Investigating Usefulness of Security Threat Reports
Author · Manuscript under review
We compared 31 incident reports from DFIR firms and cyberinsurers
to see whether they agreed on basic questions about how security
incidents start. They often did not: estimates for externally
exposed services ranged from under 2% to over 50%, and no CVE
appeared in every comparable most-exploited-CVE list. Inconsistent
categories and missing methodological details made the differences
difficult to explain.
A First Look at Governments’ Enterprise Security Guidance
Research contributor · USENIX Security '25 · August 2025
The study examined government enterprise-security guidance across
41 countries and compared 10 frameworks in depth. Only 2 of 166
observed controls were recommended by all 10, and even close
security allies differed substantially. The result showed how
little consensus exists behind many security “best practices.”
Privacy and Paternalism: The Ethics of Student Data Collection
Author · MIT SERC · August 2022
We examined student-monitoring technology and asked when
safety-focused data collection becomes too intrusive. The case
study focused on how monitoring changes student privacy and
autonomy when students have little control over what is collected
or how it is used.