inklap

Learning from safety science: designing incident reporting systems in cybersecurity

Nico Ebert, Thierry Schaltegger, Benjamin Ambuehl, Tim Geppert, Ariane Trammell, Melanie Knieps · Journal of Cybersecurity · 2025

Abstract Despite all the technical approaches to monitoring threats and detecting incidents, manual incident reporting is critical at all organizational levels of cybersecurity. However, in its current state, reporting suffers from challenges such as underreporting, lack of reporting channels, and uncertainty about what should be reported. The phenomenon of incident reporting itself is not clearly defined and occurs in different facets, from reporting phishing emails to the IT department to reporting vulnerabilities to national authorities. This makes it difficult to design effective socio-technical incident-reporting systems (IRS) according to overarching principles. This review article addresses these challenges by drawing on insights from the field of safety, where IRS are well-established. We find that a broad range of events is reported, various reporting channels on different organizational levels exist, and key design factors of successful IRS have emerged. Based on these lessons from safety, we propose a taxonomy for cybersecurity reporting that includes noncritical events, such as near misses, and latent factors, such as weak security controls. We suggest th

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً