kth.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Envisioning cyber situation awareness through participatory video prototyping
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID.ORCID iD: 0000-0003-1748-3769
FOI Swedish Defence Research Agency.ORCID iD: 0009-0001-5456-9513
2025 (English)In: Proceedings of the 22nd International Conference on Information Systems for Crisis Response and Management (ISCRAM 2025) / [ed] H. Afshari, A. Chauhan, L. Petersen, L. A. S. Britton, M. Melanson, M. Bhati, A. Habib, & R. Pelot, 2025Conference paper, Published paper (Refereed)
Abstract [en]

Our digital societies are vulnerable to cyber crises. Without cyber-resilient organizations, vital societal functions may suffer incidents or loss of service. The diverse roles involved in cybersecurity decision-making require cyber situation awareness to uphold robust cybersecurity. Existing systems and processes supporting cyber situation awareness are not tailored to organizational needs, either at the role or the group level. This study explores the need for socio-technical system support, presenting common operational pictures supporting cyber situation awareness for staff handling cyberthreats. The participatory design method video prototyping was used to elicit needs from staff in a large, complex, public sector organization providing essential services. All participants have roles in cybersecurity crisis and incident management. Results from the video prototyping workshop suggest that cybersecurity staff need (i) a single support system for incident management, and (ii) a shared data repository underpinning (iii) role-specific common operational pictures. The envisioned system support provides traceability and accountability.

Place, publisher, year, edition, pages
2025.
Keywords [en]
Cyber situation awareness, common operational picture, cyber crises, participatory design, video prototyping
National Category
Information Systems
Research subject
Human-computer Interaction
Identifiers
URN: urn:nbn:se:kth:diva-362897DOI: 10.59297/xp06tf49OAI: oai:DiVA.org:kth-362897DiVA, id: diva2:1955291
Conference
International Conference on Information Systems for Crisis Response and Management (ISCRAM 2025), May 18-21 2025, Halifax, Nova Scotia, Canada
Funder
Swedish Armed Forces
Note

Available from: 2025-04-29 Created: 2025-04-29 Last updated: 2025-05-07
In thesis
1. Cyber situation awareness and common operational pictures: Studies of the Swedish public sector
Open this publication in new window or tab >>Cyber situation awareness and common operational pictures: Studies of the Swedish public sector
2025 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

Cybersecurity is one of the pillars of successful digitalization of our societies. A key component of cybersecurity is that staff involved in cybersecurity work develop situational awareness of the cyber environment and respond to events  based on that understanding. Despite growing interest in situation awareness for cybersecurity, few empirical studies look at cyber situation awareness from the human actor’s perspective within organizational contexts. The purpose of this thesis is to contribute to research on improving cyber situation awareness capabilities in organizations, with a focus on the Swedish public sector.

The thesis includes five papers concerning different aspects of cyber situation awareness. In the first paper, a census is conducted presenting a snapshot of the cybersecurity maturity of the Swedish public sector and how the public sector communicated cybersecurity risks during the COVID-19 pandemic. In the second paper, the conditions under which cybersecurity work is conducted at Swedish administrative authorities are investigated, and results from semi-structured interviews with respondents involved in cybersecurity work are presented. In the third paper, four personas, based on empirical material from the first and second papers, are created and validated. In the fourth paper, a case study on how staff members involved in handling a cyberthreat in a large, complex organization develop cyber situation awareness while handling the threat is presented. In the fifth paper, participatory video prototyping is used to explore common operational picture system support needs to aid cyber situation awareness for staff involved in handling cyberthreats.

The thesis discusses challenges to cyber situation awareness in organizations, how cyber situation awareness can be improved, and how common operational pictures should be designed. 

Abstract [sv]

Cybersäkerhet är en av grundpelarna för en framgångsrik digitalisering av våra samhällen. En nyckelkomponent för cybersäkerhet är att personal som arbetar med cybersäkerhet utvecklar cyberlägesförståelse för att ”få koll på läget” i cybermiljön och, baserat på den förståelsen, reagerar på händelser. Trots det växande intresset för cyberlägesförståelse så finns det få empiriska studier som undersöker cyberlägesförståelse från den mänskliga aktörens perspektiv i organisatoriska sammanhang. Syftet med avhandlingen är att bidra till cyberlägesförståelseforskningen  genom att undersöka cyberlägesförståelse i organisationer och presentera empiriska studier med fokus på svensk offentlig sektor.

I denna avhandling ingår fem artiklar som studerar olika aspekter av cyberlägesförståelse. I den första artikeln har en totalundersökning av den svenska offentliga sektorn genomförts och en  ögonblicksbild av sektorns cybersäkerhetsmognad samt hur offentlig sektor kommunicerade om cybersäkerhetsrisker under COVID-19-pandemin presenteras. I den andra artikeln har de förutsättningar under vilka cybersäkerhetsarbete bedrivs vid svenska förvaltningsmyndigheter undersökts och resultat från semi-strukturerade intervjuer med respondenter som deltar i cybersäkerhetsarbetet vid förvaltningsmyndigheterna presenteras. I den tredje artikeln presenteras fyra personor, baserade på det empiriska materialet från den första och andra artikeln, som validerats. I den fjärde artikeln presenteras en fallstudie om hur personal i en stor, komplex organisation utvecklade cyberlägesförståelse under tiden de hanterade ett cyberhot. I den femte artikeln utforskas behovet av systemstöd för lägesbilder som kan underlätta för cyberlägesförståelse hos personal som hanterar cyberhot genom den deltagande design-metoden video-prototypande. 

Avhandlingen diskuterar utmaningarna för cyberlägesförståelse i organisationer, hur cyberlägesförståelse kan förbättras, samt hur systemstöd för lägesbilder bör utformas för att stödja cyberlägesförståelse.

Place, publisher, year, edition, pages
Stockholm: Kungliga Tekniska högskolan, 2025. p. ix, 67
Series
TRITA-EECS-AVL ; 2025:40
Keywords
cyber situation awareness, cybersecurity, public sector, common operational picture, crisis management, cyberlägesförståelse, cybersäkerhet, offentlig sektor, lägesbild, krishantering
National Category
Human Computer Interaction
Research subject
Human-computer Interaction
Identifiers
urn:nbn:se:kth:diva-362904 (URN)978-91-8106-241-0 (ISBN)
Public defence
2025-05-27, https://kth-se.zoom.us/j/65477700827, F3 (Flodis) Lindstedtsvägen 26 & 28, Stockholm, 14:00 (English)
Opponent
Supervisors
Funder
Swedish Armed Forces
Note

QC 20250430

Available from: 2025-04-30 Created: 2025-04-29 Last updated: 2025-05-27Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Andreasson, Annika

Search in DiVA

By author/editor
Andreasson, AnnikaLindquist, Sinna
By organisation
Media Technology and Interaction Design, MID
Information Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 100 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf