Evaluating incident reporting in cybersecurity. From threat detection to policy learning

被引:0
|
作者
Busetti, Simone [1 ]
Scanni, Francesco Maria [1 ]
机构
[1] Univ Teramo, Via R Balzarini 1, I-64100 Teramo, Italy
关键词
Cybersecurity; NIS2; Cyber incident; Incident reporting; Policy learning; Realist synthesis; LESSONS;
D O I
10.1016/j.giq.2024.102000
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
The escalating threat of cyber risks has propelled cybersecurity policy to the forefront of governmental agendas worldwide. Incident reporting, a cornerstone of cybersecurity legislation, may facilitate swift responses to cyberattacks and foster a learning process for policy enhancement. Despite its widespread adoption, there are no analyses on its efficacy, implementation, and avenues for improvement. This article provides a theory-based evaluation of incident reporting using the methods of realist synthesis and process tracing. We develop a program theory of incident reporting hypothesizing its dual role as a fire alarm and a catalyst for policy learning. The program theory is tested by drawing upon a range of literature and official documents, supplemented by insights from the Italian context through interviews with key informants. The evaluation reveals mixed findings. While incident reporting effectively serves as a fire alarm, particularly for organizations with limited cybersecurity capacity, challenges persist due to capacity gaps and a reluctance to report incidents. The link between incident reporting and policy learning remains tenuous, with evidence of inertia hindering the implementation of more radical changes. Policy recommendations include streamlining internal communications, combining rapid and in-depth reporting, fostering data-sharing agreements, ensuring dedicated communication of lessons from central cyber actors, and streamlining organizational procedures for implementing changes.
引用
收藏
页数:17
相关论文
共 47 条
  • [1] Incident Notification in Italian Cybersecurity. An Analysis of Effectiveness and Post-attack Learning
    Busetti, Simone
    Scanni, Francesco Maria
    RIVISTA ITALIANA DI POLITICHE PUBBLICHE, 2024, (01) : 145 - 171
  • [2] An Intelligent Learning Method and System for Cybersecurity Threat Detection
    Tao, Yuan
    Hu, Wei
    Li, Moyan
    5TH ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND ARTIFICIAL INTELLIGENCE (ISAI2020), 2020, 1575
  • [3] Deep Reinforcement Learning in the Advanced Cybersecurity Threat Detection and Protection
    Mohit Sewak
    Sanjay K. Sahay
    Hemant Rathore
    Information Systems Frontiers, 2023, 25 : 589 - 611
  • [4] Deep Reinforcement Learning in the Advanced Cybersecurity Threat Detection and Protection
    Sewak, Mohit
    Sahay, Sanjay K.
    Rathore, Hemant
    INFORMATION SYSTEMS FRONTIERS, 2023, 25 (02) : 589 - 611
  • [5] Deep Reinforcement Learning for Cybersecurity Threat Detection and Protection: A Review
    Sewak, Mohit
    Sahay, Sanjay K.
    Rathore, Hemant
    SECURE KNOWLEDGE MANAGEMENT IN THE ARTIFICIAL INTELLIGENCE ERA, 2022, 1549 : 51 - 72
  • [6] A New Hybrid Machine Learning for Cybersecurity Threat Detection Based on Adaptive Boosting
    Sornsuwit, Ployphan
    Jaiyen, Saichon
    APPLIED ARTIFICIAL INTELLIGENCE, 2019, 33 (05) : 462 - 482
  • [7] Enhanced Gorilla Troops Optimizer with Deep Learning Enabled Cybersecurity Threat Detection
    Alrayes F.S.
    Alotaibi N.
    Alzahrani J.S.
    Alazwari S.
    Alhogail A.
    Al-Sharafi A.M.
    Othman M.
    Hamza M.A.
    Computer Systems Science and Engineering, 2023, 45 (03): : 3037 - 3052
  • [8] Enhancing cybersecurity incident response: AI-driven optimization for strengthened advanced persistent threat detection
    Ali, Gauhar
    Shah, Sajid
    Elaffendi, Mohammed
    RESULTS IN ENGINEERING, 2025, 25
  • [9] Automated Machine Learning Enabled Cybersecurity Threat Detection in Internet of Things Environment
    Alrowais, Fadwa
    Althahabi, Sami
    Alotaibi, Saud S.
    Mohamed, Abdullah
    Hamza, Manar Ahmed
    Marzouk, Radwa
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2023, 45 (01): : 687 - 700
  • [10] Learning from excellence in healthcare: a new approach to incident reporting
    Kelly, Nicola
    Blake, Simon
    Plunkett, Adrian
    ARCHIVES OF DISEASE IN CHILDHOOD, 2016, 101 (09) : 788 - 791