Aug 2026· Proceedings of the Human Factors and Ergonomics Society Annual Meeting· 0 citations· 12 references
TL;DR
Results suggest that current public reporting can identify the type of error that occurred, but is limited in explaining why it occurred, and suggest that current public reporting can identify the type of error that occurred, but is limited in explaining why it occurred.
Abstract
Human action drives most cybersecurity breaches, yet industry reports rely on vague labels that lack diagnostic utility. This study evaluates whether public incident narratives from the VERIS Community Database provide the context required for systemic intervention to 45 Action.Error records from 2020 to 2021 were analyzed across three error varieties: misdelivery, misconfiguration, and publishing. Using the Human Factors Analysis and Classification System, we applied a strict evidence-based coding strategy to map narrative to systemic levels. Our results reveal a significant diagnostic gap: while narratives consistently support Level 1 (Unsafe Act) coding, evidence for latent preconditions, supervision failures, and organizational influences remains largely absent. Specifically, misdelivery and misconfiguration align cleanly with skill-based and decision errors, but the causal chain stops at the individual. These findings suggest that current public reporting can identify the type of error that occurred, but is limited in explaining why it occurred.
This study examines whether firms strategically adjust the readability of Item 1A (“Risk Factors”) disclosures following data breaches. Using U.S. firm‐year observations from 2006 to 2023, we find that data breaches are associated with a significant decline in Item 1A readability. This decline is not accompanied by a meaningful increase in informational content; instead, post‐breach disclosures exhibit higher syntactic complexity, more positive tone, and lower textual similarity to prior and industry peers' filings, consistent with strategic obfuscation rather than transparent reporting. The readability decline is amplified among firms facing higher litigation risk but attenuated among firms with stronger reputations for technological innovation. Notably, less readable disclosures soften negative market reactions, suggesting that obfuscation works as investors are challenged to fully process risk related information buried in complex language. These findings demonstrate that firms use narrative complexity for impression management following adverse events, with real capital market consequences.
Ling Tuo, Shipeng Han· Accounting & Finance· 0 citations
A meta-review of 18 studies between 2019 and 2026, from which 83 ICS, or ICS directly related, cybersecurity datasets are identified, harmonised, and characterised using a unified five-dimensional taxonomy, identifies three structural imbalances which constrain the scope and feasibility of several evaluation practices.
Konstantinos E. Kampourakis, Vyron Kampourakis, Georgios Kambourakis et al.· 0 citations
Large language models (LLMs) are increasingly embedded in organizational work, yet their errors often pass human review. Prior research locates such failures in users'capability to review LLM output or their engagement in doing so. We develop an alternative, retrieval-based account of human oversight and posit that error detection is more effective when oversight-relevant information is accessible to users at the moment of review. Across two randomized lab-in-the-field experiments with 640 customer-facing employees, we show that self-generated explanations improve error detection and strengthen recall of verification-relevant reasoning, while cues that reactivate such reasoning help sustain detection under repeated LLM use. Theoretically, we identify information retrievability as a distinct precondition for effective oversight and specify generative encoding and cue-supported reactivation as mechanisms that build and sustain it. Practically, lightweight onboarding self-explanations and daily retrieval cues can make human oversight more resilient as LLM use becomes routine.
The evaluation shows that IntelliAudit can support control interpretation, evidence-grounded reasoning, and audit-preparation workflows, while also revealing the importance of human oversight for calibrating sufficiency judgments and correcting overly permissive recommendations.
Allison Wilson, S. Sabet, Diar Shakimov et al.· 0 citations
The EU AI Act requires providers of high-risk systems to file technical documentation describing how the system reaches its decisions. Mechanistic interpretability is the obvious source of such evidence, and circuit discovery is its most developed instrument. We ask whether that evidence survives the condition under which it would be relied upon: two competent analysts, the same system, the same tool, different defensible settings. We pre-registered a crossed grid of seven analytic axes, every level taken from a published implementation, and mapped each discovered circuit through a deterministic claim map to a structured Annex IV statement. Across 15,840 pre-registered specifications on GPT-2 small and the indirect object identification task, of which 7,561 produced a claim, the derived statement flips across 73.2% of specification pairs (95% CI 0.725 to 0.738) and the modal claim commands 41.1% of the space. The evidence fails a filability criterion at every tolerance a conformity assessment body would plausibly accept. Standardising the single most influential choice, the evaluation metric, leaves the flip rate at 59.4%. Removing circuit size from the claim entirely and holding it fixed leaves 27.1% (95% CI 0.255 to 0.286), still above the pre-registered threshold. The circuits underlying these claims are structurally near-disjoint, median pairwise Jaccard overlap 4%, and functionally uncorrelated at Cohen's kappa 0.015, so the instability is not one mechanism described in different words. We give the filability criterion as a standalone protocol, and we report that one of the seven documented discovery objectives does not execute at all on the library's own canonical task. The study covers one model and one task, and whether the conclusion holds at scale is untested.
Ajay Pravin Mahale· 1 citation
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.