kth.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Four personas in search of cyber situation awareness
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID.ORCID iD: 0000-0003-1748-3769
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID.ORCID iD: 0000-0002-6903-9072
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS. FOI Swedish Defence Research Agency, Stockholm, Sweden.ORCID iD: 0000-0002-2677-9759
Swedish Defence University, Stockholm, Sweden.ORCID iD: 0000-0003-2017-7914
(English)Manuscript (preprint) (Other academic)
Abstract [en]

The conditions for cybersecurity work in the public sector are diverse. This study presents user-centered personas representative of the variety of Swedish administrative authority cybersecurity staff. These personas are intended to be used for communication and design purposes to improve cyber situation awareness support systems and facilitate crisis communication.

Empirical material from 17 semi-structured interviews with cybersecurity staff and data on administrative authority size, were used to create personas. The personas were validated using triangulation through three activities. Implications for practice are addressed by suggesting solutions for the personas' problems, and use cases for the persona card deck are presented and discussed. Using personas in this way captures diverse needs for cyber situation awareness for staff involved in upholding cybersecurity in public sector organizations.

Keywords [en]
cybersecurity, public sector, persona, crisis management
National Category
Computer and Information Sciences
Research subject
Human-computer Interaction
Identifiers
URN: urn:nbn:se:kth:diva-362899OAI: oai:DiVA.org:kth-362899DiVA, id: diva2:1955292
Funder
Swedish Armed Forces
Note

QC 20250430

Available from: 2025-04-29 Created: 2025-04-29 Last updated: 2025-04-30Bibliographically approved
In thesis
1. Cyber situation awareness and common operational pictures: Studies of the Swedish public sector
Open this publication in new window or tab >>Cyber situation awareness and common operational pictures: Studies of the Swedish public sector
2025 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

Cybersecurity is one of the pillars of successful digitalization of our societies. A key component of cybersecurity is that staff involved in cybersecurity work develop situational awareness of the cyber environment and respond to events  based on that understanding. Despite growing interest in situation awareness for cybersecurity, few empirical studies look at cyber situation awareness from the human actor’s perspective within organizational contexts. The purpose of this thesis is to contribute to research on improving cyber situation awareness capabilities in organizations, with a focus on the Swedish public sector.

The thesis includes five papers concerning different aspects of cyber situation awareness. In the first paper, a census is conducted presenting a snapshot of the cybersecurity maturity of the Swedish public sector and how the public sector communicated cybersecurity risks during the COVID-19 pandemic. In the second paper, the conditions under which cybersecurity work is conducted at Swedish administrative authorities are investigated, and results from semi-structured interviews with respondents involved in cybersecurity work are presented. In the third paper, four personas, based on empirical material from the first and second papers, are created and validated. In the fourth paper, a case study on how staff members involved in handling a cyberthreat in a large, complex organization develop cyber situation awareness while handling the threat is presented. In the fifth paper, participatory video prototyping is used to explore common operational picture system support needs to aid cyber situation awareness for staff involved in handling cyberthreats.

The thesis discusses challenges to cyber situation awareness in organizations, how cyber situation awareness can be improved, and how common operational pictures should be designed. 

Abstract [sv]

Cybersäkerhet är en av grundpelarna för en framgångsrik digitalisering av våra samhällen. En nyckelkomponent för cybersäkerhet är att personal som arbetar med cybersäkerhet utvecklar cyberlägesförståelse för att ”få koll på läget” i cybermiljön och, baserat på den förståelsen, reagerar på händelser. Trots det växande intresset för cyberlägesförståelse så finns det få empiriska studier som undersöker cyberlägesförståelse från den mänskliga aktörens perspektiv i organisatoriska sammanhang. Syftet med avhandlingen är att bidra till cyberlägesförståelseforskningen  genom att undersöka cyberlägesförståelse i organisationer och presentera empiriska studier med fokus på svensk offentlig sektor.

I denna avhandling ingår fem artiklar som studerar olika aspekter av cyberlägesförståelse. I den första artikeln har en totalundersökning av den svenska offentliga sektorn genomförts och en  ögonblicksbild av sektorns cybersäkerhetsmognad samt hur offentlig sektor kommunicerade om cybersäkerhetsrisker under COVID-19-pandemin presenteras. I den andra artikeln har de förutsättningar under vilka cybersäkerhetsarbete bedrivs vid svenska förvaltningsmyndigheter undersökts och resultat från semi-strukturerade intervjuer med respondenter som deltar i cybersäkerhetsarbetet vid förvaltningsmyndigheterna presenteras. I den tredje artikeln presenteras fyra personor, baserade på det empiriska materialet från den första och andra artikeln, som validerats. I den fjärde artikeln presenteras en fallstudie om hur personal i en stor, komplex organisation utvecklade cyberlägesförståelse under tiden de hanterade ett cyberhot. I den femte artikeln utforskas behovet av systemstöd för lägesbilder som kan underlätta för cyberlägesförståelse hos personal som hanterar cyberhot genom den deltagande design-metoden video-prototypande. 

Avhandlingen diskuterar utmaningarna för cyberlägesförståelse i organisationer, hur cyberlägesförståelse kan förbättras, samt hur systemstöd för lägesbilder bör utformas för att stödja cyberlägesförståelse.

Place, publisher, year, edition, pages
Stockholm: Kungliga Tekniska högskolan, 2025. p. ix, 67
Series
TRITA-EECS-AVL ; 2025:40
Keywords
cyber situation awareness, cybersecurity, public sector, common operational picture, crisis management, cyberlägesförståelse, cybersäkerhet, offentlig sektor, lägesbild, krishantering
National Category
Human Computer Interaction
Research subject
Human-computer Interaction
Identifiers
urn:nbn:se:kth:diva-362904 (URN)978-91-8106-241-0 (ISBN)
Public defence
2025-05-27, F3 (Flodis), Lindstedtsvägen 26 & 28, Stockholm, 14:00 (English)
Opponent
Supervisors
Funder
Swedish Armed Forces
Note

QC 20250430

Available from: 2025-04-30 Created: 2025-04-29 Last updated: 2025-05-09Bibliographically approved

Open Access in DiVA

No full text in DiVA

Authority records

Andreasson, AnnikaArtman, HenrikBrynielsson, JoelFranke, Ulrik

Search in DiVA

By author/editor
Andreasson, AnnikaArtman, HenrikBrynielsson, JoelFranke, Ulrik
By organisation
Media Technology and Interaction Design, MIDTheoretical Computer Science, TCS
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 33 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf