Repository logo
 

Identifying Unintended Harms of Cybersecurity Countermeasures

Accepted version
Peer-reviewed

Type

Conference Object

Change log

Authors

Chua, YT 
Parkin, S 
Edwards, M 
Oliveira, D 
Schiffner, S 

Abstract

Well-meaning cybersecurity risk owners will deploy countermeasures (technologies or procedures) to manage risks to their services or systems. In some cases, those countermeasures will produce unintended consequences, which must then be addressed. Unintended consequences can potentially induce harm, adversely affecting user behaviour, user inclusion, or the infrastructure itself (including other services or countermeasures). Here we propose a framework for preemptively identifying unintended harms of risk countermeasures in cybersecurity. The framework identifies a series of unintended harms which go beyond technology alone, to consider the cyberphysical and sociotechnical space: displacement, insecure norms, additional costs, misuse, misclassification, amplification, and disruption. We demonstrate our framework through application to the complex, multi-stakeholder challenges associated with the prevention of cyberbullying as an applied example. Our framework aims to illuminate harmful consequences, not to paralyze decisionmaking, but so that potential unintended harms can be more thoroughly considered in risk management strategies. The framework can support identification and preemptive planning to identify vulnerable populations and preemptively insulate them from harm. There are opportunities to use the framework in coordinating risk management strategy across stakeholders in complex cyberphysical environments.

Description

Keywords

46 Information and Computing Sciences, 4609 Information Systems, Prevention, Mental health

Journal Title

eCrime Researchers Summit, eCrime

Conference Name

2019 APWG Symposium on Electronic Crime Research (eCrime)

Journal ISSN

2159-1237
2159-1245

Volume Title

2019-November

Publisher

IEEE

Rights

All rights reserved
Sponsorship
Engineering and Physical Sciences Research Council (EP/M020320/1)