Purpose: Cyber-security incidents present a growing risk to organisations due to their increasing sophistication and prevalence. It is crucial for employees, often considered the ‘human firewall’ against cyber-attacks, to report these incidents promptly. Doing so can minimise damage and enable cyber-security teams to quickly detect and mitigate active attacks. Hence, the aim of this study was to investigate the relationship of a subset of factors on the reporting of cyber-security incidents. Methodology: 549 working Australian adults completed the Cyber Security Incident Reporting Inventory (CSIRI; pronounced, “Siri”) and a series of demographic questions via an online survey. Findings: Participants were significantly more likely to report incidents if their organisation had a cyber-security policy, regardless of whether it was formal or informal, or if they perceived cyber-security as being primary or relevant to their job. In addition, employees identifying with diverse gender identities exhibited significantly more negative attitudes and less perceived behavioural control in reporting cyber-security incidents, compared to the male, female, and non-binary groups. Implications: The results of this study indicate that organisations should consider introducing or modifying their existing cyber-security policies and training programs to meet the needs of their diverse employees. Organisations who leverage such insights can reinforce their ‘human firewall’ and better defend themselves against cyber-attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Improving the Human Firewall: Exploring the Factors that Influence Cyber-Security Incident Reporting

  • Kristiina Ahola,
  • Daniel Sturman,
  • Nadia Scott,
  • Malcolm Pattinson,
  • Andrew Reeves,
  • Marcus Butavicius,
  • Agata McCormac

摘要

Purpose: Cyber-security incidents present a growing risk to organisations due to their increasing sophistication and prevalence. It is crucial for employees, often considered the ‘human firewall’ against cyber-attacks, to report these incidents promptly. Doing so can minimise damage and enable cyber-security teams to quickly detect and mitigate active attacks. Hence, the aim of this study was to investigate the relationship of a subset of factors on the reporting of cyber-security incidents. Methodology: 549 working Australian adults completed the Cyber Security Incident Reporting Inventory (CSIRI; pronounced, “Siri”) and a series of demographic questions via an online survey. Findings: Participants were significantly more likely to report incidents if their organisation had a cyber-security policy, regardless of whether it was formal or informal, or if they perceived cyber-security as being primary or relevant to their job. In addition, employees identifying with diverse gender identities exhibited significantly more negative attitudes and less perceived behavioural control in reporting cyber-security incidents, compared to the male, female, and non-binary groups. Implications: The results of this study indicate that organisations should consider introducing or modifying their existing cyber-security policies and training programs to meet the needs of their diverse employees. Organisations who leverage such insights can reinforce their ‘human firewall’ and better defend themselves against cyber-attacks.