Executive decision-makers: a scenario-based approach to assessing organizational cyber-risk perception

被引:2
作者
Parkin, Simon [1 ]
Kuhn, Kristen [2 ]
Shaikh, Siraj A. [3 ,4 ]
机构
[1] Delft Univ Technol, Fac Technol Policy & Management, Jaffalaan 5, NL-2628 BX Delft, Netherlands
[2] Coventry Univ, Ctr Trust Peace & Social Relat CTPSR, Coventry CV1 5FB, Warwickshire, England
[3] Swansea Univ, Syst Secur Grp SSG, Dept Comp Sci, Bay Campus,Fabian Way, Swansea SA1 8EN, Wales
[4] Rule Law & High Technologiesnivers Nebrija, Res Ctr Secur Rule Law & High Technol Res Ctr Secu, Madrid 28015, Spain
来源
JOURNAL OF CYBERSECURITY | 2023年 / 9卷 / 01期
关键词
security management; decision making; business continuity; risk analysis;
D O I
10.1093/cybsec/tyad018
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The executive leadership in corporate organizations is increasingly challenged with managing cyber-risks, as an important part of wider business risk management. Cyber-risks are complex, with the threat landscape evolving, including digital infrastructure issues such as trust in networked supply chains, and emerging technologies. Moreover, engaging organizational leadership to assess for risk management is also difficult. This paper reports on a scenario-driven, workshop-based study undertaken with executive leadership to assess for cybersecurity and cyber-risk perception related to preparation for, and response to, potential incidents. The study involves leadership members at a large public-private organization. Our approach utilizes scenarios, which are structured in their design to explore and analyse aspects of business risk, risk ownership, technological complexity, and uncertainty faced by an organizational leadership. The method offers a means to engage with leadership at real-world organizations, capturing capacity and insights to manage business risks due to cyberattacks.
引用
收藏
页数:13
相关论文
共 35 条
  • [1] The economics of information security
    Anderson, Ross
    Moore, Tyler
    [J]. SCIENCE, 2006, 314 (5799) : 610 - 613
  • [2] [Anonymous], 2023, BBC
  • [3] [Anonymous], 2023, CYB 9 12 STRAT CHALL
  • [4] Atlantic Council, 2023, About us
  • [5] Cambridge Centre for Risk Studies, 2019, GLOB RISK IND 2020 E
  • [6] Dittrich D., 2012, Technical report
  • [7] Fiveash K., 2019, NORSK HYDROCYBER ATT
  • [8] Fragnière E, 2019, 2019 4TH INTERNATIONAL CONFERENCE ON SYSTEM RELIABILITY AND SAFETY (ICSRS 2019), P474, DOI 10.1109/ICSRS48664.2019.8987661
  • [9] Greenberg A., 2023, The Untold Story of NotPetya, the Most Devastating Cyberattack in History
  • [10] Heidt M, 2019, PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, P6145