Investigating Usefulness of Security Threat Reports
Author · Manuscript under review
We compared 31 incident reports from DFIR firms and cyberinsurers and
found surprisingly little agreement on basic questions like the most
common initial-access vectors or most-exploited CVEs. Inconsistent
definitions, missing sample sizes, and unclear methods often made the
disagreements difficult to interpret. The bigger problem was not just
conflicting numbers, but how hard it was to tell which numbers were
trustworthy.
A First Look at Governments’ Enterprise Security Guidance
Research contributor · USENIX Security '25 · August 2025
The study compared government enterprise-security guidance across 41
countries. In a deep comparison of 10 frameworks, only 2 of 166
observed controls were recommended by all 10, and even close security
allies disagreed substantially. The results raised a broader question:
how much of security “best practice” is actually backed by empirical
evidence?
Paper
Privacy and Paternalism: The Ethics of Student Data Collection
Author · MIT SERC · August 2022
We examined how school monitoring technology changed student privacy
and autonomy. The case study asked when safety-oriented data
collection becomes too intrusive, especially when students have
little control over how their data is collected or used.
Paper