Patterson, Clare M., Nurse, Jason R.C., Franqueira, Virginia N.L. (2024) “I don't think we're there yet”: The practices and challenges of organisational learning from cyber security incidents. Computers & Security, 139 . Article Number 103699. ISSN 0167-4048. (doi:10.1016/j.cose.2023.103699) (KAR id:104873)
PDF
Publisher pdf
Language: English
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
|
|
Download this file (PDF/991kB) |
Preview |
Request a format suitable for use with assistive technology e.g. a screenreader | |
XML Word Processing Document (DOCX)
Author's Accepted Manuscript
Language: English Restricted to Repository staff only
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
|
|
Contact us about this Publication
|
|
Official URL: https://doi.org/10.1016/j.cose.2023.103699 |
Abstract
Learning from cyber incidents is crucial for organisations to enhance their cyber resilience and effectively respond to evolving threats. This study employs neo-institutional and organisational learning theories to examine how organisations learn from incidents and gain insights into the challenges they face. Drawing on qualitative research methods, interviews were conducted with 34 security practitioners from organisations operating in the UK spanning a range of industries. The findings highlight the importance of consciously evaluating learning practices and creating a culture of openness to hear about incidents from employees, customers and suppliers. Deciding which incidents to learn from, as well as who should participate in the learning process, emerged as critical considerations. Overcoming defensiveness and addressing systemic causes were recognised as barriers to effective learning. The study emphasises the need to assess the value and impact of identified lessons and to avoid superficial reviews that treat symptoms rather than underlying causes to improve resilience. While progress has been made in learning from incidents, further enhancements are needed. Practical recommendations have been proposed to suggest how organisations may gain valuable insights for maximising the benefits derived from incident learning. This research contributes to the existing knowledge on organisational learning and informs future studies exploring the social and political influences on the learning process. By considering the suggested recommendations, organisations may strengthen their cyber security, foster a culture of continuous improvement, and respond effectively to the dynamic cyber security landscape.
Item Type: | Article |
---|---|
DOI/Identification number: | 10.1016/j.cose.2023.103699 |
Uncontrolled keywords: | Cyber security incidents; organisational learning; post-incident review; cyber resilience; learning practices; lessons learned; neo-institutional theory; isomorphic pressures |
Subjects: | Q Science > QA Mathematics (inc Computing science) > QA 75 Electronic computers. Computer science |
Divisions: | Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing |
Funders: | University of Kent (https://ror.org/00xkeyj56) |
Depositing User: | Clare Patterson |
Date Deposited: | 05 Feb 2024 16:40 UTC |
Last Modified: | 05 Nov 2024 13:10 UTC |
Resource URI: | https://kar.kent.ac.uk/id/eprint/104873 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):