Evaluating incident reporting in cybersecurity. From threat detection to policy learning

被引:0
|
作者
Busetti, Simone [1 ]
Scanni, Francesco Maria [1 ]
机构
[1] Univ Teramo, Via R Balzarini 1, I-64100 Teramo, Italy
关键词
Cybersecurity; NIS2; Cyber incident; Incident reporting; Policy learning; Realist synthesis; LESSONS;
D O I
10.1016/j.giq.2024.102000
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
The escalating threat of cyber risks has propelled cybersecurity policy to the forefront of governmental agendas worldwide. Incident reporting, a cornerstone of cybersecurity legislation, may facilitate swift responses to cyberattacks and foster a learning process for policy enhancement. Despite its widespread adoption, there are no analyses on its efficacy, implementation, and avenues for improvement. This article provides a theory-based evaluation of incident reporting using the methods of realist synthesis and process tracing. We develop a program theory of incident reporting hypothesizing its dual role as a fire alarm and a catalyst for policy learning. The program theory is tested by drawing upon a range of literature and official documents, supplemented by insights from the Italian context through interviews with key informants. The evaluation reveals mixed findings. While incident reporting effectively serves as a fire alarm, particularly for organizations with limited cybersecurity capacity, challenges persist due to capacity gaps and a reluctance to report incidents. The link between incident reporting and policy learning remains tenuous, with evidence of inertia hindering the implementation of more radical changes. Policy recommendations include streamlining internal communications, combining rapid and in-depth reporting, fostering data-sharing agreements, ensuring dedicated communication of lessons from central cyber actors, and streamlining organizational procedures for implementing changes.
引用
收藏
页数:17
相关论文
共 47 条
  • [41] jeder-fehler-zaehlt.de: Content of and prospective benefits from a critical incident reporting and learning system (CIRS) for primary care
    Beyer, Martin
    Blazejewski, Tatjana
    Guethlin, Corina
    Klemp, Kerstin
    Wunder, Armin
    Hoffmann, Barbara
    Mueller, Hardy
    Verheyen, Frank
    Gerlach, Ferdinand M.
    ZEITSCHRIFT FUR EVIDENZ FORTBILDUNG UND QUALITAET IM GESUNDHEITSWESEN, 2015, 109 (01): : 62 - 68
  • [42] Machine Learning for Detection of Safety Signals From Spontaneous Reporting System Data: Example of Nivolumab and Docetaxel
    Bae, Ji-Hwan
    Baek, Yeon-Hee
    Lee, Jeong-Eun
    Song, Inmyung
    Lee, Jee-Hyong
    Shin, Ju-Young
    FRONTIERS IN PHARMACOLOGY, 2021, 11
  • [43] A Machine Learning Approach to Detection of Critical Alerts from Imbalanced Multi-Appliance Threat Alert Logs
    Ndichu, Samuel
    Ban, Tao
    Takahashi, Takeshi
    Inoue, Daisuke
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 2119 - 2127
  • [44] Critical incident reports concerning anaesthetic equipment: analysis of the UK National Reporting and Learning System (NRLS) data from 2006-2008
    Cassidy, C. J.
    Smith, A.
    Arnot-Smith, J.
    ANAESTHESIA, 2011, 66 (10) : 879 - 888
  • [45] A hospital incident reporting system (2016-2019): Learning from notifier's perception on incidents' risk, severity and frequency of adverse events
    de la Torre-Perez, L.
    Granes, L.
    Prat Marin, A.
    Bertran, M. J.
    JOURNAL OF HEALTHCARE QUALITY RESEARCH, 2023, 38 (02) : 93 - 104
  • [46] Can Patient Safety Incident Reports Be Used to Compare Hospital Safety? Results from a Quantitative Analysis of the English National Reporting and Learning System Data
    Howell, Ann-Marie
    Burns, Elaine M.
    Bouras, George
    Donaldson, Liam J.
    Athanasiou, Thanos
    Darzi, Ara
    PLOS ONE, 2015, 10 (12):
  • [47] Towards Evaluating Performance of Domain Specific Transfer Learning for Pneumonia Detection from X-Ray Images
    Mahajan, Sarang
    Shah, Urmil
    Tambe, Rucha
    Agrawal, Mohit
    Garware, Bhushan
    2019 IEEE 5TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2019,