vix.ing · top · new · best · stats · spec

Determining cybersecurity culture maturity and deriving verifiable improvement measures

2024/04/11 by Dornheim, Peter, Zarnekow, Ruediger
#600 Technik #Medizin #angewandte Wissenschaften::650 Management #cybersecurity awareness #cybersecurity culture #cybersecurity maturity #information security awareness #information security culture #Öffentlichkeitsarbeit::650 Management und unterstützende Tätigkeiten

paper · doi:10.14279/depositonce-20154

Abstract

Purpose: The human factor is the most important defense asset against cyberattacks. To ensure that the human factor stays strong, a cybersecurity culture must be established and cultivated in a company to guide the attitudes and behaviors of employees. Many cybersecurity culture frameworks exist; however, their practical application is difficult. This paper aims to demonstrate how an established framework can be applied to determine and improve the cybersecurity culture of a company. Design/methodology/approach: Two surveys were conducted within eight months in the internal IT department of a global software company to analyze the cybersecurity culture and the applied improvement measures. Both surveys comprised the same 23 questions to measure cybersecurity culture according to six dimensions: cybersecurity accountability, cybersecurity commitment, cybersecurity necessity and importance, cybersecurity policy effectiveness, information usage perception and management buy-in. Findings: Results demonstrate that cybersecurity culture maturity can be determined and improved if accurate measures are derived from the results of the survey. The first survey showed potential for improving the dimensions of cybersecurity accountability, cybersecurity commitment and cybersecurity policy effectiveness, while the second survey proved that these dimensions have been improved. Originality/value: This paper proves that practical application of cybersecurity culture frameworks is possible if they are appropriately tailored to a given organization. In this regard, scientific research and practical application combine to offer real value to researchers and cybersecurity executives.

Related