Cybersecurity & AIS

What is Cybersecurity and AIS?

The Cybersecurity & AIS focus area emphasizes research, education and knowledge transfer, and interaction initiatives at UWCISA, particularly attuned to topics such as:Ìý

  • cyber incident notifications and disclosures,
  • behavioural cybersecurity,
  • national cybersecurity strategies,
  • cybersecurity policy compliance,
  • board-level cybersecurity governance,
  • and cybersecurity regulations.

Led by

Alec Cram headshot

W. Alec Cram, PhD, CISA, CISSP

UWCISA Associate Director Cybersecurity & AIS

Research

Thought Leadership, Funding Specific Research ProjectsÌý

Current Cybersecurity and AIS Research

Paper Details
Anti-Phishing Countermeasures
  • Research team:ÌýEfrim Boritz
  • Objectives:ÌýTo explore countermeasures to phishing.
  • Status:ÌýIn process –early development stage.
  • Affiliation: This paper is led by Efrim Boritz, executive director of UWCISA.
  • Research team:ÌýAlec Cram, John D’Arcy, Alex Benlian.ÌýÌý
  • Objectives:ÌýTo apply an idiographic approach, which undertakes within-person analysis of longitudinal data, to empirically test and bring a more granular perspective to neutralization theory within cybersecurity research.
  • Status:ÌýComplete –this paper was published in MIS Quarterly, Vol. 48, No. 1, 2024.
  • Affiliation: This paper is co-led by Alec Cram, an associate director of UWCISA.
  • Research team:ÌýAlec Cram, RissaileÌýMouajou-Kenfack.ÌýÌý
  • Objectives:ÌýTo examine how organizations respond to cybersecurity incidents in terms of the detail provided in incident notifications and how responses differ depending on the benefitting party.
  • Status:ÌýComplete –this paper was published in Organizational Cybersecurity Journal: Practice, Process and People, Vol. 3, No. 1, 2023.
  • Affiliation: This paper is co-led by Alec Cram, an associate director of UWCISA.
  • Research team:ÌýAlec Cram, Jonathan Yuan.ÌýÌý
  • Objectives:ÌýTo examine national cybersecurity strategies in Canada, the United Kingdom, and Australia and their level of stability or change over time.
  • Status:ÌýComplete –this paper was published in Journal of Cyber Policy, Vol. 8, No. 1, 2023.
  • Affiliation: This paper is led by Alec Cram, an associate director of UWCISA.
  • Research team:ÌýAlec Cram, John D’Arcy.ÌýÌý
  • Objectives:ÌýIntroduce employee judgments of cybersecurity illegitimacy as a new angle for understanding employee compliance with cybersecurity policies over time.
  • Status:ÌýComplete –this paper was published in Information Systems Journal, Vol. 33, No. 6, 2023.
  • Affiliation: This paper is led by Alec Cram, an associate director of UWCISA.
Weathering the Storm: Charting a Course for Organizations to Navigate the Raging Tempest of Cybersecurity Regulations.
  • Research team:ÌýAlec Cram, Jeff Proudfoot.ÌýÌý
  • Objectives:ÌýTo clarify how cybersecurity regulations are operationalized in organizations, as well as reveal theÌýcompliance and performance consequences of cybersecurity regulations.Ìý
  • Status:ÌýIn process – under review at a journal.
  • Affiliation: This paper is led by Alec Cram, an associate director of UWCISA.
Conceal or Communicate? Organizational Notifications to Stakeholders Following Ransomware Attacks
  • Research team:ÌýAlec Cram, Albert Chan, Dennis Joo, Jonathan Yuan.ÌýÌý
  • Objectives:ÌýTo examine the organizational communications following 101 ransomware attacks.
  • Status:ÌýIn process – being prepared for journal submission.
  • Affiliation: This paper is led by Alec Cram, an associate director of UWCISA.
Evaluating a Cybersecurity Operations Center Implementation Program in a Regional Healthcare System: Challenges and Lessons Learned
  • Research team:ÌýAlec Cram, Ian McKillop.ÌýÌý
  • Objectives:ÌýTo examine an early-stage program to establish a series of cybersecurity operations centers within a large, regional, publicly funded healthcare system.
  • Status:ÌýIn process – under review at a journal.
  • Affiliation: This paper is led by Alec Cram, an associate director of UWCISA.

Education and Knowledge TransferÌý

Disseminating Best Practices, Sharing Material (Workshops / Conferences)Ìý

Developing Courses, Workshops, Cases and Other Teaching Material

Student case competitions, mentorship, and awardsÌý

Cybersecurity and Privacy Institute Undergraduate Award

  • Under the leadership of Alec Cram and through the sponsorship of the UW Cybersecurity and Privacy Institute, each semester the Cybersecurity and Privacy Institute Undergraduate Award of $1,000 is given to the top student enrolled in the course AFM 347 – Cybersecurity.

UWCISA PhD & Academic Career Mentorship Program in Audit & Assurance, Cybersecurity, or Accounting Information Systems (AIS)


InteractionÌý

Engaging with Profession, Students, Public

Informing Practice

  • Through UWCISA members’ service on various task forces, the following activity was carried out:
    • Updating cybersecurity risk management material for Boards.
    • Responding to the SEC proposal on Cybersecurity Risks and the NY state proposal on Cybersecurity Assurance.