Skip to main content

Research Repository

Advanced Search

Security Culture in Industrial Control Systems Organisations: A Literature Review

Evripidou, Stefanos; Ani, Uchenna D.; D McK. Watson, Jeremy; Hailes, Stephen

Authors

Stefanos Evripidou

Jeremy D McK. Watson

Stephen Hailes



Abstract

Industrial control systems (ICS) are a key element of a country’s critical infrastructure, which includes industries like energy, water, and transport. In recent years, an increased convergence of operational and information technology has been taking place in these systems, increasing their cyber risks, and making security a necessity. People are often described as one of the biggest security risks in ICS, and historic attacks have demonstrated their role in facilitating or deterring them. One approach to enhance the security of organisations using ICS is the development of a security culture aiming to positively influence employees’ security perceptions, knowledge, and ultimately, behaviours. Accordingly, this work aims to review the security culture literature in organisations which use ICS and the factors that affect it, to provide a summary of the field. We conclude that the factors which affect security culture in ICS organisations are in line with the factors discussed in the general literature, such as security policies and management support. Additional factors related to ICS, such as safety culture, are also highlighted. Gaps are identified, with the limited research coverage being the most prominent. As such, proposals for future research are offered, including the need to conduct research with employees whose roles are not security related.

Online Publication Date Jul 22, 2022
Publication Date Jul 22, 2022
Deposit Date Jun 2, 2023
Publisher Springer
Pages 133-146
Book Title IFIP Advances in Information and Communication Technology
ISBN 978-3-031-12171-5
DOI https://doi.org/10.1007/978-3-031-12172-2_11
Additional Information First Online: 22 July 2022; Conference Acronym: HAISA; Conference Name: International Symposium on Human Aspects of Information Security and Assurance; Conference City: Mytilene, Lesbos; Conference Country: Greece; Conference Year: 2022; Conference Start Date: 6 July 2022; Conference End Date: 8 July 2022; Conference Number: 16; Conference ID: haisa2022; Conference URL: https://haisa.org/; Type: Double-blind; Conference Management System: EasyChair; Number of Submissions Sent for Review: 30; Number of Full Papers Accepted: 25; Number of Short Papers Accepted: 0; Acceptance Rate of Full Papers: 83% - The value is computed by the equation "Number of Full Papers Accepted / Number of Submissions Sent for Review * 100" and then rounded to a whole number.; Average Number of Reviews per Paper: 2.66; Average Number of Papers per Reviewer: 3; External Reviewers Involved: No