To read this content please select one of the options below:

Organisational cyber resilience: a heuristic for bridging foundations and applications

Mark-Paul Sallos (Business Analytics Program, Higher Colleges of Technology, Dubai, UAE)
Alexeis Garcia Perez (Aston Business School, Aston University, Birmingham, UK)
Anca Bocanet (Business Analytics Program, Higher Colleges of Technology, Dubai, UAE)

Journal of Enterprise Information Management

ISSN: 1741-0398

Article publication date: 9 October 2024

Issue publication date: 16 October 2024

74

Abstract

Purpose

The drive for digitalisation has increased the scope of cyber threats which can exploit the growing footprint of information and communication technology infrastructure supporting modern societies. Despite substantial interest and efforts in researching and building organisational cyber resilience, the resulting body of work is heterogeneous and has yet to reach maturity. This paper aims to address the gap in the conceptualisation of cyber resilience in academic and practice-oriented grey literature.

Design/methodology/approach

In this conceptual paper, we firstly seek to explore the available foundations of resilience as a construct and consider how these can be applied to organisational cybersecurity. To that aim, this study employs a targeted literature review approach, incorporating systematic elements to ensure rigour. Literature was identified through comprehensive searches in key academic databases, reference chaining and expert recommendations. Articles were selected based on relevance and contribution to the field, resulting in a thematic analysis to identify gaps and propose a heuristic model for cyber resilience. With this approach, we aim to position the emerging view of cyber resilience relative to risk analysis, while highlighting its domain of “conceptual comparative advantage” – the types of applications it is best suited to address. Finally, a high-level heuristic model for cyber resilience is proposed, which functions across the relevant policy, strategy and operational dimensions while also considering its relationship with cyber risk management.

Findings

A conceptual model for organisational cyber resilience is proposed which helps position and frame research contributions in this domain relative to risk analysis, highlighting its domain of comparative advantage. The model integrates policy, strategy and operational dimensions, in a manner conducive to bridging foundations and applications of the concept of cyber risk management. The proposed model provides a critical point of reference to evaluate individual models, frameworks and tools.

Originality/value

This paper is a pioneering effort to overcome the current gaps between conceptual and practical views of cyber resilience. It proposes a new, risk-aligned view of the concept of cyber resilience and provides a structural foundation for further research and practice in the field.

Keywords

Citation

Sallos, M.-P., Garcia Perez, A. and Bocanet, A. (2024), "Organisational cyber resilience: a heuristic for bridging foundations and applications", Journal of Enterprise Information Management, Vol. 37 No. 6, pp. 1926-1952. https://doi.org/10.1108/JEIM-06-2023-0317

Publisher

:

Emerald Publishing Limited

Copyright © 2024, Emerald Publishing Limited

Related articles