Publications

Investigating Usefulness of Security Threat Reports

Author · Manuscript under review

We compared 31 incident reports from DFIR firms and cyberinsurers to see whether they agreed on basic questions about how security incidents start. They often did not: estimates for externally exposed services ranged from under 2% to over 50%, and no CVE appeared in every comparable most-exploited-CVE list. Inconsistent categories and missing methodological details made the differences difficult to explain.

A First Look at Governments’ Enterprise Security Guidance

Research contributor · USENIX Security '25 · August 2025

The study examined government enterprise-security guidance across 41 countries and compared 10 frameworks in depth. Only 2 of 166 observed controls were recommended by all 10, and even close security allies differed substantially. The result showed how little consensus exists behind many security “best practices.”

Privacy and Paternalism: The Ethics of Student Data Collection

Author · MIT SERC · August 2022

We examined student-monitoring technology and asked when safety-focused data collection becomes too intrusive. The case study focused on how monitoring changes student privacy and autonomy when students have little control over what is collected or how it is used.