Summary of literature findings
| Risk | Vulnerabilities | Areas |
|---|---|---|
| Human error Non-malicious insider External attacker (malicious) | Human error related to HF Accidental (non-malicious) Personality Negligence Sabotage Rogue attitude Demographic attributes Social engineering Organisational factors (lack of security culture and awareness) Poor technological design (system failure or usability) Software vulnerabilities (new/updated technology) | Computer and information systems Internet Business systems Public (e.g. university) systems |
| Non-malicious insider Malicious insider External attacker (malicious) | Social engineering External attacker pretending to be an employee (malicious) External attacker intrudes into the system to cause harm or gain power (malicious, e.g. spear phishing, baiting and pretexting) External attacker intrudes into the system out of curiosity or hobby (non-malicious/negligent/reckless) External attacker intrudes into the system in relation to certain characteristics/attitudes Organisational factors (i.e. lack of security culture and awareness) Organisational factors (i.e. lack of systematic review of maintenance activities) Organisational factors (i.e. lack of training/monitoring) Unknown attack vectors Software vulnerabilities (new technology) Legacy systems or system integration challenges | Critical infrastructures within various sectors (nuclear, energy, railway, power grid, health, finance and aviation). Retail systems Public sector systems |
| Risk | Vulnerabilities | Areas |
|---|---|---|
| Human error | Human error related to HF | Computer and information systems |
| Non-malicious insider | Social engineering | Critical infrastructures within various sectors (nuclear, energy, railway, power grid, health, finance and aviation). |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.