
((Credit: © Oleksii - stock.adobe.com)
In a Nutshell
- A prototype tool called the Cyber Crisis Chess Board automatically turns technical hacking alerts into plain-language incident reports, assigned roles, and action tasks for company leaders.
- In a simulated ransomware attack, the tool successfully detected the incident, raised an alarm, and assigned response roles and tasks, but some test participants struggled with the software’s interface.
- Feedback was split: some professionals doubted its training value, while others, especially executives whose companies lack formal crisis plans, said they wanted to use something like it.
When ransomware tears through a company, the tech team can see exactly what’s happening, while the executives who have to make the costly calls are often flying blind. In a simulated ransomware attack, a new prototype tool detected the ransomware, correctly classified it, raised an alarm, and automatically generated response roles and tasks for company leaders. Researchers at the Norwegian University of Science and Technology built the tool, called the Cyber Crisis Chess Board, to give those leaders something they can act on fast: clear guidance on the calls that can’t wait, like how much money is at risk, what to tell customers, and which systems to shut down.
Its design borrows from chess strategy. Incidents unfold in phases, much like a chess match moves through an opening, a middle game, and an endgame, and early decisions shape everything that follows. It takes raw detection data, the kind normally only security analysts can read, and turns it into plain organizational terms: what kind of incident is happening, who needs to be pulled in, and what they should tackle first.
Researchers tested the prototype in a cyber-range exercise, a safe, realistic training environment for practicing incident response, and reported the results in the journal IEEE Access. It worked exactly as designed on the technical side, but users’ reactions were mixed. Some questioned whether the tool actually helped with training, while others said they wanted to bring it into their own organizations. Both outcomes matter, and together they suggest many companies still have a long way to go before their leadership teams are truly ready to handle a real cyberattack.
How Researchers Tested the Cyber Crisis Chess Board
Cyberattacks on hospitals, power grids, and city governments have become common enough that a 2022 study found 78% of people surveyed were worried about attacks on critical infrastructure. The researchers point to real incidents to make their case, including the 2019 ransomware attack on Norsk Hydro, a large Norwegian energy and aluminum company with about 36,000 employees, which reportedly cost the company roughly 800 million Norwegian kroner. Cases like this show that a hack is rarely just an IT problem. It becomes a business problem that pulls in finance, communications, and top leadership all at once.
To address that, the team built the Cyber Crisis Chess Board on top of an existing detection tool that scans security logs and matches suspicious activity to known hacking techniques cataloged in a widely used industry framework. Instead of stopping at a technical alert, the new tool goes a step further. It classifies the type of incident, such as a ransomware attack or a phishing campaign, then automatically creates an alarm and assigns specific roles and tasks to people in a crisis management system, organized into those chess-inspired phases of response.
Testing happened in two places at once. In Gjøvik, Norway, seven participants took part in a full simulated exercise at the cyber range, playing out roles at a fictional company called Innovative Solutions Inc., a made-up automotive manufacturer with 500 employees. During the exercise, the team launched a mock ransomware attack, and the tool was expected to detect it, classify it correctly, and start the response process automatically. Separately, in Ålesund, 35 people from a regional technology cluster, many with executive or senior management backgrounds, took part in a discussion-based session. Rather than touching the software directly, they reviewed the roles and tasks the tool generated for the same ransomware scenario and discussed whether they felt realistic and useful.
Researchers also gathered input from one participant with about 15 years of experience in crisis management and information security, along with a small number of questionnaire responses from organizations connected to the research project.
What the Cyber Crisis Chess Board Test Found
In the Gjøvik exercise, the tool did what it was designed to do. When the mock ransomware attack hit, the system detected it, correctly classified it as ransomware, created an alarm, and generated roles and tasks for participants to follow. Researchers had laid out five specific technical checks to confirm the process worked from start to finish, and all five were observed during the exercise.
That said, the exercise also turned up real friction. Some participants had trouble using the crisis management web portal the tool connects to, partly because they weren’t familiar with it and partly because of slow response times during the exercise itself. Even when the backend logic worked correctly, a clunky interface got in the way of a smooth experience, a reminder that good technology can still fall flat if people struggle to use it under pressure.
Ålesund told a different story. Since participants there reviewed the generated roles and tasks without wrestling with the actual software, their feedback skipped the usability headaches entirely. Several said their organizations don’t currently run this kind of leadership-focused cyber crisis training and expressed real interest in adopting something similar, especially at organizations without detailed emergency plans in place.
That experienced participant offered a sharper critique, noting that many organizations already rely on established crisis management platforms and predefined emergency plans. From that perspective, the tool’s real value might not be creating an entirely new system, but automatically triggering and escalating the plans organizations already have. That same participant pointed out that top decision-makers often lack basic details during a crisis, like how many devices are infected or which business functions are affected, and that better automated information flow could make a real difference.
Questionnaire respondents, meanwhile, raised concerns about trust. Could an automated system be relied on to catch everything it’s supposed to catch, especially during a complicated attack involving multiple techniques at once? They also worried about false alarms and the challenge of keeping such a tool updated as hacking methods change.
Why the Real Problem Isn’t the Technology
None of this means the Cyber Crisis Chess Board is ready for wide use, and the researchers are upfront about that. What it does show is that turning a wall of technical alerts into something a non-technical executive can act on is possible, at least for one type of attack tested in one controlled setting. The test suggests the underlying concept can work for ransomware, at least in the lab. The bigger open question is whether people trust it, understand it, and can actually use it when the pressure is on. Until organizations solve that human side of the equation, a smarter alarm system will only get them so far.
Paper Notes
Limitations
This work describes itself as an exploratory look at technical feasibility rather than a full effectiveness study. The Gjøvik exercise involved just seven participants, and the Ålesund session involved 35 people who reviewed generated outputs without using the full technical workflow. Feedback also came from one experienced participant and a limited number of questionnaire responses, which the authors do not treat as a large enough or representative enough sample to draw broad conclusions. The hands-on technical testing focused specifically on a ransomware scenario. While the prototype was designed to support ten different incident scenarios, the authors did not test the other nine through the same kind of live cyber-range exercise. The study included no comparison group, no competing tool, and no formal statistical analysis of decision quality, usability, or trust. The scenario detection rules built into the prototype were manually configured based on expert assumptions rather than statistically validated, and the authors say those rules would need further expert review before wider use. Because of all this, the authors caution that their results demonstrate technical feasibility in one tested setting rather than proof that the tool works broadly across organizations, industries, or attack types.
Funding and Disclosures
Published as an open-access article under a Creative Commons Attribution 4.0 License, the paper carries no separate funding statement or conflict-of-interest disclosure in the material provided for this review.
Publication Details
Paper Title: “A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management”
Authors: Sivert Lundli, Ehtesham Hashmi, Muhammad Mudassar Yamin, and Basel Katt, all affiliated with the Department of Information Security and Communication Technology at the Norwegian University of Science and Technology (NTNU) in Gjøvik, Norway.
Journal: IEEE Access, Volume 14 (pages 114052–114071)
Published: Online on July 24, 2026







