论文标题

网络安全事件后有效公司沟通的框架

A framework for effective corporate communication after cyber security incidents

论文作者

Knight, Richard, Nurse, Jason R. C.

论文摘要

一个重大的网络安全事件可能代表组织的网络危机,特别是由于具有重大声誉损害的风险。随着时间的流逝,由于成为网络攻击的受害者的可能性也有所增加,因此需要确切地了解攻击后有效的公司交流,以及如何最好地吸引客户,合作伙伴和其他利益相关者的担忧。这项研究旨在通过对数据泄露后危机沟通和公共关系功效的批判性,多方面的调查来解决这个问题。通过借鉴学术文献,通过系统的文献综述和现实世界案例研究获得的学术文献来做到这一点。定性数据分析用于解释和构造结果,从而为公司沟通提供了新的全面框架,以支持公司的准备和对此类事件的响应。通过对高级行业专业人员的访谈以及针对相关实践和研究的批判性评估,该框架的有效性证明了其评估。根据这些评估,进一步完善了该框架,并定义了更新的版本。这项研究代表了在网络安全事件后表征有效的公司沟通的第一个基础,全面和评估的建议。

A major cyber security incident can represent a cyber crisis for an organisation, in particular because of the associated risk of substantial reputational damage. As the likelihood of falling victim to a cyberattack has increased over time, so too has the need to understand exactly what is effective corporate communication after an attack, and how best to engage the concerns of customers, partners and other stakeholders. This research seeks to tackle this problem through a critical, multi-faceted investigation into the efficacy of crisis communication and public relations following a data breach. It does so by drawing on academic literature, obtained through a systematic literature review, and real-world case studies. Qualitative data analysis is used to interpret and structure the results, allowing for the development of a new, comprehensive framework for corporate communication to support companies in their preparation and response to such events. The validity of this framework is demonstrated by its evaluation through interviews with senior industry professionals, as well as a critical assessment against relevant practice and research. The framework is further refined based on these evaluations, and an updated version defined. This research represents the first grounded, comprehensive and evaluated proposal for characterising effective corporate communication after cyber security incidents.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源