EconPapers    
Economics at your fingertips  
 

Cyber negotiation: a cyber risk management approach to defend urban critical infrastructure from cyberattacks

Gregory Falco, Alicia Noriega and Lawrence Susskind

Journal of Cyber Policy, 2019, vol. 4, issue 1, 90-116

Abstract: Technical tools dominate the cyber risk management market. Social cybersecurity tools are severely underutilised in helping organisations defend themselves against cyberattacks. We investigate a class of non-technical risk mitigation strategies and tools that might be particularly effective in managing and mitigating the effects of certain cyberattacks. We call these social-science-grounded methods Defensive Social Engineering (DSE) tools. Through interviews with urban critical infrastructure operators and cross-case analysis, we devise a pre, mid and post cyber negotiation framework that could help organisations manage their cyber risks and bolster organisational cyber resilience, especially in the case of ransomware attacks. The cyber negotiation framework is grounded in both negotiation theory and practice. We apply our ideas, ex post, to past ransomware attacks that have wreaked havoc on urban critical infrastructure. By evaluating how to use negotiation strategies effectively (even if no negotiations ever take place), we hope to show how non-technical DSE tools can give defenders some leverage as they engage with cyber adversaries who often have little to lose.

Date: 2019
References: Add references at CitEc
Citations: View citations in EconPapers (2)

Downloads: (external link)
http://hdl.handle.net/10.1080/23738871.2019.1586969 (text/html)
Access to full text is restricted to subscribers.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:taf:rcybxx:v:4:y:2019:i:1:p:90-116

Ordering information: This journal article can be ordered from
http://www.tandfonline.com/pricing/journal/rcyb20

DOI: 10.1080/23738871.2019.1586969

Access Statistics for this article

Journal of Cyber Policy is currently edited by Emily Taylor

More articles in Journal of Cyber Policy from Taylor & Francis Journals
Bibliographic data for series maintained by Chris Longhurst ().

 
Page updated 2025-03-20
Handle: RePEc:taf:rcybxx:v:4:y:2019:i:1:p:90-116