SearcharxivSearch

arXiv · 2508.20811

When technology is not enough: Insights from a pilot cybersecurity culture assessment in a safety-critical industrial organisation

Abstract

As cyber threats increasingly exploit human behaviour, technical controls alone cannot ensure organisational cybersecurity (CS). Strengthening cybersecurity culture (CSC) is vital in safety-critical industries, yet empirical research in real-world industrial setttings is scarce. This paper addresses this gap through a pilot mixed-methods CSC assessment in a global safety-critical organisation. We examined employees' CS knowledge, attitudes, behaviours, and organisational factors shaping them. A survey and semi-structured interviews were conducted at a global organisation in safety-critical industries, across two countries chosen for contrasting phishing simulation performance: Country 1 stronger, Country 2 weaker. In Country 1, 258 employees were invited (67%), in Country 2, 113 were invited (30%). Interviews included 20 and 10 participants respectively. Overall CSC profiles were similar but revealed distinct challenges. Both showed strong phishing awareness and prioritised CS, yet most viewed phishing as the main risk and lacked clarity on handling other incidents. Line managers were default contacts, but follow-up on reported concerns was unclear. Participants emphasized aligning CS expectations with job relevance and workflows. Key contributors to differences emerged: Country 1 had external employees with limited access to CS training and policies, highlighting monitoring gaps. In Country 2, low survey response stemmed from a "no-link in email" policy. While this policy may have boosted phishing performance, it also underscored inconsistencies in CS practices. Findings show that resilient CSC requires leadership involvement, targeted communication, tailored measures, policy-practice alignment, and regular assessments. Embedding these into strategy complements technical defences and strengthens sustainable CS in safety-critical settings.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Tita Alissa Bach, Linn Pedersen, Maria Kinck Borén†, Lisa Christoffersen Temte†. 2025-08-28. When technology is not enough: Insights from a pilot cybersecurity culture assessment in a safety-critical industrial organisation. https://arxiv.org/abs/2508.20811

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Work, Wellbeing, and Choice: Empirical Lessons for AI Futures

Advances in AI-driven automation have raised questions about how humans might find wellbeing in a world where paid employment is less necessary or less available than before. Paid work has been variously characterized as both a contributor and an impediment to human wellbeing. What is already known about the relationship between paid work and wellbeing? What factors influence wellbeing among people who do not work---or who do not need to work? And how might these factors bear upon prospective AI-induced economic transformations? To help provide empirical grounding for these questions, we survey the psychological, sociological, and economic literature that investigates the relationship between wellbeing and work. We draw on evidence from multiple populations, including the unemployed, retirees, lottery winners, and financially dependent spouses. This comparative review draws from studies across OECD countries, China, India, and Gulf states. We identify three key factors that mediate the relationship between work status and wellbeing: (1) agency and choice---whether the exit from work is voluntary or involuntary, as well as long-term agency; (2) the availability of alternative sources of work's latent benefits---such as volunteering, hobbies, or state-provisioned employment; and (3) social and systemic context---including cultural norms around work and the robustness of social safety nets. We draw on these three factors to derive specific implications for different AI automation scenarios, connecting the empirical evidence to concrete policy considerations.

cs.CY

From Digital Accountability to Accountable Digitality Through Needs-Aware Information Systems: The Case of Auditable Child-Welfare Judgments

Digital accountability research asks how digital systems can, among other aims, be made transparent, explainable, auditable, contestable, and supportive of ongoing learning and improvement. This paper reverses the question: how can digital transformation make established human institutions more accountable? It theorizes this reversal as accountable digitality and specifies needs-aware information systems as the mediating mechanism. The hard and paradigmatic case is child-welfare judgment, where best-interest procedures must protect children, preserve confidentiality, and respect judicial independence while enabling aggregate learning about needs, reasons, exceptions, and disparities. The case is used diagnostically and illustratively to derive and examine the design logic, not as empirical evidence or validation. Conceptual design-oriented analysis decomposes and recombines digital and legal accountability under child-rights constraints, deriving a canonical theory-to-design chain, contingent mechanisms, implications, and safeguards. It advances IS responsibility and ethics research by showing how privacy-preserving, co-created, needs-aware information systems can support institutional self-knowledge and auditable justice.

cs.CY

(Whose defaults?) Is artificial intelligence reorienting archaeological methods?

Generative AI and the practice of "vibe coding" are changing how archaeologists carry out computational research, but their effects on the discipline's range of methods is still understudied. In this paper, we evaluate whether large language models (LLMs) are narrowing the variety of methods archaeologists use. We first analysed approximately 119,000 archaeology abstracts from Scopus, covering publications from 2010 to 2025. Using a locally run LLM, we identified the computational methods reported in each abstract and organised them into 25 broad categories (L2) and 241 finer clusters (L3). A Bayesian Dirichlet-multinomial model of method composition within sub-disciplines found a small but credible shift in method use after 2023. However, this shift was smaller than the variation already present across the full study period. No individual technique showed a significant change, and overall methodological diversity increased rather than declined. We then ran a controlled experiment to see whether LLMs recommend a narrower set of methods than archaeologists have used in practice. Two different open-weight models were asked to suggest methods for 28 archaeological research problems, with prompts providing three levels of methodological guidance: novice, intermediate, and expert. Recommendation diversity was much lower than in the published literature, particularly without methodological guidance. The models also tended to favour methods that were widely used before 2023, and their recommendations more closely resembled the post-2023 literature. Taken together, these results are consistent with LLMs pushing methodological choice towards convergence, although our study cannot establish a causal effect. They raise a broader question: how can archaeology retain methodological diversity as LLMs become more involved in research?

cs.CY