Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 92 pages
Summary

Summary Cyber Crisis Management & Resilience - Lecture Notes & Reading Summaries - Cybersecurity Governance - Crisis and Security Management - Leiden University College The Hague

Document preview thumbnail
Preview 4 out of 92 pages

Literature Included: Del-Real, C., & Kuipers, S. (2026). Cyberincidenten en crises in organisaties. In Van den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale Veiligheid (forthcoming) (Brightspace) Del-Real, C., & Kuipers, S. (2026). Leiderschap in cyber crisis management. In Van den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale Veiligheid (forthcoming) (Brightspace) MacColl, J., Hüsch, P., Mott, G., Sullivan, J., Nurse, J. R., Turner, S., & Pattnaik,N. (2024). The Scourge of Ransomware: Victim Insights on Harms to Individuals, Organisations and Society. Technical report. The Royal United Services Institute for Defence and Security Studies. Schalackl, F., Link, N., & Howhle, H. (2022). Antecedents and consequences of data breaches: A systematic review. Information & Management 59. Bryman, A. (2012). Social research methods. Oxford university press. Specifically: Chapter 1. Sub-section “Data analysis” (pp. 13-14) Chapter 2. Epistemological + ontological considerations (pp. 27-35) Chapter 17 (379-410) Chapter 24 (564-587) Nillasithanukroh, S., Park, C.H., Baek, J., Ahn, G.J., & Richards, R. (2025). Mapping the landscape of cybersecurity preparedness: A systematic review of non-technological determinants and consequences. Technology in Society 103042. Bryman, A. (2012). Social research methods. Oxford university press. Specifically: Chapter 7 (pp. 159-181) Chapter 15 (pp. 329-246) Northwave. (2022). After the crisis comes the blow. The mental impact of ransomware attacks Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center: A systematic study and open challenges. Ieee Access, 8, . Tariq, S., Baruwal Chhetri, M., Nepal, S., & Paris, C. (2025). Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys, 57(9), 1-38. Sections 4, 5 (introduction) and 5.1 Meurs, T., Cartwright, A., Cartwright, E., Houba, H., & Woods, D. (2025). The ransomware pricing paradox: An empirical study of the six stages of ransomware negotiations (No. TI 2025-052/VII). Tinbergen Institute Discussion Paper. Matthijsse, S., van‘t Hoff-de Goede, M., & Leukfeldt, E. Exploring victim-offender interactions during a ransomware attack using LockBit chat negotiations. Bentley, J. M., Oostman, K. R., & Shah, S. F. A. (2018). We're sorry but it's not our fault: Organizational apologies in ambiguous crisis situations. Journal of Contingencies and Crisis Management, 26(1), 138-149. Coombs, W. T. (2022). Situational crisis communication theory (SCCT) refining and clarifying a cognitive‐based theory of crisis communication. The handbook of crisis communication, 193-204. Masuch, K., Greve, M., Trang, S., & Kolbe, L. M. (2022). Apologize or justify? Examining the impact of data breach response actions on stock value of affected companies?. Computers & Security, 112, 102502. Crisis & Risk Communication AI Assistant (ChatGPT source available at in this LINK) Marshall, G., & Jonker, L. (2011). An introduction to inferential statistics: A review and practical guide. Radiography, 17(1), e1-e6. Introduction to statistical inference (resource online) Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2024). “I don't think we're there yet”: The practices and challenges of organisational learning from cyber security incidents. Computers & Security, 139, 103699. Tsen, E., Ko, R. K., & Slapničar, S. (2025). The effect of organizational cyber resilience on cyber incident outcomes. Journal of Cybersecurity, 11(1), tyaf040.

Content preview

Readings:
-​ Del-Real, C., & Kuipers, S. (2026). Cyberincidenten en crises in organisaties. In Van
den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale
Veiligheid (forthcoming) (Brightspace)
-​ Del-Real, C., & Kuipers, S. (2026). Leiderschap in cyber crisis management. In Van
den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale
Veiligheid (forthcoming) (Brightspace)
-​ MacColl, J., Hüsch, P., Mott, G., Sullivan, J., Nurse, J. R., Turner, S., & Pattnaik,N.
(2024). The Scourge of Ransomware: Victim Insights on Harms to Individuals,
Organisations and Society. Technical report. The Royal United Services Institute for
Defence and Security Studies.
-​ Schalackl, F., Link, N., & Howhle, H. (2022). Antecedents and consequences of data
breaches: A systematic review. Information & Management 59.
-​ Bryman, A. (2012). Social research methods. Oxford university press.
Specifically:
Chapter 1. Sub-section “Data analysis” (pp. 13-14)
Chapter 2. Epistemological + ontological considerations (pp. 27-35)
Chapter 17 (379-410)
Chapter 24 (564-587)
-​ Nillasithanukroh, S., Park, C.H., Baek, J., Ahn, G.J., & Richards, R. (2025). Mapping
the landscape of cybersecurity preparedness: A systematic review of
non-technological determinants and consequences. Technology in Society 103042.
-​ Bryman, A. (2012). Social research methods. Oxford university press.
Specifically:
Chapter 7 (pp. 159-181)
Chapter 15 (pp. 329-246)
-​ Northwave. (2022). After the crisis comes the blow. The mental impact of
ransomware attacks
-​ Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center:
A systematic study and open challenges. Ieee Access, 8, 227756- 227779.
-​ Tariq, S., Baruwal Chhetri, M., Nepal, S., & Paris, C. (2025). Alert fatigue in security
operations centres: Research challenges and opportunities. ACM Computing
Surveys, 57(9), 1-38. Sections 4, 5 (introduction) and 5.1
-​ Meurs, T., Cartwright, A., Cartwright, E., Houba, H., & Woods, D. (2025). The
ransomware pricing paradox: An empirical study of the six stages of ransomware
negotiations (No. TI 2025-052/VII). Tinbergen Institute Discussion Paper.
-​ Matthijsse, S., van‘t Hoff-de Goede, M., & Leukfeldt, E. Exploring victim-offender
interactions during a ransomware attack using LockBit chat negotiations.
-​ Bentley, J. M., Oostman, K. R., & Shah, S. F. A. (2018). We're sorry but it's not our
fault: Organizational apologies in ambiguous crisis situations. Journal of
Contingencies and Crisis Management, 26(1), 138-149.
-​ Coombs, W. T. (2022). Situational crisis communication theory (SCCT) refining and
clarifying a cognitive‐based theory of crisis communication. The handbook of crisis
communication, 193-204.
-​ Masuch, K., Greve, M., Trang, S., & Kolbe, L. M. (2022). Apologize or justify?
Examining the impact of data breach response actions on stock value of affected
companies?. Computers & Security, 112, 102502.

,-​ Crisis & Risk Communication AI Assistant (ChatGPT source available at in this LINK)
-​ Marshall, G., & Jonker, L. (2011). An introduction to inferential statistics: A review and
practical guide. Radiography, 17(1), e1-e6.
-​ Introduction to statistical inference (resource online)
-​ Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2023). Learning from cyber
security incidents: A systematic review and future research agenda. Computers &
Security, 132, 103309.
-​ Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2024). “I don't think we're there
yet”: The practices and challenges of organisational learning from cyber security
incidents. Computers & Security, 139, 103699.
-​ Tsen, E., Ko, R. K., & Slapničar, S. (2025). The effect of organizational cyber
resilience on cyber incident outcomes. Journal of Cybersecurity, 11(1), tyaf040.

,Week 1

Lecture 1
Introduction to cyber crises and what makes them different from other crises

The information age paradox: digital infrastructures that empower unprecedented
cooperation and economic growth serve the primary vector for systemic harm and social
destabilization

Two separate concepts:
1.​ What is a crisis?
→ what crises are not: not disaster
-​ instead, crisis = distinguish, choose, decide (“positive moment”)
So, when a group, organization or community experiences “a serious threat to the basic
structures or the fundamental values and norms of a system, which under time pressure and
highly uncertain circumstances necessitates making vital decisions
-​ threat to values
-​ sense of urgency
-​ uncertainty and ambiguity

2.​ What is a cyber incident?
→ an event that causes damage to:
-​ data, systems, and/or networks
-​ people, their possessions, or things they consider valuable
→ the means or the target is a digital technology
→ can be intentional or accidental
→ so: event that affects us in or through cyberspace

Crisis & cyber incidents = cyber crisis

Cyber crisis: When a group, organization or community experiences “a serious threat to the
basic structures or the fundamental values and norms of a system, which under time
preassure and highly uncertain circumstances necessitates making vital decisions
… and the mean and/or the target is a digital technology

The crisis window (t1 to t2)
→ is a window of time
-​ from the onset (t1): incident is perceived as serious/threats
-​ to the resolution (t2): threat is neutralised
→ “crisis mode”
-​ time to decide (focus on the decision-maker)

In practice: exceeds the capacity of the system, threats reputation

, Example: floods in valencia (2024) & Crowdstrike incident (2024): threats values, uncertainty
& ambiguity, need for rapid response, risk of reputational damage, escalation and cascading
effects, require public and stakeholder communication

Role of digital technologies


Means

No cyberspace Cyberspace

Harms No cyberspace Traditional crisis Cyber-enabled
crisis

Cyberspace Cyber targeted Cyber dependent
cirisis crisis


Most common cyber crises
→ Data breaches
→ ransomware attacks: malware encrypts data → pay ransom to get data back
→ DDoS: Disrupted denial of service → sending too many requests which crashes the
system
→ poisoning: we cannot identify these types of attacks yet: changing data




Analytical dimensions of cyber crises
1.​ public - private (wannacry attack 2017 (ransomware) & ICRC data breach 2022)
2.​ incidental - intentional (crowdstrike incident 2024 & notpetya attack 2016 (= ukraine,
by russia, aimed to affect critical infrastructure, wiper (kind of ransomware but here
there is no recovery)
3.​ operational - reputational (crowdstrike incident 2024 & vastaamo data breach
2018-2020)
4.​ Harms in cyberspace - via cyberspace (in = systems, network, data. via = humans
and societies) (notpetya attack 2016 & US presedential elections 2016)
5.​ localized - widespread (baltimore ransomware 2019 & wannacry attack 2017)

Document information

Study
Uploaded on
August 19, 2026
Number of pages
92
Written in
2025/2026
Type
Summary
$13.22

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
jhbos
3.5
(2)
Sold
19
Followers
10
Items
28
Last sold
10 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions