skip to main content
US FlagAn official website of the United States government
dot gov icon
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
https lock icon
Secure .gov websites use HTTPS
A lock ( lock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


Title: Cybersecurity Training in Organization as Human Capital Investment: A Qualitative Grounded Theory Analysis
This study aims to examine the impacts of organization’s cybersecurity training program on employees with qualitative data, collected from 33 college students who were attending Norfolk State University while also working either on a part-time or full-time basis participated. Open-ended questions were asked to elicit participants’ perspectives on cybersecurity training and cybersecurity protocols in organizations. Using qualitative data analysis software Nvivo 12, the authors organized and analyzed the collected data with open coding, and selective coding to recognize the major influencing impacts from cybersecurity training on employees’ routine work and behavior. Inductive and grounded theory analysis further elaborates connections between employee’s cybersecurity training and efficiency of organizations. Our findings suggest that on-the-job cybersecurity training provided by the employer is an effective investment for modern organizations to build on the organizational human capital and consequently to improve the efficiency of the organization. Findings from this study corroborates with the tenet of human capital theory that on-the-job educational program or training is economical and effective to manage the human capital challenge for modern organizations.  more » « less
Award ID(s):
1956428
PAR ID:
10428972
Author(s) / Creator(s):
; ;
Date Published:
Journal Name:
International Journal of Business and Management
Volume:
18
Issue:
4
ISSN:
1833-3850
Page Range / eLocation ID:
38
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. null (Ed.)
    This research project examines the relationship between teleworking cybersecurity protocols during the COVID-19 era and employee’s perception of their efficiency and performance predictability.  COVID-19 is the infectious disease caused by the most recently discovered coronavirus and it has been declared a pandemic by the World Health Organization. Since March 2020, many employees in the United States who used operate onsite, have been working from their homes (teleworking) to mitigate the spread of the virus through social distancing. The premise of this research project is that teleworking can transform these employees into unintentional insider threats or UITs. Iinterviews were conducted through video conferencing with nine employees in Virginia, USA to examine the problem. This is an interdisciplinary research project which brings together the disciplines of sociology and computer science. Narrative Analysis was used to unpack the interviews. The major findings from the research efforts demonstrate that employees are trusting of the cybersecurity protocols that their organizations implemented but they also believe they are vulnerable, and that the protocols are not as reliable as in-person working arrangements. While the respondents perceived that the cybersecurity protocols lend to performance predictability, they seem to think it disrupts their efficiency. 
    more » « less
  2. Cybersecurity is a concern for organizations in this era. However, strengthening the security of an organization’s internal network may not be sufficient since modern organizations depend on third parties, and these dependencies may open new attack paths to cybercriminals. Cyber Third-Party Risk Management (C-TPRM) is a relatively new concept in the business world. All vendors or partners possess a potential security vulnerability and threat. Even if an organization has the best cybersecurity practice, its data, customers, and reputation may be at risk because of a third party. Organizations seek effective and efficient methods to assess their partners’ cybersecurity risks. In addition to intrusive methods to assess an organization’s cybersecurity risks, such as penetration testing, non-intrusive methods are emerging to conduct C-TPRM more easily by synthesizing the publicly available information without requiring any involvement of the subject organization. In this study, the existing methods for C-TPRM built by different companies are presented and compared to discover the commonly used indicators and criteria for the assessments. Additionally, the results of different methods assessing the cybersecurity risks of a specific organization were compared to examine reliability and consistency. The results showed that even if there is a similarity among the results, the provided security scores do not entirely converge. 
    more » « less
  3. Time spent on the job is a fundamental aspect of working conditions that influences many facets of individuals’ lives. Here we study how an organization-wide 4-day workweek intervention—with no reduction in pay—affects workers’ well-being. Organizations undergo pre-trial work reorganization to improve efficiency and collaboration, followed by a 6-month trial. Analysis of pre- and post-trial data from 2,896 employees across 141 organizations in Australia, Canada, Ireland, New Zealand, the UK and the USA shows improvements in burnout, job satisfaction, mental health and physical health—a pattern not observed in 12 control companies. Both company-level and individual-level reductions in hours are correlated with well-being gains, with larger individual-level (but not company-level) reductions associated with greater improvements in well-being. Three key factors mediate the relationship: improved self-reported work ability, reduced sleep problems and decreased fatigue. The results indicate that income-preserving 4-day workweeks are an effective organizational intervention for enhancing workers’ well-being. 
    more » « less
  4. We discuss the NICE Cybersecurity Workforce Framework (NCWF), and its role in aligning cybersecurity jobs with candidates. As a workforce development tool, the NCWF can contribute to better retention, reduced new hire training, and cybersecurity education development. The effectiveness of the NCWF, however, requires discretion from hiring managers, academics, and job seekers. Through skills mapping and calibration, the NCWF helps to identify and resolve skill deficiencies; as a framework of core competencies for cybersecurity jobs, the NCWF helps employers to write job descriptions understood by applicants. We first review the NCWF, and then explain how it may enable mapping between jobs and qualifications. We also discuss the effects of job mapping on organizations and candidates, and its long-term benefits. 
    more » « less
  5. In the current paper, we attempt to contribute to a more comprehensive understanding of science, technology and innovation (STI) outputs and outcomes through the application of a Scientific and Technical Human Capital (STHC) evaluation framework. We do this by describing a study that focuses on a type of STI initiative that appears ripe with potential to affect STHC impacts—Industry–University Cooperative Research Centers (IUCRCs). In doing so we summarize relevant theory related to the STHC framework and social capital formation more generally. We also define IUCRCs and highlight the program mechanisms that appear likely to impact the STHC outcomes. Finally, we narrow our focus to a relatively neglected research target of the STI evaluation—science and engineering (S&E) doctoral students. We compare social capital and other students’ outcomes by employing a rare quasi-experimental design with two training modalities: IUCRC and more traditional, non-center training. We show that our results demonstrate strong evidence for positive effects of IUCRC training on graduate S&E students’ outcomes. We also explain significant moderating effect of citizenship status on some of our results where international students, who account for 50% of this population, do not receive the same social capital outcomes as students with US citizenship or permanent resident status. In addition, we describe patterns in international students’ intentions to stay in the US and how they are affected by students’ training modality. Finally, we discuss the results and implications in the context of graduate training, STHC evaluation framework and STI and immigration policy. 
    more » « less