1
Greater Cybersecurity Will Only Be Gained By Reducing Over-Reliance on Technology
ACO 131 – Global Cybersecurity
Arizona State University-Tempe
December 15, 2022
2
Greater Cybersecurity Will Only Be Gained By Reducing Over-Reliance on Technology
Organizations worldwide face the ever-shifting landscape of the cyber threat as a primary
challenge. It is becoming a serious matter that requires ever-present alertness and holistic
consideration. Technological progress has afforded us highly sophisticated security measures,
but a blind trust in technology has actually created security exposures (Hasan et al., 2021). This
is due to the fact that cyber threats are always changing, and sole technological reliance may
make you feel safe (Salahdine & Kaabouch, 2019). By accepting that technology-centric cyber
security is not enough and rather an organization should embrace a comprehensive risk
management framework, they will be able to foster a security-conscious culture, make wise use
of technology, and therefore enhance their cyber resilience. The cybersecurity framework is a
combination of technical measures, organizational policies, employee training, and round-the-
clock monitoring (Kshetri, 2017). Employing employees, management, and other third-party
service providers of the organization in the cybersecurity process is essentially the key to success
(Tunc et al., 2022). This essay is intended to point out that cybersecurity is the pivotal problem
that needs to be dealt with systematically in order for us to obtain a proper balance between
technological measures and human-oriented solutions. Simply relying on technology is not a
solution; organizations should also focus on creating a security-aware culture in which
employees are taught about best practices and changes are made as per the present organizational
needs.
Limitations of Technology-Centric Cybersecurity
The emergence of new technology is the main concern in cybersecurity. Companies are
always using the latest security equipment; however, this equipment becomes outdated or
3
vulnerable to new threats very fast (Yaacoub et al., 2022). Faults in software and hardware,
along with interconnected systems, can be used by cyberattackers as entry points (Al-Sartawi,
2020). Moreover, the complex nature of technology systems also increases risks when setting up
and interconnecting different parts of the system, resulting in more vulnerable organizational
networks. Cybersecurity lags behind as technology progresses at an accelerated rate. The
attackers can take advantage of a simple error in system setup or outdated tools to compromise
systems. In order to defend themselves, Ablon et al. (2019) suggest that organizations must
constantly scan for vulnerabilities that have been created by changing technology. Implementing
multi-layered, adaptive security that encompasses people, processes, and technology is the core
of successful cyber risk management.
Many people still ignore the human factor, one of the major cybersecurity vulnerabilities.
Attacks related to social engineering exploit human frailties, which can sometimes be even more
powerful than the most advanced cybersecurity systems (Kumar et al., 2021). Employees who
are dissatisfied or careless, along with insider threats, greatly compromise the safety of
organizations (Walton et al., 2021). Organizations that are overly dependent on technology often
overlook the crucial role that employees and human behavior play in establishing a robust
security posture. This therefore paves the way for dangers that a technical solution is unable to
prevent. According to Salahdine and Kaabouch (2019), training and awareness can address
human error, which starts with clicking on untrustworthy links, data loss, and the creation of
massive security risks. Also, Hsia et al. (2019) suggest that a holistic approach to cybersecurity
includes systematic and purposeful management of both the technological and human aspects
through steady improvement and efficient monitoring. Cybercrime does not discriminate against
individuals; rather, it exploits the vulnerabilities that criminals can easily exploit.
4
One of the subtler issues in cybersecurity is the lack of appropriate human supervision
because of overreliance on automation. Ali and Jali (2018) contend that in the initial phases of
adopting the digital transformation model, organizations implement a human-technology model
and integrate a form of social and technological hybridity. Nevertheless, a substantial number of
organizations do not reach an equilibrium order of hybridity. The result of this form of social and
technological imbalance is an advanced social communication and technological system that is
social dynamically fragile and fails to respond when an appropriate human social system and
human technology integration is paramount. As Suresh (2018) points out, crisis management on
these issues is and will continue to be of intrinsic social value because systems will always
require human social systems intuitive crisis diagnosis and contextualization in real-time. It is
precisely these issues that are solvable with automation. In addition to this, Salim (2014)
emphasizes the importance of systems thinking as a critical dimension in cybersecurity risk
management, and the social cognitive systems that one applies to the problem. Given this
perspective, the human social system rapid response to social technology presents the social
dynamic gap in the advanced systems. Antikainen (2014) argues that an integration of human
analysis, as opposed to mere computational speed, in improving information and situational
awareness is a prerequisite for refining national cybersecurity resilience. The evidence presented
assimilates to show that cybersecurity of the future will be a direct result of systems technology
and human cognitive integration.
The tendency for organizations to maintain well-structured security postures is
undermined by the rapid pace of technological advancements. Within the manufacturing sector
of industrial critical infrastructures, gaps in protection are created when advancements in
technology outstrip the improvements in cyber security readiness (Ani et al. 2017). These gaps
5
are not exclusively technical. They are also managerial in nature. Organizations are failing to
align their innovations. Sustainable digital transformations are possible when the intersections of
technology innovations, human infrastructures, and the maintenance of cyber security
components are balanced, otherwise the system uncoordinated cyber security improvements will
amplify system weaknesses rather than mitigate them (Ali and Jali 2018). A more pronounced
systems flaw is the lack of anticipatory governance regarding cyber security. In the absence of
proper alignment of cyber security systems, uncoordinated components of cyber security systems
will always leave critical weak points (Salim 2014). The research by Tabatabaei and Wells
(2017) on OSINT and security awareness highlights the need for integrating tools into a
comprehensive security framework instead of incorporating them as isolated components.
Without a cohesive framework cyber security systems will constantly lack the synchrony needed
to keep pace with the cyber security threats.
The excessive reliance on protective systems causes security-related carelessness.
Ngwenya et al. (2019) explain that virtual learning environments with sophisticated identity-
aware technologies still experience significant lapses in cybersecurity because users do not
engage in expected behaviors. This finding implies that technological defenses do not preclude
the need for cognitive and behavioral readiness. Suresh (2018) states that the dynamic human
element in the cyber crisis management process is far more important in mitigation than any
protective measures that can be put in place on a static system. This point counters the narrative
that with more technological advancements, one will get more security. Antikainen (2014) makes
a similar point concerning the human element in the interpretation of situational awareness and
complex data streams. The need for human cognition indicates that cross-disciplinary efforts and
education are vital in cyber resilience. In the same line of thought, Ali and Jali (2018) emphasize
6
the pivotal role of human-technology interface to cyber stability, particularly in rapidly evolving
digital environments. This idea suggests that systems will remain fragile without the appropriate
balance between human resources and technological advancements. Consequently, the
cultivation of cyber vigilance, initiative, and contextual intelligence in employees must be
prioritized for cyber defense efforts to be effective.
Cybersecurity frameworks oriented around defense mechanisms prioritize the
deployment of such mechanisms as opposed to the integration of the disparate systems of
information within the context of the fragmented situational awareness across information
systems. According to Antikainen (2014), the poor integration and inaccuracies of information
can lead to poor decisions being made at the national level during incidents, and thus information
quality is fundamental to a resilient national cybersecurity posture. This understanding certainly
reveals the importance of the epistemic dimensions of the operations within cybersecurity.
Supporting this assertion, Tabatabaei and Wells (2017), argue that, with respect to OSINT, the
unverified and contextually misunderstood information poses a considerable risk and can even
become a weakness, thus, an information-centric technology system that does not include
information verifications will become a thwarted structure. Salim (2014) defines the
cybersecurity as a complex adaptive system and explains that, misinformation can have a
compounding outsized negative effect on an entire computation system if a faulty element of an
entire network system is not continuously monitored. This explains the importance of a system’s
continuous learning and adaptive monitoring. In addition, during a crisis, Suresh (2018) stresses
the importance of accurate communication intersecting between people and machines, for
coordinated action to occur. This reveals the importance that the interaction of belief systems
held by humans, which is synergized with rational systems of digitized and automated
7
instruments, is an ultimate form of defense system against the unpredictability of the entire
digital ecosystem.
Infrastructural interdependence increases the vulnerabilities associated with modern
cyber security environments. In the case of Ani et al. (2017), interconnected industrial systems
increase the exposure points of connected systems to the extent that it becomes impossible to
contain a threat within a single domain. The need to reassess the cyber defensive perimeters
moving beyond the defensive architectures to perimeter security suggests the overwhelming
complexity of the cyber networks (Salim, 2014). Systems thinking ameliorates the visualization
of the interdependence as well as the feedback loops to enable organizations to predict and
manage network cascade failure. Visualizing, predicting, and managing cascade failure in the
cyber-attack networks is complicated and critical concerning the systems in Ali and Jali (2018)
and as they put it, large-scale infrastructures. The cyber network systems and feedback loops in
cyber systems should also be studied as a cyber-attack and defense network. The degree of
complexity in such systems requires operational as well as educational solutions (Ngwenya et al.
2019). That complexity must be understood not just as a technological issue, but as an
operational and educational issue as well. Infrastructural interdependence captures the essence of
predictive cyber security and governance in an organizational context.
Sophisticated technology may create an organizational veneer of control, hiding
weaknesses underneath. Suresh (2018) observes that organizations developing cyber crisis
protocols often presume the systems to be predictable, while the human factor overwhelmingly
determines the behavior during crises. The expectation-behavior gap compromises security plan
integrity. Antikainen (2014) further argues that the organization’s culture must institutionalize or
embed adaptability, as resilience is born from continuous learning rather than learning capped by
8
fixed rules. Cultures of learning will mitigate the organizational overconfidence that over
reliance on static solutions provides. As Ali and Jali (2018) argue, technology-focused
approaches to cybersecurity neglect individuals’ emotions, ethics, and social considerations,
which are pivotal in determining responses to cyber crises. These human elements are usually the
primary determinants of the practical success of policies. Similarly, Tabatabaei and Wells (2017)
state the value of Open Source Intelligence rests on human analysts, not the tools, which stave-
off the automation fallacy. Therefore, organizations that neglect the psychology of cybersecurity
are nurturing systemic fragility under the veneer of technological sophistication.
The lack of coordination in situational awareness for national cybersecurity strategies
focused predominantly on technology acquisition is problematic. According to Antikainen
(2014), resilience at the national level is dependent on the integration of multiple knowledge
areas, where information is harmonized across the technical, political, and social domains and
sectors. During crises, fragmentation causes the trust and the social responsiveness that is critical
for the effective functioning of a system to completely breakdown. Salim (2014) supports this
view by illustrating the systemic nature of cyber risks and the corresponding systemic
governance requirements resulting from the interconnectedness of the digital world. These
systemic governance frameworks will require collaboration across multiple sectors on more than
the advanced digital tools of the current technologies. Suresh (2018) adds that effective crisis
intervention is the result of interpersonal trust networks that are substantially pre-established and
can be mobilized to confront the crisis. Sociology and social structure are, therefore, intrinsic to a
nation’s cyber security alongside the technology. Ali and Jali (2018) clarify this by emphasizing
the societal adaptability and resilience at the macro level of the human-technology continuum.
9
With this in mind, national security in the future will be more about the social intelligence of the
operators and less about hegemonic possession of technology.
Education is most generally underused in cybersecurity strategy. As noted by Ngwenya et
al. (2019), ‘digital learning platforms … equipped with state-of-the-art self-analysis features …
do poorly when users do not have even a rudimentary understanding of the basic principles of
cybersecurity’ (p. 127). This highlights the difficulty of incorporating security literacy into the
digital culture. Suresh (2018) rightly asserts that training concerning the management of crises
should not be ‘the exclusive domain of specialists’ (p. 137) but should include all stakeholders.
Such all-round training provides the necessary ‘democratized’ (p. 138) defensive capacity
training that mitigates reliance on a small number of specialists. Ali and Jali (2018) state that
education within a human-technology-centric framework must be ‘continuous’ (p. 5) because
human intuition must keep pace with machine intelligence. Education, therefore, must bridge
innovation with the necessary safety measures. Antikainen (2014) further connects the
improvement of situational awareness with the mastery of information by asserting that
education ‘enhances’ (p. 6) interpretive acuity. Cybersecurity education empowers employees by
transforming them from potential risks into active defenders of the organization's digital
integrity.
Within a cybersecurity strategy, the use of open-source intelligence (OSINT) can be
valuable and detrimental. As Tabatabaei and Wells (2017) state, OSINT improves threat
anticipation by supplying contextual information that closed systems do not provide. Conversely,
the same openness that aids defenders also helps adversaries, highlighting a pivotal downside to
digital transparency. Without systems-level controls, OSINT can create uncertainty instead of
clarity, as warned by Salim (2014). His systems theory framework illustrates how uncoordinated
10
information streams can cause waterfall collapses and destable the broader situational awareness.
In working to quell the waterfall collapse, Ali and Jali (2018) argue that the inclusion of humans
in OSINT helps reduce this unrest by passing the information through ethical and contextual
frameworks. The balance of openness and control will be the key predictor in an organization’s
ability to solve the modern cybersecurity problem. The quality of information has to be managed
to create and strengthen cybersecurity resilience, as stated by Antikainen (2014). OSINT
provides unrestricted access to information, but disciplined synthesis is necessary in order to
reinforce the interrelationships of clarity, control, and the strategic flow of information.
The advancement of artificial intelligence and automation within cybersecurity
operations raises questions regarding the decline of human agency. According to Ali and Jali
(2018), the future of cybersecurity would depend on a complementarity human-technology
model with machines enhancing, and not over-replacing, human judgment. Over-automation
might risk moral detachment of responsibility from the decisions made. As Suresh (2018) notes,
the exclusion of humans from the decision-making processes during cyber crises can cause
unethical oversights and rash escalations of the situation. This insight reveals a certain imbalance
between efficiency and accountability. Salim (2014), extending this line of thought to systems
theory, states the ethical need for human involvement so that adaptive, ethically-shaping
feedback loops can be integrated into the system. This illustrates that technology must remain a
subordinate tool within a human-sustained system, and not the reverse. Ngwenya et al. (2019)
found that in virtual learning environments, systems with a hybrid of automation and human
participation are more resilient than systems with full automation. The evidence suggests that the
future of cybersecurity would not be dictated by technology, but by the human-led governance
that will oversee the systems in place.
11
Advantages of a Holistic Cybersecurity Approach
Tackling cybersecurity from a holistic perspective can bring many advantages.
Organizations can create a culture of security awareness through human factors and
organizational processes. All personnel are involved in the process (Demirkan et al.,
2020). Continued training for employees and awareness programs help them become active
collaborators in safeguarding the organization's data and systems (Hasan et al., 2021). A resilient
process for incident resolution and business continuity planning will give organizations the
ability to quickly and effectively manage and recover from cyber-attacks, reducing downtime
and damages. A comprehensive cybersecurity strategy blends people, technology, and processes
to provide a harmonious security position. This unified way of dealing with cyber threats,
regardless of how they might change, allows organizations to remain strong (Jalali et al., 2019).
It has various layers of defense, reduces the probability of human error, and allows the
organization to be able to deal with incidents quickly and continue with business as usual (Cram
et al., 2017). Embracing this full-fledged cybersecurity approach is vital to mitigating risks in the
modern online ecosystem, which is very complex.
A comprehensive cybersecurity approach also provides balanced technology
adoption. Rather than being overwhelmed with every security tool, organizations should
cautiously assess the risks and benefits, focusing on simplicity and a low technological footprint
(Al-Sartawi, 2020). This approach reduces complexity and improves interoperability across the
security infrastructure to ensure better resilience. Moreover, Yaacoub et al. (2022) indicate that
enhancing cooperation and intelligence sharing, both within the organization and with outside
12
entities, utilizes the accumulated knowledge to foresee and respond to cyber threats before they
occur. According to Cram et al. (2019), organizations can make informed decisions on security
investments based on their particular needs and risk profile by taking a holistic approach. In
doing this, Demirkan, Demirkan, and McKee (2020) state that these organizations put away
extraneous and different tools that increase the management load and potential risks. Integration
of security functions such as people, processes, and technologies provides a unified view and
control. This balanced strategy guarantees that resources are appropriately utilized to achieve the
best possible results in reducing cyber threats.
A cyber-secure framework improves strategic foresight by adding new lenses from
various disciplines for threat anticipation. Elmelhem, Bouras, and Ghemri (2018) provided a fine
illustration, where a comprehensive model integrating technological, human, and organizational
underpinnings enables organizations to preceding risk management from a proactive rather than
a reactive perspective. This ensures organizational adaptability within a systemic approach and
awareness to the challenges posed by evolving threats. Henshel et al. (2016) emphasize that the
interdependencies obscured by siloed assessments can be revealed and strengthened through
integrated quantification of modeled cyber-attack risks and mitigation strategies. Their approach
to strengthening resilience illustrates how the understanding of system fractals and minor system
failures cascading to be the ultimate causes of system failure makes a system control-strong,
predictable, and resilient. Taitto, Nevmerzhitskaya, and Virag (2018) adds that cyber-attack
simulation-driven environments built through holistic designs set institutions to iterative active,
adaptive, and experiential readiness, facilitating refreshed, sequential, and strategically pivotal
experiential learning for real-time scenario execution. Jacob, Peters, and Yang (2019)
demonstrate the added focus of interdisciplinarity in cyber research. The combination of focal
13
sociotechnical reasoning decreases the narrow view control brought by domain scholarship. The
overall vision in the body of work synthesizes to a best-practice approach that combines
technical, human, and learning elements of an organization to build a cohesive defense in a
planned systemic approach.
When building organizational maturity in cybersecurity, it is still important to develop
sustained capability. Barclay (2014) states that the Cybersecurity Capability Maturity Model
(CM²) outlines the framework to a security advantage that is sustainable, and this is built through
ongoing evaluations and improvements literally without any end. This is because, unlike simple
compliance, true resilience is built through active evolution. Choras et al. (2015) explain that it is
the comprehensive approach that builds resilience to reinforce reliability, availability, and
adaptability across the system's every tech and management layer, thereby creating self-
correcting mechanisms. This is important interlinked or 'integrated' security that is designed to
outperform the isolated, technical, defensive components. In contrast, Marotta & McShane
(2018) relative to the holistic management framework, proactive risk management moves to the
forefront to optimize 'early dedection' to reduce disruption to the operation. This speaks to the
anticipation that defines maturity in cybersecurity. In a similar vein, Elmelhem et al. (2018)
identify the unifying and holistic strategies pertaining integrated decision-making as a means to
fragment protective systems and meld them into integrated or 'synergistic' systems. All these
works describe cybersecurity's maturity as systemic because it relies on active focus,
anticipation, and integration rather than a simple, reactive, technological fix.
Promoting holistic cybersecurity encourages dynamic governance by integrating
technological operations with values and regulations of the institution. Garcia, Forscey, and
Blute (2017) suggest that a state cybersecurity governance holistic approach goes beyond the
14
network layer and intertwines cybersecurity with the legal, ethical, and societal frameworks. This
alignment achieves the integration of technological defense with democratic accountability.
Jacob et al. (2019) assert that the collaborative interdisciplinary approach to the rethinking of
cybersecurity processes also enhances the legitimacy and transparency of the processes to ensure
that the defensive strategies underpin the sovereign societal objectives. This approach
emphasizes that the governance of cybersecurity rests primarily on a moral and civic obligation,
and not on a purely technical obligation. Barclay (2014) builds on this idea by demonstrating that
the more security culture is embedded within governance frameworks, the more frameworks
become mature and the more frameworks become sources of sustainable advantage. Rege (2015)
reiterates this idea by explaining that blended experiential learning is the only way to foster the
cultural literacy required to understand cybersecurity beyond the technical domain. All of these
perspectives demonstrate that holistic governance transforms cybersecurity from being a reactive
obligation to a positive obligation on the institution as a whole.
Incorporating simulation-based training in a cybersecurity strategy enhances
understanding and readiness in decision making. Taitto et al. (2018) argue that simulation
environments using whole models allow learners to interact with and adapt to realistic attack and
defense scenarios, thereby sharpening their problem-solving skills. Simulations of system
interactions provide a lab for strategic experimentation. Supported by Rege (2015), experiential
learning frameworks encourage reflective, interdisciplinary scholarship that bridges disparate
ideas and practices in cybersecurity education. Through cognitively engaging with a crisis
simulation, learners find procedural memorization resilient. In like manner, Henshel et al. (2016)
explain that integrated risk modeling utilized in simulated contexts offers observable insight into
cascading system vulnerabilities. Thus, by stress testing a data driven approach, situational
15
awareness and coordination under pressure as a team are enhanced. Moreover, Jacob et al.
(2019) argue that interdisciplinary teamwork in such settings fosters real time convergence of
diverse skill sets for inventive solution finding. Heuristic approaches to instruction illuminate
that comprehensive cybersecurity is more than defending systems. It is about responding to a
complex problem with informed adversarial creativity.
The holistic approach deepens the connection between the management of cyber risks
and the resilience of the enterprise. According to Marotta and McShane (2018), integrating
frameworks that include proactive risk identification allows businesses to view the defensive
costs of cybersecurity differently and instead see it as an opportunity for organizational
continuity. This reframing allows companies to view security as a strategic investment. Choras et
al. (2015) support the claim that comprehensive methods improve resilience by allowing systems
to withstand attacks and preserve functionality due to redundancy and coordinated response
systems. This leads to the realization of system-level elasticity. According to Barclay (2014),
organizational maturity models direct the evolution of businesses and cyber resilience from
reactive to predictive frameworks, harmonizing cyber resilience with the business’s long-term
sustainability. This balance allows risk mitigation to encourage rather than stifle innovation.
Furthermore, Elmelhem et al. (2018) claim that holistic integration enables the synchronization
of the entire organization, the frictionless circulation of risk intelligence, and the frictionless
integration of security. This frictionless integration of security transforms protective measures
into facilitators of operational velocity. Hence, holistic cybersecurity can be viewed as a form of
operational agility amid uncertainty in digital markets.
The collaborative work of different sectors can be viewed as a benefit of a holistic
approach to cybersecurity. Garcia et al. (2017) explains how coordination across agencies and
16
sectors allows for the governance of cybersecurity to be enhanced because shared frameworks
facilitate awareness of and the exchange of threats. Fragmentation around collaborative
governance for the public and private sectors becomes less of a concern with this shared
understanding. Choras et al. (2015) further buttresses this point by stating that resilience is
strengthened with the integration of information-sharing frameworks around collaborative
synchronizations of multiple stakeholders. This type of cooperation allows for resilience to be
built in layers against threats that extend beyond borders. Elmelhem et al. (2018) suggest that
interconnectedness brought by a holistic model of cybersecurity structures different elements as
an ecosystem. Strategic cohesion is a product of systemic unity, as their findings suggest. Jacob
et al. (2019) continues the conversation by stating that the integration of different academic
disciplines can fill the gaps left by institutions and is a channel to share disciplines of technology
and policy. The point of these studies is that the holistic model for cybersecurity is the view of
the system moving from competitive isolation to coopersative stewardship, as the model
acknowledges that digital defense is one of collaboration.
Holistic cybersecurity nurtures adaptive learning as well as continuous innovation. As
cited by Rege (2015), it is multidisciplinary experiential programs that create reflexive
professionals who respond to new threats using critical inquiry as opposed to mindless
adherence. It is this type of adaptability that forms the basis of organizational resilience in
unpredictable times. Taitto et al. (2018) demonstrate that the incorporation of experiential
learning with holistic simulation systems gives rise to feedback loops that facilitate the iterative
evolution of practices in cybersecurity. Such feedback captures the essence of dynamic policies
as opposed to static frameworks. According to Barclay (2014), this type of adaptability is what
connects with maturity modeling as he demonstrates that continuous advancement in
17
differentiated pathways is possible through the sustained assessment of defined performance
metrics. He further demonstrates that learning organizations outpace their adversaries in
evolution. Tautology (2016) and Levin (2018) show that integrated risk models go further to
highlight inefficiencies embedded in the configuration of defenses and trigger innovation. A
holistic perspective fundamentally changes cyber risk management from a maintenance focus to
a learning focus, and within this paradigm, the core of the defense is adaptability.
Holistic methods enhance human decision-making by refining cognitive structures. Jacob
et al. (2019) state that interdisciplinarity develop analytical diversity and allow specialists to
examine and assess cyber risks through multiple lenses and from diverse contexts. Consequently,
multiplicity strengthens reasoning under uncertainty. Rege (2015) defends this, stating that
multidisciplinary experiential learning environments enhance cognitive flexibility and situational
awareness, especially the judgment of complex threats. Such competencies mitigate weak tunnel-
vision in narrow technical aspects. Taitto et al. (2018) state that learning through simulations
based on holistic principles fosters active integration of learning and deepens an understanding
of complex systems and behaviors. In unpredictable and complex digital systems, reflection and
‘soft systems thinking’ encourage intellectual humility. Elmelhem et al. (2018) amplify this by
stating that the human-organization interface makes sure systems decision-makers view
cybersecurity problems as dynamic patterns, rather than in isolation. These findings converge to
show that the holistic paradigm strengthens cognition and transforms professionals in
cybersecurity into strategic thinkers, equipped to tackle uncertainty with explicit and advanced
control.
Sustainability in cybersecurity can be realized through holistic practices integration at an
institutional level. Barclay (2014) illustrates how the embedding of continuous evaluation
18
mechanisms within the maturity models ensures that cybersecurity undergoes development in
parallel with changing landscapes in the environment and technology. This institutional
resilience allows a shift from short-term security fixes to enduring capabilities at organizational
levels. According to Elmelhem et al. (2018), organizations that operationalize holistic
frameworks cultivate adaptive governance systems that can embrace feedback from all levels of
an organization, and such inclusiveness bolsters institutional memory. To sustain long-term
efficiency, Marotta and McShane (2018) explain that loss and resource wastage due to repetitive
vulnerabilities should be minimized through proactive risk identification. This view strengthens
the alignment of cybersecurity sustainability to the overarching economic efficiency. Choras et
al. (2015) notes comprehensive resilience models balance proactive and reactive approaches and
in doing so, significantly reduce systemic fragility. Collectively, these studies suggest that in
cybersecurity, static protection does not lead to sustainability. Rather, it is through cultural and
institutional continuity, adaptive integration, and organizational learning that sustain holistic
practices.
Integrating a holistic model builds ethical accountability in managing cybersecurity. As
noted by Garcia et al. (2017), governance frameworks based on holistic principles foster
transparency and accountability, and align digital defensive mechanisms with public trust. This
means that ethics become part of the foundation of resilience. As noted by Jacob et al. (2019),
the inclusion of interdisciplinary approaches brings moral complexities to the forefront of
technical decision-making, thus ensuring that the cybersecurity frameworks will be implemented
without infringing upon the privacy and civil liberties of individuals. This ethical reflexivity and
moral reasoning mitigate the risk of overreach that comes with the surveillance-focused
defensive model. In support of this view, Barclay (2014) argues that progression through the
19
capability maturity model should be based on the responsible evolution of security, whereby
ethical performance is a maturity indicator alongside technical refinement. This ethical
measurement integrates social trust into the cybersecurity model. As noted by Elmelhem et al.
(2018), holistic governance draws moral coherence between the technology practiced and the
identity of the organization. This means that the ethics embedded in holistic governance will
foster a digital environment that is secure and instills trust.
Employing a holistic approach to cybersecurity encourages self-regulating resilience
driven by collective intelligence and systemic flexibility. According to Choras et al. (2015), self-
sustaining frameworks that multisource interconnected and layered defense systems are produced
that adjust during an attack and preclude collapse of the system. The system's distributed
adjustability provides biological redundancy for survival. Integrated risk is modeled to quantify
interdependencies and optimize leverage for intervention during a crisis (Henshel et al. 2016).
Knowing these relationships sharply enhances the precision of a response. Elmelhem et al.
(2018) asserted that organizations can detect and respond to threats coordinated synchronically
and cohesively when the integrated active triad of a technology-people-process system is present.
This coordinated response minimizes system accumulation and maximizes continuity. Marotta
and McShane (2018) argue that the integrated components designed to manage risk and adaptive
uncertainty permit organizations to learn in real time from disruptive events. The empathy
argument for holistic cybersecurity depicts it as an evolving ecosystem, an intelligent and
adaptive organism that thrives not by resisting change, but by continuously improving.
Implementing a Holistic Cybersecurity Strategy
20
Building a strong cybersecurity strategy begins with developing a comprehensive risk
management framework that will cover the organization's unique aspects. Kumar et al. (2021)
recommend designing this infrastructure to identify critical resources, susceptibilities, and
countermeasures. Moreover, using a risk-based approach, organizations can direct their efforts
and allocate resources effectively to the most vulnerable points (Walton et al., 2021). The
framework should also be able to incorporate the operational environment, industry regulations,
and compliance requirements, thereby providing a comprehensive security posture that satisfies
all necessary standards. Yaacoub et al. (2022) also emphasize that an organization's specific
requirements-tailored risk management plan serves as the foundation for an integrated
cybersecurity program, aligning with the organization's objectives and risk tolerance. Al-Sartawi
(2020) affirms the above, stating that it enables making informed decisions on security measures
and control points after the risk analysis. It is a data-driven approach that replaces crisis-oriented
security measures with a holistic approach that covers both technical, operational, and human
aspects. Agileness enables the monitoring and adjustment of risks and adaptations in response to
changing threats and business requirements. This particular framework's design is critical for
implementing holistic and sustainable cybersecurity systems.
A comprehensive security approach will include not only the technical part, but also the
investment in people and the creation of a culture of security consciousness. According to
Demirkan et al. (2020), we should initiate comprehensive training programs and raise awareness
across the entire organization to ensure every employee, regardless of level, can identify and
prevent these threats. As well, the organizations need to build up a culture where cybersecurity is
a shared responsibility, supportive of open communication, collaboration, and a proactive
mindset for breach identification and mitigation (Hasan et al., 2021). A culture of security
21
awareness decreases the risks of human error and insider threats. Employees' ownership of their
roles is an active line of defense in the battle against cybersecurity attacks (Kumar et al., 2019).
Training employees constantly brings to the forefront the importance of following the set
policies and procedures designed to prevent data leaks, detect social engineering attacks, and
report incidents. Additionally, Hasan et al. (2020) say an open culture encourages general
watchfulness and permits the raising of security issues without fear. By placing cybersecurity as
the top priority among all staff members, organizations are capable of building a robust security
stance against ever-changing threats. People are no longer the failure point but rather the core
strength.
As a result, the only effective cybersecurity possible is a holistic strategy that integrates
technical tools with human-centered strategies. Given that cyber threats are constantly evolving,
using technology as the sole tool to counter them is no longer a viable option. Where security
technologies are essential, a complete dependence on them can be ineffective as it may overlook
the human factor, which is vital to cybersecurity resilience. Organizations should be
implementing a comprehensive cybersecurity strategy, which would involve not only technical
measures but also robust risk management, continuous training and awareness, and a culture that
gives security a high priority at all levels. Through the combination of all the people, processes,
and technology in a coordinated way, the enterprises can be able to comprehensively manage the
risks and build a strong cybersecurity position. The effectiveness of the current strategies of the
organizations will be measured, and they will have to adopt a holistic approach to guarantee
long-term security against cyber threats that are always developing.
Devising a comprehensive cybersecurity strategy involves integrating defense objectives
with the organizational governance structure and the organization's decision-making flow. The
22
importance of embedding cybersecurity governance into the corporate structure involves
responsibility and the synchronization of protection objectives with the primary business strategy
(Dawson, 2018). This allows cybersecurity actions to become proactive and rooted in business
strategy through risk assessment. Defining structures within governance frameworks facilitates
the insurance of consistency through the technological, managerial, and policy dimensions of the
organization. According to Atoum, Otoom, and Abu Ali (2014), the unified governance model
facilitates the creation of cross-communication interdepartmental channels, enhancing response
and compliance. This coordination aligns silos and mitigates the fragmentation risk the
organizational structure imposes and deteriorates security across large enterprises. Additionally,
Boehm et al. (2018) explain that the incorporation of cyber risk estimation into governance
facilitates the making of trade-off decisions per organizational goals. This approach allows the
transformation of cybersecurity from a technical task to a strategic business function. Proper
governance equates to improved organizational compliance and fosters resilience and proactive
organizational cybersecurity through accountability in governance frameworks and decision-
making cohesion.
The development of cybersecurity resilience entails adopting adaptive mechanisms that
allow defenses to be strengthened in real time. Wei, Mann, Sha, and Yang (2016) argue that
organizations can implement multi-faceted educational frameworks in order to create iterative
feedback loops that help organizations respond to changes in threat landscapes. With threats that
continuously evolve, organizational employees and technical staff will benefit from continuous
adaptive learning. A more dynamic training model will promote agility in organizational
personnel and reduce dependence on static compliance-based awareness. Elmelhem, Bouras, and
Ghemri (2018) stress that comprehensive structural frameworks in organizations embed
23
experiential learning and, therefore, promote the connection of employees’ theoretical
knowledge frameworks to crisis response. Experiential learning in such frameworks offers
organizational personnel the necessary tacit knowledge to navigate uncertainty and pressure.
Dawson (2018) underscores this process, arguing that organizational cybersecurity practices
mature through institutional learning, self-assessment and reflection, rather than solely through
reactive crisis management. The incorporation of adaptive learning practices fundamentally
changes cybersecurity from a mere control mechanism to a vibrant, growing system.
Organizations that focus on learning can more effectively predict sophisticated cyber threats and
create innovative counter-defensive measures.
The incorporation of automation with analytics in any cybersecurity system will optimize
the functions of the system in its entirety. As stated in Boehm et al. (2018), organizations are
able to work with fully automated quantitative risk models to reasonably assess which risks
warrant attention and which risks do not based on probabilistic assessments. This enables
organizations to assess and apportion resources in a manner that focusses on the most important
and most risky weaknesses. That said, quantitative risk models will never fully replace the value
of judgement. Context of the business may be lost in the risk assessments generated by
automated models. Automated evaluation systems are of no value to organizations unless there is
human input, which is why, in the eyes of Carcary, Doherty and Conway (2019), automated
systems and human input, are to be integrated for the most balanced and justifiable decision
making in cybersecurity. In a similar way, Meinig et al. (2019) posit that strategy-based threat
modeling approaches these technologies along with the systems automation in a comprehensive
manner to ensure that automation supports rather than overshadows strategic intent. Data-based
assessments coupled with managerial input enables a system to maintain the level of strategy
24
adaptability. In comprehensive systems, automation is to reinforce human accountability, not
replace it.
Any sustainable cybersecurity strategy includes transformational culture change that
espouses common values and collective citizenship. Kohnke (2016) argues that linking job
functions within an organization to cybersecurity competencies allows every employee to
appreciate how their role fits within the defense architecture. This integration redefines
cybersecurity as the goal of collaboration rather than the focus of a single institution. Dawson
(2018) continues to expand on the idea of holistic approaches to culture by treating cultural as
infrastructure and pointing to behavioral norms that may aid or dismantle technical controls.
Embedding control within everyday tasks creates an institutional culture of vigilance. Atoum et
al. (2014) underscore the importance of collaboration in achieving holistic understanding of risk
and accountability and the links silos that lose coordination. A culture-driven model then serves
as the invisible infrastructure that sustains the implementation of technical and procedural
controls. When people embrace security as part of their identity, organizations attain a level of
resilience that no tool or policy, standing alone, can achieve.
Integrating external collaborations into strategic frameworks is also a facet of holistic
cybersecurity. Recognizing the interdependencies of national and organizational cybersecurity,
Matania, Yoffe and Mashkautsan (2016) argue for the need of multilevel cooperation among
public and private actors. Such an approach takes cybersecurity beyond a closed system and
views it as an ecosystem. Rapid collective defenses and early warning of threats to an entire
domain are possible through collaborative sharing of information. Strengthening national level
cyber defenses through shared threat intel and aligned standards is a cross-sector collaboration
documented by Galinec, Možnik, and Guberina (2017). For the individual organization, an
25
alliance of this sort extends protective boundaries far beyond the organization’s internal
perimeter. Elmelhem et al. (2018) observe that cooperative security frameworks provide
organizations with the global knowledge to adjust their systems through feedback loops that
sharpen the overall network’s systems (i.e., global knowledge). Vulnerabilities that are perceived
as isolated are actually opportunities for system improvement. By acknowledging collaboration,
holistic frameworks emphasize that resilience is as much external as it is internal, derived from
trust and mutual accountability.
The emergence of digital innovation creates deeper connections among a firm’s systems
which in turn makes implementing effective cybersecurity more complex. Carcary et al. (2019)
emphasizes the necessity of governance models within digital ecosystems that allocate equal
weight to nurturing innovation and cultivating protection. Organizations that align the
transformation of their cyber postures to their strategic objectives tend to avoid disruption risks.
Dawson (2018) claims that digital capabilities and cybersecurity maturing tend to cohesion
provided both are pursued in stride, which ensures that neither innovation nor a cyber-threat
mitigation measure is deployed out of synchrony. As reported by Boehm et al. (2018) making
cyber risk assessment an integral element at every digital tier of a project allows the
determination of calipered risk decisions. Here, cybersecurity is a driver to innovation, not a
blocker. An amalgamation of innovation and cyber defense is vital to maintain the
transformation project’s sustenance. These unifying strategies are the nexus that weaves the
fragmented facets of advancement and defense together, permitting disruptive technologies to be
crafted in a well-regulated and sheltered setting.
Implementation of holistic cybersecurity must incorporate measurement and continuous
improvement. According to Boehm et al. (2018), effective programs require measurable
26
indicators to evaluate capability maturity and residual risk. Measurement moves technocratic
frameworks to performance systems that can be actively managed. Still, to avoid numerical
reductionism, the organizational context must be kept in focus. Dawson (2018) proposes a
balanced scorecard methodology that encompasses the technical, behavioral, and procedural
aspects of security to be performance evaluated. This approach produces actionable insights from
complex datasets that tie to the organizational goals. Carcary et al. (2019) observe that the
feedback gained from monitoring processes must be used to adjust policies and risk allocation in
real time, thus ensuring that the planning and execution stages remain consistently aligned.
When measurement is embedded in a cycle of continuous learning, the compliance aspects of
cybersecurity are transformed to a dynamic strategy. Evidence-based reflection, adjustment, and
adaptation of processes are the hallmarks of thriving holistic implementation, turning
organizational defense from a liability to a sustainable competence.
Inevitably, to have a holistic approach to cybersecurity, national policy integration and
organizational alignment are required. As indicated by Galinec et al. (2017), the strategic
frameworks within a nation provide standards and cooperative mechanisms that impact the
security maturity of a firm. This micro–macro linkage ensures alignment between the goals of
policies and the reality of their implementation. According to Matania et al. (2016), the three–
layer approach of the nation, the organization, and the individual provides a full scope of the
security integration across various levels. This vertical integrity enhances the compliance and the
fortitude of the nation. As stated by Dawson (2018), organizations that are part of national
systems experience a lower level of structural vulnerability and take part in cooperative
information sharing. Closely aligned public governance and private action systems improve
communal cyber-incident response. When institutional coordination is effective, cybersecurity is
27
no longer simply an organizational advantage, and it becomes a national right. Thus, a holistic
approach to cyber defense and policy systems does not isolate systems but removes the
organization from the policy systems.
Including ethical principles in cybersecurity builds trust and contributes to lasting
viability. Kohnke (2016) explains that technical protective measures that incorporate ethical
boundaries provide transparency, which in turn instills trust in the governance of cybersecurity.
Legitimacy is more likely to be established if ethics are in the center of governance, particularly
in industries that manage sensitive information. Organizations that incorporate ethical elements
in their decision-making processes within the scope of cyber risk assessments are noted to have
improved reputational resilience in crises (Boehm et al. 2018). The incorporation of ethics
enhances the value of security from legal compliance to stewardship of digital trust. Atoum et al.
(2014) argues that comprehensive cybersecurity approaches must incorporate ethics in the risk
value chain to achieve equilibrium between security controls and individual privacy.
Counterbalances promote social trust and the goodwill of governance, which are vital for the
continuity of the operational. Integrating ethical principles within the system design increases the
scope of what is protected.
The cornerstone of comprehensive cybersecurity of the future is predictive intelligence
and proactive responsive change. Meinig et al. (2019) state that the incorporation of strategic
foresight operations within a threat modeling approach leads to the recognition of organizational
pre-weaknesses that may be targeted. The adoption of predictive modeling enables the defensive
functions of a corporate entity to operate more toward the anticipation of potential attacks rather
than reactive after the exploitation of a vulnerability. Dawson (2018) claims that foresight
scenario-based planning is more optimized by predictive framework functions that prepare
28
organization executives to recognize early warning indicators of potential attacks and
dynamically alter their organizational response. As a result of the organization’s response
planning to address threats of exploitation, Matania et al. (2016) assert that coordination of
defense innovations anticipatory governance within a sector reduces latency of organizational
response and boosts organizational defensive innovation. The integration of predictive planning
and organizational agility enables the transformation of holistic cybersecurity frameworks. These
frameworks management organizational disruption cybersecurity within the organization, while
still maintaining a flexible defense posture and dynamic adaptability responsiveness to threat
exploitation.
Understanding the Psychology Behind Cybersecurity Behavior
To successfully study human behavior in the context of cybersecurity, it is pertinent to
note that cognition is influenced by bounded rationality. McAlaney, Taylor, and Faily (2016)
point out that people tend to use cognitive ‘shortcuts’ heuristics which cloud their understanding
of cyber risk and, in the process, increase susceptibility to exploitation. It is this psychological
barrier that people perceive the possibility of breaches of security with little or no consequences.
These tendencies in the human mind suggest the need to construct awareness programs with
emphasis on engagement at the feeling level and participation at the level of doing as opposed to
mere transmitting information. Patterson and Winston-Proctor (2019) argue that the personality
traits of conscientiousness and openness affect compliance to cybersecurity policies which points
to the fact that personality traits can shape the level of vulnerability of an organisation.
Organizations can, therefore, derive compliance interventions by diagnosing the traits with a
cybersecurity role. Dalal and Gorab (2016) have gone further to suggest that insider threats
correspond with counterproductive work behavior and show the ease with which employees,
29
having frustration and disengagement, can become latent risks. These insights suggest that the
capability to protect an organization's cyber assets is not solely a technical matter, but also
involves understanding the psychological factors such as motivation, trust, and self-efficacy with
regard to behavior deemed secure.
The perception of risk shapes how people make decisions regarding cybersecurity. Das
(2017) says people tend to consider online risk in social and culturally constructed chances,
which means target awareness campaigns will fail if social context is missing, Das. This means
that the communication advocate defense to social identity and belonging rather than logic or
fear. McAlaney et al. (2016) noted that users' optimism bias makes them believe that, relative to
all other internet users, they are somehow less exposed to risk, which leads them to unevenly
comply with the set policy. This bias can be applied by designers in an attempt to make users see
security as a form of collective defense rather than defense at the individual level. According to
Carcary, Doherty and Conway (2019), social influence and peer pressure, which predominately
go unchecked in most training sessions, increase compliance with social norms and the
standardization of safe procedures. These strategies make compliance to protection individually
rather than externally mandated. The logic is unambiguous; cybersecurity projects will grow
successful if people are allowed to determine the meaning and identity they wish to have in the
grassroots digital society.
Sleeplessness and automated tasks is a deep-rooted psychological challenge. Montasari,
Hosseinian-Far, and Hill (2018) said that users are overwhelmed with threat warning systems
and intricate security measures, which leads to emotional and physical exhaustion, and their
expenditure of energy and ability is far below the required level. Over time, individuals are
exposed to so much of the same stimuli, that stimuli is reflexively zoned out, as irrelevant
30
background noise. This supports the point of overload paradoxed within cybersecurity, exposure
leads to lack of alertness, and over reminders leads to apathy. Patterson and Winston-Proctor
(2019) observed the mental exhaustion caused by various interfaces, and the narcissistic
instructions focused on mental heuristics, and rationally approximated the system to reverse
design. Design which aid human cognition and exhaust is an abrasive approach towards design,
and Wei et al. (2016) proves that hierarchical systems which gradual and self-paced learning
modularized education are actively engaged and retained over longer durations. Evidence posits
the idea that contradiction with an equilibrium focused towards cognitive overload and retentive
span is the apex. The emotional design intelligence along with the user interface in security
fatigue removes monotonous systems to maintain psychological consonance.
In a psychological sense, trust is an important factor in the effectiveness of any given
cybersecurity system. Das (2017) argues that people are more compliant with policies when a
system is perceived as equitable, transparent, and trustworthy. That is, trust serves as a
psychological lubricant for compliance. Situations that are perceived as punitive and restrictive
tend to encourage the opposite behavior, which is rule evasion. Dalal and Gorab (2016) show
that perceived organizational injustice is aligned with counterproductive work behavior theory in
the form of insider sabotage. These theories highlight the social aspect of cybersecurity risk.
According to Meinig et al. (2019), the absence of relational dynamics is a gap in the
interdisciplinary threat models that automate the analysis of such trust-based operational
vulnerabilities. Thus, trust is a form of defense and an attack surface. Compliance that is
psychologically safe and based on fair communication has the potential to change compliance
from an obligation to a self-motivated act, thus transforming fear-based control to collaborative
responsibility.
31
The motivation behind determined behavior is the most critical factor toward the
continual practice of cybersecurity within an organization. McAlaney et al. (2016) argue that the
most reliable motivation is intrinsic, the strongest being pride in one's competence or in an
organization's value system, and has greater value than compliance-driven enforcement.
Organizations then must appeal to self-determination and not merely avoidance of punitive
threats. Patterson and Winston-Proctor (2019) suggested and conceptualizes joining cyber
protective behaviors to a professional identity and performance recognition system as a means to
internalize and enhance secure conduct. Employees tend to describe the process of achieving
success in cybersecurity as becoming a part of how they define success. Motivational shifts
reinforces and are a factor within the learning environment as described by Carcary et al. (2019)
aids in the retention of desired practices. These shifts enable a psychological framing that
changes the practice from “following the rule” to “mastering the self”. The level of motivation
dictates how strong the psychological frame from “following the rule” to “mastering the self”.
Motivation acts as the unseen foundation that defends the technical. Weak motivation exposes
and reinforces the fact that the most sophisticated systems are still underdeveloped and
vulnerable to the human disengagement over time. The development of motivational ecosystems
shifts the practice of cyber security within an organization from a reactive duty to a proactive
culture.
The decision making process involved in cybersecurity is affected by social influence and
group behavior (Das, 2017). In the absence of certainty, individuals tend to mimic the actions
and behaviors of their online social contemporaries. This part of the social learning theory,
proposes that displaying desirable behavior within a group will lead to compliance on a wider
scale. Kohnke (2016) suggests that organizational structures which integrate teamwork with
32
cyber skills, intensify the phenomenon of shared accountability that emerges from the cyber team
identity. This means that the notion of cybersecurity needs to be constructed as a social
undertaking rather than a solitary one. According to McAlaney et al. (2016) the presence of role
models, in particular leaders, greatly enhances compliance with the law. Leaders who are
described as vigilant create what is referred to as cognitive shields, which are behavioral patterns
that employees will follow. These studies emphasize the fact that cybersecurity is best performed
in environments where the culture is practiced rather than the rules being enforced. Integrating
social learning theory into training helps create a supporting system of practice which fosters
secure behaviors, even in stressful situations.
Nudges and gamification do encourage better cyber security practices in a much easier
manner. Feedback, rewards, and competitive elements in interactive classrooms increase
emotional and cognitive investments. Patterson and Winston-Proctor (2019) explain these
strategies as intrinsic motivators that shift passive rule compliance to rule compliance through
challenges. Complex educational approaches as Wei et. al (2016) describes, gamified strategies
have better effectiveness in serving diverse learning needs. This, in turn, enhances inclusion and
retention. Carcary et. al (2019) show that feedback and social recognition integrated with
behavior frameworks sustain attention through micro-motivations. These elements of security
behavior are put in a playful manner, and as such, much easier to adopt and maintain. This is
very true for the gamified approach which minimizes the psychological gap between an action
and an awareness of it; it enables an active participation. When used along with other
approaches, deliberately and thoughtfully applied, it enhances enduring, effortless attention and
strengthens omnipresent self-discipline.
33
The problem with risk cognition explains why users tend to make irrational decisions
regarding cybersecurity. McAlaney et al. (2016) point out that individuals tend to arrive at
decisions using swift emotional assessments and emotional responses to digital risks. This may
lead to an unwarranted extreme sense of confidence, or an equally extreme sense of
hopelessness, and neither position is healthy in terms of secure behavior. Montasari et al. (2018)
contend that adversaries exploit these irrational biases using persuasive technologies and social
engineering that target strong emotional responses like urgency, and fear to bypass rational
judgement. Awareness of this manipulation capability argues for emotionality in cross
disciplinary cyber security training. Patterson and Winston-Proctor (2019) advocate for training
programs that immerse users in realistic phishing and other deceptive situations to enhance
emotional resilience and situational awareness. Such training prepares individuals to identify and
thwart manipulation in advance of its execution. By focusing on emotions and irrational
thinking, organizations ready users for exploitation, turning psychological gaps into an defense.
Understanding one’s actions on a computer is the result of a complex interplay of
behavioral science, company dynamics and technology. According to Meinig et al. (2019),
predictions for the chances of a breach occurring are more accurate when human behavioral
components are included together with baseline technical measures. This integration facilitates
the merging of psychological thinking and engineering thinking, and further solidifies the
argument that computer science is a field that encounters social and technical aspects. Instead,
the reaction is given to the suggestion made by Carcary et al. (2019), that policies which are
human centered are improved by the feedback created from surveys, performance metrics, and
cultural audits. This understanding of a problem amplifies operational intelligence by adding
behavioral insight. The work of Montasari et al. (2018) stresses that controls may need to be
34
changed in order to mitigate risks in cases when adaptive systems are able to learn from
behavioral patterns of people. These perspectives shift the view of computer science from
technology management to the management of human ecologies. People are protected not only
because of the understanding that their behavior is the most important element of cyber
resilience. Strategies also change because they are the very people that such tactics are aimed at.
Integrating Cyber Ethics and Digital Responsibility Frameworks
The strategic incorporation of cyber ethics within an organization begins with the
assertion that every technological decision is a decision of morality. As highlighted by
Elmelhem, Bouras, and Ghemri (2018), the social and human effects of cyber and information
systems should be ethically foresighted during the systems design stage. This placement of cyber
security design and systems within the moral frame of social trust and justice, and not merely a
technical frame, expands the ethics of cyber security beyond the traditional defensive posture of
cyber walls. When systems are designed with ethical reasoning, the risk of systemic bias and
harm in the name of efficiency is removed. Sustainable security advantage is, as Barclay (2014)
puts it, a by-product of the moral responsibility embedded in the governance systems of a
corporation. Such governance alignment ensures that ethical responsibility is operationalized and
measured as part of organizational performance, and not just as a statement of posture. The study
by Taitto, Nevmerzhitskaya, and Virag (2018) illustrates that ethics based decision making is
also enhanced through simulation environments with ethical frameworks where teams can
interact with the consequences of their actions on the morality of the situation. All of these
innovations and strategies seem to indicate that the relationship with ethics in modern businesses
is increasingly moving from compliance to conscience, and is increasingly woven into the
technical and management systems of an organization.
35
The Newhaven Institute for Cyber Security Ethics identifies three principal theories of
philosophy that underpin the discipline of cyber security ethics as deontology, consequentialism
and virtue ethics. Deontology emphasizes the ‘principled’ and duty-bound adherence to the
ethics of privacy and confidentiality as described by Ani, He and Tiwari (2017). Deontological
principles of ethics provide ‘guidance and counsel’ for ethical practitioners against a myriad of
possible compliance pressures. On the contrary ethical rigidity doesn’t resolve the electronic and
cyber security paradoxes (Marotta & McShane, 2018) ). Outcome ethics that are goals and
targets based, expands the opportunities available for ethical practitioners to operate in.
Consequentialist ethics as a technique of problem solving, however, bare the ethical practitioner
with formidable challenges. Ethical practitioners are accomplices to their own demise. The
dilemma of outcome driven ethics is the propensity to justify ethics of covert and intrusive
surveillance plus excessive and disproportionate retribution of countermeasures. Barclay (2014)
rounds off the discourse by stating that virtue ethics motivates the practitioner in cyber security
and information technology to nurture moral courage and character. The ethics of a practitioner
is a virtue that develops in a professional culture that transcends setting and obeying boundaries
of discipline. These discourses when applied in total construct ethical and moral resilience.
Reasoning without visible structures is fundamental in defining and protecting the dignity of the
organization and the ethical practitioner of the discipline.
The erosion of privacy is at the center of the ongoing tension between surveillance and
democracy with regard to algorithmic governance and modern cybersecurity issues. According to
Elmelhem et al. (2018), the user safety and user intrusion boundary has been increasingly blurred
due to the automated user behavior monitoring systems. This ethical paradox is not
straightforward and needs solutions that accommodate both the national security and civil liberty
36
frameworks. Ani et al. (2017) claim that lack of oversight on critical infrastructure monitoring
can result in an erosion of public trust and an unreasonable concentration of power. Distrust is a
consequence of lack of transparency when security measures evolve to what can be considered
overbearing surveillance. There is over-collection of information in the form of surveillance
when pseudonyms are employed during class attendance in remote learning environments. This
has been demonstrated by Ngwenya et al. (2019) and defines why such behavior is termed lack
of privacy. While these examples emphasize the importance of digital responsibility, they
simultaneously show the need to assess the technological social consequences of the technology.
With justified social consequences, digital privacy can be achieved through reflection on social
behavior, and not the technology that has been created in a democracy. This is the boundary
between `responsible security` and `timid democracy`. It is the commitment to designing systems
that center privacy and social ethics are critical for an actor to be considered a democracy.
The impact of cyber risk quantification and its resultant response also has ethical
dimensions within organizations. Henshel et al. (2016) argue that integrated risk quantification
models should include ethical constructs such as social harm and data justice, in addition to the
traditional financial exposure paradigm. The underlying premise here is to reframe risk in
broader ethical terms as opposed to just economic loss. According to Marotta and McShane
(2018), risk management driven by ethical considerations undertaken in an anticipatory fashion
serves to avert a reactive response to a crisis, thereby promoting clarity and openness in the
decision-making process. This ethical dimension integrates a technical form of thinking with an
impact on humanity. In strong support of this view, Barclay (2014) posits that the maturing of
ethical thinking improves the level of an organization’s capability, thus supporting the alignment
of the quest for a security advantage with the level of public trust. The ethical quantification of
37
risk changes its management approach to a more complex, multi-dimensional one, requiring a
balance between precision and compassion. Organizations that incorporate moral reasoning
within the risk analytics framework foster the necessary credibility and legitimacy that support
enduring cyber resilience.
The ethical concerns posed by AI-powered defense systems are unique. Nhwenya et al.
(2019) articulate how AI ‘monitoring and threat prediction’ tools are trained on biased data and
how this can perpetuate systemic inequity. It raises the concern of automated decision systems’
fairness, accountability, and transparency issues. Taitto et al. (2018) have argued that the
introduction of ethical reviews at the AI system design stage, including the system’s bias and
human oversight, moralizes excessive risks before systems are deployed. This ensures that
automation does not automate judgment. Henshel et al. (2016) argue that simulation models
which integrate ethical constraints and decision loops enable organizations to evaluate the
functional effectiveness and moral defensibility of AI decisions. The point, however, is that
moral judgment cannot be automated. The ethics of AI must instead be emphasized as a
governance oversight, the constant supervisory mechanism in which a specific innovation is
tethered to the human element.
Digital responsibility covers not only organizations, but also the individuals who design,
implement, and operate the defended systems. Rege (2015) points out that the use of experiential
learning models in the teaching of cybersecurity encourages moral sensitivity by placing students
in ethically challenging positions. Such approaches foster empathy, critical analysis, and ethical
reflexes which are needed for exercising leadership in digital spaces. According to Elmelhem et
al (2018) a holistic ethical education framework enables cybersecurity practitioners to function
effectively in situations where the technological pace outstrips the available legal and policy
38
framework. It is therefore no longer sufficient to possess only technical skills. Ethical literacy
also becomes a primary constituent. Ngwenya et al. (2019) propose that ethical role modeling
within virtual and corporate learning ecosystems enhance responsible digital citizenship. When
practitioners reflect upon ethical reasoning at the formative stage of their careers, they are able to
become moral agents who transform the culture of the organizations they work for. Such
practitioners are the result of investment in ethical education which repositions cybersecurity
from the more compliance oriented disposition to one that is value based and socially
responsible.
Currently, international cyber norms and governance frameworks have started setting
ethical boundaries across countries. As Ani et al. (2017) emphasize, the global interconnection of
systems requires the unification of ethical standards to curb the exploitation of cross-border
weaknesses. In the absence of ethical harmonization, the nation's security strategy stands to clash
with the global digital rights policies. Barclay (2014) argues that the Cybersecurity Capability
Maturity Model has the potential to embed ethical accountability at different cooperation levels
between countries, ultimately fostering sustainable collaboration. This ethical reciprocal ensures
that technology is not overused. As noted by Marotta and McShane (2018), international
proactive ethical governance promotes stability by fostering trust, which is a key component of
structural power. Collective ethical defense is resilient moral defense, which suggests that ethical
convergence is a form of defense. Coordinated cyberspace defense as well as technology requires
trust, shared ethics, and not just armament. Every model of a corporation’s governance should
consider ethical digital conduct a strategic asset. As Barclay (2014) claims, the relationship
between ethical governance and innovation helps the organization improve in terms of
adaptability.
39
Instant credibility and reputation make investors, partners, and consumers easily
accessible. Trust is the new currency. As emphasized by Elmelhem et. al (2018), auditing every
ethical cyber-attack governance and decision structure in the organization ensures that ethical
accountability prevails in the processes. Such audits also enable organizations to measure the
success of ethical actions taken. Implementing ethical models is important. Taitto et al. (2018) is
able to show that prediction of reputational impacts of actions by an organization before the
action is taken is possible by internalizing ethical provisions in the simulation paradigms. Such
predictive ethics offer a particular form of foresight that is useful to assess complex relationships
with stakeholders. In such a governance model, the organization is able to change its perception
of cyber security from an expense that is defensive to one that is strategic. Ethical governance,
when enacted through engineering, helps organizations build both technical and reputational
resilience.
The consequences of neglecting the ethics around the socio–economic impact of failures
on cybersecurity are as important as the issue of public security of the country as public as
exemplified by Ani et al. pleas around the severe breach of infrastructural boundaries and the
public safety (2017). The consequences of cyber negligence are physical as well as moral.
Understanding the moral weight of the consequences of cyber negligence shifts the discussion
from IT issues to the ethics and welfare of the society. Henshel et al. (2016) in their works argue
that sub–classes of social harms ought to be included in the models of risk evaluation to help
policymakers internalize the need for moral responsibility in restoration to operational recovery.
This strategy and any strategy for that matter places in the open and square the fact that post–
cyber incident victims are human and part of the discourse and not merely the passive target of
decision making. It echoes the argument of Marotta and McShane that in the current society,
40
organizations that are empathetic and practice ethical behavior during crises, stand better chances
of gaining public confidence when restating the value ethos of the organization in the narrative.
Responsible ethics takes the discussion beyond protective measures like prevention, and
addresses the issue of post–incident response systems where ethical response means an element
of honesty and compassion. These post–incident responses, remove the stigma attached to cyber
security, within the society and civil circles. Such responses illustrate the real and civil value of
compassion.
Moral aspects of information based technologies must advance with the emerging
technologies that could undermine and redefine established norms. Elmelhem et al. (2018) argue
that innovation often advances more rapidly than relevant regulation and peer review which
brings about moral gaps in relation to a new digital resource. Organizations shield themselves
from reacting to ethical dilemmas by investing in proactive ethical foresight which the dilemmas
could escalate to moral crises. To proactively resolve ethical dilemmas within the realm of
technological development, Barclay (2014) proposes strategic ethical proxies which are similar
to the approach used in adaptive cycles of technological development. Revamping proxies
ensures that ethical consideration development keeps in pace with technological iteration. To
extend the adaptation of mechanisms that Taitto et al. (2018) outlined, foresight simulation can
be used to assess the societal implications of technologies such as biometric identification
systems or AI surveillance prior to deployment. Underpinned by moral imagination, these
protective ethics mechanisms are adaptable anticipative governance strategies Stemming from
these arguments, ethical frameworks accompanying technological advances should help or
promote more than regulate or restrain. Progress in technology should resonate with the best
attributes of humanity and not merely with the faster attributes.
41
Strengthening Cybersecurity Governance Through National and Global Policy Integration
At the national level while designing and implementing policies and coordinating the
administrative system on the governance level, policies and technologies are ascribed most
efficiently. Mature national frameworks, according to Tatar, Karabacak and Gheorghe (2016),
constitutional cyber risk management as an integral part to and on the same plane as the national
public Administration framework and system owing to its interwoven and interlinked nexus, and
not as a silo-ed constituent. Such integration assures continuity, as well as accountability and
cross industry silo coordination In administration. Countries that centralize cyber governance,
according to Greiman (2015), streamline siloed policy governance and resource allocation. On
the other hand, centralization of policies and administrative frameworks can lead to bureaucratic
stagnation. Shackelford and Craig (2014) suggest the incorporation of hybrid models, allowing
for national policy framework and steering with local governance on underspecified and locally
developed policies, which enables swift reactions to region-specific issues. All of these studies
highlight the same conclusion, which is policy governance marshalls unity with flexible
administrative frameworks, while multi geo political and technical structures policies need
enduring adaptability.
International coordination for cybersecurity has come to be one of the central issues of
the world in the digital age. According to Greiman (2015), because of the nature of cyber threats,
isolated national defense policies are no longer useful, and governance frameworks must focus
on international collaboration. This interdependence demonstrates the common weakness of
modern interconnected economies. Sutherland (2018) goes on to explain that global governance
instruments, such as international treaties and agreements, are fundamental in establishing global
standards of conduct for the digital space. Still, the state of the world in which there are central
42
and peripheral countries creates obstacles to reaching agreement on fundamental issues.
According to Haddad and Binder (2019), the lack of national agreement in the pursuit of certain
changes often leads to a fragmented policy environment that undermines the possibility of
effective international governance. Such issues illustrate that real cooperation in cybersecurity
goes beyond the alignment of policies and frameworks to include confidence, accountability, and
mutual acknowledgment of policies and frameworks of key global players.
Both the Budapest Convention and several of the initiatives associated with the UN have
had a profound impact on global cyber security norms. Shackelford and Craig (2014) say the
Budapest Convention “provided the first legal framework for the prosecution of cybercrime …
and encouraged cooperation [among] the countries that signed the Convention…” However,
despite its popularity, lack of adoption and implementation is most common in the areas with a
lack of trust toward the West and its governance models. Haddad and Binder (2019) argue that
the UN Open-ended Working Group on ICT Security is more representative because it focuses
on a broader range of constituents, which includes developing countries and civil society. Such
pluralism adds to the scope of participation and the normative legitimacy of the process.
Greiman (2015), however, warns that progressive development of international legal instruments
is needed, responsive to the new technologies, or else they will become antiquated. These
instruments underscore that the governance of cybersecurity is a balancing act between
universalism and sensitivity to cultural and political conditions, allowing both global norms and
regional practices.
The development of strategy towards any form of cyberthreats relies heavily on public-
private partnerships. According to Hohmann, Pirang, and Benner (2017), the use of the
capabilities and resources of the private sector by the government, especially for the purpose of
43
mitigating cyber threats, has now become a norm. This form of collaboration addresses gaps in
capabilities and accelerates the pace of innovation. Structure collaboration also aids in the
development of situational awareness through the sharing of intelligence on threats and the joint
planning of responses, as noted by Sabillon, Cavaller, and Cano (2016). These types of
partnerships, however, need to find the right equilibrium between transparency and concerns
over proprietary information. Without governance structures, as Das (2017) argues, the private
sector’s domination over the decision-making processes of cyber security makes accountability
processes democratic in form only, and not in substance. Such domination fuels the erosion of
democratic accountability. Thus, a balanced, well-governed partnership model is necessary in
which both power and trust are equitably distributed. The need for such partnerships is driven by
the need to ensure sustainable, resilient, and cooperative ecosystems across sectors rather than
competitive silos.
The foundational element of enduring governance effectiveness is the advancement of
cyber capacity building. The national capacity programs that dedicate themselves to training,
institutional preparedness, and international collaboration yield sustained resilience. This is the
key to Hohmann et al (2017). The nation is equipped with human capital that is able to manage
and enact policies, as well as resolve crises. Capacity building, according to Greiman (2015),
should stay well beyond the boundaries of technical skills to include governance literacy. This is
the capacity of leaders to appreciate the technology and the politics of cyber policy. Regionally,
Sabillon et al (2016) argues that cooperation networks contribute to capacity enhancement by
cross-border pooling of resources. It is this collective learning that reduces the duplication of
effort and enhances knowledge diffusion. In particular, developing countries benefit when
capacity-building programs are designed around inclusiveness and local empowerment. Thus,
44
cyber capacity is a strategic asset to the global security commons which strengthens national as
well as international order.
Examining international frameworks demonstrates the different ways countries handle
the regulation of cybersecurity. Greiman (2015) describes the U.S. NIST Framework as
performance-based, focusing on voluntary adoption across industries and broad cross-sector
applicability. On the contrary, the EU Cybersecurity Act follows a more restictive approach
focused on enforcement of certification and regulatory compliance. The differences serve
distinctive approaches to governance: freeform as opposed to rigid, as noted by Sabillon et al.
(2016). In attempts to increase compliance efficiency and interoperability, Tatar et al. (2016)
suggest cross-recognition frameworks. However, compliance by over-standardization may lead
to the loss of innovation, especially in new and developing industries. These stark differences
pose the conclusion that governance of innovation must be balanced with regulation, focusing on
responsibility for what is created. Denationalization of frameworks accompanied by coherence at
an international level, is what fosters freedom for integration.
The sociotechnical perspectives on how nations imagine a digital society are now having
more impact on cyber governance than ever before. Haddad and Binder (2019) note that the
policy narratives that accompany a given country’s cyberspace often reflect the general political
stance of the country, be it techno-optimism or governance that focuses on the control side of
things. These narratives decide which of the two narratives dominant - whether cyberspace is a
liberating or a surveilling sphere. Sutherland (2018) argues that liberal democracies stress the
protection of the citizen and access to information, while authoritarian regimes stress control and
information monopoly. Montasari, Hosseinian-Far, and Hill (2018) further elaborate that the
cultural propensity toward control of risk and privacy of information shape how the citizens and
45
the state share the burden of responsibility in a society. These sociotechnical factors, if
appreciated, would help policymakers to formulate governance frameworks that culturally
balance the model of governance in which citizens are socially trusted and protected.
Cyber governance analytics incorporates behavioral psychology alongside governance at
the same time. Das (2017) asserts proximity to individuals strengthens the governance-social
justice-counter measure framework. Insufficient equity or net unwarranted repression within
deep control gulf structures may fire the retaliatory resistance or sabotage reaction as point
configuration condition Dalal and Gorab (2016) post. Hohmann et al (2017) attest the use of
behavioral studies in policymaking, especially with regard to incentives and the provision of an
open feedback loop, improves compliance across the board. These traits or ins. These traits or
ins. These traits or ins. Managing people in sync with technology and realizing governance
without the need for enforcement is made possible by integrating psychological insights and
strategy within state policy.
Examples of cooperation on a regional scale illustrate the deepening of governance
integration as a means of improving resilience beyond the borders of a nation. For example,
Sabillon et al. (2016) consider the EU cybersecurity strategy as a model of transnational
coordination tending to the integration of accepted standards, incident response systems, and
central command. According to Greiman (2015), parallel activities in the Asia-Pacific region
emphasize the convergence of trust and the management of interdependent infrastructure risk.
According to Hohmann et al. (2017), the success of these ventures is as a result of the multi-
tiered governance systems which blend nation-state control with regional cooperation. Such
governance systems with a collaborative framework ensure that smaller countries have access to
the pooled knowledge and resources. Effective regional governance is, therefore, the layer of
46
governance which is above a nation-state and below global polity agreements, which enhances
collective defense by the multi-tiered obligation.
The governance of cybersecurity at the national level also requires designing policies
which are flexible. Haddad and Binder (2019) argue that imposed regulations lack relevance in
the face of changing threats and thus need dynamic policy frameworks that are responsive in situ.
Tatar et al. (2016) argue that governments would benefit from engaging in scenario planning and
predictive modeling to test the impacts of rapid technological and disruptive political changes.
Montasari et al. (2018) promote the need for dynamic self-governing strategies that learn self-
critically from previous cyber events to continuously evolve rules and response strategies. Such
adaptive approaches, which mimic systems resilience at the level of biology, allow systems to
change and grow rather than fail under pressure. In such scenarios, governance is responsive,
which means that focus shifts from the designing of policies to the management of policies. In
doing so, the effectiveness of the system is preserved even in the face of unpredictability.
In dealing with cybersecurity on a global scale, a balance still has to be struck between
sovereignty and interdependence. “Shared responsibility” challenges the idea of sovereignty and
state control, given that no nation can single-handedly secure cyberspace. Shackelford and Craig
(2014) assert that cooperative sovereignty enhances collective capability without eroding
independence. Sutherland (2018) suggests that such arrangements need robust diplomatic
mechanisms to regulate the balance of power and sustain trust. The outcomes discussed above
are fundamental in emphasizing that cybersecurity governance is in a new era of networked
sovereignty, in which cooperation is a form of geo-economic power. Strong and resilient digital
governance now means accepting interdependence as a condition of security rather than a
liability of sovereignty.
47
Blending domestic and international policies on cybersecurity amounts to the resolution
of fundamental ethical and operational issues. Haddad and Binder (2019) observe that effective
governance embraces overlapping jurisdictions on the principles of transparency, proportionality,
and accountability. As Greiman (2015) insists, the alignment of these principles with technical
criteria provides an overriding framework that integrates ethics with policy action. Das (2017)
has argued that the inclusion of social equity in global governance structures increases
legitimacy by allowing all countries, irrespective of their capabilities, to participate in the joint
rule-making exercise. Ethical alignment is the fundamental layer that integrates different systems
into an architectural framework of trust. The outcome is not uniformity but rather an adaptable
and harmonious system that fosters cooperative autonomy and concord to advance digital
resilience.
Advancing Cybersecurity Metrics and Performance Evaluation Systems
Metaphorically comparing cybersecurity threats to actual actions, cybersecurity
‘measurement’ suggests a more progressive approach. According to Ali and Jali (2019), it is
imperative to augment technology-driven performance with people-oriented measures when
undertaking evaluations within organizations. This equilibrium paradigm approximation attempts
to portray the intricate system-user relations that mark most security environments. Situational
awareness and the information’s substance is what Antikainen (2014) advocates for regarding
matters concerning metrics and their practicality in assessing resilience at the national level. This
model points to the failure to integrate accuracy, relevance, and timeliness in the analysis as a
major shortcoming, especially in matters concerning cybersecurity. Salim (2014) broadens the
scope by integrating systems thinking which views metrics as portrayals of interdependence at
social, technical, and organizational layers. Salim’s perspective makes it possible to understand
48
the systems thinking model. Treating the social system as a subsystem of the technical system
within which a social system exists. In cybernetic systems thinking, Heisenberg's uncertainty
principle suggests the focus of interest is directly proportional to what is left unaccounted. Thus,
by intentionally viewing cybersecurity in such a contextual manner, analysis is made possible for
the oversights which often pass as ‘known vulnerabilities’ or ‘labeled hidden’. These oversights
are often hyper-failures within ineffective cyber security. Therefore, the volume of data legally
captured and the discovered data are often proportional to the level of ignorance in the
sociotechnical system.
Across different systems, quantitative metrics continue to be important for measuring
different risks. As Ani, He, and Tiwari (2017) point out, industrial infrastructures use
quantitative approaches such as the Common Vulnerability Scoring System (CVSS) to
categorize risks and determine the severity of the required response. These models are uniform
and logical, but their abstraction tends to omit the context. Salim (2014) points out that
numerical risk matrices can reduce very complicated relationships to a simple level that misses
the potential for cascading failures and errors of omission and commission by people. Antikainen
(2014) advocates for the use of information fusion techniques to enhance the qualitative
information which such numerical models are based. The Quantitative and qualitative viewpoints
in such fused models create composite indicators that can be used to monitor ever evolving threat
environments. Over reliance on qualitative indicators such as numerical scores can be and often
is a case of false precision. True integrity indicators of cyber resilience come from constructing a
balance between qualitative and quantitative measures. Therefore, metrics need to change from
rigid numbers to responsive elements that determine real time strategic moves.
49
The complements of qualitative evaluation attend to behavioral and cultural aspects of
cybersecurity. As Suresh (2018) points out, analyzing how people cope in a crisis sheds light on
what an organization is able to do in addition to technical capabilities. These trust, decision
speed, and communication effectiveness factors behavioral metrics are often absent in risk
models. Ngwenya et al. (2019) showed that in virtual learning settings, certain self-analysis tools
that measure user engagement and awareness provide qualitative data that can be used to
improve security. Ali and Jali (2018) contend that people-technology interaction metrics improve
digital transformation by pinpointing deficient interfaces in human-automation systems. These
the qualitative insights point out assessment gaps in the reliability of a system and the
corresponding adaptability of a person. Motivation, culture, and perception of qualitative metrics
by the organization shift measurement from a mechanical form of auditing to learning.
The use of composite indices provides a balance between flexibility and accuracy when
assessing cyber security in an organization. According to Antikainen (2014), the integration of
diverse indicators, technical, processual, and human, creates a unified resilience index that can
serve both national and corporate governance. Composite indices bring different indicators and
data streams to a single analytical and evaluative perspective. Taitto, Nevmerzhitskaya and Virág
(2018) modeling simulation environments with composite indices enable policy makers to
anticipate and identify systemic weaknesses before the onset of a crisis. Such models serve as
ethical and operational testing laboratories. According to Salim (2014), systems composite
indices depict interdependency and interrelation of organizational processes and therefore,
prevent silo thinking. Thus, the use of composite indices improves the decision-making process
in the organization by converting data to knowledge that can and should be acted upon. The
50
diverse indicators, through synergy, create a single unified, coherent and interrelated narrative of
resilience that allows for strategic wisdom.
The development of evidence-based cybersecurity governance now includes considering
the importance of key performance indicators (KPIs) as critical evidence tools. Ali and Jali
(2018) note that it is important to integrate KPI targets to different organizational levels so that
every investment made into a security resource system is aligned to a strategic outcome. This
change enables the transformation of cyber security investment from a loss to a value gaining. As
noted by Suresh (2018), even people-centered KPI indicators such as incident reporting and
compliance system participation relate to organizational culture levels as much as they do to
technical proficiency. Ngwenya et al (2019) argue that performance indicators integrated into
'anytime, anywhere' teaching and learning systems promote accountability as well as
transparency. On the contrary, a singular focus on numeric goals can hamper genuine
organizational resilience. This is the essence of over compliance. These fundamental, over
compliance defined, are the most critical components to effective performance evaluation, to
remind oneself that the measures are there to be performance indicators, rather than performance
restrictors.
The metrics presented within OSINT now hold weight when evaluating national and
corporate cyber security systems (Tabatabaei & Wells, 2017). OSINT frameworks enhance
situation awareness through the analysis of emerging threats backed by publicly available data,
which improves the pre novice cyber defenses (Antikainen, 2014). Amongst the multitude of
open and freely available cyber threat intelligence, OSINT derived indicators seamlessly
integrated within cyber resilience frameworks improve responsiveness by uncovering weak
signals of attack before attack escalation (Antikainen, 2014). Ani et al. (2017) demonstrate how
51
OSINT based monitoring in industrial settings reveals critical supply-chain vulnerabilities that
remain undetected by internal audits. These case studies present the notion that external
intelligence provides value in conjunction with internal measures to build a more complete
depiction of exposure. They exemplify the value of internal metrics, demonstrating how external
sources of intelligence deepen the insight derived from internal measures. The possible OSINT
derived data should be recognized within the context of accountability frameworks so that
organizations balance the use of collective intelligence responsibly with the improved speed of
detection, and increased trust in the systems.
The learning cycles highlighted in this work are greatly supported by cybersecurity
metrics. Salim (2014) suggests a systems-thinking framework that uses the feedback from each
of the incidents to refine the policy to the essential elements of the analysis. Such a framework
creates a cycle that turns the metrics to evaluation learning instruments. Antikainen (2014)
demonstrates the usefulness of models of situational awareness that use real time data fusion to
show how organizations can change controls in real time. Suresh (2018) asserts that metrics that
quantify incidents during training greatly improve people-centric crisis management. These
adaptable processes are what demonstrate that metrics are relevant in the changing worlds of
threats. Therefore, the ability to measure such metrics reflects an intelligent organization, the
ability to learn, anticipate, and improve through introspective analysis. Such metrics demonstrate
that the organization has attained learned resilience. In this case, resilience is the purely defined
the feedback score cut through the adaptation cycle.
Across critical sectors of infrastructure, accuracy is one of the cornerstones of reliability
and safety. In manufacturing, Ani et al. (2017) articulates the importance of stringent auditing
and control metrics to prevent disruption of physical operations by cyber incidents. Antikainen
52
(2014) notes that resilience models that include indicators of operational continuity perform
better along the fusion of digital and physical protective layers. Salim (2014) defends the notion
that system-theoretic process models, which evaluate the interactions of subsystems, enhance
predictive and preventative capabilities toward cascading failures. These models exhibit cyber-
physical security’s need for multi-layered metrics on performance, safety, and resource
efficiency. The combination of engineering standards with cyber security measures provides
systematic balance between operational reliability and digital defensive measures. This balance
shifts the dominant narrative of security governance as a hindrance to productivity and
innovation, to a strategic facilitator.
An account of measurement in cybersecurity also needs to account for ethical and social
dimensions. With reference to Ali and Jali (2018), evaluation frameworks that focus on human-
technology interfaces promote social accountability through social responsibility evaluation
frameworks. These frameworks evaluate digital spaces for fairness, privacy, and social equity.
According to Salim (2014), systems thinking reveals the unintended negative outcomes that
poorly constructed criteria can have on the policies that center ethical performance in their over-
optimizing policies. Taitto et al. (2018) demonstrate the use of ethical composite indicators
which, through ethical simulations, help forecast moral challenges to the use of certain
technologies. Their approach to ethical evaluation, when integrated with measurement systems,
ensures the ethical alignment of societal progress with technological advancement. Having
ethical frameworks transforms cybersecurity from a functional technicality to its moral essence
of fairness and transparency. Organizations that measure responsibility and risk emerge with
intact systems and unassailable societal legitimacy.
53
Integrating metrics with human performance remains crucial for evaluation purposes.
Suresh (2018) states success in crisis management requires rational alignment of capabilities
with performance indicators. Excessively complex metrics can cause cognitive overload and may
lower decision making quality in emergency situations. Ngwenya et al. (2019) demonstrated that
self-assessment adaptive learning systems enable people to better align their aspirations and
outcomes with current expectations. Ali and Jali (2018) go a step further to state that interactive
dashboards which amalgamate human and machine metrics improve cross team situational
awareness. These results support the idea that measurement should enable and not restrict human
agency. When metrics represent which people truly believe and perform under pressure,
confidence and accountability within the whole organization increases. Bridging human
psychology with analytical precision turns performance evaluation to a relationship between
thought and computation.
The techniques of simulation and modeling furnish experimental environments for
refining metrics in cybersecurity. According to Taitto et al. (2018), virtual simulation
environments enable scholars to assess how different measurement frameworks work prior to
their deployment in the actual world. These simulation-based studies help determine how various
systems react to different stress levels. As Salim (2014) points out, systems thinking in
cybernetics enhances predictive assessment through simulation by pinpointing failure and
interdependence. Antikainen (2014) advocates for the inclusion of information fusion at basic
levels of simulation in order to augment data for performance assessment. Such approaches
transform the formulation of concepts and positions into practical ways of reflecting on and
simulating the phenomena. Within certain limits, organizations may adjust and fine-tune their
pre-crisis threshold indicators by simulating measurement pressures. In this regard, simulation
54
casts evaluation in the light of multifaceted experimentation, rather than unidimensional
hindsight, thus enhancing both precision and flexibility.
Establishing some level of standardized but flexible metrics is important for a country’s
cybersecurity resiliency. In her work, Antikainen (2014) develops a model that describes the
integration of national information systems with local feedback loops for real-time awareness at
all governance levels. Such integrated measurement frameworks enhance support for
transparency and coordination. As per Salim (2014), systems-based national metrics
geopolitically enhance policy coherence by integrating the institutional and the technological.
Furthermore, Ali and Jali (2018) maintain that dashboards for nations ought to include human-
centric indicators to strengthen inclusivity and accountability. These strategies enhance a robust
governance structure that is proactive in detecting governance stringency and systemic dangers.
The more nations standardize metrics to achieve comparability, the more adaptable and
responsive they become at the same time. Thus, national metrics that are non-standardized
become governing instruments that enable policymakers to ensure a level of security while
fostering innovation.
The change in evolution concerning the measurement of cybersecurity indicates a move
change in ownership from control to collaboration. According to Suresh (2018), metrics are
owned and answerable to by users and managers as well as the technical team when employees,
policymakers, and technical teams are integrated in the design of the performance metrics. The
measurement processes are more transparent as suggested by Tabatabaei and Wells (2017) when
open intelligence approaches are used in the assessment. Ngwenya et al. (2019) highlight that
self-analysis platforms that support collaborative monitoring of the activities self-analyzed
improve the extent of collective responsibility held by employees concerning cyber hygiene.
55
These models of participation in governance and design give ownership of the security
participatory paradigm and evaluation marks a change to distributed ownership from control.
Collaboration disburses measurement of security and fosters trust among stakeholders. As threats
to cybersecurity are more and more interconnected, trust among stakeholders and participation
without oversight ensures that measurement approaches to resilience are both meaningful and
measurable through compliance, context, and collective commitment.
Balancing Artificial Intelligence, Automation, and Human Oversight in Cyber Defense
The field of machine learning (ML) has enabled the automation of mundane and complex
tasks across several domains. For example, Henshel et al. (2016) emphasize the importance of
machine learning-based automation and its effectiveness in enhancing the precision of modelling
cyber risks by processing large datasets. Studies such as Morris and McShane (2018) have
showcased the increased diffusion of cyber threats because of the speed at which threats are
responded to. Such studies emphasize the importance of balance, as backward and forward
planning, when structuring the approach to incident response. Today, integrated cyber security
measures are more effective paired with human oversight (e.g. automated cyber security
systems) rather than deployed in isolation (Barclay, 2014). The principles of cyber security
capability maturity models reflect the importance of ethical accountability in the use of machine
learning. As such, the most defendable environments are those in which there is a synergy of
speed, precision and accountability in the machine learning processes deployed.
Choras et al. (2015) reports that adaptive models using unsupervised learning can
effectively identify evolving attack signatures, even in the absence of prior knowledge of
associated attack patterns. This flexibility enables unsupervised models to modify their formation
56
defense to novel threats in real time. Nevertheless, Jacob, Peters, and Yang (2019) remark that
algorithmic learning has a propensity to generate high false positive rates, which defies the
contextual baselines of the model. The alerts that are produced are detrimental to the
effectiveness of security operations centers and lead to the desensitization of security analysts.
Automated systems that calibrate their focuses using human feedback loops are more efficient in
operational tasks (Garcia, Forscey and Blute, 2017). The balance of between alertness and
efficiency is defined by the synergy of automation and human intuition. Intelligent systems
whose learning are unsupervised, algorithm-based and contextual to human reasoning are the
most effective.
Transparency and transparency are challenges in the application of AI in cybersecurity.
According to Barclay (2014), the use of non-transparent algorithms undermers trust and
accountability in the organizational governance and its frameworks. When some decisions are
made in a non-transparent manner, the ethical and legal accountability of any party is. Henshel et
al. (2016) remarked that having interpretable models enhances the confidence of the stakeholders
because the decision-makers are able to follow through the reasoning of the algorithms on which
particular outcomes are produced. This also aids in the auditing and compliance to regulations.
Marotta and McShane (2018) propose the incorporation of explainability as a design element of
automated defense systems, as a means of ensuring that the reasoning of the algorithms remain in
line with the ethical values of the institution. All these show that the efficiency of AI is as much
dependent on the capability as it is on the clarity. Explainability changes artificial intelligence
from a non-collaborative technology to an integrated partner in the governance of the overall
risk, thus, enhancing accountability and the trust.
57
The emergence of adversarial AI has made cybersecurity more complex as it transformed
algorithms into instruments as well as objectives of attacks. Choras et al. (2015) contend that
adversaries can undermine a machine‐learning model by deploying the strategies of data
poisoning and subsequent evasion to alter its threat perception and classifications. Such
weaknesses highlight the paradox of AI defense: the very systems designed to provide security
can in turn themselves be used as attack vectors. Jacob et al. (2019) suggest that algorithm
resilience may be enhanced through diversified defense modeling by fostering cross‐disciplinary
cooperation between computer scientists and behavioral analysts. Garcia et al. (2017) state that
the combination of human red‐teaming and automated systems in a defense posture reveals gaps
that automated frameworks miss. All these studies emphasize the fact that AI defense must
consider intelligent adversaries that would seek to exploit its underlying logic. Effective cyber
defense thus requires not just intelligent algorithms but also interdisciplinary imagination that
predicts and addresses potential circumventions.
The level of automation permitted in Security Operation Center(s) (SOCs) has changed
the entire domain of response management. As Marotta and McShane (2018) noted, integrating
automated, AI-driven triage to the first level of response and alerting systems significantly
reduces response times to incidents and allows human analysts to focus on more complicated and
rewarding aspects of the task. This changed division of labor optimizes the system and reduces
fatigue. On the other hand, Henshel et al. (2016) suggest that too much automation can result in
the lack of situational awareness. Analysts disengaging from the operational detail of processes
may lose the context of the system. Jacob et al. (2019) suggest that hybrid models of SOCs can
be optimized so that automated systems do the pattern recognition and human analysts do the
higher-order strategy thinking. This kind of integration ensures that the human decision making
58
cycle is receiving the proper machine-generated insights. SSCs succeed in achieving automation
when the extend of such automation is designed to sustain, rather than sever, the cognitive
engagement of the analyst in the decision making processes underlying the interpretation of the
changing threat landscape.
The “human-in-the-loop” model acts as a critical boundary to the ethical and practical
challenges posed by AI-enabled cyber defense. As noted by Garcia et al. (2017), uninterrupted
human monitoring guarantees responsibility and situational awareness, especially in the domain
of algorithms attending to potentially catastrophic outcomes. Barclay (2014) argues that adding
human review to the automated workflow bolsters the organization’s integrity and adherence to
the legal frameworks. Rege (2015), adds that the experiential learning systems train analysts to
work seamlessly with intelligent systems with an ‘intuitive’ sense of when to intervene and
override the machine’s decisions. These structures thesis that human supervision is not a
limitation, but an overwhelming anchor that sustains ethical integrity and critical analysis. The
practice of integrating people within automated systems is to ensure that the ethical and
geopolitical dimensions of the field of cyber defense is not lost as computation systems become
more powerful.
For AI-supported security systems, ethical governance goes beyond just system
capabilities. According to Henshel et al (2016), in making ethical AI decision systems,
organizations would consider the reputational and legal risks associated with failing to predict
these consequences. Marotta and McShane (2018) to mention, “the governance frameworks that
are open and accessible serve to close the gap between the technical aspects of a problem and the
ethical issues that arise from its solution.” To encourage pluralist constructs on ethical
governance, Jacob et al. (2019) suggest the inclusion of interdisciplinary ethics committees
59
within the governance of cybersecurity to evaluate the use of compliant AI systems and their
social impact. This suggested model approaches AI ethics from a social, rather than policy,
viewpoint, arguing that sociotechnical governance is a sustained conversation rather than a top-
down policy. The public and social context is very important and continues to change with
increasing capability in technology, public expectations, and the governance of ethical aids in
pro-active cyber defense. The retention of social legitimacy, therefore, in automated defense aids
is contingent upon the open interdependence of the sustainability of advancement, social
responsibility, and ethical development of designed systems.
Without neglecting the essence of human supervision, the potential of AI requires
training and workforce development. According to Rege (2015), learning by doing and gamified
simulations enhances analyst adaptability to AI interactivity by fostering AI immersion. These
learning methods instill critical reflexes that technical training alone cannot achieve.
Furthermore, Jacob et al. (2019) highlight the need interdisciplinary training, focusing on data
science, psychology, and ethics to prepare professionals for partnership with AI. Continuous
professional education, as argued by Garcia et al. (2017), assists human operatives in
overcoming the challenges of bias that systemically AI outputs and enables them to understand
AI’s outputs. This dedication to capability building emphasizes human’s active role in
partnership with machine intelligence to achieve optimum results. This development of cognitive
and ethical AI literacy emphasizes the human element as the foundation of cybersecurity
resilience.
The inclusion of AI in holistic frameworks of risk management improves responsiveness
and adaptive capacity. According to Barclay (2014), AI boosts the Cybersecurity Capability
Maturity Model by providing predictive analytics and early warning systems. Henshel et al.
60
(2016) show that the risk quantification models on AI data fusion fusses out interdependencies
that would otherwise be missed by human assessment. McShane and Marotta (2018) suggest that
AI-driven insights should be embedded in the continuous monitoring systems utilized to steer
resource allocation and resilience planning. AI can be a powerful feedback resource when
embedded in strategic governance systems. The concern that algorithmic predictions remain
aligned with plausible strategic interpretations is important. The human component ensures that
ethical and organizational bounds, rather than purely computational reasoning, surround risk
analysis.
The growth of AI in cybersecurity is the intersection of advanced technology and the art
of reasoning. According to Choras et al. (2015), achieving quantitative growth is only possible
through automation and adaptability, which means the system has to develop in step with human
thought. In their synthesis, Jacob et al. (2019) envision a future in which cybersecurity operates
as the nexus of multiple disciplines, integrating computational sciences with brain science and
legal governance. Ch ascribes the human-augmented intelligent system as the means of shifting
cybersecurity from a reactive defensive posture to one of proactive stewardship. The interplay
between human oversight and AI examining, appreciating the tact in the use of speed and
wisdom. Cybersecurity, as a domain, becomes intelligent and humane the moment automation is
used to extend human creativity rather than replace it. The intelligent and humane character of
cybersecurity is a hallmark of digital age, which is attributed to defining the global future with
integrity.
Future Directions in Cyber Resilience for Quantum and Emerging Technologies
61
Bohem et al. (2018) characterize one aspect of quantum computing as a quantum security
cyber risk. Bohem et al. (2018) and Dawson (2018) explain that the hypothetical construction of
a quantum computer that can run Shor's algorithm demonstrates the need for a radical rethink of
the construction of data encryption and public key cryptography. Dawson (2018) advocates for
organization cyber risk readiness that goes beyond the core technical readiness. Bohem et al.
(2018) and Dawson (2018) emphasize the need for the integration of risk based scenario
planning and quantum security cyber collaborations across disparate sectors. Carcary, Doyle and
Conway (2019) support these ideas suggesting that quantum security cyber risk can and should
be classified as a tier one risk, and the organization as a whole can adapt and build strategic
cyber resilient frameworks. All the cited literature indicates that the cyber risk posed by quantum
technology should be viewed by organizations as a governance and cyber security strategy issue,
not just as a cyber-technology challenge.
Developing post-quantum cryptography is key to securing digital ecosystems. As pointed
out by Matania, Yoffe, and Mashkautsan (2016), some of the novel encryption frameworks using
cryptographic lattices and hash functions aim to keep encryption unreadable, even to quantum
computers. Atoum, Otoom, and Abu Ali (2014) contend that implementing such algorithms to a
holistic approach of cybersecurity will aid in achieving equilibrium among the system’s
confidentiality, integrity and performance. Dawson (2018) contends that unified policy and
coordinated international standards would be needed to avoid the fragmentation of practices in
the implementation of the transition. This goes to show that quantum resilience is a product of
both regulation and innovation in parallel. Post-quantum cryptography will only be resilient to
quantum computer attacks and enduring when under cohesive, trust, transparency, and implied
governance interoperability, and disparate systems.
62
The expanding capabilities of blockchain technology increase the potential for the
development of new decentralized architectures in cybersecurity. According to Elmelhem,
Bouras, and Ghemri (2018), blockchain technology increases the integrity of data through the
distributed consensus model, which prevents the existence of single points of failure. This form
of decentralization moves the frontier of security guarantee systems away from trust frameworks
to systems based on mathematical proofs. Toehm et al. (2018) propose the use of blockchain and
post-quantum cryptographic protocols in the development of hybrid frameworks to overcome
new hybrid systems challenges. Meinig et al. (2019) argues the need to incorporate adaptive
consensus protocols to mitigate new quantum attacks. Such systems would fundamentally
transform the nature of trust from a social construct to an algorithmically driven testament of
proof. Ensuring the systems incorporate ethical flexibility for the need of holistic digital
governance frameworks will be a critical factor in the development of future frameworks.
The lack of adequately planned network 6G and IoT in the future will pose a multitude of
problems in regard to the issues of cyberscape. According to Galinec et al. (2017), hyper-
connectivity will incur a greater attack surface and liabilities at all levels of the digital supply
chain. As Dawson (2018) argues, this connectivity challenges the conventional security
boundaries, thus requiring the adoption of zero-trust frameworks that authenticate constantly and
validate each request. To guarantee persistent integrity, Atoum et al. (2014) suggest
incorporating dynamic identity proofing and behavioral analytics within these frameworks.
Consequently, the combination of IoT and 6G technologies heightens the magnitude of industrial
constants that will need to be in place. The greatest risk will be ensuring that the reach of
technology will not limit control, influence, and ethical boundaries.
63
The rapid advance of technologies requires adaptive governance to safeguard resilience
in the face of challenges. As Carcary et al. (2019) contend, digital governance is shifting from a
focus on compliance to on-the-fly adaptive governance shaped by real-time data analytics.
According to Boehm et al. (2018), resilience stems from a convergence of governance and
continuous feedback from the technical, ethical, and operational domains. Matania et al. (2016)
argues that adaptive governance is the key to a coordinated public and private sector approach to
cybersecurity in a crisis, leading to the effective integration of crisis response. This response
indicates that cyber resilience is a function of institutional adaptability and agility. Agility
requires new governance models that are capable of predicting and accommodating
discontinuities, tolerating and building adaptive mechanisms in the resourcing and decision
processes of protection.
The future of cybersecurity innovation will depend on ethical foresight. As Dawson
(2018) notes, AI and quantum technologies will become even more autonomous and, thus, will
need more ethical restraints to maintain human oversight. Wei, Mann, Sha, and Yang (2016)
argue that moral reasoning should be taught in cybersecurity education because professionals
will have to deal with ethical challenges caused by automated systems and decision-making.
Wrapped in ethics, products will be more aligned to the pace of societal values, and
technological advancement will be less problematic (Elmelhem et al. 2018). These claims
confirm that innovation without moral dimensions could destabilize the very systems it seeks to
defend. Consequently, building cyber resilience will depend on the balance of ethical reasoning
and technical proficiency.
64
References
Ali, F. A. B. H., & Jali, M. Z. (2018, May). Human-technology centric in cyber security
maintenance for digital transformation era. In Journal of Physics: Conference
Series (Vol. 1018, No. 1, p. 012012). IOP Publishing.
Al-Sartawi, A. M. M. (2020). Information technology governance and cybersecurity at the board
level. International Journal of Critical Infrastructures, 16(2), 150-161.
Ani, U. P. D., He, H., & Tiwari, A. (2017). Review of cybersecurity issues in industrial critical
infrastructure: manufacturing in perspective. Journal of Cyber Security Technology, 1(1),
32-74.
Antikainen, J. (2014). Model for national cybersecurity resilience and situation awareness
improvement: An information quality–centric approach leveraging fusion of established
practitioner and academic disciplines.
Atoum, I., Otoom, A., & Abu Ali, A. (2014). A holistic cyber security implementation
framework. Information Management & Computer Security, 22(3), 251-264.
Barclay, C. (2014, June). Sustainable security advantage in a changing environment: The
Cybersecurity Capability Maturity Model (CM 2). In Proceedings of the 2014 ITU
kaleidoscope academic conference: Living in a converged world-Impossible without
standards? (pp. 275-282). IEEE.
Boehm, J., Merrath, P., Poppensieker, T., Riemenschnitter, R., & Stähle, T. (2018). Cyber risk
measurement and the holistic cybersecurity approach. McKinsey & Company,
November, 18.
65
Carcary, M., Doherty, E., & Conway, G. (2019, July). A framework for managing cybersecurity
effectiveness in the digital context. In European Conference on Cyber Warfare and
Security (pp. 78-86). Academic Conferences International Limited.
Choras, M., Kozik, R., Bruna, M. P. T., Yautsiukhin, A., Churchill, A., Maciejewska, I., ... &
Jomni, A. (2015, August). Comprehensive approach to increase cyber security and
resilience. In 2015 10th International Conference on Availability, Reliability and
Security (pp. 686-692). IEEE.
Dalal, R. S., & Gorab, A. K. (2016). Insider threat in cyber security: What the organizational
psychology literature on counterproductive work behavior can and cannot (yet) tell us.
In Psychosocial dynamics of cyber security (pp. 92-110). Routledge.
Das, S. (2017). Social Cybersecurity: Reshaping Security Through An Empirical Understanding
of Human Social Behavior (Doctoral dissertation, Carnegie Mellon University, USA).
Dawson, M. (2018). Applying a holistic cybersecurity framework for global IT
organizations. Business Information Review, 35(2), 60-67.
Demirkan, S., Demirkan, I., & McKee, A. (2020). Blockchain technology in the future of
business cyber security and accounting. Journal of Management Analytics, 7(2), 189-208.
Elmelhem, J., Bouras, A., & Ghemri, F. (2018, December). Towards a Holistic Approach of
Cybersecurity. In 2018 3rd Technology Innovation Management and Engineering
Science International Conference (TIMES-iCON) (pp. 1-4). IEEE.
66
Galinec, D., Možnik, D., & Guberina, B. (2017). Cybersecurity and cyber defence: national level
strategic approach. Automatika: časopis za automatiku, mjerenje, elektroniku,
računarstvo i komunikacije, 58(3), 273-286.
Garcia, M., Forscey, D., & Blute, T. (2017). Beyond the network: A holistic perspective on state
cybersecurity governance. Neb. L. Rev., 96, 252.
Greiman, V. A. (2015). Cybersecurity and global governance. Journal of Information
Warfare, 14(4), 1-14.
Haddad, C., & Binder, C. (2019). Governing through cybersecurity: national policy strategies,
globalized (in-) security and sociotechnical visions of the digital society. Österreichische
Zeitschrift Für Soziologie, 44(Suppl 1), 115-134.
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness
of organizations and its influence on performance. Journal of Information Security and
Applications, 58, 102726.
Henshel, D., Alexeev, A., Cains, M., Rowe, J., Cam, H., Hoffman, B., & Neamtiu, I. (2016,
May). Modeling cybersecurity risks: Proof of concept of a holistic approach for
integrated risk quantification. In 2016 IEEE Symposium on Technologies for Homeland
Security (HST) (pp. 1-5). IEEE.
Hohmann, M., Pirang, A., & Benner, T. (2017). Advancing Cybersecurity Capacity
Building. Global Public Policy Institute (GPPi).
67
Jacob, J., Peters, M., & Yang, T. A. (2019). Interdisciplinary cybersecurity: Rethinking the
approach and the process. In National Cyber Summit (pp. 61-74). Cham: Springer
International Publishing.
Kohnke, A. (2016, October). A Holistic Approach to Cybersecurity: Mapping the NICE
Workforce Framework to the Critical Infrastructure Cybersecurity Framework.
In Journal of The Colloquium for Information Systems Security Education (Vol. 4, No. 1,
pp. 20-20).
Kumar, S., Biswas, B., Bhatia, M. S., & Dora, M. (2021). Antecedents for enhanced level of
cyber-security in organisations. Journal of Enterprise Information Management, 34(6),
1597-1629.
Marotta, A., & McShane, M. (2018). Integrating a proactive technique into a holistic cyber risk
management approach. Risk Management and Insurance Review, 21(3), 435-452.
Matania, E., Yoffe, L., & Mashkautsan, M. (2016). A three-layer framework for a
comprehensive national cyber-security strategy. Geo. J. Int'l Aff., 17, 77.
McAlaney, J., Taylor, J., & Faily, S. (2016). The social psychology of
cybersecurity. Psychologist, 29(9), 686-689.
Meinig, M., Sukmana, M. I., Torkura, K. A., & Meinel, C. (2019). Holistic strategy-based threat
model for organizations. Procedia Computer Science, 151, 100-107.
Montasari, R., Hosseinian-Far, A., & Hill, R. (2018). Policies, innovative self-adaptive
techniques and understanding psychology of cybersecurity to counter adversarial attacks
in network and cyber environments. Cyber criminology, 71-93.
68
Ngwenya, T. M., Elleh, F., McKoy, C., Lloyd, F., Kemp, R., Carrillo, R., ... & Cochran, T.
(2019). Self-Analysis Technology, Roles, and Cybersecurity in the Virtual Learning
Environments. In Recent Advances in Applying Identity and Society Awareness to Virtual
Learning (pp. 226-254). IGI Global.
Patterson, W., & Winston-Proctor, C. E. (2019). Behavioral cybersecurity: Applications of
personality psychology and computer science. CRC Press.
Rege, A. (2015). Multidisciplinary experiential learning for holistic cybersecurity education,
research and evaluation. In 2015 USENIX Summit on Gaming, Games, and Gamification
in Security Education (3GSE 15).
Sabillon, R., Cavaller, V., & Cano, J. (2016). National cyber security strategies: global trends in
cyberspace. International Journal of Computer Science and Software Engineering, 5(5),
67.
Salim, H. M. (2014). Cyber safety: A systems thinking and systems theory approach to managing
cyber security risks (Doctoral dissertation, Massachusetts Institute of Technology).
Shackelford, S. J., & Craig, A. N. (2014). Beyond the new digital divide: Analyzing the evolving
role of national governments in internet governance and enhancing cybersecurity. Stan. J.
Int'l L., 50, 119.
Suresh, P. K. (2018). People centric cyber crisis management.
Sutherland, E. (2018, March). Cybersecurity: Governance of a new technology. In Proceedings
of the PSA18 Political Studies Association International Conference, Cardiff (pp. 26-28).
69
Tabatabaei, F., & Wells, D. (2017). OSINT in the Context of Cyber-Security. Open Source
Intelligence Investigation: From Strategy to Implementation, 213-231.
Taitto, P., Nevmerzhitskaya, J., & Virag, C. (2018). Using holistic approach to developing
cybersecurity simulation environments. In The International Scientific Conference
eLearning and Software for Education (Vol. 4, pp. 77-84). " Carol I" National Defence
University.
Tatar, U., Karabacak, B., & Gheorghe, A. (2016, March). An assessment model to improve
national cyber security governance. In 11th International Conference on Cyber Warfare
and Security: ICCWS2016 (p. 312).
Walton, S., Wheeler, P. R., Zhang, Y., & Zhao, X. (2021). An integrative review and analysis of
cybersecurity research: Current state and future directions. Journal of Information
Systems, 35(1), 155-186.
Wei, W., Mann, A., Sha, K., & Yang, T. A. (2016, September). Design and implementation of a
multi-facet hierarchical cybersecurity education framework. In 2016 IEEE Conference on
Intelligence and Security Informatics (ISI) (pp. 273-278). IEEE.
Yaacoub, J. P. A., Noura, H. N., Salman, O., & Chehab, A. (2022). Robotics cyber security:
Vulnerabilities, attacks, countermeasures, and recommendations. International Journal of
Information Security, 21(1), 115-158.