Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Human Factor In Organisational Cyber Resilience
Articles

The Human Factor In Organisational Cyber Resilience

ISBuzz TeamBy ISBuzz TeamNovember 15, 2019Updated:July 15, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
MetaMask Alerts Crypto Users About Address Poisoning Scam
MetaMask Alerts Crypto Users About Address Poisoning Scam
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The academic and industry literature is full of extremely useful research, insights and advice on how people interface with security technology and how that interaction can be enhanced to reduce the chance of a malicious attack. However, the role of the human in enhancing the overall resilience of an organisation operating within an environment where the cyber risks of any type are high is discussed much less. 

Clearly, stopping the risk at source with technological measures such as security to prevent anything malicious penetrating the organisations IT systems and fool-proof systems that work first time every time is the ideal. But no security is 100 percent effective, threats frequently emanate from within an organisation and, whilst malicious attacks dominate the news, other, more mundane, IT issues such as hardware failures, network outages and user error are far more common and often cause a similar disruptive impact on an organisation. 

An organisation therefore needs to be able to function despite glitches, attacks, accidents and disasters with its IT systems. A well designed and maintained Business Continuity and Disaster Recovery capability will interface with security measures to ensure that the organisation “survives” such disruption by enabling operations to continue to produce critical products and services at a predefined level and return to business as usual as fast as possible. But other skills, capabilities and behaviours are required for the organisation as a whole to “thrive” despite cyber risk. 

This paper looks at two of the most common human behavioural mistakes and suggest ways to overcome them.

Underestimating the enemy

Any corporate strategist or military general will tell you that the fasted way to lose a battle is by failing to understand, and match, what you are up against. Whilst, script kiddies who are trying to impress their social circles can still wreak havoc, the main malicious threats to business are now skilled business people whose general aim is to profit from exploitative attacks.

As opposed to armies fighting over territory or corporate giants fighting over market share, the new battleground is “information” where professional cyber criminals battle to gain information that has the potential to earn them substantial profits.  

Although, it has long been known that there exists a certain level of organisation with cyber criminality, recent actor profiling on the dark web has shown that a clear value chain exists for exploitative attacks such as ransomware. The actors within the cybercrime economy generally fulfil roles that are similar to those in a conventional organisational value chain. For example a typical “cyber organisation” will include: Vulnerability Researchers who search for zero-day vulnerabilities and sell the information to Malware Authors who can write exploit code; Malware Vendors and Distributors who buy and sell ransomware in marketplaces; Website Crackers and Designers who recreate websites that look authentic to the user and could act as a trap; and Money Mules who steal identities from individuals and sets up intermediary bank accounts that they offer to vendors to stores ransom funds.

These “cyber organisations” operate in much the same way as a conventional organisation looking at markets and deciding their attack strategy based on costs as well as their strengths, e.g. the encryption algorithm employed, their reputation, partnership opportunities etc., and the potential targets weaknesses that are meticulously researched and tested. 

The average boardroom is supremely occupied with identifying, analysing and creating corporate strategies to stave off legitimate competition. However, most organisations seem to have a blind spot when it comes to “illegal” competition and attempt to enter the information battleground not with a fully resourced and trained army but with a couple of foot soldiers armed with bayonets.

The cyber economy has reached the scale and sophistication that it is dangerous not to analyse the illegal cyber organisations that are competing for your information in the same way as you would a new market entrant. Likewise, it is no longer effective to pursue a defence only strategy that focuses on an insular understanding of your organisation but now necessary to be prepared to create opportunities to defeat them through strategy.

Misjudging the effect of gossip

It is an extremely rare news day when some organisation or another is not publicly exposed for losing personal data. Most executives will emit a sigh of relief that it is not them. Some will immediately take action to find out if their organisation is also at risk and rush through security measures. Others will bury their heads in the sand confident that it will never happen to them. But a small proportion will seek to capitalise on their competitor’s misfortune.  

This may seem harsh, but business is business, and if a customer is unable to find what they need from their normal source there is nothing inherently wrong with positioning yourself favourably for when the customer looks elsewhere. 

The problem, however, that a data loss obeys “Gossip Theory” which means that not only is it not possible to capitalise on your competitor’s misfortune the whole industry, including you, is very likely to be disadvantaged financially.

Gossip is defined as “the unsanctioned transmissions of personal information about a vulnerable third party” – which is exactly what happens when an organisation that you trusted suffers a data breach and your personal data, name address, bank account details and passwords etc., are released without your knowledge or control to a malicious third party.

The typical reactions to learning that you are being gossiped about are feelings of betrayal and violation accompanied by loss of trust in “all” the holders of your personal information – not just the one that gossiped. It is also typical to vocalise these feelings leading to others to also start to distrust the type of people who hold such information.

In the case of a data breach, such word of mouth effects can be extremely damaging to the bottom line but are relatively easy to counteract with data policies that emphasise transparency and control. For example, Martin, Borah & Palmatier, calculated that if Citigroup had had such a privacy policy in place at the time of their recent data breaches their losses could have been reduced dramatically. 

In summary

Organisations have got quite good at “surviving” operational disruptions by employing business continuity and disaster recovery capabilities. Likewise, they have become fairly proficient at preventing the likelihood of cyber-attacks with security measures. However, information is now arguably the new corporate battleground and competitors, who are often are illegal, are upping their game. The impact of a successful cyber-attack is now very rarely simply an operational disruption but a full-blown strategic shockwave impacting not simply the organisation in question but the whole industry that surrounds it. However, there are some simple behavioural changes that an organisation can take right now that will minimise both the impact and likelihood of an attack.   

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}