Abstract
Cyber security incident response (CSIR) plays a critical role in supporting the continuity of digital infrastructures by detecting, responding to, and recovering from cyber-attacks. The work of CSIR practice is becoming harder to achieve effectively due to the increased number and sophistication of attacks and the ever-changing complexity of digital networks. Although a range of studies have sought to improve CSIR effectiveness, there is no clear definition of CSIR effectiveness. Moreover, to my knowledge, no one has sought to understand what impact this has had on the wider CSIR practice and the people upon whom it is critically dependent. This thesis uses a novel Systemic Design approach, combining Systems Thinking and design methods, to empirically investigate CSIR effectiveness with industry practitioners and stakeholders, with the overall aim of improving CSIR effectiveness.The three studies in this thesis aimed to gain a deeper understanding of the interrelationships among people, processes, tools, technologies, and environments to inform improvements in CSIR practice. Study 01 is a qualitative Gigamap (extensive mapping) workshop study with CSIR practitioners and stakeholders from four organisations investigating CSIR effectiveness and systemic impact. This explored how effectiveness is understood and evaluated within the context of the complex system in which it operates, in addition to investigating what limits effectiveness and how it could be improved. Similarly, study 02 examined the same questions using a complementary method of semi-structured interviews with seven CSIR practitioners and stakeholders to elicit different insights into the system. Finally, study 03 is a qualitative guided interview study aimed at building on the findings from the first two studies and generating a vision for improving CSIR effectiveness with 15 CSIR practitioners and stakeholders.
The key findings of this thesis are that there is no standardisation of how effectiveness is understood or evaluated in practice; instead, a range of methods are used to evaluate it, mainly from a program theory lens, including impact, outcomes, effectiveness, and benchmarking maturity. However, the current methods for evaluating CSIR effectiveness are problematic due to the system's complexity. Critically, this approach to understanding effectiveness is a first-order problem in the field that affects a range of elements, including decision-making, practitioner well-being and motivation, and resource allocation, all of which negatively impact CSIR effectiveness overall. By embracing and investigating CSIR through a complex systems lens and demonstrating the relationships between problems, needs, and challenges, this thesis has uncovered a range of leverage points – areas in the system where a small change in one place can positively impact the whole – to improve CSIR effectiveness. This has implications for supporting both practice and research by prioritising efforts in specific areas of the complex system that have been shown to have the potential to improve CSIR practice overall. Furthermore, this thesis builds on existing knowledge in the field by presenting a complementary perspective and a case study to better understand and improve the effectiveness of the complex system of CSIR.
| Date of Award | 20 May 2026 |
|---|---|
| Original language | English |
| Awarding Institution |
|
| Sponsors | EPSRC Centre for Doctoral Training |
| Supervisor | Danae Stanton Fraser (Supervisor), Adam Joinson (Supervisor) & Barnaby Craggs (Supervisor) |
Keywords
- Cyber security incident response
- Systems thinking
- Systemic Design
- Effectiveness
Cite this
- Standard