Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Document preview thumbnail
Voorbeeld 4 van de 90 pagina's
Samenvatting

Summary Cyber Crisis Management & Resilience - Lecture Notes & Reading Summaries - Cybersecurity Governance - Crisis and Security Management

Document preview thumbnail
Voorbeeld 4 van de 90 pagina's

Literature Included: Del-Real, C., & Kuipers, S. (2026). Cyberincidenten en crises in organisaties. In Van den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale Veiligheid (forthcoming) (Brightspace) Del-Real, C., & Kuipers, S. (2026). Leiderschap in cyber crisis management. In Van den Berg, B., Muller, E., Oldengarm, P., & Weggemans, D., Handboek Digitale Veiligheid (forthcoming) (Brightspace) MacColl, J., Hüsch, P., Mott, G., Sullivan, J., Nurse, J. R., Turner, S., & Pattnaik,N. (2024). The Scourge of Ransomware: Victim Insights on Harms to Individuals, Organisations and Society. Technical report. The Royal United Services Institute for Defence and Security Studies. Schalackl, F., Link, N., & Howhle, H. (2022). Antecedents and consequences of data breaches: A systematic review. Information & Management 59. Bryman, A. (2012). Social research methods. Oxford university press. Specifically: Chapter 1. Sub-section “Data analysis” (pp. 13-14) Chapter 2. Epistemological + ontological considerations (pp. 27-35) Chapter 17 (379-410) Chapter 24 (564-587) Nillasithanukroh, S., Park, C.H., Baek, J., Ahn, G.J., & Richards, R. (2025). Mapping the landscape of cybersecurity preparedness: A systematic review of non-technological determinants and consequences. Technology in Society 103042. Bryman, A. (2012). Social research methods. Oxford university press. Specifically: Chapter 7 (pp. 159-181) Chapter 15 (pp. 329-246) Northwave. (2022). After the crisis comes the blow. The mental impact of ransomware attacks Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center: A systematic study and open challenges. Ieee Access, 8, . Tariq, S., Baruwal Chhetri, M., Nepal, S., & Paris, C. (2025). Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys, 57(9), 1-38. Sections 4, 5 (introduction) and 5.1 Meurs, T., Cartwright, A., Cartwright, E., Houba, H., & Woods, D. (2025). The ransomware pricing paradox: An empirical study of the six stages of ransomware negotiations (No. TI 2025-052/VII). Tinbergen Institute Discussion Paper. Matthijsse, S., van‘t Hoff-de Goede, M., & Leukfeldt, E. Exploring victim-offender interactions during a ransomware attack using LockBit chat negotiations. Bentley, J. M., Oostman, K. R., & Shah, S. F. A. (2018). We're sorry but it's not our fault: Organizational apologies in ambiguous crisis situations. Journal of Contingencies and Crisis Management, 26(1), 138-149. Coombs, W. T. (2022). Situational crisis communication theory (SCCT) refining and clarifying a cognitive‐based theory of crisis communication. The handbook of crisis communication, 193-204. Masuch, K., Greve, M., Trang, S., & Kolbe, L. M. (2022). Apologize or justify? Examining the impact of data breach response actions on stock value of affected companies?. Computers & Security, 112, 102502. Crisis & Risk Communication AI Assistant (ChatGPT source available at in this LINK) Marshall, G., & Jonker, L. (2011). An introduction to inferential statistics: A review and practical guide. Radiography, 17(1), e1-e6. Introduction to statistical inference (resource online) Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. Patterson, C. M., Nurse, J. R., & Franqueira, V. N. (2024). “I don't think we're there yet”: The practices and challenges of organisational learning from cyber security incidents. Computers & Security, 139, 103699. Tsen, E., Ko, R. K., & Slapničar, S. (2025). The effect of organizational cyber resilience on cyber incident outcomes. Journal of Cybersecurity, 11(1), tyaf040.

Voorbeeld van de inhoud

Week 1

Lecture 1
Introduction to cyber crises and what makes them different from other crises

The information age paradox: digital infrastructures that empower unprecedented
cooperation and economic growth serve the primary vector for systemic harm and social
destabilization

Two separate concepts:
1.​ What is a crisis?
→ what crises are not: not disaster
-​ instead, crisis = distinguish, choose, decide (“positive moment”)
So, when a group, organization or community experiences “a serious threat to the basic
structures or the fundamental values and norms of a system, which under time pressure and
highly uncertain circumstances necessitates making vital decisions
-​ threat to values
-​ sense of urgency
-​ uncertainty and ambiguity

2.​ What is a cyber incident?
→ an event that causes damage to:
-​ data, systems, and/or networks
-​ people, their possessions, or things they consider valuable
→ the means or the target is a digital technology
→ can be intentional or accidental
→ so: event that affects us in or through cyberspace

Crisis & cyber incidents = cyber crisis

Cyber crisis: When a group, organization or community experiences “a serious threat to the
basic structures or the fundamental values and norms of a system, which under time
preassure and highly uncertain circumstances necessitates making vital decisions
… and the mean and/or the target is a digital technology

The crisis window (t1 to t2)
→ is a window of time
-​ from the onset (t1): incident is perceived as serious/threats
-​ to the resolution (t2): threat is neutralised
→ “crisis mode”
-​ time to decide (focus on the decision-maker)

In practice: exceeds the capacity of the system, threats reputation

,Example: floods in valencia (2024) & Crowdstrike incident (2024): threats values, uncertainty
& ambiguity, need for rapid response, risk of reputational damage, escalation and cascading
effects, require public and stakeholder communication

Role of digital technologies


Means

No cyberspace Cyberspace

Harms No cyberspace Traditional crisis Cyber-enabled
crisis

Cyberspace Cyber targeted Cyber dependent
cirisis crisis


Most common cyber crises
→ Data breaches
→ ransomware attacks: malware encrypts data → pay ransom to get data back
→ DDoS: Disrupted denial of service → sending too many requests which crashes the
system
→ poisoning: we cannot identify these types of attacks yet: changing data




Analytical dimensions of cyber crises
1.​ public - private (wannacry attack 2017 (ransomware) & ICRC data breach 2022)
2.​ incidental - intentional (crowdstrike incident 2024 & notpetya attack 2016 (= ukraine,
by russia, aimed to affect critical infrastructure, wiper (kind of ransomware but here
there is no recovery)
3.​ operational - reputational (crowdstrike incident 2024 & vastaamo data breach
2018-2020)
4.​ Harms in cyberspace - via cyberspace (in = systems, network, data. via = humans
and societies) (notpetya attack 2016 & US presedential elections 2016)
5.​ localized - widespread (baltimore ransomware 2019 & wannacry attack 2017)

,Differences, or particularities
1.​ technical/technological complexity
2.​ detection and visibility (creeping crises)
→ incubation period (dwell time)
3.​ public perception and understanding* (spain flood disaster 2024 & vastaamo data
breach 2018-2020)
4.​ transboundary nature (countries affected by the wannacry attack 2017)
5.​ authority vacuum (optus)
6.​ threat agent masquerading
7.​ the victim-culprit dilemma
8.​ cross-sectoral governance = different levels of governance come into play
9.​ centralization vs distribution

Implications for crisis management
+ complexity, - detection, ? public perception, + transboundary =
→ different expertise required for preparation, detection, and response
-​ cybersecurity training
-​ security operation centers
-​ CRT/CSIRT
-​ forensic teams
-​ cyber threat intelligence analysts
→ difficulties obtaining a shared situation awareness that leads to good decision-making

How does the “dwell time” of cyber crisi challenge the crisis window?

crises are about perceptions

, Lecture 2 (Introduction & Simulation)
Cyber crisis management = the process through which an organization deals with disruptive
and unexpected cyber incident that threatens to harm the organization and/or its
stakeholders
→ occurs in organizations
→ it is a process (phases and tasks)
→ triggered by a cyber incident
→ aims to protect

Two processes: socio-technical approach to cyber crisis management
→ technical processes & social processes, internal (organization, management) and
external (communication, what do i tell my employees, stakeholders, customers etc.)

Types of cycles (1/x)
→ the timeline (van den
berg)
-​ prevention was
last course




→ the sans model →


→ nist model →

detection & analysis &
response → they
overlap

Two cycles
→ event-centric cycle
(starts before
leadership cycle)
→ leadership tasks-centric cycle they are
complementary
the cycles are not reality → components overlap

Pre-crisis (preparedness) → crisis (detection →
triage → analysis → response → detection.) →
post-crisis (accountability and learning)

So three phases: pre-incident/pre-crisis,
incident/crisis, post-incident/post-crisis

Documentinformatie

Geüpload op
19 augustus 2026
Aantal pagina's
90
Geschreven in
2025/2026
Type
Samenvatting
€10,99

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
jhbos
3,5
(2)
Verkocht
19
Volgers
10
Items
28
Laatst verkocht
10 maanden geleden

Echte notities, van echte studenten
Elk document op Stuvia is geschreven door een medestudent die hetzelfde vak deed. Zo leer je van iemand die het al heeft gehaald.



Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen