A Comprehensive Multilevel Taxonomy of Cyber Security Incident Response Performance

Stephen J. Zaccaro, Amber K. Hargrove, Tiffani R. Chen, Kristin M. Repchick, Tracy C. McCausland · 2016

Highly damaging intrusions and attacks on our cyber network have become practically daily constants. Many organizations have experienced such attacks in one form or another, including insurance, retail, entertainment, educational, and government institutions. Other organizations that are vulnerable to such attacks include those in critical infrastructure sectors (e.g., financial services, information technology, energy, water, emergency services, transportation systems, the defense industrial base) where damage or breakdown could create devastating effects for our nation’s economy and security. The costs of responding to cyber threats have increased exponentially year after year. The 2014 Global Report on the Cost of Cyber Crime found that, in the United States alone, costs had increased from $3.8 million to $12.7 million in the previous five years, up 96 percent (Ponemon Institute, 2010, 2014). Cyber attacks can be financially devastating, even ruinous, to single companies. For example, in a recent financial results forecast report, Sony estimated that costs related to the investigation and remediation of a cyber attack might be $15 million (Sony Corporation, 2015). Likewise, Jervis (2014), summarizing a study from the National Cyber Security Alliance in a recent news report, noted that “60% of small companies are unable to sustain their business within six months of a cyber crime attack” (para. 11). NSA Director General Keith Alexander cautioned that “the ongoing cyber-thefts from the networks of public and private organizations, including Fortune 500 companies, represent the greatest transfer of wealth in human history” (Alexander, 2012). Indeed, President Obama recently declared that cyber threats represent “one of the most serious economic and national security challenges we face as a nation” (Obama, 2015).

Read the paper · More papers on PaperTik