Skills for overcoming a negative cybersecurity culture

TL;DR: Organizations should encourage good emotions around openness to new experiences and suggestions, creative thought expression, along with proper training within the cybersecurity domain.

During my literature review, I have discovered a great article by Reddy, D., & Dietrich, G. titled “Identifying Multiple Categories of Cybersecurity Skills that Affect User Acceptance of Protective Information Technologies.” (and some related literature). This literature reviews the psychology of security user acceptance of “Protective Information Technologies” and what role cybersecurity skills (CS) play in that acceptance. Specifically, they name three skills, both technical and non-technical: Cybersecurity Computing Skills (CCS), Cybersecurity Initiative Skills (CIS), and Cybersecurity Action Skills (CAS).

  • CCS is defined as “the knowledge, experience and ability of users to use applications like antivirus software to protect computers and information systems” (Choi et al. 2013:pg4)
  • CIS is defined as “the knowledge, experience and ability needed to seek, and take advantage of, best security practices and security software like antivirus” (Choi et al. 2013:pg5). Rank et al., (2004)
  • CAS is defined as “the ability, experience and knowledge to commit to objectives that meet security compliance” (Choi et al. 2013:pg6).

This literature review suggests that three components should be considered when working to improve acceptance of ideal cybersecurity related acceptance.

1) Appropriateness of cyber related skills improvement for staff to effectively leverage cyber innovation and functions.

2) There are three required psychological processes to reach a desired outcome: initiative, creativity, and innovation. (Rank et al., 2004). Taken from the study: “In cybersecurity context, we posit CIS will self-motivate a computer user to proactively use and extract the benefits of PIT irrespective of obstacles created by lack of technical skills. CIS motivates a computer user to proactively make the right decisions and seek solutions to cyber threats.”.

3) Users should be oriented toward achieving specific results for specific threats. Additional research is needed to test these posits, but the review suggests that for organizations to achieve success with security program implementation, leadership should support environments that encourage acquiring cybersecurity knowledge and skills, encourage initiative, creativity, and innovation from security staff, and encourage improving specific objective orientations.

When faced with organizations with a negative cybersecurity culture, there is likely a breakdown of the second, Cybersecurity Initiative Skills (CIS). Organizational leadership should work to develop and implement practices which encourage staff members to improve initiative, creativity, and innovation. Here is an excellent quote Chapter 4 from a book titled “Psychology of Innovation: Innovating Human Psychology?” 

“Innovation is conceived as a means of changing an organization, either as a response to changes in the external environment or as a pre-emptive action to influence the environment. Hence, innovation is here broadly defined to encompass a range of types, including new product or services, new process technology, new organization structure or administrative systems, or new plans or programmes to organization members’ (Damanpour 1996, p. 1326 cited in Baregheh et al. 2009). It also refers to successful exploitation of new ideas (UK Department of Trade and Industry 1998 in Adams et al. 2006). Apart from good emotions being a facilitator for generation of good ideas (Simonton 1977), a culturally creative outside environment being a facilitator of production of creative thoughts (Simonton 2000), a risk-taking attitude and having the right training and expertise are all crucial for someone to be creative (Simon 1986).”

The last lines are the most applicable. Organizations should encourage good emotions around openness to new experiences and suggestions, creative thought expression, along with proper training within the cybersecurity domain. This could center on following the ‘okay-to-fail’ mentality. This can include encouraging open brainstorming sessions, facilitate anonymous suggestions (similar to an idea box), and leadership’s willingness to act on good ideas.

References:

Adams R, Bessant J, Phelps R (2006) Innovation management measurement: a review. Int J Manag Rev 8(1):21–47. doi:10.1111/j.1468-2370.2006.00119.x

Baregheh A, Rowley J, Sambrook S (2009) Towards a multidisciplinary definition of innovation. Manag Decis 47(8):1323–1339. doi:10.1108/00251740910984578

Choi, M. S., Levy, Y., & Hovav, A. (2013, December). The Role of User Computer Self-Efficacy, Cybersecurity Countermeasures Awareness, and CS Influence on Computer Misuse. In Proceedings of the pre-ICIS workshop on information security and privacy (WISP2013), Milan, Italy.

Rank, J., Pace, V. L., & Frese, M. (2004). Three avenues for future research on creativity, innovation, and initiative. Applied Psychology, 53(4), 518-528.

Reddy, D., & Dietrich, G. (2016). Identifying Multiple Categories of Cybersecurity Skills that Affect User Acceptance of Protective Information Technologies. AMCIS

Simon H (1986) How managers express their creativity. Across Board 23(3):11–17

Simonton DK (1977) Cross-sectional time-series experiments: some suggested statistical analyses. Psychol Bull 84(3):489–502. doi:10.1037//0033-2909.84.3.489

Related Post

Leave a Reply

Discover more from kobaltfox Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading