Learning from cyber security incidents: A systematic review and future research agenda

被引:15
|
作者
Patterson, Clare M. [1 ]
Nurse, Jason R. C. [2 ,3 ]
Franqueira, Virginia N. L. [2 ,3 ]
机构
[1] Univ Kent, Sch Comp, Cyber Secur, Canterbury CT2 7NZ, Kent, England
[2] Univ Kent, Inst Cyber Secur Soc iCSS, Cyber Secur, Canterbury CT2 7NZ, Kent, England
[3] Univ Kent, Sch Comp, Canterbury CT2 7NZ, Kent, England
关键词
Cyber security; Incident investigation; Incident response; Lessons learned; Learning process; Organisational learning; Post -incident review; Security incident; Systematic literature review; Research agenda; SAFETY MANAGEMENT; HEALTH-CARE; INFORMATION; CHALLENGES; FRAMEWORK;
D O I
10.1016/j.cose.2023.103309
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security incidents are now prevalent in many organisations. Arguably, those who can learn from security incidents and address the underlying causes will reduce the prevalence of similar ones in the future. This research provides a new examination of how organisations learn from incidents by systematically reviewing academic research on organisational learning from cyber security incidents and identifying further research needed in this area. To do this, it considers three research questions: what research has been conducted on learning from cyber security incidents, what learning practices in organisations have been found by research and what improvements have been recommended, and what further research is needed as organisations learn from such incidents. Using the PRISMA method, a total of 3,986 articles were extracted and, from these, a relevant set of 30 were selected for analysis to map the body of research, and to identify future research avenues. Despite learning lessons being recommended by both researchers and industry standards, our findings suggest that this advice is not being fully adopted by organisations. Importantly, these studies have found inadequate participation in learning activities, with superficial causal investigations, scarce effort on ensuring lessons are implemented and no evaluation of whether the actions taken actually reduce future security incidents. More research is needed to understand the right level and which learning practices to invest in for the greatest impact. For practitioners, this review discusses the essential elements of an effective process to learn from incidents. This review provides academics with a novel synthesis of the research undertaken on this topic, enabling them to incorporate the significant findings into their work and potentially explore the research agenda suggested. & COPY; 2023 The Author(s). Published by Elsevier Ltd. ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Research and development agenda for Learning from Incidents
    Margaryan, Anoush
    Littlejohn, Allison
    Stanton, Neville A.
    SAFETY SCIENCE, 2017, 99 : 5 - 13
  • [2] "I don't think we're there yet": The practices and challenges of organisational learning from cyber security incidents
    Patterson, Clare M.
    Nurse, Jason R. C.
    Franqueira, Virginia N. L.
    COMPUTERS & SECURITY, 2024, 139
  • [3] Mobile advertising: A systematic literature review and future research agenda
    Jebarajakirthy, Charles
    Maseeh, Haroon Iqbal
    Morshed, Zakir
    Shankar, Amit
    Arli, Denni
    Pentecost, Robin
    INTERNATIONAL JOURNAL OF CONSUMER STUDIES, 2021, 45 (06) : 1258 - 1291
  • [4] Research communities in cyber security vulnerability assessments: A comprehensive literature review
    Heiding, Fredrik
    Katsikeas, Sotirios
    Lagerstroem, Robert
    COMPUTER SCIENCE REVIEW, 2023, 48
  • [5] Telework: systematic literature review and future research agenda
    Athanasiadou, Chrisalena
    Theriou, Georgios
    HELIYON, 2021, 7 (10)
  • [6] Mortality Salience Effects of Critical Incidents - A Systematic Literature Review and Research Agenda
    Leung, Hoi-Ting
    Chew, Peter K. H.
    Caltabiano, Nerina J.
    OMEGA-JOURNAL OF DEATH AND DYING, 2024, 90 (01) : 73 - 119
  • [7] Machine learning in supply chain management: systematic literature review and future research agenda
    Vlachos, Ilias
    Reddy, Pulagam Gautam
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2025,
  • [8] Systematic review of features for co-simulating security incidents in Cyber-Physical Systems
    Czekster, Ricardo M.
    Morisset, Charles
    Clark, John A.
    Soudjani, Sadegh
    Patsios, Charalampos
    Davison, Peter
    SECURITY AND PRIVACY, 2021, 4 (03)
  • [9] Place Branding: A Systematic Literature Review and Future Research Agenda
    Swain, Swapnarag
    Jebarajakirthy, Charles
    Sharma, Bhuvanesh Kumar
    Maseeh, Haroon Iqbal
    Agrawal, Amee
    Shah, Jinal
    Saha, Raiswa
    JOURNAL OF TRAVEL RESEARCH, 2024, 63 (03) : 535 - 564
  • [10] Brand hate: A systematic literature review and future research agenda
    Yadav, Abhishek
    Chakrabarti, Somnath
    INTERNATIONAL JOURNAL OF CONSUMER STUDIES, 2022, 46 (05) : 1992 - 2019