Making cyber security more resilient: adding social considerations to technological fixes
Open access
Date
2023Type
- Journal Article
ETH Bibliography
yes
Altmetrics
Abstract
How can a focus on socio-technical vulnerability and uncertainty make cyber security more resilient? In this article, we provide a conceptual discussion of how to increase cyber resilience. First, we show how cyber security and resilience thinking co-evolved through their connection to critical infrastructures, and how the ensuing dominant technical focus inevitably always falls short due to the diverse societal values that underpin their critical social functions. We argue that a sole focus on aggregate systems neglects the important differences in how cyber threats are experienced and dealt with by individuals. Second, we draw on insights from social resilience and disaster management literature to establish a better link between individuals and cyber systems. We focus on two key aspects of cyber security that highlight its social nature: vulnerability and uncertainty. Instead of thinking of cyber security as a “technical problem + humans,” we suggest cyber security should be conceptualized as a “social problem + technology.” We conclude by highlighting three ways forward for researchers, policymakers, and practitioners: interdisciplinary research, public debate about a set of normative questions, and the need for an uncertainty discourse in politics and policymaking. Show more
Permanent link
https://doi.org/10.3929/ethz-b-000611485Publication status
publishedExternal links
Journal / series
Journal of Risk ResearchVolume
Pages / Article No.
Publisher
Taylor & FrancisSubject
Cyber resilience; vulnerability; (embodied) uncertainty; affluence-vulnerability interface; risk; systemic inequalityOrganisational unit
03515 - Wenger, Andreas / Wenger, Andreas
More
Show all metadata
ETH Bibliography
yes
Altmetrics