This paper critically examines the role of human factors in organiza- tional cybersecurity through a bibliometrics approach supported by qualitative analyses. In an evolving digital landscape, cyber threats have outpaced the ca- pacity of organizations to secure their operations, with economic and psycholog- ical implications escalating. While technology-based defenses are essential, the paper posits that cybersecurity strategy should also account for human behaviors and vulnerabilities. The results highlight individuals' critical role as potential weak links or safeguards within the digital realm. Bibliometric analysis con- ducted on a pool of 200 papers extracted from Web of Science (WoS) database. Findings consolidate the idea of cybersecurity as a sociotechnical domain and underscore the need for a comprehensive cybersecurity strategy, transcending purely technological defenses, to incorporate aspects of human behavior, emo- tions, and organizational culture. This work also stresses the efficacy of strategies such as deterrence, fear appeal, continuous education, and sector-specific policies in improving Information Security Policy (ISP) compliance. The paper concludes by suggesting some potential future research to bolster both theory and practice.

The Interplay of Human Factors and Cybersecurity: An Organizational Outlook

Bernardi, Paolo;Cecere, Raffaele;
2023

Abstract

This paper critically examines the role of human factors in organiza- tional cybersecurity through a bibliometrics approach supported by qualitative analyses. In an evolving digital landscape, cyber threats have outpaced the ca- pacity of organizations to secure their operations, with economic and psycholog- ical implications escalating. While technology-based defenses are essential, the paper posits that cybersecurity strategy should also account for human behaviors and vulnerabilities. The results highlight individuals' critical role as potential weak links or safeguards within the digital realm. Bibliometric analysis con- ducted on a pool of 200 papers extracted from Web of Science (WoS) database. Findings consolidate the idea of cybersecurity as a sociotechnical domain and underscore the need for a comprehensive cybersecurity strategy, transcending purely technological defenses, to incorporate aspects of human behavior, emo- tions, and organizational culture. This work also stresses the efficacy of strategies such as deterrence, fear appeal, continuous education, and sector-specific policies in improving Information Security Policy (ISP) compliance. The paper concludes by suggesting some potential future research to bolster both theory and practice.
2023
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR - Sede Secondaria Napoli
organizational cybersecurity, information system security, organizational behavior, human factor.
File in questo prodotto:
File Dimensione Formato  
The Interplay of Human Factors and Cybersecurity_ An Organization.pdf

accesso aperto

Licenza: Dominio pubblico
Dimensione 865.86 kB
Formato Adobe PDF
865.86 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/536758
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact