Situational awareness about data breaches and ransomware attacks: A multi-dimensional cyber threat impact framework and content analyses of practitioner-public discourses
{"title":"Situational awareness about data breaches and ransomware attacks: A multi-dimensional cyber threat impact framework and content analyses of practitioner-public discourses","authors":"Paras Bhatt , Rohit Valecha , H. Raghav Rao","doi":"10.1016/j.ijinfomgt.2025.102902","DOIUrl":null,"url":null,"abstract":"<div><div>Cyber threat incidents are increasingly on the rise resulting in concern among the public. Recently, data breaches and ransomware attacks have emerged as two types of critical cyber threats in terms of impact to both organizations and individuals. As such, organizations and the public have started to discuss these threats in various forms. While the former discusses the threats in practitioner reports that are available for public consumption, social media platforms are the preferred avenue for the public. Though literature has started to examine the issues regarding such cyber threat incidents, research on cyber threats, its resultant discourse on social media and its potential for situational awareness and for extracting meaningful or actionable cyber intelligence is scarce. This paper makes a twofold contribution: first, it extracts multiple dimensions of cyber threats from an examination of theoretical, regulatory and domain specific literature. We term these dimensions, leak, laws, cause, and cost and use them for creating a cyber-threat impact framework. Second, by undertaking text mining for content analysis of large datasets from Verizon’s Data Breach Investigation Reports (DBIR) as well as social media discourses from Twitter, this paper investigates the practitioner-public discourses about the two types of cyber threat incidents to uncover relative significance of different dimensions for situational awareness. The paper finds that topical similarities and differences exist between data breach and ransomware attack incidents on different dimensions in the cyber-threat impact framework. The dual analysis of practitioner and public discourses allows situational awareness that policy makers can use for developing appropriate cyber intelligence and cyber threat defense policies.</div></div>","PeriodicalId":48422,"journal":{"name":"International Journal of Information Management","volume":"83 ","pages":"Article 102902"},"PeriodicalIF":20.1000,"publicationDate":"2025-03-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Information Management","FirstCategoryId":"91","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0268401225000349","RegionNum":1,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"INFORMATION SCIENCE & LIBRARY SCIENCE","Score":null,"Total":0}
引用次数: 0
Abstract
Cyber threat incidents are increasingly on the rise resulting in concern among the public. Recently, data breaches and ransomware attacks have emerged as two types of critical cyber threats in terms of impact to both organizations and individuals. As such, organizations and the public have started to discuss these threats in various forms. While the former discusses the threats in practitioner reports that are available for public consumption, social media platforms are the preferred avenue for the public. Though literature has started to examine the issues regarding such cyber threat incidents, research on cyber threats, its resultant discourse on social media and its potential for situational awareness and for extracting meaningful or actionable cyber intelligence is scarce. This paper makes a twofold contribution: first, it extracts multiple dimensions of cyber threats from an examination of theoretical, regulatory and domain specific literature. We term these dimensions, leak, laws, cause, and cost and use them for creating a cyber-threat impact framework. Second, by undertaking text mining for content analysis of large datasets from Verizon’s Data Breach Investigation Reports (DBIR) as well as social media discourses from Twitter, this paper investigates the practitioner-public discourses about the two types of cyber threat incidents to uncover relative significance of different dimensions for situational awareness. The paper finds that topical similarities and differences exist between data breach and ransomware attack incidents on different dimensions in the cyber-threat impact framework. The dual analysis of practitioner and public discourses allows situational awareness that policy makers can use for developing appropriate cyber intelligence and cyber threat defense policies.
IF 9.6 1区 医学EClinicalMedicinePub Date : 2024-07-13DOI: 10.1016/j.eclinm.2024.102716
Myong Cheol Lim, Youn Jin Choi, Soo-Young Hur, Yong-Man Kim, Jae Hong No, Byoung-Gie Kim, Chi Heum Cho, Sung Hoon Kim, Dae Hoon Jeong, Jae-Kwan Lee, Ji Hyun Kim, Yoon-Jeong Choi, Jung Won Woo, Young Chul Sung, Jong Sup Park
期刊介绍:
The International Journal of Information Management (IJIM) is a distinguished, international, and peer-reviewed journal dedicated to providing its readers with top-notch analysis and discussions within the evolving field of information management. Key features of the journal include:
Comprehensive Coverage:
IJIM keeps readers informed with major papers, reports, and reviews.
Topical Relevance:
The journal remains current and relevant through Viewpoint articles and regular features like Research Notes, Case Studies, and a Reviews section, ensuring readers are updated on contemporary issues.
Focus on Quality:
IJIM prioritizes high-quality papers that address contemporary issues in information management.