Journal article icon

Journal article

Risk and the small-scale cyber security decision making dialogue — a UK case study

Abstract:
Despite a long-standing understanding that developments in personal and cloud computing practices would change the way we approach security, small-scale IT users (SSITUs) remain ill-served by existing cyber security practices. This paper discusses results from a survey that considered (in part) cyber security decisions made by SSITUs. We determine that: SSITUs are focusing on easy-to-implement technical measures, leading to a disconnect between the security implemented and any risks identified; available resources, knowledge, prioritisation of business processes, reduced system control and a lack of threat intelligence all combine to limit the ability to make cyber security decisions; and assessing risk in SSITUs will not lead to sufficient investment to mitigate risks for risk-holding stakeholders in the supply chain. We conclude that the constraints faced by SSITUs have far greater impact on the decisions they make than either our risk-holding, or security- providing, participants may have anticipated. Any limitations faced by SSITUs as they make their security decisions will have a significant impact on both the measures they are able to apply and the security of the supply chain as a whole.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Files:
Publisher copy:
10.1093/comjnl/bxx093

Authors


More by this author
Institution:
University of Oxford
Oxford college:
St Catherine's College
Role:
Author
More by this author
Institution:
University of Oxford
Division:
Societies, Other & Subsidiary Companies
Department:
Kellogg College
Oxford college:
Kellogg College
Role:
Author


Publisher:
Oxford University Press
Journal:
Computer Journal More from this journal
Volume:
61
Issue:
4
Pages:
472–495
Publication date:
2017-09-28
Acceptance date:
2017-07-27
DOI:
EISSN:
1460-2067
ISSN:
0010-4620


Keywords:
Pubs id:
pubs:722829
UUID:
uuid:b0c15e13-0dd3-42a4-9c16-9940e03858dc
Local pid:
pubs:722829
Source identifiers:
722829
Deposit date:
2017-08-21

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP