A framework for effective corporate communication after cyber security incidents

09/19/2020
by   Richard Knight, et al.
0

A major cyber security incident can represent a cyber crisis for an organisation, in particular because of the associated risk of substantial reputational damage. As the likelihood of falling victim to a cyberattack has increased over time, so too has the need to understand exactly what is effective corporate communication after an attack, and how best to engage the concerns of customers, partners and other stakeholders. This research seeks to tackle this problem through a critical, multi-faceted investigation into the efficacy of crisis communication and public relations following a data breach. It does so by drawing on academic literature, obtained through a systematic literature review, and real-world case studies. Qualitative data analysis is used to interpret and structure the results, allowing for the development of a new, comprehensive framework for corporate communication to support companies in their preparation and response to such events. The validity of this framework is demonstrated by its evaluation through interviews with senior industry professionals, as well as a critical assessment against relevant practice and research. The framework is further refined based on these evaluations, and an updated version defined. This research represents the first grounded, comprehensive and evaluated proposal for characterising effective corporate communication after cyber security incidents.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/24/2021

A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures

Command, Control, Communication, and Intelligence (C3I) system is a kind...
research
06/28/2021

Developing a cyber security culture: Current practices and future needs

While the creation of a strong security culture has been researched and ...
research
02/27/2023

Bridging the Bubbles: Connecting Academia and Industry in Cybersecurity Research

There is a perceived disconnect between how ad hoc industry solutions an...
research
02/05/2023

Towards a Contemporary Definition of Cybersecurity

The report provides an intricate analysis of cyber security defined in c...
research
04/24/2020

Cyber Security Behaviour In Organisations

This review explores the academic and policy literature in the context o...
research
04/14/2020

Fidelity of Statistical Reporting in 10 Years of Cyber Security User Studies

Studies in socio-technical aspects of security often rely on user studie...
research
01/26/2023

A Process Model to Improve Information Security Governance in Organisations

Information security governance (ISG) is a relatively new and under-rese...

Please sign up or login with your details

Forgot password? Click here to reset