Abstract
Background: Cyber operations unfold at superhuman speeds where cyber defense decisions are based on human-to-human communication aiming to achieve a shared cyber situational awareness. The recently proposed Orient, Locate, Bridge (OLB) model suggests a three-phase metacognitive approach for successful communication of cyber situational awareness for good cyber defense decision-making. Successful OLB execution implies applying cognitive control to coordinate self-referential and externally directed cognitive processes. In the brain, this is dependent on the frontoparietal control network and its connectivity to the default mode network. Emotional reactions may increase default mode network activity and reduce attention allocation to analytical processes resulting in sub-optimal decision-making. Vagal tone is an indicator of activity in the dorsolateral prefrontal node of the frontoparietal control network and is associated with functional connectivity between the frontoparietal control network and the default mode network.
Aim: The aim of the present study was to assess whether indicators of neural activity relevant to the processes outlined by the OLB model were related to outcomes hypothesized by the model.
Methods: Cyber cadets (N = 36) enrolled in a 3-day cyber engineering exercise organized by the Norwegian Defense Cyber Academy participated in the study. Differences in prospective metacognitive judgments of cyber situational awareness, communication demands, and mood were compared between cyber cadets with high and low vagal tone. Vagal tone was measured at rest prior to the exercise. Affective states, communication demands, cyber situational awareness, and metacognitive accuracy were measured on each day of the exercise.
Results: We found that cyber cadets with higher vagal tone had better metacognitive judgments of cyber situational awareness, imposed fewer communication demands on their teams, and had more neutral moods compared to cyber cadets with lower vagal tone.
Conclusion: These findings provide neuroergonomic support for the OLB model and suggest that it may be useful in education and training. Future studies should assess the effect of OLB-ing as an intervention on communication and performance.
1 Introduction
Cyber operations unfold at superhuman speeds, which pose high demands on human cyber operators. Due to the growing global network coverage and increasing interconnectedness between cyber and physical domains, cyber operations are conducted in a complex socio-technical system consisting of diverse human-machine and human-human interactions. Performance in this socio-technical system is influenced by several factors across multiple contexts including unique challenges spanning cyber, physical, cognitive, and social domains (Jøsok et al., , ; Agyepong et al., ). The resulting working-environment poses a complex selective pressure requiring a seemingly unique but currently understudied competency profile (Jøsok et al., , ; Knox et al., , ; Lugo and Sütterlin, ).
Organizations source their cyber operations to Security Operation Centers (SOCs) consisting of teams and organizational units that work around the clock to detect, assess, and respond to cyber threats. SOCs are usually hierarchically organized where analyst-level responsibilities such as detecting, investigating, and reporting on cyber threats are assigned to technical personnel (cyber operators), while decision-making responsibilities are assigned to other individuals higher up in the SOC hierarchy (Staheli et al., ). Thus, cyber operators are responsible for establishing situational awareness (SA) during cyber threat situations and communicating their SA to decision-makers. According to the SA model (Endsley, ), establishing SA for decision-making in a socio-technical system is achieved in three levels (Figure 1A), where all levels must be achieved in order to have full SA. SA Level 1 entails perceiving the elements of the situation, SA Level 2 entails comprehending the relationship between these elements, and SA Level 3 entails using the comprehension to predict possible future situational states (Endsley, ).
Figure 1
Seven requirements for achieving cyber SA (CSA) for decision-making during cyber threat situations have been proposed (Barford et al.,
Figure 2

The Hybrid Space (HS) framework and the OLB model. (A) The Hybrid Space (HS; Jøsok et al.,
Transitioning between quadrants in the Hybrid Space to relay technical information to non-technical individuals, will in theory require the cyber operator to switch between mindsets (Jøsok et al.,
Recent reviews suggest that there is a lack of research on individual- and team-level SOC team communication and performance indicators (Agyepong et al.,
In more general terms, OLB-ing can be understood as a stepwise cognitive control process involving the deliberate (endogenously controlled) and flexible transition between attention to internal and self-referential states (e.g., Hybrid Space location, stress levels) and externally oriented cognitive processes. Cognitive control is the goal-directed coordination of task-relevant cognitive processes while inhibiting task-irrelevant automatic processes (Friedman and Robbins,
Both the FPN and DMN have anatomical hubs in the prefrontal cortex (PFC; Raichle,
Both the DLPFC and MPFC are involved in metacognitive processes (Fleur et al.,
From a neuroergonomics perspective, when faced with a challenging environment, the brain will find something akin to “the path of least resistance” to optimal performance (Botvinick,
Expert cyber incident response teams impose less communication demands on their teams compared to novices (Buchler et al.,
The main aim of this study is to assess some of the neurocognitive assumptions of the OLB model (Knox et al.,
The processing of emotional stimuli may influence cyber team performance (Lugo et al.,
Metacognition is required for establishing accurate SA (Endsley,
2 Methods
2.1 Participants and setting
Cyber cadets (N = 36) that participated in the Norwegian Defense University College, Cyber Academy (NDCA) annual Cyber Engineering Exercise (CEX) were recruited for the study. The CEX is conducted during the fifth semester for graduating students at the NDCA. By this stage in their bachelor degree education, they have chosen and begun their specialized training. The specializations are military Information Communication Technology (ICT) systems and Cyber Operations. The specialization split was eleven (11) cadets pursuing Cyber Operations and the remaining twenty-five (25) military ICT. The CEX is intended to provide cyber cadets with a deeper understanding and appreciation for the breadth of a cyber engineer’s profession and tasks in a military operative context. In particular, they develop more advanced technical skills in the domain of cyber operations and gain insight into how incidents occurring in the military cyber domain may influence and be influenced by operations in other military and non-military domains. The cadets learn how to make good judgments, give honest recommendations through clear communication, and make good decisions that result in the effective use of cyber tools and technologies to achieve operational goals. The CEX was divided into two independent operations: military ICT Operations and Cyber Operations. Both operations lasted for 5 days (see Figure 3 for an overview of the CEX and study).
Figure 3

Overview of the study and the cyber engineering exercise. CEX, Cyber engineering exercise; HRV, Heart rate variability.
For the CEX, the cadets were divided into two platoons, with each platoon consisting of three teams. One platoon participated in military ICT Operations for 5 days, while the other platoon participated in Cyber Operations for 5 days. Each team consisted of six individuals that were composed of a mix of military ICT and Cyber Operations cadets. The first 2 days involved orders, preparation, and training. This was followed by 3 days of mission execution. On day 6, there was a rotation where the platoons switched operations so that the platoon that started out in the military ICT operations track switched to the Cyber Operations track, and vice versa. Participants per rotation (n = 16).
The present study took measurements when each platoon was undertaking the Cyber Operations track of the CEX. The defensive Cyber Operations involved scenario-based investigations of a network intrusion where the cadets experienced technical and operational uncertainty and complexity related to exploitation of their military cyber domain. After the initial preparation and training phase, the cadets deployed to a notional area of operations. For the CEX, this took the form of teams being assigned separate rooms, where the cadets deployed network sensor capabilities into their infrastructure and began targeted network surveillance based on their operational assessment and plans. The scenario developed allowing cadets to conduct different analytical tasks and investigate specific types and instances of network traffic. The cadets advanced through the exercise by solving these analytical and investigative missions. Each day the exercise would begin at 8:00 a.m. and end at 10:00 p.m., with the level of intensity (operational uncertainty and technical complexity) imposed upon the cadets gradually increasing each day. There were organized regular breaks for eating three times per day, once in the morning, once around noon, and once in the evening, where all the cadets participating in the Cyber Operations track could eat simultaneously. If any of the teams operated in shifts, this was organized within the teams, but usually meant that someone would bring with them food from the cafeteria to the individual(s) that did not join the common breaks.
Data from four participants were excluded from the analysis. Data from one participant were excluded for only providing baseline HRV data and not filling out daily questionnaires. A second participant was excluded due to measurement error during the recording of inter-beat intervals. Lastly, two participants were excluded due to not filling out relevant questionnaires for most of the exercise.
2.2 Materials and procedure
On the first day of the study, 2 days before the start of the CEX all participants answered a battery of questionnaires followed by recording of cardiac activity for quantification of vmHRV. Affective state, performance rating, team, and CSA measurements were collected on each day of the exercise. On the morning of each day of the exercise (approx. 7:30 a.m.), participants answered questionnaires pertaining to their affective state and judgments about how well they think they would perform. At the end of each day (approx. 9:00 p.m.), participants answered questionnaires pertaining to judgments about how well they thought they had performed, team-workload demands, and CSA.
2.2.1 Vagally mediated heart rate variability
Cardiac activity was recorded at rest for 7 min 2 days prior to the start of the exercise using the Alive Software (AliveTM by Somatic Vision, Inc., Encinitas, CA, United States) biofeedback system. Alive measures heart rate through photoplethysmography. The recordings were conducted one at a time in a separate room that was secluded from other activities. Participants were seated in comfortable chairs. Three finger sensors were placed on the participant’s non-dominant hand, after which they were told to rest for some minutes by themselves. After giving the instructions, the researcher left the room for the entirety of the 7-min recording period.
Five minutes in the middle of the recordings were used for quantification of vmHR. Inter-beat intervals were extracted via R-peak detection and HRV was analyzed using ARTiiFACT software (Kaufmann et al.,
2.2.2 Self-assessment manikin
The self-assessment manikin (SAM) is a non-verbal assessment of affective states (Bradley and Lang,
2.2.3 Judgment of performance
A prospective judgment of performance (JOP) questionnaire was used to assess the participants’ prospective estimations of how well they would perform. The JOP questionnaire is used to assess how confident participants are about their future performance (e.g., Sütterlin et al.,
For this study, daily perspective JOP at the individual and team level were z-transformed before averaging to generate prospective self-assessment (JOP) and team assessment (JOP team) JOP scores.
2.2.4 Team workload questionnaire
Establishing CSA is a team effort (McNeese et al.,
2.2.5 Cyber situational awareness questionnaire for analysts
To assess CSA among participants, the CSA questionnaire for analysts (Lif et al.,
For all CSA items, participants had to indicate which estimate they thought was correct on a Likert scale from 1 to 7. For the Kill chain item, participants had to indicate on a Kill chain flow chart where the attack was (seven options). Their answers were converted to a score from 1 to 7 depending on where in the kill chain they indicated that the attack was, with 7 corresponding to “Action on objectives”, which is the last step in the kill chain.
Participants were instructed to leave items they did not know what to answer blank, but to write their participant ID on the front page, in which case those items were coded as 0 (thus making CSA items range from 0 to 7). Responses were coded as missing if the entire form was left empty. Reliability for CSA items was good (Cronbach’s α = 0.771).
The correct answer for the kill chain item was 7. The correct answer for attack severity was 7. The correct answer for action urgency was 7. The correct answers for system critical was 6. CSA scores for the participants were generated by scoring correct assessments on the questionnaires for each day as 1 and erroneous assessments as 0. The scores for each day were z-transformed before averaging to generate CSA scores. Kill chain estimations could in theory be inferred from exercise instructions thus being too easy to tax metacognitive abilities. Metacognitive estimations for easy tasks are less subject to bias than for harder tasks (Fleur et al.,
The same procedure was done at the team level, where team CSA scores were generated based on the averaged correct CSA estimations for the entire team, and a team CSA2 variable was generated by excluding kill chain scores.
Due to the structure of the exercise, participants would only be able to make informed judgments on the attack severity item on days 4 and 5, while informed judgments on the kill chain, how critical the system was, and action urgency were possible on all 3 days. There was a very low number of correct CSA answers on day one which was likely due to participants spending time on sensor deployment and only starting to establish CSA during the tail end of the day.
2.2.6 Metacognitive accuracy
The individual and team CSA scores for each day, and the personal and team JOP scores for each day were used to generate the metacognitive accuracy (MCA) scores. CSA scores were range converted to a 0–100 scale. MCA scores were calculated as a deviation score using the approach described by Meessen et al. (
Because JOP scores are subtracted from the accuracy scores, CSA performance that matches performance estimations will give a score of zero, while performance estimations that are below or above CSA performance will give a score that deviates from zero. Squaring the product returns an equal positive value for all negative and positive equivalent deviations from zero. Thus, a low MCA score indicates high metacognitive accuracy, and a high MCA score indicates low metacognitive accuracy regardless of inaccuracy resulting from overconfidence or underconfidence. At the team level, a high metacognitive accuracy means having high accuracy when judging team-level CSA.
The z-transformed MCA scores for each day were averaged to generate two sets of MCA variables, MCA and team MCA. While the DLPFC is needed for making prospective metacognitive judgments about performance (Vaccaro and Fleming,
2.3 Statistical analysis
Descriptive statistics were generated for all variables and presented in tables as mean, standard deviation (SD), minimum (min), and maximum (max) values for continuous and numerical variables, and frequencies and percentages (%) for ordinal variables.
Inspecting box-and-whisker plots of variables identified one outlier (value > 1.5 times the interquartile range above the upper quartile) for HFHRV. After re-inspection of inter-beat interval recording and artifact analysis for the HFHRV outlier, it was concluded that measurement error was unlikely, thus, HFHRV was log-transformed to pull in the outlier. Follow-up inspecting box-and-whisker plots confirmed that the log-transformed variable no longer contained extreme values. All subsequent analyses were performed on the log-transformed HFHRV variable.
For the purpose of the present study, we were mainly interested in the communication demand item of the team workload questionnaire due to reported differences between expert and novice teams (Buchler et al.,
Pearson and Spearman correlation analyses (2-tailed) was performed simultaneously for all variables and results were presented in a heat map as Spearman correlation coefficients (ρ) for nonparametric associations and Pearson’s correlation coefficients (r) for parametric associations. RMSSD was included in the correlation analysis to check for associations with HFHRV but was not included in the heat map. Separate linear regression analyses were performed for significant correlations. All regressions were checked for violation of assumptions regarding homoscedasticity, normality, linearity, and multicollinearity.
2.3.1 Analysis of group differences
The differences between high and low HFHRV groups were assessed using Pillai’s MANOVA and ANOVA for parametric comparisons and Kruskal-Wallis H tests for nonparametric comparisons. Results for the Pillai test were reported as Pillai’s Trace (TracePillai), approximate F(degrees of freedom 1, degrees of freedom 2; F(df1, df2)), and p-values. Results for ANOVA were reported as F statistic(df), p-values, and effect size. Kruskal-Wallis H test was reported as H statistic(df), p-values, and effect size.
Effect size (η2) for the Kruskal-Wallis H test was calculated as (H−k + df)/(n−k); where H was the Kruskal-Wallis statistic, k was the number of groups, and n was the total number of observations (32). Effect size (ω2) for ANOVA was calculated as (sum of squares between − (k − 1) mean square within)/(sum of squares total + mean square within). Dunn’s post-hoc test was used to assess significant relationships for non-parametric variables between groups and was reported as z-statistic and Bonferroni adjusted p-values (pbonf). Tukey’s post-hoc test was used to assess significant relationships for parametric variables between groups and was reported as mean difference (MD) and pbonf.
Violation of assumptions for MANOVA analyses were assessed with Box’s M-test for homogeneity and Shapiro-Wilk test for multivariate normality. Violation of assumptions for ANOVA analyses were assessed with Levene’s test for equality of variance and by inspecting Q-Q plots of residuals. There were no violations at any time.
2.3.2 Comparisons between low and high vagal tone groups
A median split was performed on the HFHRV variable to divide the sample into high HFHRV (HFHRV > median) and low HFHRV (HFHRV ≤ median) groups according to whether they had values above or below the median. This method is commonly used in studies aiming to assess vagal tone-related group differences in cognitive performance (Hansen et al.,
2.3.3 Comparisons between low and high metacognitive accuracy groups
Both vagal tone and prospective metacognitive judgments are influenced by DLPFC activity (Brunoni et al.,
2.3.4 Comparisons of MCA between CSA accuracy groups
In the present study, high metacognitive accuracy (indicated by low MCA scores) could be due to accurately judging good or bad performance (e.g., having 0% correct answers and judging performance at 0%, and having 100% correct answers and judging performance at 100% would both give a score of 0). A median split was performed on the summed total of correct CSA ratings for both days to divide the sample into two groups (CSA accuracy) according to whether they were less accurate or more accurate in their CSA ratings. To test the hypothesis that individuals with higher metacognitive accuracy have more correct CSA ratings than individuals with lower metacognitive accuracy (H3), two separate analyses were performed using MCA or MCA2 as a dependent variable and CSA accuracy as the fixed factor. This procedure was repeated for team MCA variables also, where the median split was performed on the summed total of correct team CSA ratings after averaging for the number of team members.
Alpha levels for hypothesis testing were set at the 0.05 level for all analyses. All data were analyzed using JASP version 0.15 (JASP Team, 2021).
3 Results
3.1 Descriptive statistics
Descriptive statistics for HRV indices, SAM, team workload questionnaire, JOP, CSA, and MCA variables are presented in Table 1.
Table 1
| High HFHRV | Low HFHRV | |||||||
|---|---|---|---|---|---|---|---|---|
| Variables | Mean | SD | Min | Max | Mean | SD | Mean | SD |
| Mean RR | 935.73 | 174.06 | 677.63 | 1,342.760 | 1,023.570 | 175.60 | 847.89 | 123.78 |
| HFHRV | 1,473.190 | 1,501.760 | 124.82 | 5,079.730 | 2,547.500 | 1,471.220 | 398.88 | 185.10 |
| HFHRV_log | 6.75 | 1.09 | 4.82 | 1.62 | 7.65 | 0.68 | 5.86 | 0.54 |
| RMSSD | 60.92 | 28.38 | 32.08 | 136.95 | 82.05 | 26.03 | 39.80 | 5.87 |
| CSA | 0.23 | 0.17 | 0.00 | 0.75 | 0.26 | 0.19 | 0.20 | 0.14 |
| CSA2 | 0.18 | 0.17 | 0.00 | 0.66 | 0.22 | 0.19 | 0.14 | 0.15 |
| Team CSA | 0.23 | 0.67 | 0.18 | 0.36 | 0.24 | 0.07 | 0.22 | 0.05 |
| Team CSA2 | 0.18 | 0.84 | 0.74 | 0.33 | 0.21 | 0.07 | 0.15 | 0.08 |
| Z-Transformed variables | ||||||||
| HFHRV | −0.00 | 1.00 | −1.76 | 1.62 | 0.81 | 0.62 | −0.81 | 0.50 |
| RMSSD | 0.00 | 1.00 | −1.01 | 2.67 | 0.74 | 0.91 | −0.74 | 0.20 |
| Mood | 0.00 | 1.00 | −2.02 | 1.84 | −0.47 | 0.90 | 0.47 | 0.87 |
| Activation | −0.00 | 1.00 | −2.20 | 1.90 | −0.17 | 1.01 | 0.17 | 0.98 |
| Control | −0.00 | 1.00 | −2.08 | 2.44 | −0.21 | 0.97 | 0.21 | 1.01 |
| Judgment of performance | −0.00 | 1.00 | −1.91 | 2.36 | −0.16 | 0.91 | 0.16 | 1.08 |
| Judgment of performance team | −0.00 | 1.00 | −1.69 | 2.21 | −0.25 | 1.08 | 0.25 | 0.86 |
| Communication demand | 0.00 | 1.00 | −2.53 | 1.32 | −0.49 | 1.06 | 0.49 | 0.63 |
| Coordination demand | 0.00 | 1.00 | −2.08 | 2.08 | −0.26 | 0.98 | 0.26 | 0.97 |
| Team performance monitoring | 0.00 | 1.00 | −1.79 | 2.07 | −0.17 | 0.94 | 0.16 | 1.05 |
| Time-share demand | 0.00 | 1.00 | −1.32 | 2.33 | −0.01 | 0.94 | 0.01 | 1.08 |
| Team support demand | 0.00 | 1.00 | −1.90 | 2.09 | 0.04 | 0.83 | −0.04 | 1.15 |
| Team emotion demand | 0.00 | 1.00 | −2.43 | 1.94 | 0.05 | 1.14 | −0.05 | 0.87 |
| Perceived team success | −0.00 | 1.00 | −2.00 | 1.72 | −0.54 | 0.79 | 0.50 | 0.91 |
| CSA | 0.00 | 1.00 | −1.36 | 3.04 | 0.16 | 1.14 | −0.16 | 0.83 |
| CSA2 | −0.00 | 1.00 | −1.07 | 2.73 | 0.23 | 1.09 | −0.23 | 0.85 |
| Team CSA | 0.00 | 1.00 | −0.76 | 1.92 | 0.17 | 1.11 | −0.17 | 0.87 |
| Team CSA2 | −0.00 | 1.00 | −1.34 | 1.75 | 0.35 | 0.09 | −0.35 | 0.99 |
| Metacognitive accuracy | −0.00 | 0.663 | −0.79 | 1.95 | −0.08 | 0.75 | 0.08 | 0.56 |
| Metacognitive accuracy2 | 0.00 | 0.703 | −1.07 | 1.58 | −0.17 | 0.69 | 0.17 | 0.69 |
| Team metacognitive accuracy | 0.00 | 2.168 | −4.52 | 4.55 | −0.89 | 1.15 | 0.89 | 2.5 |
| Team metacognitive accuracy2 | −0.00 | 0.800 | −1.44 | 1.35 | −0.38 | 0.46 | 0.38 | 0.89 |
Descriptive statistics for HRV, SAM, TWLQ, JOP, CSA, and MCA variables (N = 32).
Notes. HRV, Heart rate variability; SAM, self-assessment manikin; TWLQ, Team workload questionnaire; JOP, judgment of performance; RR, R-to-R peak interval; HFHRV, High frequency component heart rate variability; _log, log-transformed; RMSSD, Root mean square of successive RR differences; CSA, Cyber situational awareness; CSA2 and Metacognitive accuracy2, CSA and Metacognitive accuracy without Kill chain scores.
3.2 Correlations between HFHRV, SAM, team workload questionnaire, JOP, CSA, and MCA scores
HFHRV was significantly associated with RMSSD (ρ = 0.928, p < 0.001), indicating that the indices were of good quality. Spearman and Pearson correlations between HFHRV, SAM, team workload questionnaire, JOP, CSA, and MCA variables are presented in Figure 4.
Figure 4

Correlation heat map for HRV, SAM, team workload questionnaire, JOP, CSA, and MCA variables. 2-tailed. *p < 0.050, **p < 0.010, ***p < 0.001. Matrix numbers are Pearson correlation coefficients (r) and Spearman’s correlation coefficients (ρ). Pearson’s r is indicated with black frames. Red, Negative correlation; Blue, Positive correlation. Color intensity indicates the strength of correlation. HFHRV, High frequency component heart rate variability; JOP, Judgment of performance; TPM, Team performance monitoring; CSA, Cyber situational awareness; MCA, Metacognitive accuracy; CSA2 and MCA2, CSA and MCA without Kill chain scores.
HFHRV was significantly and negatively associated with mood (p = 0.003). There were no significant relationships between HFHRV and activation (p = 0.841), or control (p = 0.457). There were no significant correlations between mood and activation (p = 0.602) or control (p = 0.382), or between activation and control (p = 0.759).
HFHRV was significantly and negatively associated with perceived team success (p = 0.017). Mood was significantly and positively associated with perceived team success (p = 0.029). Neither HFHRV (p = 0.142), mood (p = 0.086), activation (p = 0.214), nor control (p = 0.091) were associated with communication demand. Neither HFHRV, mood, nor activation was associated with any other team workload variables. Control was significantly and negatively associated with time-share demand (p = 0.043) but not any other team workload questionnaire items.
HFHRV was not significantly associated with JOP (p = 0.122) or JOP team (p = 0.106). The mood was significantly and positively associated with JOP (p = 0.004) and the JOP team (p < 0.001). JOP was not significantly associated with activation (p = 0.457), nor control (p = 0.135). JOP team was not significantly associated with activation (p = 0.567), nor control (p = 0.505).
HFHRV was significantly and positively associated with team CSA2 (p = 0.035). HFHRV was not significantly associated with CSA (p = 0.597), CSA2 (p = 0.238), nor team CSA (p = 0.516). The mood was significantly and negatively associated with team CSA2 (p = 0.029). Mood was not significantly associated with CSA (p = 0.706), CSA2 (p = 0.384), and nor team CSA (p = 0.342). No other significant associations between SAM variables and CSA variables.
Perceived team success was significantly and negatively associated with team CSA2 (p = 0.033). No other significant associations between team workload questionnaire scores and CSA scores.
HFHRV was significantly and negatively associated with MCA2 (p = 0.031), team MCA (p = 0.032), and team MCA2 (p = 0.012). HFHRV was not significantly associated with MCA (p = 0.156). Mood was significantly and positively associated with MCA (p = 0.004), MCA2 (p = 0.003), team MCA (p < 0.001), and team MCA2 (p = 0.004). No other SAM variables were associated with MCA variables. Perceived team success was significantly and positively associated with team MCA (p < 0.001) and team MCA2 (p < 0.001). No other associations between team workload questionnaire and MCA variables were significant.
Separate linear regression analysis was performed for significant relationships. Table 2 shows the results for the regression analyses.
Table 2
| Predictor | Dependent variable | β | p | R2Adj | F(1) |
|---|---|---|---|---|---|
| HFHRV | Mood | −0.512 | 0.003 | 0.237 | 10.644 |
| HFHRV | Perceived team success | −0.382 | 0.034 | 0.116 | 4.949 |
| HFHRV | MCA2 | −0.382 | 0.031 | 0.117 | 5.122 |
| HFHRV | Team MCA | −0.380 | 0.032 | 0.116 | 5.049 |
| HFHRV | Team MCA2 | −0.441 | 0.012 | 0.167 | 7.223 |
| HFHRV | Team CSA2 | 0.331 | 0.064 | 0.080 | 3.702 |
| Mood | JOP | 0.481 | 0.005 | 0.206 | 9.020 |
| Mood | JOP team | 0.518 | 0.002 | 0.244 | 10.999 |
| Mood | Perceived team success | 0.384 | 0.033 | 0.118 | 5.018 |
| Mood | MCA | 0.424 | 0.016 | 0.152 | 6.575 |
| Mood | MCA2 | 0.493 | 0.004 | 0.217 | 9.609 |
| Mood | Team MCA | 0.532 | 0.002 | 0.259 | 11.858 |
| Mood | Team MCA2 | 0.569 | <0.001 | 0.302 | 14.394 |
| Mood | Team CSA2 | −0.310 | 0.085 | 0.066 | 3.180 |
| Perceived team success | Team MCA2 | 0.571 | <0.001 | 0.303 | 14.058 |
| Perceived team success | Team MCA | 0.567 | <0.001 | 0.298 | 13.760 |
| Perceived team success | Team CSA2 | −0.299 | 0.102 | 0.058 | 2.853 |
Results for linear regression analyses (N = 32).
Notes. HFHRV, High frequency component heart rate variability; MCA, Metacognitive accuracy; CSA, Cyber situational awareness; JOP, Judgments of performance; CSA2 and MCA2, CSA and MCA without Kill chain scores.
HFHRV was a significant negative predictor of mood (p = 0.003), perceived team success (p = 0.034), MCA2 (p = 0.031), team MCA (p = 0.032), and team MCA2 (p = 0.012). HFHRV was not a significant predictor of team CSA2 (p = 0.064). Figure 5 shows regressions for HFHRV and mood, MCA2, team MCA, and team MCA2.
Figure 5

Scatter plots with regression lines. Stapled lines are 95% confidence intervals. (A) HFHRV and mood. (B) HFHRV and MCA2. (C) HFHRV and team MCA. (D) HFHRV and team MCA2. HFHRV, High frequency component heart rate variability; MCA, Metacognitive accuracy; MCA2, MCA without Kill chain scores.
Mood was a significant positive predictor of JOP (p = 0.005), JOP team (p = 0.002), perceived team success (p = 0.033), MCA (p = 0.016), MCA2 (p = 0.004), team MCA (p = 0.002), and team MCA2 (p < 0.001). Mood was not a significant negative predictor of team CSA2 (p = 0.085).
Perceived team success was a significant positive predictor of team MCA (p < 0.001) and team MCA2 (p < 0.001). Perceived team success was not a significant predictor of team CSA2 (p = 0.102).
3.3 Between-group comparisons
Table 3 shows the results from all the comparisons.
Table 3
| Kruskal-Wallis test | Dunn’s post-hoc | |||||
|---|---|---|---|---|---|---|
| Fixed factors | Dependent variables | H(1) | p | η2 | z | pbonf |
| Vagal tone groups (low, high) | Communication demand | 7.549 | 0.006 | 0.218 | 2.74 | 0.003 |
| CSA | 0.645 | 0.422 | −0.011 | - | ||
| CSA2 | 1.484 | 0.223 | 0.016 | - | - | |
| Team CSA | 0.862 | 0.353 | −0.004 | - | - | |
| Team CSA2 | 5.207 | 0.022 | 0.140 | −2.28 | 0.011 | |
| MCA | 1.841 | 0.175 | 0.028 | - | - | |
| Team MCA2 | 6.960 | 0.008 | 0.198 | 2.63 | 0.004 | |
| CSA accuracy (low, high) | MCA | 6.937 | 0.008 | 0.197 | 2.63 | 0.004 |
| Team CSA accuracy (low, high) | Team MCA2 | 5.205 | 0.023 | 0.140 | 2.28 | 0.011 |
| Pillai’s MANOVA | Tukey’s post-hoc | |||||
| F(3,28) | p | Ω2 | MD | pbonf | ||
| Vagal tone groups (low, high) | MCA2 | 1.975 | 0.170 | 0.030 | - | - |
| Team MCA | 6.363 | 0.017 | 0.144 | 1.78 | 0.017 | |
| Mood | 9.026 | 0.005 | 0.201 | 0.94 | 0.005 | |
| One-way ANOVA | Tukey’s post-hoc | |||||
| F(1) | p | Ω2 | MD | pbonf | ||
| MCA groups (low, high) | HFHRV | 4.576 | 0.041 | 0.101 | −0.71 | 0.041 |
| Team MCA groups (low, high) | HFHRV | 6.301 | 0.018 | 0.142 | −0.82 | 0.018 |
| CSA accuracy (low, high) | MCA2 | 8.393 | 0.007 | 0.198 | 0.67 | 0.007 |
| Team CSA accuracy (low, high) | Team MCA | 14.393 | <0.001 | 0.295 | 2.55 | <0.001 |
Comparison of differences between groups (N = 32).
Notes. HFHRV, High frequency component heart rate variability; CSA, Cyber situational awareness. MCA, Metacognitive accuracy; η2 and ω2, Effect size; CSA2 and MCA2, CSA and MCA without Kill chain scores.
3.3.1 H1: Individuals with higher vagal tone have higher metacognitive accuracy and impose lower communication demands on their teams than individuals with lower vagal tone
Pillai’s MANOVA was performed using mood, MCA2, and team MCA as dependent variables and vagal tone groups as fixed factor; the Kruskal-Wallis H tests were performed using MCA, team MCA2, CSA, CSA2, team CSA, team CSA2, and communication demand as dependent variables and vagal tone groups as fixed factor. The Pillai test for vagal tone groups was significant (TracePillai = 0.269, F(3,28) = 5.863, p = 0.030). Figures 6A–D shows interval plots for differences between high and low HFHRV groups for MCA, CSA, and communication demand variables.
Figure 6

Interval plots for group comparisons. (A–D) Interval plots for differences in communication demand, team MCA, team MCA2, and team CSA2 scores between individuals with low and high HFHRV. (E) Interval plot showing differences in HFHRV between high and low MCA groups. (F) Interval plot showing differences in HFHRV between high and low team MCA groups. Whiskers are 95% confidence intervals. MCA, Metacognitive accuracy; CSA, Cyber situational awareness; HFHRV, High frequency component heart rate variability; CSA2 and MCA2, CSA and MCA without Kill chain scores.
Communication demand was significantly different between low and high HFHRV groups (p = 0.006). Dunn’s post-hoc test revealed that individuals with low HFHRV posed significantly more communication demands on their team compared to individuals with high HFHRV (z = 2.748, pbonf = 0.003).
Team MCA was significantly different between low and high HFHRV groups (p = 0.017). Tukey’s post-hoc test revealed that individuals with low HFHRV had significantly higher team MCA scores than individuals with high HFHRV (MD = 1.78, pbonf = 0.017). Team MCA2 was significantly different between low and high HFHRV groups (p = 0.008). Dunn’s post-hoc test revealed that Individuals with low HFHRV had significantly higher team MCA2 scores compared to individuals with high HFHRV (z = 2.63, pbonf = 0.004). Team CSA2 was significantly different between low and high HFHRV groups (p = 0.022). Dunn’s post-hoc test revealed that Individuals with low HFHRV had significantly lower team CSA2 scores compared to individuals with high HFHRV (z = 2.28, pbonf = 0.011).
3.3.1.1 Individuals with higher metacognitive accuracy have higher vagal tone than individuals with lower metacognitive accuracy
HFHRV was significantly different between low and high MCA groups (p = 0.041). Tukey’s post-hoc test showed that individuals with lower metacognitive accuracy had lower HFHRV compared to individuals with higher metacognitive accuracy (MD = −0.71, pbonf = 0.041). HFHRV was significantly different between low and high team MCA groups (p = 0.018). Tukey’s post-hoc test showed that individuals with lower team metacognitive accuracy had lower HFHRV compared to individuals with higher team metacognitive accuracy (MD = −0.82, pbonf = 0.018). Figures 6E,F show interval plots for differences in HFHRV between high and low MCA groups, and high and low team MCA groups, respectively.
3.3.2 H2: Individuals with higher vagal tone have different self-reported mood ratings than individuals with lower vagal tone
Results are found in Table 3. Mood was significantly different between low and high HFHRV groups (p = 0.005). Tukey’s post-hoc test revealed that individuals with low HFHRV had significantly higher mood scores compared to individuals with high HFHRV (MD = 0.94, pbonf = 0.005). Figures 7A,B show the interval plot for differences in mood between high and low HFHRV groups, and valence-arousal plots for each day for high and low HFHRV groups, respectively. The valence-arousal plots suggested that individuals with high vagal tone had more neutral moods on day 3 of the exercise, while individuals with low vagal tone had more positive moods.
Figure 7

Interval and valence arousal plots. (A) Interval plot for differences in mood between high and low HFHRV groups. Whiskers are 95% confidence intervals. (B) Valence-arousal plots for high (red) and low (blue) HFHRV groups. Line with squares indicates HFHRV group-means per day. Colors are the brightest for day 1 and darkest for day 3 of the exercise. Transparent circles indicate the mean for all 3 days for each participant.
3.3.3 H3: Individuals with more correct CSA ratings have higher metacognitive accuracy than individuals with less correct CSA ratings
To assess whether individuals with high MCA were correctly estimating good performance or bad performance, ANOVA and Kruskal-Wallis H tests were performed using MCA2, team MCA, and MCA, and team MCA2 as dependent variables, respectively, and CSA accuracy and team CSA accuracy as fixed factor. Results are found in Table 3. Descriptive statistics for the number and percentage of correct CSA answers on each day for the whole sample, and for MCA groups can be found in Table 4.
Table 4
| Low MCA | High MCA | Low team MCA | High team MCA | |||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Variable | Count | % | Count | % | Count | % | Count | % | Count | % |
| Day 1 Kill chain ratings | 4 | 12.50 | 2 | 12.50 | 2 | 12.50 | 2 | 12.50 | 2 | 12.50 |
| Day 1 System critical ratings | 6 | 18.75 | 2 | 12.50 | 4 | 25.00 | 2 | 12.50 | 4 | 25.00 |
| Day 1 Severity ratings | 2 | 6.25 | 0 | 0.00 | 2 | 12.50 | 0 | 0.00 | 2 | 12.50 |
| Day 1 Action urgency ratings | 1 | 3.12 | 1 | 6.25 | 0 | 0.00 | 1 | 6.25 | 0 | 0.00 |
| Day 2 Kill chain ratings | 14 | 43.76 | 4 | 25.00 | 10 | 62.50 | 6 | 37.50 | 8 | 50.00 |
| Day 2 System critical ratings | 3 | 9.37 | 1 | 6.25 | 2 | 12.50 | 1 | 6.25 | 2 | 12.50 |
| Day 2 Attack severity ratings | 7 | 21.87 | 2 | 12.50 | 5 | 31.25 | 2 | 12.50 | 5 | 32.25 |
| Day 2 Action urgency ratings | 10 | 31.25 | 3 | 18.75 | 7 | 43.75 | 4 | 25.00 | 6 | 37.50 |
| Day 3 Kill chain ratings | 17 | 53.12 | 7 | 43.75 | 10 | 62.50 | 8 | 50.00 | 9 | 56.25 |
| Day 3 System critical ratings | 8 | 25.00 | 3 | 18.75 | 5 | 31.25 | 3 | 18.75 | 5 | 31.25 |
| Day 3 Attack severity ratings | 7 | 21.87 | 1 | 6.25 | 6 | 37.50 | 3 | 18.75 | 4 | 25.00 |
| Day 3 Action urgency ratings | 10 | 31.25 | 3 | 18.75 | 7 | 43.75 | 5 | 32.25 | 5 | 31.25 |
| Day 1 mean team ratings* | 13 | 10.15 | 5 | 9.68 | 8 | 10.62 | 5 | 8.75 | 8 | 11.56 |
| Day 2 mean team ratings* | 34 | 26.56 | 10 | 24.47 | 24 | 28.64 | 13 | 22.70 | 21 | 30.41 |
| Day 3 mean team ratings* | 42 | 32.81 | 14 | 30.72 | 28 | 34.89 | 19 | 30.31 | 23 | 35.31 |
Number and percentage of correct CSA answers for each day (N = 32).
Notes. CSA, Cyber Situational Awareness; MCA, Metacognitive accuracy. The sum of the percentage of correct sub-group answers is equal to the percentage of correct answers for the whole group multiplied by number of groups. *Count is the total sum of correct CSA assessments across participants’ daily assessments, percentage is the mean of the mean percentage of correct CSA assessments within teams.
MCA was significantly different between CSA accuracy groups (p = 0.008). Dunn’s post-hoc test revealed that individuals with less accurate CSA ratings had significantly higher MCA scores compared to individuals with more accurate CSA ratings (z = 2.63, pbonf = 0.004). MCA2 was significantly different between CSA accuracy groups (p = 0.007). Tukey’s post-hoc test revealed that individuals with less accurate CSA ratings had significantly higher MCA2 scores compared to individuals with more accurate CSA ratings (MD = 0.67, pbonf = 0.007).
Team MCA was significantly different between team CSA accuracy groups (p < 0.001). Tukey’s post-hoc test showed that individuals with lower team CSA accuracy had higher team MCA scores compared to individuals with higher team CSA accuracy (MD = 2.55, pbonf < 0.001). Team MCA2 was significantly different between team CSA accuracy groups (p = 0.023). Dunn’s post-hoc test showed that individuals with lower team CSA accuracy had higher team MCA2 scores compared to individuals with higher team CSA accuracy (z = 2.28, pbonf = 0.011).
4 Discussion
In this study, we aimed to assess some of the neurocognitive assumptions of the OLB model (Knox et al.,
Being a proxy for activity in prefrontal structures relevant for OLB-ing (Brunoni et al.,
Our findings should be interpreted in light of previous research suggesting that communication inefficiencies are one of the main problems facing SOC teams (Agyepong et al.,
Our sample consisted of cyber cadets that know and are used to interact with each other. Nevertheless, our findings may also have relevance for the challenges that arise when information has to be communicated between people that have different priorities spanning the cyber-physical and strategic-tactical dimensions of cyber operations (Jøsok et al.,
The present findings may shed light on results from other studies on cyber defense teams indicating that experts impose less communication demands on their teams than novices (Buchler et al.,
It has been suggested that individual and team-based metacognitions depend on different processes (Shea et al.,
This article argues that the processes outlined by the OLB model rely on the coordinated and flexible transition between FPN- and DMN-related information processing, which is a cognitive control process (Nee and D’Esposito,
The valence-arousal plots showing daily mood and arousal for individuals with high and low vagal tone indicated that individuals with high vagal tone had more neutral moods on day 3 of the exercise, while individuals with low vagal tone had more positive moods. In a previous study, we found that variations in daily affect were associated with experienced team workloads among cyber cadets participating in a cyber defense exercise (Ask et al., 2021b). While the significance of such findings may be unclear with respect to exercise outcomes (Lund,
In the present study, having high metacognitive accuracy could be either due to accurately judging performance as bad or as good. Thus, it was technically possible that individuals with high metacognitive accuracy could perform equal to- or even worse on CSA estimations than individuals with low metacognitive accuracy as long as they were more correct in their performance estimations. Because good cyber defense decision-making is based on having accurate CSA (Barford et al.,
To the best of our knowledge, this is the first study providing neuroergonomic insights into the relationship between communication in teams and metacognitive CSA accuracy in a cybersecurity setting. While we aimed to provide neuroergonomic support for the OLB model, the present findings could also be used to argue for the importance of psychophysiological measurements in recruitment, training, and performance monitoring. Previous research found associations between vagal tone and performance among tactical personnel in non-cybersecurity settings (including military; Tomes et al.,
4.1 Limitations and future directions
The aim of this study was to assess the neurocognitive assumptions of the OLB model (Knox et al.,
Albeit comparing team-level and individual level metacognitive accuracy is not addressed in this study, Table 4 indicates that the number of correct individual answers for each CSA item per day is mostly overlapping between individuals with high individual- and team-level metacognitive accuracy, although slightly favoring individual metacognitive accuracy. However, when looking at the descriptive statistics for the mean percent of correct answers within teams, the proportion of the mean of correct team answers appears larger for individuals with high team metacognitive accuracy, even though the number of their individual contributions is lower. As noted in previous studies (Ask et al.,
As part of the exercise, the cadets were also assessed on leadership skills and factors other than CSA and mission success. It is possible that some participants included these factors when making prospective judgments of their own and the team performance, thus inflating or deflating their confidence relative to our outcome measurements. Because excluding this possibility would require probing each participant about what they based their estimations on, it is safer to assume that our metacognitive accuracy estimates are conservative. Furthermore, there have been reported sex differences in relationships between social orientations and vagal tone (Lischke et al.,
5 Conclusion
Prefrontally modulated vagal tone, an indicator of activity in brain structures relevant for coordinating the cognitive processes underlying OLB model execution, is associated with metacognitive cyber situational awareness and imposing lower communication demands on the team. Based on the assumption that individuals working in high-stress-, high-cognitive load-environments will choose neuroergonomic cognitive strategies to reach task goals, the present findings suggest that the OLB model is neuroergonomic in such environments. Individuals with higher vagal tone had more neutral moods which could be necessary for allocating more attentional resources to analytical processing. Furthermore, individuals with higher CSA had higher metacognitive accuracy compared to individuals with lower CSA supporting previous studies suggesting that metacognitive accuracy is necessary for achieving situational awareness. The present study highlights the potential of using neurophysiological measurements as performance indicators. Future studies are needed to explicitly address the effect of using the OLB model as the basis for a metacognitive intervention to improve communication and team performance, as well as replicating the findings of the present study.
Statements
Data availability statement
The datasets presented in this article are not readily available because access to raw and processed data is restricted in accordance with agreement between the researchers and the Norwegian Defense University College, Cyber Academy (NDCA). Requests to access the datasets should be directed to corresponding author.
Ethics statement
Ethical review and approval was not required for the study on human participants in accordance with the local legislation and institutional requirements. The patients/participants provided their written informed consent to participate in this study. The present study conformed to institutional guidelines and was eligible for automatic approval by the Norwegian Social Science Data Services’ (NSD) ethical guidelines for experimental studies. Participation was voluntary and all participants were informed about the aims of the study, the methods applied, that they could withdraw from participation at any time and without any consequences, and that if they did so all the data that was gathered from them would be deleted. After volunteering to participate in the study, participants were asked to provide informed consent on the first page of an online form where baseline data was collected. Participants were asked to generate and remember a unique participant ID that they would use during data collection for the duration of the study.
Author contributions
TA: study design and methods, data collection, analysis, writing of original draft, review and editing. BK: study design, writing of original draft, review and editing. RL and SS: study design and methods, review and editing. IH: exercise organization, scoring of CSA questionnaires for analysis, writing of original draft. All authors contributed to the article and approved the submitted version.
Funding
This study was conducted as part of the Advancing Cyber Defense by Improved Communication of Recognized Cyber Threat Situations (ACDICOM) project. ACDICOM is funded by the Norwegian Research Council (project #302941; Norges Forskningsråd).
Acknowledgments
A preprint of this article is available at PsyArXiv preprints (Ask et al.,
Conflict of interest
The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.
Publisher’s note
All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.
References
1
AgyepongE.CherdantsevaY.ReineckeP.BurnapP. (2019). Challenges and performance metrics for security operations center analysts: a systematic review. J. Cyber Security Technol.4, 125–152. 10.1080/23742917.2019.1698178
2
AhrendJ. M.JirotkaM.JonesK. (2016). “On the collaborative practices of cyber threat intelligence analysts to develop and utilize tacit threat and defence knowledge,” in 2016 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), (London, UK). 10.1109/CyberSA.2016.7503279
3
AppelhansB. M.LueckenL. J. (2006). Heart rate variability as an index of regulated emotional responding. Rev. Gen. Psychol.10, 229–240. 10.1037/1089-2680.10.3.229
4
AskT. F.KnoxB. J.LugoR.HelgetunI.SütterlinS. (2022). Neurophysiological and emotional influences on team communication and metacognitive cyber situational awareness during a cyber engineering exercise. PsyArXiv [Preprint]. 10.31234/osf.io/jsnu8
5
AskT. F.LugoR. G.KnoxB. J.SütterlinS. (2021a). “Human-human communication in cyber threat situations: a systematic review,” in HCI International 2021 - Late Breaking Papers: Cognition, Inclusion, Learning and Culture. HCII 2021. Lecture Notes in Computer Science, ed StephanidisC.(Cham: Springer), 21–43.
6
AskT. F.SütterlinS.KnoxB. J.LugoR. G. (2021b). “Situational states influence on team workload demands in cyber defense exercise,” in HCI International 2021 - Late Breaking Papers: Cognition, Inclusion, Learning and Culture. HCII 2021. Lecture Notes in Computer Science, ed StephanidisC.(Cham: Springer), 3–20. 10.1007/978-3-030-90328-2_1
7
BaekE. C.FalkE. B. (2018). Persuasion and influence: what makes a successful persuader. Curr. Opin. Psychol.24, 53–57. 10.1016/j.copsyc.2018.05.004
8
BarfordP.DacierM.DietterichT. G.FredriksonM.GiffinJ.JajodiaS.et al. (2009). “Cyber SA: situational awareness for cyber defense,” in Cyber Situational Awareness Advances in Information Security, eds JajodiaS.LiuP.SwarupV.WangC. (Cham: Springer), 3–13.
9
BerntsonG. G.LozanoD. L.ChenY. J. (2005). Filter properties of root mean square successive difference (RMSSD) for heart rate. Psychophysiology42, 246–252. 10.1111/j.1469-8986.2005.00277.x
10
BerntsonG. G.StowellJ. R. (1998). ECG artifacts and heart period variability: don’t miss a beat!Psychophysiology35, 127–132.
11
BotvinickM. M. (2007). Conflict monitoring and decision making: reconciling two perspectives on anterior cingulate function. Cogn. Affect. Behav. Neurosci.7, 356–366. 10.3758/cabn.7.4.356
12
BradleyM. M.LangP. J. (1994). Measuring emotion: the self-assessment manikin and the semantic differential. J. Behav. Ther. Exp. Psychiatry25, 49–59.
13
BrunoniA. R.VanderhasseltM. A.BoggioP. S.FregniF.DantasE. M.MillJ. G.et al. (2013a). Polarity- and valence-dependent effects of prefrontal transcranial direct current stimulation on heart rate variability and salivary cortisol. Psychoneuroendocrinology38, 58–66. 10.1016/j.psyneuen.2012.04.020
14
BrunoniA. R.KempA. H.DantasE. M.GoulartA. C.NunesM. A.BoggioP. S.et al. (2013b). Heart rate variability is a trait marker of major depressive disorder: evidence from the sertraline vs. electric current therapy to treat depression clinical study. Int. J. Neuropsychopharmacol.16, 1937–1949. 10.1017/S1461145713000497
15
BuchlerN.FitzhughS. M.MarusichL. R.UngvarskyD. M.LebiereC.GonzalezC. (2016). Mission command in the age of network-enabled operations: social network analysis of information sharing and situation awareness. Front. Psychol.7:937. 10.3389/fpsyg.2016.00937
16
ButaviciusM.ParsonsK.PattinsonM.McCormacA. (2016). Breaching the human firewall: social engineering in phishing and spear-phishing emails. arXiv [Preprint]. 10.48550/arXiv.1606.00887
17
CanhamM.SütterlinS.AskT. F.KnoxB. J.GlenisterL.LugoR. G. (2022). Ambiguous self-induced disinformation (ASID) attacks: weaponizing a cognitive deficiency. J. Info. Warfare23, 41–58.
18
ChampionM. A.RajivanP.CookeN. J.JariwalaS. (2012). “Team-based cyber defense analysis,” in 2012 IEEE International Multi-Disciplinary Conference on Cognitive Methods in situation Awareness and Decision Support (New Orleans, LA, USA), 218–221. 10.1109/CogSIMA.2012.6188386
19
ChandT.LiM.JamalabadiH.WagnerG.LordA.AlizadehS.et al. (2020). Heart rate variability as an index of differential brain dynamics at rest and after acute stress induction. Front. Neurosci.14:645. 10.3389/fnins.2020.00645
20
ChangC.GloverG. H. (2009). Effects of model-based physiological noise correction on default mode network anti-correlations and correlations. Neuroimage47, 1448–1459. 10.1016/j.neuroimage.2009.05.012
21
ChenA. C.OathesD. J.ChangC.BradleyT.ZhouZ. W.WilliamsL. M.et al. (2013). Causal interactions between fronto-parietal central executive and default-mode networks in humans. Proc. Nat. Acad. Sci. U S A110, 19944–19949. 10.1073/pnas.1311772110
22
DuncanJ. (2010). The multiple-demand (MD) system of the primate brain: mental programs for intelligent behaviour. Trends Cogn. Sci.14, 172–179. 10.1016/j.tics.2010.01.004
23
EfklidesA. (2008). Metacognition: defining its facets and levels of functioning in relation to self- regulation and co-regulation. Eur. Psychol.13, 277–287. 10.1027/1016-9040.13.4.277
24
EndsleyM. R. (1995). Toward a theory of Situation Awareness in dynamic systems. J. Hum. Factors Ergon. Soc.37, 32–64. 10.1518/001872095779049543
25
EndsleyM. R. (2020). The divergence of objective and subjective situation awareness: a meta- analysis. J. Cogn. Eng. Decis. Mak.14, 34–53. 10.1177/1555343419874248
26
FisherK. (2022). The role of gender in providing expert advice on cyber conflict and artificial intelligence for military personnel. Front. Big Data5:992620. 10.3389/fdata.2022.992620
27
FlavellJ. H. (1979). Metacognition and cognitive monitoring: a new area of cognitive- developmental inquiry. Am. Psychol.34, 906–911. 10.1037/0003-066x.34.10.906
28
FleurD. S.BredewegB.van den BosW. (2021). Metacognition: ideas and insights from neuro- and educational sciences. NPJ Sci. Learn.6:13. 10.1038/s41539-021-00089-5
29
FoxM. D.SnyderA. Z.VincentJ. L.CorbettaM.Van EssenD. C.RaichleM. E. (2005). The human brain is intrinsically organized into dynamic, anticorrelated functional networks. Proc. Nat. Acad. Sci. U S A102, 9673–9678. 10.1073/pnas.0504136102
30
FrankeU.BrynielssonJ. (2014). Cyber situational awareness - a systematic review of the literature. Comput. Security46, 18–31. 10.1016/j.cose.2014.06.008
31
FriedmanN. P.RobbinsT. W. (2022). The role of prefrontal cortex in cognitive control and executive function. Neuropsychopharmacology47, 72–89. 10.1038/s41386-021-01132-0
32
FujimotoA.MurrayE. A.RudebeckP. H. (2021). Interaction between decision-making and interoceptive representations of bodily arousal in frontal cortex. Proc. Nat. Acad. Sci. U S A118:e2014781118. 10.1073/pnas.2014781118
33
GeislerF. C. M.KubiakT. (2009). Heart rate variability predicts self-control in goal pursuit. Eur. J. Personal.23, 623–633. 10.1002/per.727
34
GoedhartA. D.van der SluisS.HoutveenJ. H.WillemsenG.de GeusE. J. (2007). Comparison of time and frequency domain measures of RSA in ambulatory recordings. Psychophysiology44, 203–215. 10.1111/j.1469-8986.2006.00490.x
35
GolkarA.LonsdorfT. B.OlssonA.LindstromK. M.BerrebiJ.FranssonP.et al. (2012). Distinct contributions of the dorsolateral prefrontal and orbitofrontal cortex during emotion regulation. PLoS One7:e48107. 10.1371/journal.pone.0048107
36
GutzwillerR. S.CleggB. A. (2013). The role of working memory in levels of situation awareness. J. Cogn. Eng. Decis. Mak.7, 141–154. 10.1177/1555343412451749
37
HámornikB. P.KrasznayC. (2018). “Ateam-level perspective of human factors in cyber security: security operations centers,“ in AHFE 2017. AISC, ed NicholsonD.(Cham: Springer), 224–236.
38
HaguraN.HaggardP.DiedrichsenJ. (2017). Perceptual decisions are biased by the cost to act. eLife6:e18422. 10.7554/eLife.18422
39
HansenA. L.JohnsenB. H.ThayerJ. F. (2003). Vagal influence on working memory and attention. Int. J. Psychophysiol.48, 263–274. 10.1016/s0167-8760(03)00073-4
40
HansenA. L.JohnsenB. H.ThayerJ. F. (2009). Relationship between heart rate variability and cognitive function during threat of shock. Anxiety Stress Coping22, 77–89. 10.1080/10615800802272251
41
HartS. G.StavelandL. E. (1988). Development of NASA-TLX (Task Load Index): results of empirical and theoretical research. Adv. Psychol. 52, 139–183.
42
HildebrandtL. K.McCallC.EngenH. G.SingerT. (2016). Cognitive flexibility, heart rate variability and resilience predict fine-grained regulation of arousal during prolonged threat. Psychophysiology53, 880–890. 10.1111/psyp.12632
43
JøsokØ.KnoxB. J.HelkalaK.WilsonK.SütterlinS.LugoR. G.et al. (2017). Macrocognition applied to the hybrid space: team environment, functions and processes in cyber operations. Lecture Notes in Comput. Sci.486–500. 10.1007/978-3-319-58625-0_35
44
JøsokØ.KnoxB. J.HelkalaK.LugoR. G.SütterlinS.WardP. (2016). “Exploring the hybrid space,” in Augmented Cognition 2016. Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence), eds SchmorrowD. D. D.FidopiastisC. M. M. (Cham: Springer) 9744, 178–188.
45
JøsokØ.LugoR.KnoxB. J.SütterlinS.HelkalaK. (2019). Self-regulation and cognitive agility in cyber operations. Front. Psychol.10:875. 10.3389/fpsyg.2019.00875
46
JampenD.GürG.SutterT.TellenbachB. (2020). Don’t click: towards an effective anti- phishing training. a comparative literature review. Human-Centric Comput. Info. Sci.10, 1–41. 10.1186/s13673-020-00237-7
47
JariwalaS.ChampionM.RajivanP.CookeN. J. (2012). Influence of team communication and coordination on the performance of teams at the iCTF competition. Proc. Hum. Factors Ergon. Soc. Annu. Meet.56, 458–462. 10.1177/1071181312561044
48
KaufmannT.SütterlinS.SchulzS. M.VögeleC. (2011). ARTiiFACT: a tool for heart rate artifact processing and heart rate variability analysis. Behav. Res. Methods43, 1161–1170. 10.3758/s13428-011-0107-7
49
KhalilR.GoddeB.KarimA. A. (2019). The link between creativity, cognition and creative drives and underlying neural mechanisms. Front. Neural Circuits13:18. 10.3389/fncir.2019.00018
50
KnoxB. J.JøsokØ.HelkalaK.KhooshabehP.ØdegaardT.LugoR. G.et al. (2018). Socio-technical communication: the hybrid space and the OLB model for science- based cyber education. Mil. Psychol.30, 350–359. 10.1080/08995605.2018.1478546
51
KnoxB. J.LugoR. G.HelkalaK. M.SütterlinS. (2019). Slow education and cognitive agility: improving military cyber cadet cognitive performance for better governance of cyberpower. Int. J. Cyber Warfare Terrorism (IJCWT)9, 48–66. 10.4018/IJCWT.2019010104
52
KnoxB. J.LugoR. G.JøsokØ.HelkalaK.SütterlinS. (2017). “Towards a cognitive agility index: the role of metacognition in human computer interaction,” in HCI International 2017 - Posters’ Extended Abstracts (Cham: Springer), 330–338. 10.1007/978-3-319-58750-9_46
53
LanktonP. (2007). Endsley’s model of situational awareness [jpg]. Available online at: https://en.wikipedia.org/wiki/File:Endsley-SA-model.jpg.
54
LifP.GranasenM.SommestadT. (2017). “Development and validation of technique to measure cyber situation awareness,” in 2017 International Conference on Cyber Situational Awareness, Data Aanalytics and Assessment (Cyber SA), (London, UK). 10.1109/cybersa.2017.8073388
55
LischkeA.Mau-MoellerA.JacksteitR.PahnkeR.HammA. O.WeippertM. (2018). Heart rate variability is associated with social value orientation in males but not females. Sci. Rep.8:7336. 10.1038/s41598-018-25739-4
56
ListonC.ChenA. C.ZebleyB. D.DrysdaleA. T.GordonR.LeuchterB.et al. (2014). Default mode network mechanisms of transcranial magnetic stimulation in depression. Biol. Psychiatry76, 517–526. 10.1016/j.biopsych.2014.01.023
57
LugoR. G.AskT. F.SütterlinS.KnoxB. J. (2021). “The influence of team workload demands during a cyber defense exercise on team performance,” in HCI International 2021 - Late Breaking Posters. HCII 2021. Communications in Computer and Information Science, eds StephanidisC.AntonaM.NtoaS. (Cham: Springer), 1499, 545–549. 10.1007/978-3-030-90179-0_70
58
LugoR.Kwei-NahrP.JøsokØ.KnoxB. J.HelkalaK.SütterlinS. (2017a). “Team workload demands influence on cyber detection performance,” in 13th International Conference on Naturalistic Decision Making(Bath, UK), 223–225.
59
LugoR.HelkalaK.KnoxB.JosøkØ.LandeN. M.SütterlinS. (2017b). Interoceptive sensitivity as a proxy for emotional intensity and its relationship with perseverative cognition. Psychol. Res. Behav. Manage.11, 1–8. 10.2147/PRBM.S139790
60
LugoR. G.SütterlinS. (2018). Cyber officer profiles and performance factors. Lecture Notes Comput. Sci.10906, 181–190. 10.1007/978-3-319-91122-9_16
61
LugoR. G.SütterlinS.KnoxB. J.JøsokØ.HelkalaK.LandeN. M. (2016). The moderating influence of self-efficacy on interoceptive ability and counterintuitive decision making in officer cadets. J. Mil. Stud. 7, 44–52. 10.1515/jms-2016-0005
62
LundM. S. (2022). Øving på cybersikkerheit: ein casestudie av ei cybersikkerheitsøving. Scand. J. Mil. Studies5, 244–256. 10.31374/sjms.119
63
McDonaldK. R.PearsonJ. M.HuettelS. A. (2020). Dorsolateral and dorsomedial prefrontal cortex track distinct properties of dynamic social behavior. Soc. Cogn. Affect. Neurosci.15, 383–393. 10.1093/scan/nsaa053
64
McNeeseM.CookeN. J.ChampionM. A. (2011). “Situating cyber situation awareness,” in Proceedings of the 10th International Conference on Naturalistic Decision Making (Orlando, FL).
65
MeessenJ.SütterlinS.GauggelS.ForkmannT. (2018). Learning by heart-the relationship between resting vagal tone and metacognitive judgments: a pilot study. Cogn. Process.19, 557–561. 10.1007/s10339-018-0865-6
66
MenonV.D’EspositoM. (2022). The role of PFC networks in cognitive control and executive function. Neuropsychopharmacology47, 90–103. 10.1038/s41386-021-01152-w
67
MoralesJ.LauH.FlemingS. M. (2018). Domain-general and domain-specific patterns of activity supporting metacognition in human prefrontal cortex. J. Neurosci.38, 3534–3546. 10.1523/JNEUROSCI.2360-17.2018
68
NeeD. E. (2021). Integrative frontal-parietal dynamics supporting cognitive control. eLife10:e57244. 10.7554/eLife.57244
69
NeeD. E.D’EspositoM. (2016). The hierarchical organization of the lateral prefrontal cortex. eLife5:e12112. 10.7554/eLife.12112
70
NejatiV.MajdiR.SalehinejadM. A.NitscheM. A. (2021). The role of dorsolateral and ventromedial prefrontal cortex in the processing of emotional dimensions. Sci. Rep.11:1971. 10.1038/s41598-021-81454-7
71
NeyerS.WitthöftM.CropleyM.PawelzikM.LugoR. G.SütterlinS. (2021). Reduction of depressive symptoms during inpatient treatment is not associated with changes in heart rate variability. PLoS One16:e0248686. 10.1371/journal.pone.0248686
72
NikolinS.BoonstraT. W.LooC. K.MartinD. (2017). Combined effect of prefrontal transcranial direct current stimulation and a working memory task on heart rate variability. PLoS One12:e0181833. 10.1371/journal.pone.0181833
73
ParkG.Van BavelJ. J.EganE. J. L.VaseyM. W.ThayerJ. F. (2012). From the heart to the mind’s eye: cardiac vagal tone is related to visual perception of fearful faces at high spatial frequency. Biol. Psychol.90, 171–178. 10.1016/j.biopsycho.2012.02.012
74
ParkG.Van BavelJ. J.VaseyM. W.ThayerJ. F. (2013). Cardiac vagal tone predicts attentional engagement to and disengagement from fearful faces. Emotion13, 645–656. 10.1037/a0032971
75
PothC. H. (2021). Urgency forces stimulus-driven action by overcoming cognitive control. eLife10:e73682. 10.7554/eLife.73682
76
PuJ.SchmeichelB. J.DemareeH. A. (2010). Cardiac vagal control predicts spontaneous regulation of negative emotional expression and subsequent cognitive performance. Biol. Psychol.84, 531–540. 10.1016/j.biopsycho.2009.07.006
77
RaichleM. E. (2015). The brain’s default mode network. Ann. Rev. Neurosci.38, 433–447. 10.1146/annurev-neuro-071013-014030
78
RaichleM. E.MacLeodA. M.SnyderA. Z.PowersW. J.GusnardD. A.ShulmanG. L. (2001). A default mode of brain function. Proc. Natl. Acad. Sci. U S A98, 676–682. 10.1073/pnas.98.2.676
79
ReynardA.GevirtzR.BerlowR.BrownM.BoutelleK. (2011). Heart rate variability as a marker of self-regulation. Appl. Psychophysiol. Biofeedback36, 209–215. 10.1007/s10484-011-9162-1
80
SegerstromS. C.NesS. L. (2007). Heart rate variability reflects self-regulatory strength, effort and fatigue. Psychol. Sci.18, 275–281. 10.1111/j.1467-9280.2007.01888.x
81
SellersJ.HeltonW. S.NäswallK.FunkeG. J.KnottB. A. (2014). Development of the team workload questionnaire (TWLQ). Proc. Hum. Factors Ergon. Soc. Annu. Meet.58, 989–993. 10.1177/1541931214581207
82
SheaN.BoldtA.BangD.YeungN.HeyesC.FrithC. D. (2014). Supra-personal cognitive control and metacognition. Trends Cogn. Sci.18, 186–193. 10.1016/j.tics.2014.01.006
83
ShimamuraA. P. (2008). “A neurocognitive approach to metacognitive monitoring and control,” in Handbook of Metamemory and Memory, eds DunloskyJ.BjorkR. A. (New York, NY: Psychology Press), 373–390.
84
SkopikF.SettanniG.FiedlerR. (2016). A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing. Comput. Security60, 154–176. 10.1016/j.cose.2016.04.003
85
StaheliD.MancusoV.HarnaschR.FulcherC.ChmielinskiM.KearnsA.et al. (2016). “Collaborative data analysis and discovery for cyber security,” in SOUPS 2016: Twelfth Symposium on Usable Privacy and Security (Denver, CO).
86
SteinkeJ.BolunmezB.FletcherL.WangV.TomassettiA. J.RepchickK. M.et al. (2015). Improving cybersecurity incident response team effectiveness using teams-based research. IEEE Security Privacy13, 20–29. 10.1109/MSP.2015.71
87
SütterlinS.LugoR.AskT.VengK.EckJ.FritschiJ.et al. (2022). “The role of IT background for metacognitive accuracy, confidence and overestimation of deep fake recognition skills,” in Augmented Cognition. HCII 2022. Lecture Notes in Computer Science, eds SchmorrowD. D.FidopiastisC. M. (Cham: Springer), 13310, 103–119. 10.1007/978-3-031-05457-0_9
88
Task Force of the European Society of Cardiology and the North American Society of Pacing and Electrophysiology (1996). Heart rate variability. Standards of measurement, physiological interpretation and clinical use. Circulation93, 1043–1065. 10.1161/01.CIR.93.5.1043
89
TerasawaY.FukushimaH.UmedaS. (2013). How does interoceptive awareness interact with the subjective experience of emotion? An fMRI study. Hum. Brain Mapp.34, 598–612. 10.1002/hbm.21458
90
ThayerJ. F.AhsF.FredriksonM.SollersJ. J.3rdWagerT. D. (2012). A meta-analysis of heart rate variability and neuroimaging studies: implications for heart rate variability as a marker of stress and health. Neurosci. Biobehav. Rev.36, 747–756. 10.1016/j.neubiorev.2011.11.009
91
TomesC.SchramB.OrrR. (2020). Relationships between heart rate variability, occupational performance and fitness for tactical personnel: a systematic review. Front. Public Health8:583336. 10.3389/fpubh.2020.583336
92
VaccaroA. G.FlemingS. M. (2018). Thinking about thinking: a coordinate-based meta- analysis of neuroimaging studies of metacognitive judgements. Brain Neurosci. Adv.2:2398212818810591. 10.1177/2398212818810591
93
VishwanathA.HarrisonB.NgY. J. (2018). Suspicion, cognition and automaticity model of phishing susceptibility. Commun. Res.45, 1146–1166. 10.1177/0093650215627483
94
WheelerA.DensonL.NeilC.TuckerG.KennyM.BeltrameJ.et al. (2014). Investigating the effect of mindfulness training on heart rate variability in mental health outpatients: a pilot study. Behav. Change31, 175–188. 10.1017/bec.2014.14
95
WickensC. D.GutzwillerR. S.SantamariaA. (2015). Discrete task switching in overload: a meta-analyses and a model. Int. J. Hum. Comput. Stud.79, 79–84. 10.1016/j.ijhcs.2015.01.002
96
WilliamsD. P.FeelingN. R.HillL. K.SpanglerD. P.KoenigJ.ThayerJ. F. (2017). Resting heart rate variability, facets of rumination and trait anxiety: implications for the perseverative cognition hypothesis. Front. Hum. Neurosci.11:520. 10.3389/fnhum.2017.00520
97
WilliamsD. P.KoenigJ.CarnevaliL.SgoifoA.JarczokM. N.SternbergE. M.et al. (2019). Heart rate variability and inflammation: a meta-analysis of human studies. Brain Behav. Immun.80, 219–226. 10.1016/j.bbi.2019.03.009
98
WinstonJ. S.VuilleumierP.DolanR. (2003). Effects of low-spatial frequency components of fearful faces on fusiform cortex activity. Curr. Biol.13, 1824–1829. 10.1016/j.cub.2003.09.038
99
ZhouH. X.ChenX.ShenY. Q.LiL.ChenN. X.ZhuZ. C.et al. (2020). Rumination and the default mode network: meta-analysis of brain imaging studies and implications for depression. Neuroimage206:116287. 10.1016/j.neuroimage.2019.116287
Summary
Keywords
vagal tone, cognitive control, cyber operations, neuroergonomics, metacognition, cyber situational awareness, emotion, cyber team communication
Citation
Ask TF, Knox BJ, Lugo RG, Helgetun I and Sütterlin S (2023) Neurophysiological and emotional influences on team communication and metacognitive cyber situational awareness during a cyber engineering exercise. Front. Hum. Neurosci. 16:1092056. doi: 10.3389/fnhum.2022.1092056
Received
07 November 2022
Accepted
16 December 2022
Published
05 January 2023
Volume
16 - 2022
Edited by
Craig Speelman, Edith Cowan University, Australia
Reviewed by
Oliver Guidetti, Edith Cowan University, Australia; Francesco Di Nocera, Sapienza University of Rome, Italy
Updates

Check for updates
Copyright
© 2023 Ask, Knox, Lugo, Helgetun and Sütterlin.
This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.
*Correspondence: Torvald F. Ask torvaldfask@gmail.com
Specialty section: This article was submitted to Cognitive Neuroscience, a section of the journal Frontiers in Human Neuroscience
Disclaimer
All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.