Our digital societies are vulnerable to cyber crises. Without cyber-resilient organizations, vital societal functions may suffer incidents or loss of service. The diverse roles involved in cybersecurity decision-making require cyber situation awareness to uphold robust cybersecurity. Existing systems and processes supporting cyber situation awareness are not tailored to organizational needs, either at the role or the group level. This study explores the need for socio-technical system support, presenting common operational pictures supporting cyber situation awareness for staff handling cyberthreats. The participatory design method video prototyping was used to elicit needs from staff in a large, complex, public sector organization providing essential services. All participants have roles in cybersecurity crisis and incident management. Results from the video prototyping workshop suggest that cybersecurity staff need (i) a single support system for incident management, and (ii) a shared data repository underpinning (iii) role-specific common operational pictures. The envisioned system support provides traceability and accountability.
QC 20250818