_1_3_2_66_2","volume-title":"The Ideas Industry","author":"Drezner Daniel W.","year":"2017","unstructured":"Daniel W. Drezner. 2017. The Ideas Industry. Oxford University Press."},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3461702.3462563"},{"key":"e_1_3_2_68_2","volume-title":"Proceedings of the 32st USENIX Security Symposium (USENIX Security \u201923)","author":"Hielscher Jonas","year":"2023","unstructured":"Jonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge, and M. Angela Sasse. 2023. \u201cEmployees who don\u2019t accept the time security takes are not aware enough\u201d: The CISO view of human-centred security. In Proceedings of the 32st USENIX Security Symposium (USENIX Security \u201923)."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355571"},{"key":"e_1_3_2_70_2","first-page":"481","volume-title":"Proceedings of the Conference on Computer and Communications Security","author":"Rahaman Sazzadur","year":"2019","unstructured":"Sazzadur Rahaman, Gang Wang, and Danfeng Yao. 2019. Security certification in payment card industry: Testbeds, measurements, and recommendations. In Proceedings of the Conference on Computer and Communications Security, 481\u2013498. ACM."},{"key":"e_1_3_2_71_2","first-page":"1517","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Mahmud Samin Yaseer","year":"2020","unstructured":"Samin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck, and Bradley Reaves. 2020. Cardpliance: PCI DSS compliance of android applications. In Proceedings of the 29th USENIX Security Symposium, 1517\u20131533."},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2015.2397395"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/13665.001.0001"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.102"},{"key":"e_1_3_2_75_2","first-page":"99","volume-title":"Proceedings of the Symposium on Security and Privacy","author":"Herley Cormac","year":"2017","unstructured":"Cormac Herley and Paul C. Van Oorschot. 2017. SoK: Science, security and the elusive goal of security as a scientific pursuit. In Proceedings of the Symposium on Security and Privacy, 99\u2013120. IEEE."},{"key":"e_1_3_2_76_2","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security","author":"Bouwman X. B.","year":"2025","unstructured":"X. B. Bouwman, A. M. Ethembabaoglu, B. Hermans, C. Hernandez Ganan, and M. J. G. van Eeten. 2025. Can IOCs impose cost? The effects of publishing threat intelligence on adversary behavior. In Proceedings of the ACM Conference on Computer and Communications Security. ACM."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3788676","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T13:07:51Z","timestamp":1773666471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3788676"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,16]]},"references-count":75,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3,31]]}},"alternative-id":["10.1145\/3788676"],"URL":"https:\/\/doi.org\/10.1145\/3788676","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,16]]},"assertion":[{"value":"2024-11-26","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-17","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}