Empirical Security
Investigating Usefulness of Security Threat Reports
Author · Manuscript under review
We compared 31 incident reports from DFIR firms and cyberinsurers
and found surprisingly little agreement on basic questions like the
most common initial-access vectors or most-exploited CVEs.
Inconsistent definitions, missing sample sizes, and unclear methods
often made the disagreements difficult to interpret. The bigger
problem was not just conflicting numbers, but how hard it was to
tell which numbers were trustworthy.
Expected
Major incident reports should converge on basic threat trends
Found
No CVE appeared in all five comparable most-exploited lists
Empirical Security
A First Look at Governments’ Enterprise Security Guidance
Research contributor · USENIX Security '25 · August 2025
The study compared government enterprise-security guidance across
41 countries. In a deep comparison of 10 frameworks, only 2 of 166
observed controls were recommended by all 10, and even close
security allies disagreed substantially. The results raised a
broader question: how much of security “best practice” is actually
backed by empirical evidence?
Expected
Security “best practices” should broadly agree
Found
Only 2 of 166 observed controls were universal
Paper
Privacy · Technology Ethics
Privacy and Paternalism: The Ethics of Student Data Collection
Author · MIT SERC · August 2022
We examined how school monitoring technology changed student
privacy and autonomy. The case study asked when safety-oriented
data collection becomes too intrusive, especially when students
have little control over how their data is collected or used.
Paper