Enhancing Cyber Resilience Management: Exploring Attributes in the Context of Security and Resilience
Thavaselvi Munusamy, Touraj Khodadadi · 2023
Organizations face increasing cyber risks and threats due to widespread dependency on cyberspace. Approaches to understanding and managing cyber security have also become demanding due to the challenges involving constantly changing technologies and sophisticated cyberattacks. The existing cybersecurity models primarily focus on security-related standards based on the traditional perspective of protection and prediction. In volatile cyberspace, existing approaches are considered insufficient in addressing risk. Cyber resilience is recommended as the way forward; however, it is a multi-faceted construct rooted in diverse attributes, resulting in a fragmented understanding of how to manage the security to achieve it. This research paper aims to identify fundamental attributes that enable organizations to be resilient by enhancing security measures. The study examines underlying concepts of cybersecurity and resilience by reviewing existing frameworks, models, studies, and surveys from industry practitioners. It employs exploratory study to refine the theoretical framework and deduces towards proposing a model featuring seven main variables: Rationale, Reliability, Readiness, Resistance, Robust, Rebound, and Reflective across the Physical, Logical, and Social cyber domains. The study's findings highlight the significance of the attributes in the dimensions of cyberspace domain areas, adding scientific evidence to the theoretical basis of the model. This study offers valuable guidance on improving cyber resilience management as it considers all the aspects in which the organization operates, providing coverage of possible factors that may lead to cyber risk exploitation. The study also provides insight to industry practitioners and policymakers on improving cyber security from the aspect of resilience.