Table 3

Types of initiatives to mitigate cyber risks

InitiativesType of initiativeReferences
Employ a chief information security officer (CISO) or data protection officer (DPO)Internal organizational initiativesPre-attackKhursheed et al. (2016), Boyson (2014) 
Conduct personnel background checksInternal organizational initiativesPre-attackKim and Im (2014), Stephens and Valverde (2013) 
Presence of an information security strategyInternal organizational initiativesPre-attackSindhuja (2014), Xue et al. (2013); Bartol (2014) 
Specific data and information insuranceInternal organizational initiativesPost-attackBoyson (2014), Keegan (2014); Mukhopadhyay et al. (2013) 
Employee security awareness training programme (cyber hygiene)Training and internal awarenessPre-attackBoyson (2014), Sindhuja and Kunnathur (2015); Stephens and Valverde (2013), Tran et al. (2016); Xue et al. (2013), Windelberg (2016) 
Secure data access and control measuresInternal data managementPre-attackSindhuja and Kunnathur (2015), Pandey et al. (2020); Windelberg (2016), Trombley (2015) 
Accurate record of personnel handling sensitive dataInternal data managementPre- and trans-attackPandey et al. (2020), Windelberg (2016) 
IPS, data and URL filtering (antivirus and antispam)Internal IT security and resilience toolsPre-attackCharitoudi and Blyth (2014) 
Multiple data backupInternal IT security and resilience toolsPre-attackSindhuja (2014), Secci and Murugesan (2014) 
Geographical distributed datacentresInternal IT security and resilience toolsPre-attackSindhuja (2014), Secci and Murugesan (2014) 
Require suppliers and customers to comply with the privacy and security policiesCompliance and external awarenessPre-attackBoyson (2014), Sindhuja and Kunnathur (2015); Sindhuja (2014), Tran et al. (2016); Bandyopadhyay et al. (2010), Li and Xu (2020); Pandey et al. (2020) 
Conduct supply chain partners security auditsCompliance and external awarenessPre-attackBoyson (2014), Stephens and Valverde (2013) 
Communication procedures with involved supply chain partnersExternal event managementTrans- and post-attackBoyson (2014), Kim and Im (2014); Radanliev et al. (2020), Sindhuja (2014); Li and Xu (2020), Tran et al. (2016); Tao et al., 2016; Scholten and Schilder, 2015; Järveläinen (2013) 
Business continuity and disaster recovery plansExternal event managementTrans- and post-attackTao et al., 2016; Järveläinen (2013) 

Note:

URL = Uniform resource locator

Source: Adapted from Ghadge et al., 2020 and Colicchia et al., 2019 and related references

or Create an Account

Close Modal
Close Modal