I need this revised today omgggggg
a year ago
8
Project_Plan_Template3.doc
feedback52825.docx
annotated-ProjectplanV8926main12028129-1.docx.pdf
- ProjectPlanGuideCapstoneFinal.pdf
Project_Plan_Template3.doc
feedback52825.docx
Hi Brittany,
Thank you for resubmitting your project plan. Your work continues to reflect a deep interest in organizational and behavioral responses to ransomware threats in healthcare settings. This topic is both timely and significant. However, to move your plan forward, several key revisions are still required.
Template Use Is Mandatory
I must emphasize that your project plan must be submitted using the official Capella DIT Project Plan Template. I have reminded you of this requirement on at least ten occasions across this course and the previous one. This is not a recommendation—it is a program requirement.
Without the proper template, your submission:
· Cannot be fully reviewed using the DIT rubric
· Will not move forward to secondary review
· Lacks the structural elements required by Capella and the academic review process
Please ensure your next submission is formatted using the template available in the course room.
Specific Business Problem – Overloaded with Multiple Constructs
Your current version of the specific business problem includes too many distinct and complex issues, such as:
· Underdeveloped training programs
· Policy enforcement gaps
· Insider threats
· Employee noncompliance
· Delayed recovery
· Regulatory failure
· Organizational culture
· Cognitive biases
Each of these is a separate organizational or technical challenge. Including them all makes it impossible to maintain alignment with your research question, framework, and methodology.
Recommended Narrowed Focus
To create alignment across your project, I recommend focusing on a more defined issue:
Revised Specific Business Problem: The specific business problem is that IT professionals in healthcare organizations face challenges addressing ransomware threats due to the combined influence of cognitive biases and inconsistent policy enforcement, resulting in delayed response and increased organizational risk (Vishwanath, 2020).
This version is:
· Practice-based
· Supported by literature
· Feasible for qualitative inquiry
· Aligns with human-centered cybersecurity frameworks
Revised Research Question (Aligned with GQI)
How do IT professionals in healthcare organizations address the influence of organizational policies and cognitive biases when responding to ransomware threats?
This open-ended question avoids causal language, aligns with generic qualitative inquiry, and supports your intended exploration of organizational and behavioral factors.
Framework Misalignment
Your current framework references are vague and inconsistent with your constructs. To support your revised problem and question, I recommend selecting a framework that explicitly explains how behavior and decision-making are shaped by organizational or cognitive factors.
Recommended frameworks include:
· Cognitive Heuristics in Cybersecurity (Vishwanath, 2020)
· Protection Motivation Theory (PMT) – Focused on how individuals assess and react to threats
· Theory of Planned Behavior (TPB) – Useful for understanding compliance-related actions
Whichever framework you choose, it must:
· Clearly align with your constructs (e.g., cognitive bias, organizational policy)
· Inform your data collection and interpretation
Define Your Target Population
You reference "IT professionals" broadly, but your project plan lacks details on:
· Who qualifies as an IT professional (e.g., engineers, analysts, CISOs)?
· Where they work (e.g., mid-sized U.S. healthcare organizations)?
· How many participants you plan to include?
Suggested Language:
The target population for this study consists of IT professionals—including engineers, analysts, and cybersecurity managers—working in U.S.-based healthcare organizations that have implemented ransomware response protocols.
Clarifying your population now will help with recruitment planning and IRB preparation in Week 10.
Action Items for Revision
1. Transfer your content into the official DIT Project Plan Template.
2. Revise your specific business problem to focus on one issue.
3. Submit one open-ended research question that aligns with the problem.
4. Select a framework that directly supports your constructs and research design.
5. Clearly define your target population, including roles, setting, and scope.
Once you’ve addressed these issues, I’ll be happy to re-review your plan for secondary submission to the DIT program reviewer. Please feel free to schedule a time to discuss if that would be helpful.
Best regards, Dr. Marbury https://raymondmarbury.youcanbook.me
Reference Vishwanath, A. (2020). The weakest link: A psychological perspective on why employees fail to adhere to security policies. Cyberpsychology, Behavior, and Social Networking, 23(5), 321–327. 10.4018/978-1-60566-036-3.ch004
annotated-ProjectplanV8926main12028129-1.docx.pdf
Britney Jackson
Learner ID: 2658828
Capella University
Information Technology
Capstone
Qualitative
Spring 2025/ DIT-V8926
Project topic
Enhancing Ransomware Mitigation Strategies Among IT Professionals: A Qualitative
Exploration of Organizational Resilience and Response Frameworks.
Alignment to the Program of Study
By focusing on why and how systems and people resist ransomware attacks, the project helps
develop skills important to cybersecurity. The study bases its analysis on what healthcare IT
experts do and decide which links human aspects to the organizational requirements in
information assurance and security compliance. The curriculum focuses on outcomes for incident
response, protecting computer systems and managing risks in important sectors.
Project Problem
This research focuses on the issue that cybercriminals are rapidly evolving ransomware, and their
attacks push mid-sized healthcare organizations to handle human factors and cognitive errors
more efficiently. There are many technical ways to protect systems, but little is understood about
how IT professionals’ approach, carry out or resist these rules. Because firms do not fully
understand resilience, they keep experiencing similar weaknesses and recovery challenges.
Problem to be Addressed
Despite a rise in ransomware attacks on mid-sized healthcare companies, many have not fully
developed training programs for staff, follow compliance or notice threats from staff actions. In
these circumstances, IT specialists frequently lack understanding of how cognitive biases and
company culture influence their ability to stick to the required safety steps. Due to this, security
is regularly compromised, recovery takes time, and companies fail to meet regulations, posing
different types of financial and functional risks in major service areas.
Gap
Very little has been written about linking technical, behavioral and organizational approaches to
ransomware prevention. The present literature on the subject examines technical problems and
compliance requirements without delving into how professionals working in IT understand and
manage these practices. This research reviews the need to see how IT professionals decide and
respond to various situations. With the speed of ransomware rising and more healthcare services
being handled electronically, it is especially important to know several aspects of cybersecurity.
Supporting Evidence
Several academic publications have established core concepts regarding ransomware attacks and
their defensive strategies.
Lee and Choi (2022) apply the theoretical framework of cyber-routine activities to
understand ransomware role in Bitcoin usage since terrorists employ this digital money for
various mysterious reasons.
Ryan (2021) inspects the economic aspects of ransomware, explaining how attackers
build their ransom demands while examining the financial costs faced by organizations.
The research provides essential economic and theoretical knowledge, yet fails to assess
how organizations respond to real incidents in practice. Wang et al. (2021) conducted research
establishing NIDS and EDR solutions as practical tools that enhance proactive defense
capabilities (Wang et al., 2021). A lack of comprehensive research exists that evaluates how well
cybersecurity training programs work in practice alongside AI technology when detecting and
stopping ransomware attacks.
Primary Orientation
Experts believe that managing ransomware risks means combining technological approaches
with changes in people’s and organizations’ behaviors. The main ways this research frames the
exploration are the Technology Acceptance Model (TAM) and theories of information security
compliance. Lee and Choi (2022) talk about how ransomware, financial motives and
organizational actions are related and McConnell et al. (2024) describe how security compliance
could be impacted by biased thinking. These views explain why it is important to approach
online security through studies of human behavior.
Efforts to Address the Problem
The main approaches used earlier were putting in place technologies like intrusion detection and
making sure all regulations are followed. Yet, according to Ryan (2021) and McConnell et al.
(2024), these approaches are limited because they do not address behavioral drives such as bias,
habit and organizational climate. The authors of this work suggest that using economics and
game theory adds even more threats to the picture. There have been very few attempts to unite
these views with qualitative analysis to see how ransomware affects IT professionals in real
settings.
Synthesis of the Evidence
According to current research, threats from ransomware are rising in healthcare, but it is not
clear how technical, behavioral and organizational aspects relate. They discuss how ransomware
attacks are tied to digital currency, using routine activity theory, but their paper does not
investigate how organizations decide on their response. Ryan (2021) offers good economic
insights into ransom demands, even though he does not look at the consequences for people
working in the IT field. In 2021, Wang et al. applied game theory to cybersecurity tools NIDS
and EDR to support planning ahead, but they did not focus on human or cultural aspects.
McConnell et al. (2024) fill part of the gap by investigating how different approaches to thinking
affect policy compliance in the healthcare sector among Linux server administrators. According
to their results, human factors should be incorporated into compliance more, yet what they
review only applies to one platform and role. There is general agreement in the research that
technology is not the sole solution. Despite this, studies exploring the way professionals think
about and deal with security through words and stories are still rather uncommon. This project
aims to fill that gap by analyzing the experiences of IT experts in digital health and seeing how
attitudes, biases and company policies affect their strategies against ransomware attacks.
Purpose of the Project and Project Questions
1. How do IT professionals in healthcare organizations perceive and respond to
organizational policies intended to mitigate ransomware threats?
2. What role do cognitive heuristics and biases play in shaping IT professionals’ decisions
related to ransomware response and compliance?
3. How do organizational culture and structure influence the behavior of IT professionals in
managing ransomware risks?
Purpose of the Project
The aim of this study is to learn about how IT workers in mid-sized U.S. healthcare
organizations address ransomware threats, with attention to how mental biases, organizational
traditions and behavioral actions relate to information security policies.
Statement of Primary Question(s)
1. What gaps do IT professionals identify in current incident response frameworks for
ransomware attacks?
2. How do organizational policies, employee training, and technological solutions
collectively impact resilience against ransomware threats?
3. What role do IT professionals see Artificial Intelligence playing in enhancing
ransomware detection and response?
Definition of Terms
Ransomware: A type of malicious software that restricts access to data or systems and demands
payment to restore functionality.
Information Security Policy Compliance: The extent to which IT professionals follow
organizational protocols to protect digital assets.
Cognitive Heuristics and Biases: Mental shortcuts and distortions in thinking that affect how
individuals process information and make decisions.
Organizational Resilience: The ability of an organization to anticipate, adapt to, and recover
from cybersecurity incidents.
Qualitative Research: An approach focused on understanding human behavior and experiences
through interviews, observations, and thematic analysis.
References
McConnell, John, et al. “The role of heuristics and biases in linux server administrators’
Information Security Policy Compliance at healthcare organizations.” Proceedings of the
10th International Conference on Information Systems Security and Privacy, 2024, pp.
30–41, https://doi.org/10.5220/0012297000003648
Lee, Hannarae, and Kyung-Shick Choi. “Interrelationship between Bitcoin, ransomware, and
terrorist activities: Criminal Opportunity Assessment via cyber-routine activities
theoretical framework.” The New Technology of Financial Crime, 10 May 2022, pp. 82–
103, https://doi.org/10.4324/9781003258100-5.
Ryan, M. (2021). Ransomware Economics. In Ransomware Revolution: The Rise of a
Prodigious Cyber Threat (pp. 67–90). Springer. https://doi.org/10.1007/978-3-030-
66583-8_4
Wang, L., Guo, Y., & Lin, L. (2021). An analysis of ransomware defense strategies using
game theory. Journal of Cybersecurity and Privacy, 1(3), 495–508.
https://doi.org/10.3390/jcp1030025
- PAD 510 WEEK 2 DISCUSSION (FIVE ANSWERS POSTED CHOOSE 1)
- HLT-205 Week 4 U.S. Health Care Timeline
- Assignment
- Conflicting Viewpoints Essay
- Security Policies
- The Negotiation Process: Four Stages
- How long is the spinal cord and how much does it weigh?
- BUS-340 Module 5 DQ 1- How is ethics and ethical behavior apparent in corporate culture What is the relationship between law, values, and ethical behavior?…..
- Write a one to two (1–2) page paper in which you describe a potential best practice
- One-Variable Compound Inequalities