VLDB 2026 Research / reviewers in the wild / expert
Edward J. Cartwright
dblp:63/11319
· DBLP profile ↗
5ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0003-0194-9368ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Impact of employee cybersecurity training on knowledge of best practice for secure passwords and use of public Wi-FiabstractThere is widely recognized challenge to improve cybersecurity awareness and understanding in the workforce. In this paper we assess the impact of cybersecurity training in the workplace on an individual’s awareness of basic cybersecurity best practice. We report the results of a survey ( n = 965 ) of individuals resident in the UK, who’s cybersecurity knowledge was assessed on two key dimensions: secure passwords and use of public Wi-Fi. Despite using a forgiving definition of best practice we find that only 8.6% of participants correctly identified best practice. Around a half of participants had received cybersecurity training through their current employer with a mix of online training, in-person training and training outside the workplace. We find that those who received online training were significantly less likely to identify best practice than those with no training. Those who received in-person training and training outside the workplace were no more likely to identify best practice than those with no training. We also measured participants self-assessed familiarity with cybersecurity and confidence in spotting a phishing attack. We find a positive relationship between training and self-assessed familiarity and confidence. Our results, therefore, suggest that training typical training in use increases confidence without improving awareness or end-user behavior. Anna Cartwright 0001, Edward J. Cartwright |
Comput. Secur. | 2 |
| 2024 | Deception in double extortion ransomware attacks: An analysis of profitability and credibilityabstractRansomware attacks have evolved with criminals using double extortion schemes, where they signal data exfiltration to inflate ransom demands. This development is further complicated by information asymmetry, where victims are compelled to respond to ambiguous and often deceptive signals from attackers. This study explores the complex interactions between criminals and victims during ransomware attacks, especially focusing on how data exfiltration is communicated. We use a signaling game to understand the strategies both parties use when dealing with uncertain information. We identify five distinct equilibria, each characterized by the criminals' varied approaches to signaling data exfiltration, influenced by the strategic parameters inherent in each attack scenario. Calibrating the game parameters with real-world like values, we identify the most probable equilibrium, offering insights into anticipated ransom amounts and corresponding payoffs for both victims and criminals. Our findings suggest criminals are likely to claim data exfiltration, true or not, highlighting a strategic advantage for intensifying attack efforts. The study underscores the need for victims' caution towards criminals' claims and highlights the unintended consequences of policies making false claims costlier for criminals. Tom Meurs, Edward J. Cartwright, Anna Cartwright 0001, Marianne Junger, Abhishta |
Comput. Secur. | 2 |
| 2023 | Game Theoretic Modelling of a Ransom and Extortion Attack on Ethereum ValidatorsabstractConsensus algorithms facilitate agreement on and resolution of blockchain functions, such as smart contracts and transactions. Ethereum uses a Proof-of-Stake (PoS) consensus mechanism, which depends on financial incentives to ensure that validators perform certain duties and do not act maliciously. Should a validator attempt to defraud the system, legitimate validators will identify this and then staked cryptocurrency is ‘burned’ through a process of slashing. Alpesh Bhudia, Anna Cartwright 0001, Edward J. Cartwright, Darren Hurley-Smith, Julio César Hernández Castro |
ARES | 3 |
| 2023 | Cascading information on best practice: Cyber security risk management in UK micro and small businesses and the role of IT companiesabstractMicro and small businesses are increasingly reliant on digital and online technology. They have, though, very limited resources and expertise to devote to cyber security. There is, thus, a pressing economic and social challenge of how to improve cyber security in small businesses. We look at the potential role of IT companies as a conduit through which to cascade information on best practice, focusing on the United Kingdom. We first present an analysis of the UK’s Cyber Security Breaches Survey (2018–2021) distinguishing different channels through which micro and small businesses access information on cyber security. We find that the main channel, by far, is through IT companies. Very few businesses directly access information from the government or law enforcement. To further explore the role of IT companies we conducted a series of focus groups and interviews with experts in IT and cyber security for small businesses in the UK. One theme to emerge is that IT companies, while they can be part of the solution, can also be part of the problem and so a number of interventions are needed if IT companies are to effectively disseminate best practice. These include advice and guidance for micro and small businesses on how to distinguish ‘good’ IT companies, as well as appropriate support for IT companies, who themselves are typically micro and small businesses that lack expertise on cyber security. Anna Cartwright 0001, Edward J. Cartwright, Esther Solomon Edun |
Comput. Secur. | 2 |
| 2023 | Between a rock and a hard(ening) place: Cyber insurance in the ransomware eraabstractCyber insurance and ransomware are two of the most studied areas within security research and practice to date, and their interplay continues to raise concerns in industry and government. This article offers substantial new insights and analysis into the complex question of whether cyber insurance can help organisations in mitigating the threat of ransomware, particularly its impacts. Having conducted an interview or workshop with 96 industry professionals spanning the cyber insurance, cyber security, ransomware negotiations, policy, and law enforcement sectors, we identify that ransomware has been a key cause of the ‘hardening’ of the cyber insurance market, which is exhibited at almost all levels of the market. Such hardening has been beneficial in raising the security standards required prior to purchase, but has also created a situation where some organisations may not be able to acquire viable cyber insurance at all. In presenting the outcomes of our thematic analysis of the interview and workshop outputs, the paper provides significant new empirical evidence to support the theory that cyber insurance can act as a form of governance for improving cyber security amongst organisations. Nonetheless, the hardening market does nothing to increase the penetration of cyber insurance. Questions were also raised as to the likelihood of unintended unethical – and potentially illegal – outcomes given the professionalisation of a remediation process that has to determine the most cost-effective solution to an organisation being held ransom. We conclude that insurance, at best, can help to mitigate the ransomware threat for those that can access it, as part of a wider basket of actions that must also come from different stakeholders. Gareth Mott, Sarah Turner, Jason R. C. Nurse, Jamie MacColl, James Sullivan, Anna Cartwright 0001, Edward J. Cartwright |
Comput. Secur. | 7 |