Cybersecurity KPIs in Higher Institutions: A Systematic Review
Fathima Zulfa Mohamed Irzam, Hamed Taherdoost · 2024
This study systematically reviews the cybersecurity KPIs in the higher education industry. With the evolving technological landscape, higher institutions are facing significant advantages from teaching and learning methods impacting all the stakeholders. However, on the other side they are facing several cyber security threats that have led several stakeholders of higher institutions to face losses and repercussions. The ever-increasing threats and malpractice brings the attention for higher education institutions to adopt effective cybersecurity KPIs. This study aims to focus on assessing the evolution of the research topic and its trends and documenting the rising awareness, implications, and challenges of adopting cybersecurity KPIs within higher institutions. Through a detailed analysis of a systematic literature review, it highlights the various adoption of KPIs within higher education institutions and their outcomes. We use a systematic study from 12 papers between the years 2011 to 2023 that were a part of inclusion criteria which supports the study of this paper. Furthermore, it discusses the stakeholder's implication and the importance of considering cybersecurity KPI by all stakeholders and not just the IT department, hence it needs to be implemented and measured by the rest of the stakeholders in order to achieve it successfully. The findings of this study recommend 15 KPIs of cybersecurity, keeping the model of Kirkpatrick's as a guide developed by previous researchers. The KPIs are chosen based on the systematic review and are recommended by future authors to conduct a survey based on the content validity method in order to validate that the developed KPIs are effective and suitable to be used by higher education institutions in the future.