Changing Hearts and Minds: The Role of Cybersecurity Champion Programs in Cybersecurity Culture

被引:1
作者
Granova, Victoria [1 ]
Mashatan, Atefeh [1 ]
Turetken, Ozgur [1 ]
机构
[1] Toronto Metropolitan Univ, Toronto, ON, Canada
来源
AUGMENTED COGNITION, AC 2023 | 2023年 / 14019卷
关键词
Cybersecurity; Cybersecurity Culture; Cybersecurity Champions; Culture Change; Innovation; INNOVATION;
D O I
10.1007/978-3-031-35017-7_26
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Humans have often been written off as the weakest link in the cybersecurity industry. This paper looks at the human factor from a different perspective, seeking ways to leverage the human element to improve cybersecurity. The human element and its importance in cybersecurity defense and security incidents have been widely studied. The relationship between organizational cybersecurity culture and cybersecurity posture has also been examined in the literature. What is lacking is the examination of how an organization could improve its cybersecurity culture. Accordingly, we explore the possibility of cybersecurity champions to impact organizational cybersecurity culture, thereby improving the organization's cybersecurity posture. The option of leveraging cybersecurity champions to impact culture is proposed, and existing theoretical bases of Champion Theory and Promotor Theory in innovation management are explored to support the implementation of cybersecurity champions. These theories are then applied to existing cybersecurity culture research. Innovation champions exhibit transformational leadership characteristics to inspire innovation; four types of promotors (expert promotors, power promotors, process promotors and relationship promotors) use their various sources of power to remove barriers to innovation. Eight hypotheses are developed about the possible effect of the presence of cybersecurity innovation champions and cybersecurity promotors on four factors which have been found to have significant impact on information security culture in previous research (Tejay & Mohammed, 2022): group cohesiveness or alignment, professional codes (codes of ethics or conduct), informal work practices, and cybersecurity awareness.
引用
收藏
页码:416 / 428
页数:13
相关论文
共 44 条
[1]  
Adnams S., CIOs need to address culture, people and process change in dynamic environments
[2]   From awareness to influence: toward a model for improving employees’ security behaviour [J].
Alshaikh M. ;
Adamson B. .
Personal and Ubiquitous Computing, 2021, 25 (05) :829-841
[3]   Developing cybersecurity culture to influence employee behavior: A practice perspective [J].
Alshaikh, Moneer .
COMPUTERS & SECURITY, 2020, 98
[4]  
[Anonymous], 2017, Computer Fraud & Security, V2017
[5]  
[Anonymous], Information technology (IT) worldwide spending from 2005 to 2022
[6]  
[Anonymous], 2022, Major cybersecurity agenda revealed for Canalys Forums
[7]   Security awareness of computer users: A phishing threat avoidance perspective [J].
Arachchilage, Nalin Asanka Gamagedara ;
Love, Steve .
COMPUTERS IN HUMAN BEHAVIOR, 2014, 38 :304-312
[8]   Innovation Agents in the Public Sector: Applying Champion and Promotor Theory to Explore Innovation in the Australian Public Service [J].
Bankins, Sarah ;
Denness, Bonnie ;
Kriz, Anton ;
Molloy, Courtney .
AUSTRALIAN JOURNAL OF PUBLIC ADMINISTRATION, 2017, 76 (01) :122-137
[9]  
CNBC, If you got an email about the $117.5 million Yahoo data breach settlement, here are your options
[10]   Exploring Workers' Subjective Experiences of Habit Formation in Cyber-Security: A Qualitative Survey [J].
Collins, Emily I. M. ;
Hinds, Joanne .
CYBERPSYCHOLOGY BEHAVIOR AND SOCIAL NETWORKING, 2021, 24 (09) :599-604