Authors:
Costas Boletsis
1
;
Ragnhild Halvorsrud
1
;
J. Brian Pickering
2
;
Stephen Phillips
2
and
Mike Surridge
2
Affiliations:
1
SINTEF Digital, Oslo, Norway
;
2
IT Innovation Centre, University of Southampton, Southampton, U.K.
Keyword(s):
Cybersecurity, Modelling, Socio-technical Risk Assessment, User Journey, Visualisation.
Abstract:
Small and medium-sized enterprises (SMEs) rarely conduct a thorough cyber-risk assessment and they may face various internal issues when attempting to set up cyber-risk strategies. In this work, we apply a user journey approach to model human behaviour and visually map SMEs’ practices and threats, along with a visualisation of the socio-technical actor network, targeted specifically at the risks highlighted in the user journey. By using a combination of cybersecurity-related visualisations, our goals are: i) to raise awareness about cybersecurity, and ii) to improve communication among IT personnel, security experts, and non-technical personnel. To achieve these goals, we combine two modelling languages: Customer Journey Modelling Language (CJML) is a visual language for modelling and visualisation of work processes in terms of user journeys. System Security Modeller (SSM) is an asset-based risk-analysis tool for socio-technical systems. By demonstrating the languages’ supplementary
nature through a threat scenario and considering related theories, we believe that there is a sound basis to warrant further validation of CJML and SSM together to raise awareness and handle cyber threats in SMEs.
(More)