2022
DOI: 10.1007/978-3-030-95484-0_20
|View full text |Cite
|
Sign up to set email alerts
|

Why IT Security Needs Therapy

Abstract: Over the past decade, researchers investigating IT security from a socio-technical perspective have identified the importance of trust and collaboration between different stakeholders in an organisation as the basis for successful defence. Yet, when employees do not follow security rules, many security practitioners attribute this to them being “weak” or “careless”; many employees in turn hide current practices or planned development because they see security as “killjoys” who “come and kill our baby”. Negativ… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
2
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
3
1

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(4 citation statements)
references
References 35 publications
0
2
0
Order By: Relevance
“…Fostering a healthy relationship between privacy experts and developers. Different parties with different backgrounds perceive each other in a blocking manner has also been found in security research (e.g., [9,13,35,91]), such as end users seeing security experts and the measures they deploy within their company as a hindrance, resulting in a dysfunctional relationship between the two groups [51]. This may limit the interaction of the groups, hindering the establishment of a Personal Common Ground.…”
Section: Recommendations For Academiamentioning
confidence: 96%
“…Fostering a healthy relationship between privacy experts and developers. Different parties with different backgrounds perceive each other in a blocking manner has also been found in security research (e.g., [9,13,35,91]), such as end users seeing security experts and the measures they deploy within their company as a hindrance, resulting in a dysfunctional relationship between the two groups [51]. This may limit the interaction of the groups, hindering the establishment of a Personal Common Ground.…”
Section: Recommendations For Academiamentioning
confidence: 96%
“…These information security breaches are caused by insiders and outsiders (Ncubukezi, 2022). Insider information threats are often caused by employee ignorance, poor decision making, lack of skills, poorly enforced security strategies, understaffing, poor security guidelines, and a technological knowledge gap (Kluge, Sasse & Verret, 2022;Singh & Singh, 2022).…”
Section: Impact Of Information Threatsmentioning
confidence: 99%
“…The Verizon 2022 Data Breach Investigations Report emphasizes that 82 percent of the breaches that occurred were made possible by the decisions and/or active unconscious behavior of humans, involving phishing, the theft of credentials, misuse, and error [4]. However, Menges et al [5] point out that using negative language and blaming employees are indicators of dysfunctional relationships. Information security awareness (ISA) among employees is important but should not be seen as a panacea [5].…”
Section: Introductionmentioning
confidence: 99%
“…However, Menges et al [5] point out that using negative language and blaming employees are indicators of dysfunctional relationships. Information security awareness (ISA) among employees is important but should not be seen as a panacea [5]. It cannot resolve organizational and technical deficiencies, implement security protocols that go beyond staff capabilities, or manage conflicts with the productivity goals that companies expect of their employees.…”
Section: Introductionmentioning
confidence: 99%