Executive decision-makers

a scenario-based approach to assessing organizational cyber-risk perception

Journal Article (2023)
Author(s)

S.E. Parkin (TU Delft - Organisation & Governance)

Kristen Kuhn (Coventry University)

Siraj A. Shaikh (Swansea University, Universidad Nebrija)

Research Group
Organisation & Governance
Copyright
© 2023 S.E. Parkin, Kristen Kuhn, Siraj A. Shaikh
DOI related publication
https://doi.org/10.1093/cybsec/tyad018
More Info
expand_more
Publication Year
2023
Language
English
Copyright
© 2023 S.E. Parkin, Kristen Kuhn, Siraj A. Shaikh
Research Group
Organisation & Governance
Issue number
1
Volume number
9
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

The executive leadership in corporate organizations is increasingly challenged with managing cyber-risks, as an important part of wider business risk management. Cyber-risks are complex, with the threat landscape evolving, including digital infrastructure issues such as trust in networked supply chains, and emerging technologies. Moreover, engaging organizational leadership to assess for risk management is also difficult. This paper reports on a scenario-driven, workshop-based study undertaken with executive leadership to assess for cybersecurity and cyber-risk perception related to preparation for, and response to, potential incidents. The study involves leadership members at a large public-private organization. Our approach utilizes scenarios, which are structured in their design to explore and analyse aspects of business risk, risk ownership, technological complexity, and uncertainty faced by an organizational leadership. The method offers a means to engage with leadership at real-world organizations, capturing capacity and insights to manage business risks due to cyberattacks.