Developing a cyber security culture: Current practices and future needs
Betsy Uchendu, Jason R. C. Nurse, Maria Bada, Steven Furnell

TL;DR
This paper systematically reviews recent research on organisational cyber security culture, identifying key factors, frameworks, and measurement tools, and highlights open issues for future exploration.
Contribution
It provides an up-to-date synthesis of cyber security culture research, clarifies definitions, and identifies essential factors and frameworks for practitioners and researchers.
Findings
Top management support is critical for security culture.
Questionnaires are the most common measurement tool.
Organisational culture significantly influences security practices.
Abstract
While the creation of a strong security culture has been researched and discussed for decades, it continues to elude many businesses. Part of the challenge faced is distilling pertinent, recent academic findings and research into useful guidance. In this article, we aim to tackle this issue by conducting a state-of-the-art study into organisational cyber security culture research. This work investigates four questions, including how cyber security culture is defined, what factors are essential to building and maintaining such a culture, the frameworks proposed to cultivate a security culture and the metrics suggested to assess it. Through the application of the PRISMA systematic literature review technique, we identify and analyse 58 research articles from the last 10 years (2010-2020). Our findings demonstrate that while there have been notable changes in the use of terms (e.g.,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
