Tong Xin 0003

dblp:166/9948-3 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0002-9016-9680ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A cyber risk economics model for organization-wide risk management (CYREM-ORM)
abstract
The increasing sophistication of cyber risks has made it challenging for organizations to assess their business impacts. The key challenge is the technical and language “barrier” between cybersecurity teams and business teams who make strategic investment decisions on cybersecurity. This often leads to delays, budget issues that prevent timely responses to cyber incidents. Existing research lacks a transparent, traceable, and reproducible method to communicate cyber risks and their impacts on businesses. We introduce a novel cyber risk economics model for organization-wide risk management (CYREM-ORM) that captures complex cyber risks and expresses them using financial terms. This is achieved by mapping Cyber Threat Intelligence (CTI) to the Factor Analysis of Information Risk (FAIR) model, enriched by cyber cost typologies. CYREM-ORM provides a traceable workflow that links organisation-related CTI to FAIR factor estimation, cost breakdowns, and ultimately to monetary loss amounts and prioritised risk scenarios. This design improves transparency in risk management, helps organisations prioritise mitigations in line with strategic business objectives, and enables stakeholders to assess the rationale behind results when needed. By grounding risk parameters in CTI, the model also facilitates proactive screening of organisation-relevant threats, instead of reactive, control-gap reporting. We evaluate the CYREM-ORM through three complementary case studies: the 2017 Equifax breach case proves its feasibility with historical data and open-source CTI, while the Small and Medium Enterprise (SME) education company and the large retail company cases show its effectiveness in communicating cyber risks at an organizational-wide strategic level within real-world contexts.
Tong Xin 0003, Ying He 0004, Efpraxia D. Zamani, Mark Glenn Evans, Cunjin Luo
Comput. Secur.1
2024 Poster: Cyber Security Economics Model (CYSEM)
abstract
The increasing sophistication of cyberattacks and the evolution of security risks make it challenging for organizations to understand their impact on businesses.The habitual reliance on the judgment of cyber security experts and communication gaps between cyber security team and board members, responsible for making strategic cyber security investment decisions further weaken organization's capability to respond to cyber threats.Existing research lacks a transparent approach to quantify security risks and their impact on businesses.This paper introduces a novel CYSEM that express security risk in financial terms, through integrating Cyber Threat Intelligence (CTI) with the Factor Analysis of Information Risk (FAIR) model, elaborated with cyber security cost typologies.CYSEM facilitates communication among multi-stakeholders and improves transparency and quality of investment decision-making at the strategic level.We evaluate the CYSEM using a case study, which has showed its effectiveness in understanding the impact of cyber threat from an economics perspective. CCS Concepts• Security and privacy → Human and societal aspects of security and privacy; Economics of security and privacy.
Tong Xin 0003, Ying He 0004, Efpraxia D. Zamani, Cunjin Luo
CCS1
2022 Understanding the inward emotion-focused coping strategies of individual users in response to mobile malware threats
abstract
According to coping theory, individuals cope with information system threats by adopting either problem-focused coping (PFC) or emotion-focused coping (EFC). However, little is known about EFC in the information security (ISec) literature. Moreover, there is potential confusion regarding the meaning of some EFC strategies. Hence, ISec scholars and practitioners may (i) have a narrow view of EFC or (ii) confuse it with other concepts. In this study, we offer one response to this issue. We first address the ambiguity regarding EFC before differentiating five inward EFC strategies and assessing them empirically in the mobile malware context. To the best of our knowledge, this study is the first to compare several inward EFC strategies in the ISec field.We contribute two new findings on EFC: 1) response efficacy is a crucial factor that impedes users from implementing EFC strategies; 2) avoidance and fatalism significantly impede PFC. Our study also contributes to the ISec literature by categorising EFC into active and passive forms. We showed that individuals’ use of passive inward EFC strategies was positively associated with threat vulnerability. Finally, we provide interesting insights into the complicated responses of individuals to mobile malware threats, presenting implications for ISec research and practice.
Tong Xin 0003, Mikko Siponen, Sihua Chen
Behav. Inf. Technol.1