Insights from next frontiers in cybersecurity research
Four cutting-edge PhD researchers, selected through a competition to present at the ONE Conference, will take the stage. In this dynamic lightning-talk session, they will showcase their research on secure and usable online election platforms, cyber hygiene and patching, Fully Homomorphic Encryption, and the inner workings of ransomware organizations. Together, their multidisciplinary perspectives offer a glimpse into emerging frontiers in cybersecurity research and connect technological, legal, organizational, and societal challenges. Get ready for a fast-paced dive into research that could help shape tomorrow’s digital defences.
Abstracts of talks
- Online election platforms
Online election platforms face challenges related to security, usability, and trust. Floris Jansen’s research proposes an election platform based on identity wallets, which could help address these challenges. He will explain the design decisions that contribute to usable, accessible, and secure online elections for local consultations or internal political party elections.
- Cyber hygiene, including patching
We all understand the importance of basic cyber hygiene, including patching (‘security updates’), yet research shows that organisations often install security patches too late or not at all. With the rise of new attack vectors, including AI-driven exploitation, and the mean time to exploitation now under 24 hours, regulators and practitioners urgently need to take concrete action to improve timely patching. Lisa Rooij’s PhD research presents the results of interviews with 30 CISOs from large organisations in the Netherlands, examining their patching policies and practices, and proposes recommendations to ‘patch’ the implementation gap between law and practice.
- Fully Homomorphic Encryption (FHE)
Governments, businesses, and critical infrastructure operators increasingly depend on cloud providers that fall under foreign jurisdiction, contributing to a push for European digital sovereignty. Traditional encryption offers only a partial solution, as data must be decrypted when it needs to be used or analysed, exposing it to whoever operates the system. Fully Homomorphic Encryption (FHE) is a special type of encryption that solves this problem by allowing computations to be performed directly on encrypted data, so a cloud server can process information it never sees in plaintext. Vasco Rikkers will introduce FHE and explain how it can protect confidential data on cloud infrastructure that we do not fully trust, using cross-bank fraud detection as an example.
- Ransomware organizations
Ransomware groups have evolved into structured organizations that resemble legitimate businesses. Using Conti’s chat logs and the cybercrime value chain, Cécile Volten explores how funds are distributed within ransomware organizations. The analysis shows that the development phase is the operation’s critical dependency, concentrating both salary payments and the operational costs of scarce resources, thereby making it the most promising target for disruption.