Change that Respects Business Expertise: Stories as Prompts for a Conversation about Organisation Security

Simon Parkin, Simon Arnell, Jeremy Ward

Research output: Chapter in Book/Conference proceedings/Edited volumeConference contributionScientificpeer-review

61 Downloads (Pure)

Abstract

Leaders of organisations must make investment decisions relating to the security of their organisation. This often happens through consultation with a security specialist. Consultations may be regarded as conversations taking place in a trading zone between the two domains. We propose that supporting the trading zone is a route to sustainable, workable security change improvements. Prompts for such improvements are already in place, in the security stories that reach business leaders through news media, or anecdotes from trusted peers. However, a shift in perspective is needed to view these stories and anecdotes as prompts for individual decision makers to enter into the trading zone with security specialists. We illustrate how to facilitate this shift by recasting security ontology tools, previously centred around security-specific expertise, as a support device to enrich conversations between business expertise and security advice toward finding workable security choices. We frame our proposal within a broader view of community transformation, exploring the important principle of identifying practical opportunities to inform discussions about security solutions that are appropriate in the business context. Community-level discussions have potential to lead to more lasting, effective improvements than those instigated by one-way interventions from security specialists. We extend the view, applying the paradigm to articulate the importance of two-way conversations between business peers and security specialists.
Original languageEnglish
Title of host publicationNew Security Paradigms Workshop, NSPW 2021
PublisherAssociation for Computing Machinery (ACM)
Pages28-42
Number of pages15
ISBN (Electronic)9781450385732
DOIs
Publication statusPublished - 2021
Event12th New Security Paradigms Workshop, NSPW 2021 - Virtual, Online, United States
Duration: 26 Oct 202128 Oct 2021

Publication series

NameACM International Conference Proceeding Series

Conference

Conference12th New Security Paradigms Workshop, NSPW 2021
Country/TerritoryUnited States
CityVirtual, Online
Period26/10/2128/10/21

Keywords

  • Cyber security management
  • security stories
  • security transformation

Fingerprint

Dive into the research topics of 'Change that Respects Business Expertise: Stories as Prompts for a Conversation about Organisation Security'. Together they form a unique fingerprint.

Cite this