Back to Search Start Over

Enhancing cybersecurity capability investments: Evidence from an experiment.

Authors :
Pigola, Angélica
Da Costa, Priscila Rezende
Ferasso, Marcos
Cavalcanti da Silva, Luís Fabio
Source :
Technology in Society; Mar2024, Vol. 76, pN.PAG-N.PAG, 1p
Publication Year :
2024

Abstract

In recent years, investments in cybersecurity capabilities (C C) have emerged as an essential practice in reducing cyberattacks and optimizing the usage of technologies. Therefore, optimal investments in capabilities must be determined according to the cybersecurity scenario of firms. This experiment pursues an understanding of the effectiveness of the iterative learning process in investments in C C. Through a simulator game, experienced and inexperienced participants overcome challenges related to uncertainties of cyber incidents to decision-making in cybersecurity capability investments. The collected data were empirically tested from 119 participants analyzing 3,808 simulation runs. The findings demonstrated that there is a slight difference in the learning curve between the two groups even if they learn proactively and iteratively. However, experienced, and inexperienced groups did not demonstrate enough capacity to analyze the cybersecurity ecosystems designed in the simulator game to mitigate cyber incidents. Both groups exhibited similar results regarding gaps to invest in C C to address uncertainties associated with cyber threats. In this sense, this experiment highlights the relevance of learning about C C investments in any context to avoid resource losses and time to uncover the complexities related to incident responses. • Simulator game demonstrated good acceptance among participants. • Cybersecurity capabilities investments might be learnt proactively and iteratively. • There is a slight difference in the learning curve between experience and inexperience groups. • Experience and inexperience groups did not demonstrate knowledge in cybersecurity capabilities to mitigate cyber incidents. • Participants did not demonstrate knowledge in the relationship between cybersecurity capabilities and technological ecosystem. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
0160791X
Volume :
76
Database :
Supplemental Index
Journal :
Technology in Society
Publication Type :
Academic Journal
Accession number :
175871589
Full Text :
https://doi.org/10.1016/j.techsoc.2023.102449