Organisational Cyber Resilience: Management Perspectives

S. Bagheri, Gail Ridley, B. Williams
{"title":"Organisational Cyber Resilience: Management Perspectives","authors":"S. Bagheri, Gail Ridley, B. Williams","doi":"10.3127/ajis.v27i0.4183","DOIUrl":null,"url":null,"abstract":"As cyberthreats pose strategic risk, both IT and business management awareness are critical for effective organisational decision making. Many cyber system failures arise from organisational, and not technical issues. This study investigates senior manager awareness of organisational cyber resilience, using case study method. The Cyber Resilience Matrix is used as a theoretical framework to communicate the multifaceted meaning of cyber resilience. This study examines whether the multilayered nature of cyber resilience is understood by both managerial levels to include the periods before and after cyber incidents. As the higher education sector faces complex cyber challenges, research data were gathered from two Australian universities. Analysis found the two management groups differed in their resilience approach. The authors posit that principles-based cyber policies contribute to an organisational view of cyber resilience. The engineering resilience approach, accompanied by a non-bureaucratic organisational structure, was preferred by IT managers. Business managers favoured an ecological approach with a vertical organisational structure. Both managerial groups emphasised the period before cyber crisis when compared to after cyber incidents. This research contributes to the limited theoretical development in the field and attempts to shift the focus from cyber security to cyber resilience.","PeriodicalId":106236,"journal":{"name":"Australas. J. Inf. Syst.","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-02-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Australas. J. Inf. Syst.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3127/ajis.v27i0.4183","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

As cyberthreats pose strategic risk, both IT and business management awareness are critical for effective organisational decision making. Many cyber system failures arise from organisational, and not technical issues. This study investigates senior manager awareness of organisational cyber resilience, using case study method. The Cyber Resilience Matrix is used as a theoretical framework to communicate the multifaceted meaning of cyber resilience. This study examines whether the multilayered nature of cyber resilience is understood by both managerial levels to include the periods before and after cyber incidents. As the higher education sector faces complex cyber challenges, research data were gathered from two Australian universities. Analysis found the two management groups differed in their resilience approach. The authors posit that principles-based cyber policies contribute to an organisational view of cyber resilience. The engineering resilience approach, accompanied by a non-bureaucratic organisational structure, was preferred by IT managers. Business managers favoured an ecological approach with a vertical organisational structure. Both managerial groups emphasised the period before cyber crisis when compared to after cyber incidents. This research contributes to the limited theoretical development in the field and attempts to shift the focus from cyber security to cyber resilience.
组织网络弹性:管理视角
由于网络威胁构成战略风险,IT和业务管理意识对于有效的组织决策至关重要。许多网络系统故障是由组织问题引起的,而不是技术问题。本研究采用个案研究法,调查高级经理人对组织网络弹性的认知。本文以网络弹性矩阵作为理论框架,阐述了网络弹性的多方面含义。本研究考察了管理层是否理解网络弹性的多层性质,以包括网络事件前后的时期。由于高等教育部门面临复杂的网络挑战,研究数据收集自两所澳大利亚大学。分析发现,两个管理小组在弹性方法上存在差异。作者认为,基于原则的网络政策有助于组织对网络弹性的看法。工程弹性方法,加上非官僚主义的组织结构,受到IT经理的青睐。企业管理者青睐垂直组织结构的生态方法。与网络事件发生后相比,这两个管理团队都强调了网络危机前的时期。本研究弥补了该领域理论发展的不足,并试图将研究重点从网络安全转向网络弹性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信