Practitioners’ Views on Cybersecurity Control Adoption and Effectiveness

Louise Axon, Arnau Erola, Alastair Janse van Rensburg, Jason R. C. Nurse, Michael H. Goldsmith, Sadie Creese · 2021

Cybersecurity practitioners working in organisations implement risk controls aiming to improve the security of their systems. Determining prioritisation of the deployment of controls and understanding their likely impact on overall cybersecurity posture is challenging, yet without this understanding there is a risk of implementing inefficient or even harmful security practices. There is a critical need to comprehend the value of controls in reducing cyber-risk exposure in various organisational contexts, and the factors affecting their usage. Such information is important for research into cybersecurity risk and defences, for supporting cybersecurity decisions within organisations, and for external parties guiding cybersecurity practice such as standards bodies and cyber-insurance companies.

Read the paper · More papers on PaperTik