Hacker behind cybersecurity data breach

((Credit: © Oleksii - stock.adobe.com)

In a Nutshell

  • A prototype tool called the Cyber Crisis Chess Board automatically turns technical hacking alerts into plain-language incident reports, assigned roles, and action tasks for company leaders.
  • In a simulated ransomware attack, the tool successfully detected the incident, raised an alarm, and assigned response roles and tasks, but some test participants struggled with the software’s interface.
  • Feedback was split: some professionals doubted its training value, while others, especially executives whose companies lack formal crisis plans, said they wanted to use something like it.

When ransomware tears through a company, the tech team can see exactly what’s happening, while the executives who have to make the costly calls are often flying blind. In a simulated ransomware attack, a new prototype tool detected the ransomware, correctly classified it, raised an alarm, and automatically generated response roles and tasks for company leaders. Researchers at the Norwegian University of Science and Technology built the tool, called the Cyber Crisis Chess Board, to give those leaders something they can act on fast: clear guidance on the calls that can’t wait, like how much money is at risk, what to tell customers, and which systems to shut down.

Its design borrows from chess strategy. Incidents unfold in phases, much like a chess match moves through an opening, a middle game, and an endgame, and early decisions shape everything that follows. It takes raw detection data, the kind normally only security analysts can read, and turns it into plain organizational terms: what kind of incident is happening, who needs to be pulled in, and what they should tackle first.

Researchers tested the prototype in a cyber-range exercise, a safe, realistic training environment for practicing incident response, and reported the results in the journal IEEE Access. It worked exactly as designed on the technical side, but users’ reactions were mixed. Some questioned whether the tool actually helped with training, while others said they wanted to bring it into their own organizations. Both outcomes matter, and together they suggest many companies still have a long way to go before their leadership teams are truly ready to handle a real cyberattack.

How Researchers Tested the Cyber Crisis Chess Board

Cyberattacks on hospitals, power grids, and city governments have become common enough that a 2022 study found 78% of people surveyed were worried about attacks on critical infrastructure. The researchers point to real incidents to make their case, including the 2019 ransomware attack on Norsk Hydro, a large Norwegian energy and aluminum company with about 36,000 employees, which reportedly cost the company roughly 800 million Norwegian kroner. Cases like this show that a hack is rarely just an IT problem. It becomes a business problem that pulls in finance, communications, and top leadership all at once.

To address that, the team built the Cyber Crisis Chess Board on top of an existing detection tool that scans security logs and matches suspicious activity to known hacking techniques cataloged in a widely used industry framework. Instead of stopping at a technical alert, the new tool goes a step further. It classifies the type of incident, such as a ransomware attack or a phishing campaign, then automatically creates an alarm and assigns specific roles and tasks to people in a crisis management system, organized into those chess-inspired phases of response.

Testing happened in two places at once. In Gjøvik, Norway, seven participants took part in a full simulated exercise at the cyber range, playing out roles at a fictional company called Innovative Solutions Inc., a made-up automotive manufacturer with 500 employees. During the exercise, the team launched a mock ransomware attack, and the tool was expected to detect it, classify it correctly, and start the response process automatically. Separately, in Ålesund, 35 people from a regional technology cluster, many with executive or senior management backgrounds, took part in a discussion-based session. Rather than touching the software directly, they reviewed the roles and tasks the tool generated for the same ransomware scenario and discussed whether they felt realistic and useful.

Researchers also gathered input from one participant with about 15 years of experience in crisis management and information security, along with a small number of questionnaire responses from organizations connected to the research project.

Cyber Crisis Chess Board infographic showing how ransomware alerts are translated into roles and response tasks for company leaders.
Infographic by StudyFinds

What the Cyber Crisis Chess Board Test Found

In the Gjøvik exercise, the tool did what it was designed to do. When the mock ransomware attack hit, the system detected it, correctly classified it as ransomware, created an alarm, and generated roles and tasks for participants to follow. Researchers had laid out five specific technical checks to confirm the process worked from start to finish, and all five were observed during the exercise.

That said, the exercise also turned up real friction. Some participants had trouble using the crisis management web portal the tool connects to, partly because they weren’t familiar with it and partly because of slow response times during the exercise itself. Even when the backend logic worked correctly, a clunky interface got in the way of a smooth experience, a reminder that good technology can still fall flat if people struggle to use it under pressure.

Ålesund told a different story. Since participants there reviewed the generated roles and tasks without wrestling with the actual software, their feedback skipped the usability headaches entirely. Several said their organizations don’t currently run this kind of leadership-focused cyber crisis training and expressed real interest in adopting something similar, especially at organizations without detailed emergency plans in place.

That experienced participant offered a sharper critique, noting that many organizations already rely on established crisis management platforms and predefined emergency plans. From that perspective, the tool’s real value might not be creating an entirely new system, but automatically triggering and escalating the plans organizations already have. That same participant pointed out that top decision-makers often lack basic details during a crisis, like how many devices are infected or which business functions are affected, and that better automated information flow could make a real difference.

Questionnaire respondents, meanwhile, raised concerns about trust. Could an automated system be relied on to catch everything it’s supposed to catch, especially during a complicated attack involving multiple techniques at once? They also worried about false alarms and the challenge of keeping such a tool updated as hacking methods change.

Why the Real Problem Isn’t the Technology

None of this means the Cyber Crisis Chess Board is ready for wide use, and the researchers are upfront about that. What it does show is that turning a wall of technical alerts into something a non-technical executive can act on is possible, at least for one type of attack tested in one controlled setting. The test suggests the underlying concept can work for ransomware, at least in the lab. The bigger open question is whether people trust it, understand it, and can actually use it when the pressure is on. Until organizations solve that human side of the equation, a smarter alarm system will only get them so far.

Paper Notes

Limitations

This work describes itself as an exploratory look at technical feasibility rather than a full effectiveness study. The Gjøvik exercise involved just seven participants, and the Ålesund session involved 35 people who reviewed generated outputs without using the full technical workflow. Feedback also came from one experienced participant and a limited number of questionnaire responses, which the authors do not treat as a large enough or representative enough sample to draw broad conclusions. The hands-on technical testing focused specifically on a ransomware scenario. While the prototype was designed to support ten different incident scenarios, the authors did not test the other nine through the same kind of live cyber-range exercise. The study included no comparison group, no competing tool, and no formal statistical analysis of decision quality, usability, or trust. The scenario detection rules built into the prototype were manually configured based on expert assumptions rather than statistically validated, and the authors say those rules would need further expert review before wider use. Because of all this, the authors caution that their results demonstrate technical feasibility in one tested setting rather than proof that the tool works broadly across organizations, industries, or attack types.

Funding and Disclosures

Published as an open-access article under a Creative Commons Attribution 4.0 License, the paper carries no separate funding statement or conflict-of-interest disclosure in the material provided for this review.

Publication Details

Paper Title: “A Design Science Approach to Bridging Operational Cyber Detection and Strategic Crisis Management”

Authors: Sivert Lundli, Ehtesham Hashmi, Muhammad Mudassar Yamin, and Basel Katt, all affiliated with the Department of Information Security and Communication Technology at the Norwegian University of Science and Technology (NTNU) in Gjøvik, Norway.

Journal: IEEE Access, Volume 14 (pages 114052–114071)

Published: Online on July 24, 2026

DOI: 10.1109/ACCESS.2026.3716866

About StudyFinds Analysis

Called "brilliant," "fantastic," and "spot on" by scientists and researchers, our acclaimed StudyFinds Analysis articles are created using an exclusive AI-based model with complete human oversight by the StudyFinds Editorial Team. For these articles, we use an unparalleled LLM process across multiple systems to analyze entire journal papers, extract data, and create accurate, accessible content. Our writing and editing team proofreads and polishes each and every article before publishing. With recent studies showing that artificial intelligence can interpret scientific research as well as (or even better) than field experts and specialists, StudyFinds was among the earliest to adopt and test this technology before approving its widespread use on our site. We stand by our practice and continuously update our processes to ensure the very highest level of accuracy. Read our AI Policy (link below) for more information.

Our Editorial Process

StudyFinds publishes digestible, agenda-free, transparent research summaries that are intended to inform the reader as well as stir civil, educated debate. We do not agree nor disagree with any of the studies we post, rather, we encourage our readers to debate the veracity of the findings themselves. All articles published on StudyFinds are vetted by our editors prior to publication and include links back to the source or corresponding journal article, if possible.

Our Editorial Team

Steve Fink

Editor-in-Chief

John Anderer

Associate Editor