kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Cyber situation awareness during an emerging cyberthreat: a case study
Stockholm School of Economics, Box 6501, SE-113 83, Stockholm, Sweden.
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID.ORCID iD: 0000-0002-6903-9072
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS. FOI Swedish Defence Research Agency, SE-164 90, Stockholm, Sweden.ORCID iD: 0000-0002-2677-9759
KTH, School of Electrical Engineering and Computer Science (EECS), Human Centered Technology, Media Technology and Interaction Design, MID. Swedish Defence University, Box 278 05, SE-115 93, Stockholm, Sweden.ORCID iD: 0000-0003-2017-7914
2025 (English)In: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 24, no 5, article id 217Article in journal (Refereed) Published
Abstract [en]

The digitalization of our societies makes them increasingly vulnerable to emerging cyberthreats. These cyberthreats can manifest themselves in the form of organized, sophisticated, and persistent threat actors, as well as nonadversarial mistakes. Staff involved in responding to cyberthreats and handling incidents in organizations need cyber situation awareness. This paper presents a case study on what challenges members of staff involved in cybersecurity in a large, complex organization experience when developing cyber situation awareness while handling a remote code execution vulnerability in the form of Log4Shell. Two types of qualitative empirical material were used for the case study, data collected through semi-structured interviews with ten informants, and internal documentation. The empirical material was analyzed to create a timeline of events in the organization. The results show how information about the threat spread throughout the organization, the types of artifacts that served as common operational pictures, and the role played by information sharing in maintaining staff cyber situation awareness. Three major challenges to the organization were found: (i) information sharing among staff was not effortless, (ii) there was no organization-wide common operational picture established, and (iii) inaccurate information was shared. This study adds a real-world contribution to the literature on organizational handling of cyberthreats.

Place, publisher, year, edition, pages
Springer Nature , 2025. Vol. 24, no 5, article id 217
Keywords [en]
Common operational picture, Cyber situation awareness, Cybersecurity, Log4j, Log4Shell, Public sector
National Category
Information Systems, Social aspects Information Systems Business Administration
Identifiers
URN: urn:nbn:se:kth:diva-372052DOI: 10.1007/s10207-025-01106-zISI: 001581739200001Scopus ID: 2-s2.0-105017586059OAI: oai:DiVA.org:kth-372052DiVA, id: diva2:2008658
Note

Not duplicate with DiVA 1955293

QC 20251023

Available from: 2025-10-23 Created: 2025-10-23 Last updated: 2025-10-23Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Artman, HenrikBrynielsson, JoelFranke, Ulrik

Search in DiVA

By author/editor
Artman, HenrikBrynielsson, JoelFranke, Ulrik
By organisation
Media Technology and Interaction Design, MIDTheoretical Computer Science, TCS
In the same journal
International Journal of Information Security
Information Systems, Social aspectsInformation SystemsBusiness Administration

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 86 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf