Improving the Human Firewall: Exploring the Factors that Influence Cyber-Security Incident Reporting
摘要
Purpose: Cyber-security incidents present a growing risk to organisations due to their increasing sophistication and prevalence. It is crucial for employees, often considered the ‘human firewall’ against cyber-attacks, to report these incidents promptly. Doing so can minimise damage and enable cyber-security teams to quickly detect and mitigate active attacks. Hence, the aim of this study was to investigate the relationship of a subset of factors on the reporting of cyber-security incidents. Methodology: 549 working Australian adults completed the Cyber Security Incident Reporting Inventory (CSIRI; pronounced, “Siri”) and a series of demographic questions via an online survey. Findings: Participants were significantly more likely to report incidents if their organisation had a cyber-security policy, regardless of whether it was formal or informal, or if they perceived cyber-security as being primary or relevant to their job. In addition, employees identifying with diverse gender identities exhibited significantly more negative attitudes and less perceived behavioural control in reporting cyber-security incidents, compared to the male, female, and non-binary groups. Implications: The results of this study indicate that organisations should consider introducing or modifying their existing cyber-security policies and training programs to meet the needs of their diverse employees. Organisations who leverage such insights can reinforce their ‘human firewall’ and better defend themselves against cyber-attacks.