Skip to content

Author

Basel Katt

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access 2026

A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management

Cyber threats are increasing in scale and complexity in an increasingly interconnected world, as reflected by several high-profile incidents in recent years. Such crises often require organizations to make difficult decisions under time pressure while balancing competing priorities, uncertainty, and limited resources. Effective cyber incident management therefore depends not only on technical capabilities, but also on the availability of appropriate tools and training for organizational response. This study is based on the premise that access to relevant information during an incident is essential, and that effective information flow is critical for successful coordination and decision-making. To address this, we investigate how operational knowledge can be translated into strategic insight through the design and development of a prototype artifact termed the Cyber Crisis Chess Board. The artifact is intended to support the presentation, analysis, and use of incident-related information, particularly in full-scale cyber exercises involving multiple organizational levels. The study follows a Design Science Research approach. The prototype was evaluated through an applied cyber-range exercise involving seven participants in Gjøvik and a discussion-based session involving 35 participants in Ålesund. Qualitative feedback from the exercise settings and affiliated organizations was synthesized through thematic analysis. The prototype was evaluated in an applied experiment at the ncr, using qualitative feedback from participants as well as input from technology clusters in Norway. The findings were mixed: some participants questioned the usefulness of the tool for training, whereas others expressed strong interest in adopting it within their own exercise settings. Despite this variation, the study demonstrates the technical feasibility of the proof-of-concept artifact in a realistic cyber-range exercise involving a ransomware scenario. The evaluation does not establish effectiveness across all supported incident scenarios, but provides a foundation for further research on organizational cyber crisis management and strategic decision-making support in cyber-range training. Future development should focus on severity-aware escalation, richer situational-awareness information, integration with existing organizational crisis-management systems, and evaluation across additional incident scenarios.

Lundli Sivert, Ehtesham Hashmi, M. Yamin et al. · 0 citations