# Cybersecurity as a decision-making, organizational and educational problem

Research synthesis · Cybersecurity
Canonical page: https://www.narasimharao.net/research/focus-areas/cybersecurity/
Author: Narasimha Rao Vajjhala, Professor and Chair of Computer Science, American University in Bulgaria (ORCID 0000-0002-8260-2392)
Updated: 2026-09-25

> Vajjhala and colleagues treat cyber risk as a problem of decision-making, organizational behaviour and education as much as technology: most major attacks exploit missed warnings, unpatched systems and insecure contractors, and awareness and compliance depend on social, cultural and organizational factors.

## Synthesis

Narasimha Rao Vajjhala’s cybersecurity research treats cyber risk as a problem of decision-making, organizational behaviour and education as much as of technology. In an analysis of 25 major cyberattacks between 2020 and 2022, [Strang and Vajjhala (2023b)](https://www.narasimharao.net/research/cyberattacks-disrupt-society-mitigate-risk-industry-4-0/) found that extortion was the most common motive (44%), followed by service disruption (32%) and data theft (24%), and that 36% of attacks involved bitcoin ransom. They traced many incidents to missed warnings, unpatched or unmonitored systems, insecure contractors and insecure software updates, and recommended regular log audits, prompt patching, scanning of software updates, awareness training, contractual cybersecurity clauses and intrusion detection systems.

The group has also shown how machine learning can make cyber risk measurable. [Strang and Vajjhala (2024b)](https://www.narasimharao.net/research/cybersecurity-risks-higher-education-machine-learning/) applied t-SNE, radial analysis and correspondence analysis to hypertext extracted from about 848 US higher-education website records, containing over 4,000 potential security indicators, and scored each institution’s breach likelihood on a 1–3 scale; a combined control feature was the most useful signal for flagging very high-risk components. [Olaniyan et al. (2023)](https://www.narasimharao.net/research/ueba-user-entity-behavioral-analytics-cyber-threat-detection/) positioned user and entity behavioural analytics as an AI approach for discovering where attacks originate and recommending responses to organizational decision-makers.

A distinctive strand of the work concerns the human and cultural context of security. [Nasir and Vajjhala (2020)](https://www.narasimharao.net/research/information-security-awareness-compliance-sub-saharan-africa-smes/) argued that low information security awareness and compliance in sub-Saharan Africa are only partly explained by Internet penetration, infrastructure, literacy and technology costs, and that behavioural, social, cultural and organizational factors are neglected by a literature centred on developed countries; they set out an interpretivist multisite design covering 50 managers in 20 Nigerian firms. On the education side, [Strang et al. (2020a)](https://www.narasimharao.net/research/teaching-blockchain-cybersecurity-management-computer-science/) found only five peer-reviewed papers on teaching blockchain and proposed a two-dimensional typology — from programmer to managerial decision-maker, and from theoretical to hands-on teaching — concluding that blockchain is an essential part of modern cybersecurity education.

Vajjhala has extended this agenda through edited volumes aimed at practitioners and policymakers: evidence-based strategies for managers and policymakers ([Vajjhala & Strang, 2023](https://www.narasimharao.net/research/cybersecurity-for-decision-makers/)), the protection of organizational knowledge assets through AI-based detection, malware classification and insider-threat cases ([Vajjhala & Strang, 2025](https://www.narasimharao.net/research/cybersecurity-in-knowledge-management-cyberthreats-solutions/)), and AI-enabled threat intelligence and cyber risk assessment ([Martiri et al., 2025](https://www.narasimharao.net/research/ai-enabled-threat-intelligence-cyber-risk-assessment/)).

The common conclusion is that organizations reduce cyber risk most reliably by combining technical controls with informed decision-makers, security-aware cultures and curricula that prepare both technical and managerial graduates.

## Key claims with sources

1. Of 25 major cyberattacks in 2020–2022, 44% were extortion, 32% service disruption and 24% data theft; 36% involved bitcoin ransom ([Strang & Vajjhala, 2023b](https://www.narasimharao.net/research/cyberattacks-disrupt-society-mitigate-risk-industry-4-0/)).
2. Unsupervised machine learning on hypertext from about 848 US higher-education website records can score breach likelihood ([Strang & Vajjhala, 2024b](https://www.narasimharao.net/research/cybersecurity-risks-higher-education-machine-learning/)).
3. Low information security awareness in sub-Saharan African SMEs is only partly explained by infrastructure, literacy and cost ([Nasir & Vajjhala, 2020](https://www.narasimharao.net/research/information-security-awareness-compliance-sub-saharan-africa-smes/)).

## References

- Martiri, E., Vajjhala, N. R., & Dalipi, F. (Eds.). (2025). AI-Enabled Threat Intelligence and Cyber Risk Assessment. CRC Press. https://doi.org/10.1201/9781003504979 — summary and key findings: https://www.narasimharao.net/research/ai-enabled-threat-intelligence-cyber-risk-assessment/
- Nasir, S., & Vajjhala, N. R. (2020). Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective. In Miguel Baptista Nunes, Pedro Isaías, Philip Powell, Boyan Bontchev (Eds.), Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020) (pp. 187–190). IADIS Press. https://www.iadisportal.org/digital-library/evaluating-information-security-awareness-and-compliance-in-sub-saharan-africa-an-interpretivist-perspective — summary and key findings: https://www.narasimharao.net/research/information-security-awareness-compliance-sub-saharan-africa-smes/
- Olaniyan, R., Rakshit, S., & Vajjhala, N. R. (2023). Application of User and Entity Behavioral Analytics (UEBA) in the Detection of Cyber Threats and Vulnerabilities Management. In Prasenjit Chatterjee, Dragan Pamucar, Morteza Yazdani, Dilbagh Panchal (Eds.), Computational Intelligence for Engineering and Management Applications: Select Proceedings of CIEMA 2022 (pp. 419–426). Springer Nature Singapore. https://doi.org/10.1007/978-981-19-8493-8_32 — summary and key findings: https://www.narasimharao.net/research/ueba-user-entity-behavioral-analytics-cyber-threat-detection/
- Strang, K. D., & Vajjhala, N. R. (2023b). Why Cyberattacks Disrupt Society and How to Mitigate Risk. In Narasimha Rao Vajjhala, Kenneth David Strang (Eds.), Cybersecurity for Decision Makers (pp. 1–28). CRC Press / Taylor & Francis. https://doi.org/10.1201/9781003319887-1 — summary and key findings: https://www.narasimharao.net/research/cyberattacks-disrupt-society-mitigate-risk-industry-4-0/
- Strang, K. D., & Vajjhala, N. R. (2024b). Exploring Cybersecurity Risks in Higher Education Environments with Machine Learning. In 2024 4th International Conference on Pervasive Computing and Social Networking (ICPCSN) (pp. 1–6). IEEE. https://doi.org/10.1109/ICPCSN62568.2024.00008 — summary and key findings: https://www.narasimharao.net/research/cybersecurity-risks-higher-education-machine-learning/
- Strang, K. D., Che, F., & Vajjhala, N. R. (2020a). Ideologies and Issues for Teaching Blockchain Cybersecurity in Management and Computer Science. In K. Daimi, G. Francia III (Eds.), Innovations in Cybersecurity Education (pp. 109–126). Springer. https://doi.org/10.1007/978-3-030-50244-7_7 — summary and key findings: https://www.narasimharao.net/research/teaching-blockchain-cybersecurity-management-computer-science/
- Vajjhala, N. R., & Strang, K. D. (Eds.). (2023). Cybersecurity for Decision Makers. CRC Press. https://doi.org/10.1201/9781003319887 — summary and key findings: https://www.narasimharao.net/research/cybersecurity-for-decision-makers/
- Vajjhala, N. R., & Strang, K. D. (Eds.). (2025). Cybersecurity in Knowledge Management: Cyberthreats and Solutions. CRC Press. https://doi.org/10.1201/9781003498094 — summary and key findings: https://www.narasimharao.net/research/cybersecurity-in-knowledge-management-cyberthreats-solutions/
