Show-and-Tell or Hide-and-Seek? Examining Organizational Cybersecurity Incident Notifications

W. Cram, Rissaile Mouajou-Kenfack
{"title":"Show-and-Tell or Hide-and-Seek? Examining Organizational Cybersecurity Incident Notifications","authors":"W. Cram, Rissaile Mouajou-Kenfack","doi":"10.24251/hicss.2022.825","DOIUrl":null,"url":null,"abstract":"PurposeThe growing frequency of cybersecurity incidents commonly requires organizations to notify customers of ongoing events. However, the content contained within these notifications varies widely, including differences in the level of detail, apportioning of blame, compensation and corrective action. This study seeks to identify patterns contained within cybersecurity incident notifications by constructing a typology of organizational responses.Design/methodology/approachBased on a detailed review of 1,073 global cybersecurity incidents occurring during 2020, the authors obtained and qualitatively analyzed 451 customer notifications.FindingsThe results reveal three distinct organizational response types associated with the level of detail contained within the notification (full transparency, guarded and opacity), as well as three response types associated with the benefitting party (customer interest, balanced interest and company interest).Originality/valueThis work extends past classifications of cybersecurity incident notifications and provides a template of possible notification approaches that could be adopted by organizations.","PeriodicalId":74512,"journal":{"name":"Proceedings of the ... Annual Hawaii International Conference on System Sciences. Annual Hawaii International Conference on System Sciences","volume":"114 1","pages":"1-10"},"PeriodicalIF":0.0000,"publicationDate":"2022-12-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the ... Annual Hawaii International Conference on System Sciences. Annual Hawaii International Conference on System Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.24251/hicss.2022.825","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

PurposeThe growing frequency of cybersecurity incidents commonly requires organizations to notify customers of ongoing events. However, the content contained within these notifications varies widely, including differences in the level of detail, apportioning of blame, compensation and corrective action. This study seeks to identify patterns contained within cybersecurity incident notifications by constructing a typology of organizational responses.Design/methodology/approachBased on a detailed review of 1,073 global cybersecurity incidents occurring during 2020, the authors obtained and qualitatively analyzed 451 customer notifications.FindingsThe results reveal three distinct organizational response types associated with the level of detail contained within the notification (full transparency, guarded and opacity), as well as three response types associated with the benefitting party (customer interest, balanced interest and company interest).Originality/valueThis work extends past classifications of cybersecurity incident notifications and provides a template of possible notification approaches that could be adopted by organizations.
“告诉你”还是“捉迷藏”?检查组织网络安全事件通知
日益频繁的网络安全事件通常要求组织通知客户正在发生的事件。但是,这些通知所载的内容差别很大,包括详细程度、责任分摊、赔偿和纠正行动等方面的差异。本研究试图通过构建组织响应的类型来识别网络安全事件通知中包含的模式。基于对2020年发生的1,073起全球网络安全事件的详细审查,作者获得并定性分析了451起客户通知。结果揭示了三种不同的组织响应类型与通知中包含的详细程度相关(完全透明、谨慎和不透明),以及三种与受益方相关的响应类型(客户利益、平衡利益和公司利益)。原创性/价值本工作扩展了过去的网络安全事件通知分类,并提供了组织可以采用的可能通知方法的模板。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信