Abstract This paper designs and offers a framework that expands a strategic sensemaking approach that boards of directors can follow and apply in order to improve their oversight over cybersecurity threats looming over their organizations. We explain how this sensemaking process, which involves scanning, interpretation, and action activities, unfolds across the different phases—in routine (prior to the cybersecurity event), under the attack (during the cybersecurity event), and recovery (post-cybersecurity breach event). We use real case studies to illustrate the process in ways that deepen the understanding regarding the processes boards of directors should use to guide their organizations.
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً