Bruno Verweijen Bruno Verweijen is onderzoeker bij het lectoraat Maatschappelijke Veiligheid van Hogeschool Saxion.
Citaties in dit artikel
Ahmad, Maijnard, Shanks
A case analysis of information systems and security incident responses
International Journal of Information Management ,6, 2015
Argyris, Schön
Organizational learning II: Theory, method and practice , 1996
Carroll, Rudolph, Hatakenaka
Learning from experience in high-hazard organizations
Research in organizational behavior , 2002
Pauw, Deprins, Spithoven
Samenwerken in de veiligheidsketen. In: R. Spithoven, M. van der Land, L. Kleijer-Kool, R.C. van Halderen, F. Vorenkamp, E. de Pauw, J. Wildenburg, B. Nissen (red.), Basisboek Integrale Veiligheid , 2022
Denzin, LincolnDenzin, Lincoln
Handbook of Qualitative Research , 2000
Doorewaard, Kil, Ven, van de
Praktijkgericht kwalitatief onderzoek. Een praktische handleiding , 2019
Cybercrisis bij gemeenten: een verkennend onderzoek naar de voorbereidingen, ervaringen en uitdagingen , 2021
Eeten, van
Blussen met nullen en enen: Cyber-rampen, cyber-exceptionalisme en de rol van de overheid
Bestuurskunde ,1, 2020
Gherardi, Nicolini
Learning in a constellation of interconnected practices: canon , 2002
He, Johnson
Challenges of information security incident learning: an industrial case study in a Chinese healthcare organization. Informatics for Health and Social Care, 42(4) , 2017
HollnagelHollnagel, Paries, Woods, Wreathall
Resilience Engineering in Practice. A Guidebook , 2011
Madsen, Desai
No firm is an island: The role of population-level actors in organizational learning from failure
Organization Science ,4, 2018
Miles, Huberman
Qualitative data analysis: An expanded sourcebook , 1994
Miner, Mezias
Ugly duckling no more: Pasts and futures of organizational learning research
Organization science ,1, 1996
Reason
Managing the risks of organizational accidents , 1997
Rothrock
Digital resilience: Is your company ready for the next cyber threat? Amacom , 2018
Sagan
The limits of safety: Organizations, accidents, and nuclear weapons , 1993
Toft, Reynolds
Learning from disasters. A management approach , 2005
Tøndel, Line, Jaatun
Information security incident management: Current practice as reported in the literature
Computers & Security , 2014
Verweijen, Lauche
How many blowouts does it take to learn the lessons? An institutional perspective , 2019
Download citeerwijze bij dit artikel
Onderwerpen
Criminologie > Criminologie algemeen
Criminologie > Veiligheid
Samenvatting
Many organisations fall victim to cyberattacks, such as ransomware attacks. Nevertheless, organisations have opportunities to bolster their cyber resilience. One way to achieve this is by learning vicariously from the experience of victims. This allows organisations to learn meaningful lessons, while not being burdened by the impact of an incident. However, vicarious learning requires victims to share lessons learned resulting from the investigation into causes and consequences of a cyber incident. Fortunately, some organisations disseminate lessons learned and recommendations through the publication of a publicly available evaluation report. Despite the potential of such sources for meaningful learning, most studies on organisational learning from cyberincidents focus on how <i>individual</i> organisations learn from their <i>own</i> experiences. As a consequence, such studies fail to identify recurring patterns of lessons learned that may generalize to other organisations. This meta-analysis addresses this issue by comparing multiple evaluation reports. The research objective is twofold: 1) to identify recurring lessons learned about causes and consequences of cyberincidents, and 2) to study from which frames of reference incidents are evaluated to understand why certain lessons are learned and others are not. The research question is: <i>which lessons are drawn in evaluation reports into the causes and consequences of cyberincidents at organisations, in order to prevent these from recurring in the future</i>. Various recurring lessons are identified and classified using an analytical framework that incorporates different risk management phases and categories of lessons learned. It is recommended to improve sharing of lessons learned within a network of trusted partners to enable broad vicarious learning and collective cyber resilience.
U heeft geen toegang tot deze publicatie Beste bezoeker, om de inhoud te raadplegen heeft u een abonnement nodig op deze publicatie of de collectie waar deze publicatie deel van uitmaakt. Neem contact op met klantenservice@boomportaal.nl voor meer informatie over de mogelijkheden en prijzen.
Kopen in de webshop Deze publicatie is ook te vinden in onze webshop. Sommige publicaties hebben ook de mogelijkheid om direct toegang te kopen tot het online boek.