Cyber-Security Culture Assessment in Academia: A COVID-19 Study: Applying a Cyber-Security Culture Framework to assess the Academia's resilience and readiness
A. Georgiadou, Ariadni Michalitsi-Psarrou, D. Askounis
{"title":"Cyber-Security Culture Assessment in Academia: A COVID-19 Study: Applying a Cyber-Security Culture Framework to assess the Academia's resilience and readiness","authors":"A. Georgiadou, Ariadni Michalitsi-Psarrou, D. Askounis","doi":"10.1145/3538969.3544467","DOIUrl":null,"url":null,"abstract":"Times of crisis have long been combined with an increase in cybercrime, exploiting the general instability; therefore, in such times, systems and infrastructures face greater exposure to vulnerabilities. On top of that, the COVID-19 crisis has increased our reliance on the internet, while working-from-home has been the daily reality for a large proportion of the population worldwide. Increased cyber-security awareness becomes a necessity for everyone, starting from a more knowledgeable audience; IT professionals, and software engineers. In this context, this paper aims to assess the cyber-security culture readiness of representatives studying or working within a European Polytechnique Academic Institution, during the COVID-19 crisis. Towards that end, a targeted evaluation campaign was launched for two weeks, from 28th February 2022 to 13th March 2022. The campaign consisted of four questionnaires of increased difficulty and a phishing quiz, all assessing the security culture of the participants against three dimensions; their security attitude, their competency, and their actual behavior. The campaign results have been thoroughly analyzed, and the findings were unforeseen in many cases, supporting the identification of security awareness weaknesses and assisting in drafting targeted, customized training programs.","PeriodicalId":306813,"journal":{"name":"Proceedings of the 17th International Conference on Availability, Reliability and Security","volume":"40 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-08-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 17th International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3538969.3544467","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Times of crisis have long been combined with an increase in cybercrime, exploiting the general instability; therefore, in such times, systems and infrastructures face greater exposure to vulnerabilities. On top of that, the COVID-19 crisis has increased our reliance on the internet, while working-from-home has been the daily reality for a large proportion of the population worldwide. Increased cyber-security awareness becomes a necessity for everyone, starting from a more knowledgeable audience; IT professionals, and software engineers. In this context, this paper aims to assess the cyber-security culture readiness of representatives studying or working within a European Polytechnique Academic Institution, during the COVID-19 crisis. Towards that end, a targeted evaluation campaign was launched for two weeks, from 28th February 2022 to 13th March 2022. The campaign consisted of four questionnaires of increased difficulty and a phishing quiz, all assessing the security culture of the participants against three dimensions; their security attitude, their competency, and their actual behavior. The campaign results have been thoroughly analyzed, and the findings were unforeseen in many cases, supporting the identification of security awareness weaknesses and assisting in drafting targeted, customized training programs.