Table 1.

Summary of literature findings

RiskVulnerabilitiesAreas
Human error
Non-malicious insider
External attacker (malicious)
Human error related to HF
Accidental (non-malicious)
Personality
Negligence
Sabotage
Rogue attitude
Demographic attributes
Social engineering
Organisational factors (lack of security culture and awareness)
Poor technological design (system failure or usability)
Software vulnerabilities (new/updated technology)
Computer and information systems
Internet
Business systems
Public (e.g. university) systems
Non-malicious insider
Malicious insider
External attacker (malicious)
Social engineering
External attacker pretending to
be an employee (malicious)
External attacker intrudes into
the system to cause harm or gain power (malicious, e.g. spear phishing, baiting and pretexting)
External attacker intrudes into the system out of curiosity or hobby (non-malicious/negligent/reckless)
External attacker intrudes into the system in relation to certain characteristics/attitudes
Organisational factors (i.e. lack of security culture and awareness)
Organisational factors (i.e. lack of systematic review of maintenance activities)
Organisational factors (i.e. lack of training/monitoring)
Unknown attack vectors
Software vulnerabilities (new technology)
Legacy systems or system integration challenges
Critical infrastructures within various sectors (nuclear, energy, railway, power grid, health, finance and aviation).
Retail systems
Public sector systems
Source: Created by authors

or Create an Account

Close subscription notice
Close access options