Effective Communication of Cyber Security Risks

Jason R. C. Nurse · Kent Academic Repository (University of Kent) · 2013

By now, it should be well-known that technology alone cannot solve the security problem. A central component to achieving security in organisations, businesses and home environments is supporting user awareness of security and designing security functionality that is highly usable. In this paper, we concentrate on this problem with special emphasis on the increasingly important issue of how to effectively communicate cybersecurity risks. This focus is motivated by the prevalence and success of online attacks, the large amount of people online nowadays (some aware of security risks, but a majority, complete novices), and the wide spectrum of activities that users engage in online, that is, everything from banking to social media (each with its own security risks). Specifically, this work reflects on our recent research on addressing this concern through focus on the fields of Information Trust, Risk Communication and Security Usability. The outcome of that reflection has been the definition of some key recommendations for trustworthy and effective communication of cybersecurity risks that can be applied across a variety of security contexts (e.g., online interfaces, security tools and security operation centres). We present a subset of these in this paper, with special note to some of the most important ones for system designers. The next step of our work is to critically evaluate these recommendations and refine them where possible, towards creating the most useful security communication practices. We believe that once adopted, these practices will have a significant positive affect on the decisions that user and individuals make regarding security risks online.

Read the paper · More papers on PaperTik