Cybersecurity Research Questions
1.
How does employee participation in phishing-awareness training affect the rate of successful phishing
incidents in U.S. small businesses?
2.
What is the relationship between multifactor authentication adoption and account-compromise incidents
among small and medium-sized businesses in the United States?
3.
How does cybersecurity insurance coverage influence ransomware preparedness and incident-response
practices among U.S. healthcare organizations?
4.
To what extent does implementing a formal vulnerability-management program reduce the time organizations
take to remediate critical software vulnerabilities?
5.
How do cybersecurity staffing levels and employee turnover affect the frequency of security incidents in U.S.
hospitals?
6.
What factors influence employees' compliance with cybersecurity policies when working remotely for U.S.
organizations?
7.
How effective are simulated phishing exercises in improving employees' ability to identify social-engineering
attacks over a six-month period?
8.
How does the use of zero-trust security practices affect unauthorized access incidents in U.S. organizations
with hybrid cloud environments?
9.
What is the relationship between third-party vendor security assessments and the frequency of
supply-chain-related cybersecurity incidents among U.S. businesses?
10.
How do cybersecurity incident-response exercises affect recovery time following simulated ransomware
attacks in U.S. public-sector organizations?
11.
How does the use of artificial intelligence for security monitoring affect the speed and accuracy of threat
detection in U.S. enterprise networks?
12.
What factors are associated with successful reporting of suspected cybercrime among adults who receive
phishing or online fraud attempts in the United States?
13.
How do cybersecurity preparedness levels differ between rural and urban healthcare organizations in the
United States, and how are those differences associated with reported security incidents?
14.
To what extent does regular cybersecurity risk assessment improve the adoption of security controls among
U.S. critical-infrastructure organizations?