全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Trust, Risk, and Investment Confidence in Defensive Cyber Deception Adoption

DOI: 10.4236/ti.2026.173013, PP. 200-215

Keywords: Cyber Deception, Cybersecurity Investment, Investment Confidence, Operational Technology, Risk Perception, Technology Adoption, Trust

Full-Text   Cite this paper   Add to My Lib

Abstract:

Defensive cyber deception technologies use decoys, honeytokens, simulated services, and false artifacts to create high-confidence signals when adversaries interact with resources that legitimate users should not touch. Although these tools are often discussed as technical controls, their adoption also depends on investment confidence: whether practitioners believe the capability is valuable, trustworthy, controllable, and worth organizational resources. This study examines that problem using secondary analysis of an existing deidentified survey dataset collected from industrial control system and operational technology professionals. The analysis tested whether investment confidence, self-efficacy/direct experience, social validation, and instructional support predicted adoption readiness and effective utilization beyond education, experience, and sector. The complete-case sample for the primary regression was 264. Demographics alone explained little variance in adoption readiness, R-squared = 0.026, p = 0.225. Adding perception-based predictors increased explained variance to R-squared = 0.639, p < 0.001. Investment confidence remained a significant predictor in the full model, beta = 0.251, p < 0.001, alongside self-efficacy/direct experience and instructional support. A second model showed that self-efficacy and social validation significantly predicted investment confidence itself. The findings suggest that defensive cyber deception investment is not only a tool-budget issue. It is a trust, capability, and risk-communication issue that must be addressed before organizations can treat deception as a credible security investment.

References

[1]  Beltran-Lopez, P., Gil Perez, M., & Nespoli, P. (2025). Cyber deception: Taxonomy, state of the art, frameworks, trends, and open challenges. IEEE Communications Surveys & Tutorials.
https://doi.org/10.1109/COMST.2025.3594788
[2]  Cranford, E. A., Gonzalez, C., Aggarwal, P., Tambe, M., Cooney, S., & Lebiere, C. (2021). Towards a cognitive theory of cyber deception. Cognitive Science, 45(7), e13013.
https://doi.org/10.1111/cogs.13013
[3]  Dwivedi, Y. K., Rana, N. P., Jeyaraj, A., Clement, M., & Williams, M. D. (2019). Re-examining the unified theory of acceptance and use of technology (UTAUT): Towards a revised theoretical model. Information Systems Frontiers, 21(3), 719-734.
https://doi.org/10.1007/s10796-017-9774-y
[4]  Ferguson-Walter, K. J., Shade, T. B., Rogers, A. V., Niedbala, E., Trumbo, M. C. S., Nauer, K. S., Divis, K. M., Jones, A., Combs, A., & Abbott, R. G. (2019). The Tularosa Study: An experimental design and implementation to quantify the effectiveness of cyber deception. Proceedings of the 52nd Hawaii International Conference on System Sciences.
https://hdl.handle.net/10125/59938
[5]  Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438-457.
https://doi.org/10.1145/581271.581274
[6]  IBM. (2025). Cost of a Data Breach Report 2025.
https://www.ibm.com/reports/data-breach
[7]  International Electrotechnical Commission. (2024). IEC 62443-2-1:2024: Security for industrial automation and control systems-Part 2-1: Security program requirements for IACS asset owners.
https://webstore.iec.ch/en/publication/62883
[8]  National Cyber Security Centre. (2025). Cyber deception trials: What we have learned so far.
https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far
[9]  National Institute of Standards and Technology. (2023). Guide to operational technology (OT) security (NIST Special Publication 800-82 Revision 3).
https://doi.org/10.6028/NIST.SP.800-82r3
[10]  National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0.
https://doi.org/10.6028/NIST.CSWP.29
[11]  Reeves, A., & Ashenden, D. (2023). Understanding decision making in security operations centres: Building the case for cyber deception technology. Frontiers in Psychology, 14, 1165705.
https://doi.org/10.3389/fpsyg.2023.1165705
[12]  Reeves, A. (2025). Deploying cyber deception in a SOC. Proceedings of the 58th Hawaii International Conference on System Sciences.
https://hdl.handle.net/10125/109838
[13]  Reid, I., Okeke-Ramos, A., & Serafin, M. (2024). Exploring the ethics of cyber deception technologies for defensive cyber deception. In P. Bednar, J. Kavrestad, E. Bergstrom, M. Rajanen, H. V. Hult, A. M. Braccini, A. S. Islind, & F. Zaghloul (Eds.), Proceedings of the 10th International Conference on Socio-Technical Perspectives in Information Systems (pp. 140-148). CEUR Workshop Proceedings.
https://ceur-ws.org/Vol-3857/paper9.pdf
[14]  Venkatesh, V., Morris, M. G., Davis, G. B., & Davis, F. D. (2003). User acceptance of information technology: Toward a unified view. MIS Quarterly, 27(3), 425-478.
https://doi.org/10.2307/30036540
[15]  Venkatesh, V., Thong, J. Y. L., & Xu, X. (2012). Consumer acceptance and use of information technology: Extending the unified theory of acceptance and use of technology. MIS Quarterly, 36(1), 157-178.
https://doi.org/10.2307/41410412
[16]  Ward, D. (2025). Enhancing security: A comprehensive study on deception technology integration in manufacturing and critical infrastructure [Doctoral dissertation, University of the Cumberlands]. ProQuest Dissertations & Theses.
[17]  Ward, D. (2026a). Operationalizing deception technology in ICS/OT: A control mapping framework for critical infrastructure cybersecurity. International Journal of Soft Computing and Engineering, 16(3), 1-9.
https://doi.org/10.35940/ijsce.C3723.16030726
[18]  Ward, D. (2026b). Deception architecture for water and wastewater operational technology environments. International Journal of Engineering Research & Technology, 15(6).
https://doi.org/10.5281/zenodo.20745399
[19]  Ward, D. (2026c). A workforce readiness model for deception technology in ICS and OT cybersecurity programs. International Research Journal of Engineering and Technology, 13(6), 610-614.
https://www.irjet.net/archives/V13/i6/IRJET-V13I0693.pdf
[20]  Ward, D. (2026d). A deception readiness index for ICS and OT cybersecurity programs. International Journal for Research in Applied Science & Engineering Technology, 14(VI), 2401-2406.
https://doi.org/10.22214/ijraset.2026.83810
[21]  Zhang, F., & Thing, V. L. L. (2021). Three decades of deception techniques in active cyber defense: Retrospect and outlook. Computers & Security, 106, 102288.
https://doi.org/10.1016/j.cose.2021.102288

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133