2022
DOI: 10.3390/systems10020049
|View full text |Cite
|
Sign up to set email alerts
|

Decision-Makers’ Understanding of Cyber-Security’s Systemic and Dynamic Complexity: Insights from a Board Game for Bank Managers

Abstract: Cyber-security incidents show how difficult it is to make optimal strategic decisions in such a complex environment. Given that it is hard for researchers to observe organisations’ decision-making processes driving cyber-security strategy, we developed a board game that mimics this real-life environment and shows the challenges of decision-making. We observed cyber-security experts participating in the game. The results showed that decision-makers who performed poorly tended to employ heuristics, leading to fa… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
5
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(5 citation statements)
references
References 45 publications
0
5
0
Order By: Relevance
“…They are static and thus do not account for the dynamic nature of cyber risk (Falco et al, 2019;Homeland Security 2018). The dynamic nature of cyber risk can be recognized in, for instance, evolving adversary tactics and skills, shifting organizational priorities, emerging security events, changing budgets, and new technology (Zeijlemaker, 2022). The complex dynamic nature of cyber risks cannot be covered by traditional risk management approaches (Lambert et al, 2013;Linkov et al, 2014).…”
Section: Cyber Risk and Decision-makingmentioning
confidence: 99%
See 4 more Smart Citations
“…They are static and thus do not account for the dynamic nature of cyber risk (Falco et al, 2019;Homeland Security 2018). The dynamic nature of cyber risk can be recognized in, for instance, evolving adversary tactics and skills, shifting organizational priorities, emerging security events, changing budgets, and new technology (Zeijlemaker, 2022). The complex dynamic nature of cyber risks cannot be covered by traditional risk management approaches (Lambert et al, 2013;Linkov et al, 2014).…”
Section: Cyber Risk and Decision-makingmentioning
confidence: 99%
“…The purpose of this is to explore how simulation techniques can augment the static approaches for cyber risk management decisionmaking. System Dynamics has rarely been used in the field of cyber risk (Jalili, 2019;Zeijlemaker, 2022).…”
Section: Cyber Risk and Decision-makingmentioning
confidence: 99%
See 3 more Smart Citations