Types of initiatives to mitigate cyber risks
| Initiatives | Type of initiative | References | |
|---|---|---|---|
| Employ a chief information security officer (CISO) or data protection officer (DPO) | Internal organizational initiatives | Pre-attack | Khursheed et al. (2016), Boyson (2014) |
| Conduct personnel background checks | Internal organizational initiatives | Pre-attack | Kim and Im (2014), Stephens and Valverde (2013) |
| Presence of an information security strategy | Internal organizational initiatives | Pre-attack | Sindhuja (2014), Xue et al. (2013); Bartol (2014) |
| Specific data and information insurance | Internal organizational initiatives | Post-attack | Boyson (2014), Keegan (2014); Mukhopadhyay et al. (2013) |
| Employee security awareness training programme (cyber hygiene) | Training and internal awareness | Pre-attack | Boyson (2014), Sindhuja and Kunnathur (2015); Stephens and Valverde (2013), Tran et al. (2016); Xue et al. (2013), Windelberg (2016) |
| Secure data access and control measures | Internal data management | Pre-attack | Sindhuja and Kunnathur (2015), Pandey et al. (2020); Windelberg (2016), Trombley (2015) |
| Accurate record of personnel handling sensitive data | Internal data management | Pre- and trans-attack | Pandey et al. (2020), Windelberg (2016) |
| IPS, data and URL filtering (antivirus and antispam) | Internal IT security and resilience tools | Pre-attack | Charitoudi and Blyth (2014) |
| Multiple data backup | Internal IT security and resilience tools | Pre-attack | Sindhuja (2014), Secci and Murugesan (2014) |
| Geographical distributed datacentres | Internal IT security and resilience tools | Pre-attack | Sindhuja (2014), Secci and Murugesan (2014) |
| Require suppliers and customers to comply with the privacy and security policies | Compliance and external awareness | Pre-attack | Boyson (2014), Sindhuja and Kunnathur (2015); Sindhuja (2014), Tran et al. (2016); Bandyopadhyay et al. (2010), Li and Xu (2020); Pandey et al. (2020) |
| Conduct supply chain partners security audits | Compliance and external awareness | Pre-attack | Boyson (2014), Stephens and Valverde (2013) |
| Communication procedures with involved supply chain partners | External event management | Trans- and post-attack | Boyson (2014), Kim and Im (2014); Radanliev et al. (2020), Sindhuja (2014); Li and Xu (2020), Tran et al. (2016); Tao et al., 2016; Scholten and Schilder, 2015; Järveläinen (2013) |
| Business continuity and disaster recovery plans | External event management | Trans- and post-attack | Tao et al., 2016; Järveläinen (2013) |
| Type of initiative | References | ||
|---|---|---|---|
| Internal organizational initiatives | Pre-attack | ||
| Internal organizational initiatives | Pre-attack | ||
| Internal organizational initiatives | Pre-attack | ||
| Internal organizational initiatives | Post-attack | ||
| Training and internal awareness | Pre-attack | ||
| Internal data management | Pre-attack | ||
| Internal data management | Pre- and trans-attack | ||
| Internal IT security and resilience tools | Pre-attack | ||
| Internal IT security and resilience tools | Pre-attack | ||
| Internal IT security and resilience tools | Pre-attack | ||
| Compliance and external awareness | Pre-attack | ||
| Compliance and external awareness | Pre-attack | ||
| External event management | Trans- and post-attack | ||
| External event management | Trans- and post-attack | ||
Note:
URL = Uniform resource locator
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.