Skip to main content
Kent Academic Repository

“I don't think we're there yet”: The practices and challenges of organisational learning from cyber security incidents

Patterson, Clare M., Nurse, Jason R.C., Franqueira, Virginia N.L. (2024) “I don't think we're there yet”: The practices and challenges of organisational learning from cyber security incidents. Computers & Security, 139 . Article Number 103699. ISSN 0167-4048. (doi:10.1016/j.cose.2023.103699) (KAR id:104873)

PDF Publisher pdf
Language: English


Download this file
(PDF/991kB)
[thumbnail of 1-s2.0-S0167404823006090-main.pdf]
Preview
Request a format suitable for use with assistive technology e.g. a screenreader
XML Word Processing Document (DOCX) Author's Accepted Manuscript
Language: English

Restricted to Repository staff only

Contact us about this Publication
[thumbnail of Accepted pre-print “I don’t think we’re there yet”.docx]
Official URL:
https://doi.org/10.1016/j.cose.2023.103699

Abstract

Learning from cyber incidents is crucial for organisations to enhance their cyber resilience and effectively respond to evolving threats. This study employs neo-institutional and organisational learning theories to examine how organisations learn from incidents and gain insights into the challenges they face. Drawing on qualitative research methods, interviews were conducted with 34 security practitioners from organisations operating in the UK spanning a range of industries. The findings highlight the importance of consciously evaluating learning practices and creating a culture of openness to hear about incidents from employees, customers and suppliers. Deciding which incidents to learn from, as well as who should participate in the learning process, emerged as critical considerations. Overcoming defensiveness and addressing systemic causes were recognised as barriers to effective learning. The study emphasises the need to assess the value and impact of identified lessons and to avoid superficial reviews that treat symptoms rather than underlying causes to improve resilience. While progress has been made in learning from incidents, further enhancements are needed. Practical recommendations have been proposed to suggest how organisations may gain valuable insights for maximising the benefits derived from incident learning. This research contributes to the existing knowledge on organisational learning and informs future studies exploring the social and political influences on the learning process. By considering the suggested recommendations, organisations may strengthen their cyber security, foster a culture of continuous improvement, and respond effectively to the dynamic cyber security landscape.

Item Type: Article
DOI/Identification number: 10.1016/j.cose.2023.103699
Uncontrolled keywords: Cyber security incidents; organisational learning; post-incident review; cyber resilience; learning practices; lessons learned; neo-institutional theory; isomorphic pressures
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 75 Electronic computers. Computer science
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Funders: University of Kent (https://ror.org/00xkeyj56)
Depositing User: Clare Patterson
Date Deposited: 05 Feb 2024 16:40 UTC
Last Modified: 05 Nov 2024 13:10 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/104873 (The current URI for this page, for reference purposes)

University of Kent Author Information

Patterson, Clare M..

Creator's ORCID: https://orcid.org/0000-0002-8480-406X
CReDIT Contributor Roles:

Nurse, Jason R.C..

Creator's ORCID: https://orcid.org/0000-0003-4118-1680
CReDIT Contributor Roles:

Franqueira, Virginia N.L..

Creator's ORCID: https://orcid.org/0000-0003-1332-9115
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.