4.5 Article

Cybersecurity awareness training programs: a cost-benefit analysis framework

期刊

INDUSTRIAL MANAGEMENT & DATA SYSTEMS
卷 121, 期 3, 页码 613-636

出版社

EMERALD GROUP PUBLISHING LTD
DOI: 10.1108/IMDS-08-2020-0462

关键词

Awareness training; Benefit; Cost; Cybersecurity; Level of security

向作者/读者索取更多资源

Through a cost-benefit analysis, the study classifies different types of CSAT programs to help organizations develop effective cybersecurity awareness training. Findings show that CSAT programs with different costs play a differing role in maintaining, upgrading or lowering a company's existing security level. Ideally, CSAT programs should allocate more expenses towards training employees to deal with security threats at lower security levels and reducing more losses at higher security levels.
Purpose - Employees must receive proper cybersecurity training so that they can recognize the threats to their organizations and take the appropriate actions to reduce cyber risks. However, many cybersecurity awareness training (CSAT) programs fall short due to their misaligned training focuses. Design/methodology/approach - To help organizations develop effective CSAT programs, we have developed a theoretical framework for conducting a cost-benefit analysis of those CSAT programs. We differentiate them into three types of CSAT programs (constant, complementary and compensatory) by their costs and into four types of CSAT programs (negligible, consistent, increasing and diminishing) by their benefits. Also, we investigate the impact of CSAT programs with different costs and the benefits on a company's optimal degree of security. Findings - Our findings indicate that the benefit of a CSAT program with different types of cost plays a disparate role in keeping, upgrading or lowering a company's existing security level. Ideally, a CSAT program should spend more of its expenses on training employees to deal with the security threats at a lower security level and to reduce more losses at a higher security level. Originality/value - Our model serves as a benchmark that will help organizations allocate resources toward the development of successful CSAT programs.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据