Note: When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher.
Some full text articles may not yet be available without a charge during the embargo (administrative interval).
What is a DOI Number?
Some links on this page may take you to non-federal websites. Their policies may differ from this site.
-
PurposeUnderstanding the type of information security culture (ISC) present in organizations is important because it guides how employees navigate the use of technology and information resources. This study aims to develop and evaluate a situational judgment test (SJT) designed to measure the underlying assumptions level of ISC through employee security tendencies. The goal is to determine if this approach could provide an engaging format and useful information on different types of cultures. Design/methodology/approachA novel ISC-SJT was developed to simultaneously measure cultural alignment and security behavior tendencies as a reflection of ISC. The 24-item ISC-SJT was administered to 330 employees across five US industries: technology, government/military, manufacturing/heavy, health care and education. Analysis included correlations, analysis of variance and post-hoc comparisons. Additional questions assessed participant perspectives on the format and realism of the items. FindingsResults revealed that specific cultural orientations – means-oriented, internally driven, strict work discipline, open system and employee-oriented – are associated with more desirable security behavior tendencies. Significant US industry-level differences were also identified, with education showing an easygoing work discipline culture and the lowest overall security scores. The ISC-SJT was found to be both realistic and engaging, offering contextually grounded insights. Originality/valueThis research utilized a novel methodology and perspective to assess the underlying assumptions level of organizational ISC. It focused on evaluating the type of culture, rather than influencing factors of culture, through the lens of Hofstede’s organizational culture dimensions and security behavior tendencies. The study investigated cultural differences between five US industries and explored differences between cultural orientations.more » « lessFree, publicly-accessible full text available June 5, 2027
-
PurposeAll US defense contractors were required to have fully implemented the 110 security requirements included in NIST Special Publication 800-171 entitled “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” by 1 January 2018 whenever a system owned or operated by or for a contractor processes, stores or transmits controlled unclassified information. Despite the mandate, adoption has been minimal, mostly because the requirement is so costly and time consuming that medium and small firms cannot afford to comply. Because the adoption of security precautions is costly and time consuming, the purpose of this paper is to propose a constrained optimization methodology to examine this issue. Design/methodology/approachIn this paper, the authors introduce a method to significantly reduce the number of required precautions by soliciting expert opinion as to the perceived benefits and costs of all precautions. The authors defined the difference between benefits and costs as value. FindingsIn the key constrained optimization exercise conducted, the authors show that including only the top 50 security precautions (out of the 110 security precautions) led to just a very small decline in value. Originality/valueThis paper makes an important contribution to information security research. To the best of the authors’ knowledge, no one has conducted similar analysis on the 110 proposed precautions.more » « lessFree, publicly-accessible full text available September 22, 2026
-
We study how firms adjust their cybersecurity postures after experiencing a cyber attack. We combine publicly disclosed ransomware cyber incidents with detailed data on security products and vendor deployments from the Spiceworks Ziff Davis (SWZD) Company Intelligence Database (CIDB) over multiple years. Our empirical approach compares attacked firms to similar non-attacked firms using econometrics and employing a difference-in-difference (DID) framework. Controlling for common changes made by all firms over time, we find that “attacked” firms increased the breadth of their security posture relative to non-attacked firms. They adopted more National Institute of Standards and Technology (NIST) functions and had broader “category coverage” than non-attacked firms in the “post attack” period. Attacked firms also increased the usage of security products from large and “platform” vendors relative to non-attacked firms in the “post attack” period.more » « lessFree, publicly-accessible full text available June 2, 2027
-
Free, publicly-accessible full text available December 1, 2026
-
Multifactor authentication (MFA) is one of the most important security controls, topping most lists of cyber hygiene activities advocated by experts. While the security benefits may be substantial, less attention has been paid to the impact on users by the added friction introduced by the more stringent precautions. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on opportunity costs experienced by users: (1) log-in failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a deny/approve mobile notification to a more cumbersome two-digit code mobile notification confirmation, we show that there are significant increases in the number of log-in failures and in time spent away following failures when using mobile MFA. We also briefly examine which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.more » « less
-
Cybersecurity risk presents a significant and growing challenge for firms. Understanding better how firms are defending themselves can help answer important questions about which controls are more effective and whether firms are investing enough in their defenses. Unfortunately, data on firm-level cybersecurity investments have been difficult for researchers to obtain at large scale. This paper describes a method for constructing firm-level cybersecurity posture metrics by aggregating a selection of data on security products tracked in the SWZD Company Information database. Our exploratory analysis demonstrates this dataset's value in enriching cybersecurity research, offering novel perspectives that could shape sector-specific best practices and enable empirical evaluation of security controls.more » « less
An official website of the United States government

Full Text Available