top of page

Summer Reports

banner_background2.png

The Human-Centric Cybersecurity Summer Report Project brings together postgraduate students across Canada to work with our private and public partners. Together, the teams produce reports analyzing wicked cybersecurity problems through a transdisciplinary lens.  

This project provides students with an opportunity to learn, improve skills, access mentors, work with industry and government partners and experience the practice of research, all while advancing the greater understanding of cybersecurity for the benefit of the Canadian cybersecurity ecosystem.   

Each year the project focuses on important topics and questions as raised by the membership of the HC2P. The reports generated are provided to allow organizations and individuals to tap into human-centric research and the next wave of Canadian talent. 

Summer Program 2024

The 2024 Summer school program presents a three-volume series comprising the following reports:  

  • Artificial Intelligence and Trust: Securing Digital Identities  

  • Misinformation & Cybersecurity: Examining the Threat of Misinformation to Digital Media  

  • Quantum Ready Cybersecurity: Understanding and Managing the Risk

 

These reports analyze these critical, current and pressing issues through societal, regulatory and behavioural lenses. 

Artificial Intelligence and Trust

AI Report Cover_edited.png

This report explores how artificial intelligence could transform digital identity management by making systems faster, more accurate, and better at detecting unauthorized access than traditional approaches. Despite this potential, the report explains that many organizations are hesitant to adopt AI because of trust-related concerns, including opaque decision-making, risks to privacy, built-in bias, security vulnerabilities, high costs, and the absence of clear regulatory guidance.

To help readers understand how these concerns can be addressed, the report outlines four main ways to build trust in AI-driven identity systems. First, AI technologies themselves must be designed to be transparent, fair, and secure. Second, human oversight is essential, including an independent review of AI systems before deployment and giving users greater control over how their identity data is used. Third, the report highlights the importance of clear and cooperative regulation developed across public, private, and academic sectors to ensure accountability and ethical use. Finally, it emphasizes the role of incentives, such as public funding and training, to encourage responsible innovation and adoption.

Misinformation & Cybersecurity

Misinformation Report Cover.jpg

This report explains how misinformation has become a serious cybersecurity challenge, particularly due to its rapid spread on social media. It shows how false information can distort public opinion, undermine democratic processes, and cause real-world harm, as seen in political and health-related misinformation. The report also highlights how technologies such as AI and deepfakes make misinformation harder to detect and control.

To address these risks, the report reviews both proactive and reactive responses, including digital literacy initiatives, prebunking, fact-checking, content labelling, and AI-based detection tools, while noting their limitations. It concludes that combating misinformation requires a coordinated approach that combines regulation, education, technological innovation, and collaboration among governments, industry, and civil society.

Quantum Ready Cybersecurity

Quantum Report Cover.jpg

This report explains why quantum computing, although still developing, already represents a serious future threat to cybersecurity that must be addressed now. It highlights the risk of “harvest now, decrypt later” attacks, in which adversaries collect encrypted data today to decrypt it once quantum capabilities mature. To frame this challenge, the report asks how quantum computing will disrupt cybersecurity, how those risks can be mitigated, and how Canada should prepare for a post-quantum world. It organizes these risks into known-knowns, such as the vulnerability of current encryption methods, known-unknowns related to the timing and scale of future attacks, and unknown-unknowns that point to longer-term uncertainties involving emerging technologies.

Building on this analysis, the report offers a practical roadmap for action across policy, technology, and governance. Key recommendations include accelerating the adoption of post-quantum cryptography, updating legislation and regulatory frameworks, investing in research and public education, strengthening risk management and supply chain resilience, and expanding international cooperation. Together, these steps are presented as essential to preparing Canada for the cybersecurity impacts of quantum computing while protecting privacy, resilience, and digital equity.

  1. Alsiyat, Y., Amouie, M., Burgess, A., Chu, N., Marmorato, P., & Mogra, P. (2025). Artificial intelligence and trust: Securing digital identities. Human-Centric Cybersecurity Partnership (HC2P)
                          

  2. Abdi, S., Arif, M. Z., Blake, T., Chaîné, A., Oxeus, G., & Weekes, C. (2025). Misinformation & cybersecurity: Examining the threat of misinformation to digital media. Human-Centric Cybersecurity Partnership (HC2P).                                                                                                               

  3. Chan, J., Jereza, B., Machnee, R., Ngan, J., Singh, S. & Vanderkooi, D. (2025) Quantum Ready Cybersecurity: Understanding and Managing the Risk. Human-Centric Cybersecurity Partnership HC2P.

Summer Program 2023

The 2023 Summer school program presents a report examining the phenomena of ransomware in Canada in terms of the issues and potential solutions through societal, regulatory and behavioural lenses. 

Decrypting Ransomware

ANALYZING AND ADDRESSING THE THREAT IN THE CANADIAN CONTEXT

2023 HC2P Summer Program Final Draft.png

Ransomware is a problem that has grown to global proportions, regularly resulting in economic, social and personal harms. Ransomware represents an extortive malicious use of technology that involves and exploits human and social factors to achieve its ends. This report examines the problem of ransomware through a multi-disciplinary lens with the aim of uncovering novel aspects of the problem and shed light on potential new avenues for solutions.

Ransomware is revealed to be a phenomena that evolves when new technology emerges that facilitates successful evolutions of iillicit practices. Particularly concerning are its impacts on Critical infrastructure, small businesses, and society generally through

emergent harms. The technologies to mitigate ransomware generally exist, however they are often not known, not prioritized or not feasible

for the public. There are good solutions to support ransomware mitigation but their implementation needs to be better understood and better resourced.

Carr, C., Deng, B., Huayhua, S., Ibrahim, K., Jawad, A., Jung, F., Leveille, D., Mohd, S., Napoli, D., Piché-Bustros, A., Robins, E., Rostamalizadeh, ., Selim, M., Vanderkooi, D., Zhang, C., Assal, H., Bergeron, A., & Pustogarov (2023) Decrypting Ransomware: Analysing and Addressing the Threat in the Canadian Context, Human-Centric Cybersecurity Partnership (HC2P)

Summer Program 2022

The 2022 Summer school program presents a three-volume series comprising the following reports:  

  • Challenges of Virtual Trust: A Matter of Cooperation, Education, and Cybersecurity  

  • Digital Twins: Cyber Security Prospects, Pitfalls, and Recommendations  

  • Cybersecurity Through Human Behaviour  

 

These reports analyze these critical, current and pressing issues through societal, regulatory and behavioural lenses. 

Challenges of Virtual Trust

In recent years, the rise of e-commerce has resulted in significant changes to consumer spending habits. Trust between consumers and vendors has been shown to be one of the most important variables that makes e-commerce successful. Increasingly, fraudulent online actors seek to abuse and exploit people’s trust for financial gain or to gather personal information, thereby negatively affecting trust-building measures.

 

Trust is understood to include three primary elements through which individuals evaluate organisations:

competence, integrity, and benevolence. Trust enhancing factors, also referred to as “trust antecedents,” can be leveraged by organisations to strengthen trust relationships with their users. Trust antecedents depend on the individual characteristics of consumers (e.g., socio-demographics or personality), the design and functioning of a website (e.g., visual design, ease of use, or interactivity), and interactions between individuals and the organisation (e.g., prior experience of users or perceived reputation of an organisation)

 

Governments and organisations can take measures to ensure the perceived trustworthiness of legitimate websites, and leverage public awareness campaigns to reduce individuals’ risk of falling victim to fraud or other cyber threats.

Digital Twins

Digital twins, synchronized digital counterparts of a physical environment, are being extensively deployed in an array of new applications by government and private actors. The technology offers:

  • Adaptiveness to monitor evolving ecosystems;

  • To enable robust cybersecurity testing and analysis through simulation; and 

  • To allow stakeholders to deliver accurate, predictive results.

 

At the same time, the technology poses cybersecurity risks from:

  • Unintended and adversarial uses through potential compromises of data collection sensors and attacks on data integrity;

  • New opportunities for intellectual property theft; and

  • New vectors of attack on the integrity of cyber-infrastructure from vulnerabilities in data storage, systems, and software of digital twin technologies themselves.

Cybersecurity Through Human Behaviour

This research analyzed a wide range of essential behavioural aspects surrounding cybersecurity themes to determine which techniques may result in better cybersecurity practices and extend the time frame that training is effective. There are several factors in training that influence the practice of cybersecurity, including frequency of training, how employees are motivated, and if they are aware of the impacts of cybersecurity threats.

Focus group interaction was leveraged to explore and clarify participants’ experiences regarding their cybersecurity training. It aimed to provide focused and concise research based on experiences with cybersecurity training. Demographically diverse focus groups were assembled to lead a guided discussion about questions and succeeded in collecting data on employees’ behaviours, perceptions, beliefs, and views regarding cybersecurity and training. After conducting focus groups to gauge behaviours surrounding cybersecurity training and practices, seven themes were identified.

  1. Adediji, D., Aldridge, M., Ouellet, M., Puopolo, A., Thompson, D., & Frank, R. (2022) Challenges of Virtual Trust: A Matter of Cooperation, Education, and Cybersecurity. Human-Centric Cybersecurity Partnership HC2P.                         

  2. Wassim Samy Azzoug, W. S., Canaan, R. G., Islam, M. K., Lakpini, C. S. Malone, M., Smalley, C., Woo, T. & David Murakami Wood, D. (2022) Digital Twins: Cyber Security Prospects, Pitfalls, and Recommendations. Human-Centric Cybersecurity Partnership HC2P.                                                                                                               

  3. Liu, S., Sayoto-Poulin, C., Rim, S., Seval D., Vanderkooi, D., Warkentin, N. & Décary-Hétu, D. (2022) Cybersecurity Through Human Behaviour. Human-Centric Cybersecurity Partnership HC2P.

3744, Jean-Brillant Street, Montréal, Québec

© 2024 by HC2P. All rights Reserved.

bottom of page