Practitioners’ Views on Cybersecurity Control Adoption and Effectiveness
Louise Axon, Arnau Erola, Alastair Janse van Rensburg, Jason R. C. Nurse, Michael H. Goldsmith, Sadie Creese · 2021
Cybersecurity practitioners working in organisations implement risk controls aiming to improve the security of their systems. Determining prioritisation of the deployment of controls and understanding their likely impact on overall cybersecurity posture is challenging, yet without this understanding there is a risk of implementing inefficient or even harmful security practices. There is a critical need to comprehend the value of controls in reducing cyber-risk exposure in various organisational contexts, and the factors affecting their usage. Such information is important for research into cybersecurity risk and defences, for supporting cybersecurity decisions within organisations, and for external parties guiding cybersecurity practice such as standards bodies and cyber-insurance companies.