Insights into Organizational Security Readiness: Lessons Learned from Cyber-Attack Case Studies

dc.contributor.authorQuader, Faisal
dc.contributor.authorJaneja, Vandana
dc.date.accessioned2022-01-06T18:09:14Z
dc.date.available2022-01-06T18:09:14Z
dc.date.issued2021-11-11
dc.description.abstractThis paper focuses on understanding the characteristics of multiple types of cyber-attacks through a comprehensive evaluation of case studies of real-world cyber-attacks. For each type of attack, we identify and link the attack type to the characteristics of that attack and the factors leading up to the attack, as observed from the review of case studies for that type of attack. We explored both the quantitative and qualitative characteristics for the types of attacks, including the type of industry, the financial intensity of the attack, non-financial intensity impacts, the number of impacted customers, and the impact on users’ trust and loyalty. In addition, we investigated the key factors leading up to an attack, including the human behavioral aspects; the organizational–cultural factors at play; the security policies adapted; the technology adoption and investment by the business; the training and awareness of all stakeholders, including users, customers and employees; and the investments in cybersecurity. In our study, we also analyzed how these factors are related to each other by evaluating the co-occurrence and linkage of factors to form graphs of connected frequent rules seen across the case studies. This study aims to help organizations take a proactive approach to the study of relevant cyber threats and aims to educate organizations to become more knowledgeable through lessons learned from other organizations experiencing cyber-attacks. Our findings indicate that the human behavioral aspects leading up to attacks are the weakest link in the successful prevention of cyber threats. We focus on human factors and discuss mitigation strategies.en_US
dc.description.urihttps://www.mdpi.com/2624-800X/1/4/32en_US
dc.format.extent22 pagesen_US
dc.genrejournal articlesen_US
dc.identifierdoi:10.13016/m2m5zz-lrkz
dc.identifier.citationQuader, F.; Janeja, V.P. Insights into Organizational Security Readiness: Lessons Learned from Cyber-Attack Case Studies. J. Cybersecur. Priv. 2021, 1, 638–659. https://doi.org/10.3390/jcp1040032en_US
dc.identifier.urihttps://doi.org/10.3390/jcp1040032
dc.identifier.urihttp://hdl.handle.net/11603/23869
dc.language.isoen_USen_US
dc.publisherMDPIen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.en_US
dc.rightsAttribution 4.0 International (CC BY 4.0)*
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/*
dc.titleInsights into Organizational Security Readiness: Lessons Learned from Cyber-Attack Case Studiesen_US
dc.typeTexten_US
dcterms.creatorhttps://orcid.org/0000-0003-0130-6135en_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
jcp-01-00032-v3 (4).pdf
Size:
3.18 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: