Learning from cyber security incidents: A systematic review and future research agenda

被引:15
|
作者
Patterson, Clare M. [1 ]
Nurse, Jason R. C. [2 ,3 ]
Franqueira, Virginia N. L. [2 ,3 ]
机构
[1] Univ Kent, Sch Comp, Cyber Secur, Canterbury CT2 7NZ, Kent, England
[2] Univ Kent, Inst Cyber Secur Soc iCSS, Cyber Secur, Canterbury CT2 7NZ, Kent, England
[3] Univ Kent, Sch Comp, Canterbury CT2 7NZ, Kent, England
关键词
Cyber security; Incident investigation; Incident response; Lessons learned; Learning process; Organisational learning; Post -incident review; Security incident; Systematic literature review; Research agenda; SAFETY MANAGEMENT; HEALTH-CARE; INFORMATION; CHALLENGES; FRAMEWORK;
D O I
10.1016/j.cose.2023.103309
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security incidents are now prevalent in many organisations. Arguably, those who can learn from security incidents and address the underlying causes will reduce the prevalence of similar ones in the future. This research provides a new examination of how organisations learn from incidents by systematically reviewing academic research on organisational learning from cyber security incidents and identifying further research needed in this area. To do this, it considers three research questions: what research has been conducted on learning from cyber security incidents, what learning practices in organisations have been found by research and what improvements have been recommended, and what further research is needed as organisations learn from such incidents. Using the PRISMA method, a total of 3,986 articles were extracted and, from these, a relevant set of 30 were selected for analysis to map the body of research, and to identify future research avenues. Despite learning lessons being recommended by both researchers and industry standards, our findings suggest that this advice is not being fully adopted by organisations. Importantly, these studies have found inadequate participation in learning activities, with superficial causal investigations, scarce effort on ensuring lessons are implemented and no evaluation of whether the actions taken actually reduce future security incidents. More research is needed to understand the right level and which learning practices to invest in for the greatest impact. For practitioners, this review discusses the essential elements of an effective process to learn from incidents. This review provides academics with a novel synthesis of the research undertaken on this topic, enabling them to incorporate the significant findings into their work and potentially explore the research agenda suggested. & COPY; 2023 The Author(s). Published by Elsevier Ltd. ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Organisational agility: systematic literature review and future research agenda
    Franco, Mario
    Guimaraes, Jaiandra
    Rodrigues, Margarida
    KNOWLEDGE MANAGEMENT RESEARCH & PRACTICE, 2023, 21 (06) : 1021 - 1038
  • [42] Online Atmospherics: A Systematic Literature Review and Future Research Agenda
    Suraj, J.
    Joseph, Ajay
    INTERNATIONAL JOURNAL OF CONSUMER STUDIES, 2025, 49 (01)
  • [43] A systematic literature review of startup survival and future research agenda
    Azeem, Mohd
    Khanna, Ashu
    JOURNAL OF RESEARCH IN MARKETING AND ENTREPRENEURSHIP, 2024, 26 (01) : 111 - 139
  • [44] Viral marketing: a systematic literature review and future research agenda
    Kaur, Divyaneet
    Kushwah, Shiksha
    Kumar, Satish
    MARKETING INTELLIGENCE & PLANNING, 2025,
  • [45] Secondhand consumption: A systematic literature review and future research agenda
    Gilal, Faheem Gul
    Shaikh, Abdul Rehman
    Yang, Zhiyong
    Gilal, Rukhsana Gul
    Gilal, Naeem Gul
    INTERNATIONAL JOURNAL OF CONSUMER STUDIES, 2024, 48 (03)
  • [46] Multichannel integration quality: A systematic review and agenda for future research
    Hossain, Tasnim M. Taufique
    Akter, Shahriar
    Kattiyapornpong, Uraiporn
    Dwivedi, Yogesh K.
    JOURNAL OF RETAILING AND CONSUMER SERVICES, 2019, 49 : 154 - 163
  • [47] Corporate entrepreneurship: a systematic literature review and future research agenda
    David Urbano
    Andreu Turro
    Mike Wright
    Shaker Zahra
    Small Business Economics, 2022, 59 : 1541 - 1565
  • [48] Social innovation: a systematic literature review and future agenda research
    do Adro, Francisco
    Fernandes, Cristina, I
    INTERNATIONAL REVIEW ON PUBLIC AND NONPROFIT MARKETING, 2020, 17 (01) : 23 - 40
  • [49] Assessing competitiveness through intellectual capital research: a systematic literature review and agenda for future research
    Abdallah, Amr S.
    Amin, Hala M. G.
    Abdelghany, Mohammed
    Elamer, Ahmed A.
    COMPETITIVENESS REVIEW, 2025, 35 (01) : 190 - 220
  • [50] Anthropomorphism in hospitality and tourism: A systematic review and agenda for future research
    Ding, Anni
    Lee, Rachel Hyunkyung
    Legendre, Tiffany S.
    Madera, Juan
    JOURNAL OF HOSPITALITY AND TOURISM MANAGEMENT, 2022, 52 : 404 - 415