Paper Type
Complete
Abstract
Most cybersecurity research and incident postmortems treat attacks as beginning at initial access or execution. Yet practitioners increasingly argue that attacks are often decided earlier during a pre-attack period when a malicious idea is forming but has not yet crystallized into committed action. This study investigates that early window (attack conception) and examines (i) how organizations infer ideation onset despite ambiguity, and (ii) how organizations can interrupt ideation before execution. We conduct a qualitative study with nine practitioners (4 CISOs and 5 cybersecurity analysts), surfacing how practitioners reframe attack genesis as pre-attack learning rather than execution, and a set of early cognitive and contextual signals that practitioners associate with ideation onset. The paper extends behavioral IS security and criminological opportunity perspectives to an earlier temporal phase of cyber harm.
Paper Number
1913
Recommended Citation
Singh, Raghvendra; Cleary, Kevin; and Smith, Sanjukta Das, "Detecting Cyberattacks at Conception: A Role-Intent View of Early Ideation Signals" (2026). AMCIS 2026 Proceedings. 43.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/43
Detecting Cyberattacks at Conception: A Role-Intent View of Early Ideation Signals
Most cybersecurity research and incident postmortems treat attacks as beginning at initial access or execution. Yet practitioners increasingly argue that attacks are often decided earlier during a pre-attack period when a malicious idea is forming but has not yet crystallized into committed action. This study investigates that early window (attack conception) and examines (i) how organizations infer ideation onset despite ambiguity, and (ii) how organizations can interrupt ideation before execution. We conduct a qualitative study with nine practitioners (4 CISOs and 5 cybersecurity analysts), surfacing how practitioners reframe attack genesis as pre-attack learning rather than execution, and a set of early cognitive and contextual signals that practitioners associate with ideation onset. The paper extends behavioral IS security and criminological opportunity perspectives to an earlier temporal phase of cyber harm.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC