Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework
Abstract
:1. Introduction
2. Approaches and Models for Cyber Resilience
3. Research Procedure
4. Digitalization Capabilities
5. Digitalization Capabilities and Cyber Resilience
6. Discussion and Conclusions
- Employing heterogeneous resources is a driver of prevention and training practices that belongs to the plan/prepare phase of the managerial cyber resilience process.
- Promoting continuous learning is a driver of the practice of training, belonging to the plan/prepare phase of the managerial cyber resilience process.
- Online informational capabilities are drivers of prevention and review practices, respectively belonging to the Plan/Prepare and Adapt phases of the managerial cyber resilience process.
- Improvisational capabilities are drivers of the Update practice, which belongs to the Adapt phase of the managerial cyber resilience process.
- Scanning the evolution of the digital environment and Timely reconfiguration of resources are drivers of the adaptation to the context that belongs to the Adapt phase of the managerial cyber resilience process.
Author Contributions
Funding
Conflicts of Interest
References
- Annarelli, A.; Battistella, C.; Nonino, F. A framework to evaluate the effects of organizational resilience on service quality. Sustainability 2020, 12, 958. [Google Scholar] [CrossRef] [Green Version]
- Vial, G. Understanding digital transformation: A review and a research agenda. J. Strateg. Inf. Syst. 2019, 28, 118–144. [Google Scholar] [CrossRef]
- Nylén, D.; Holmström, J. Digital innovation strategy: A framework for diagnosing and improving digital product and service innovation. Bus. Horiz. 2015, 58, 57–67. [Google Scholar] [CrossRef] [Green Version]
- Kaplan, J.; Ritcher, W.; Ware, D. Cybersecurity: Linchpin of the Digital Enterprise|McKinsey. McKinsey Co., no. July. 2019. Available online: https://www.mckinsey.com/business-functions/risk/our-insights/cybersecurity-linchpin-of-the-digital-enterprise# (accessed on 1 July 2021).
- Khan, O.; Estay, D.A.S. Supply Chain Cyber-Resilience: Creating an Agenda for Future Research. Technol. Innov. Manag. Rev. 2015, 5, 6–12. [Google Scholar] [CrossRef]
- Armenia, S.; Angelini, M.; Nonino, F.; Palombi, G.; Schlitzer, M.F. A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs. Decis. Support Syst. 2021, 147, 113580. [Google Scholar] [CrossRef]
- Annarelli, A.; Battistella, C.; Nonino, F.; Parida, V.; Pessot, E. Literature review on digitalization capabilities: Co-citation analysis of antecedents, conceptualization and consequences. Technol. Forecast. Soc. Chang. 2021, 166, 120635. [Google Scholar] [CrossRef]
- Annarelli, A.; Nonino, F.; Palombi, G. Understanding the management of cyber resilient systems. Comput. Ind. Eng. 2020, 149, 106829. [Google Scholar] [CrossRef]
- Bodeau, D.; Graubart, R.; Picciotto, J.; McQuaid, R. Cyber Resiliency Engineering Framework. 2011. Available online: http://www.mitre.org/work/tech_papers/2012/11_4436/%5Cnpapers2://publication/uuid/F03D9287-780F-4B61-AC47-E77BEDC3F939 (accessed on 1 July 2021).
- BBurstein, M.; Goldman, R.; Robertson, P.; Laddaga, R.; Balzer, R.; Goldman, N.; Geib, C.; Kuter, U.; Mcdonald, D.; Maraist, J.; et al. STRATUS: Strategic and tactical resiliency against threats to ubiquitous systems. In Proceedings of the 2012 IEEE Sixth International Conference on Self-Adaptive and Self-Organizing Systems Workshops, Lyon, France, 10–14 September 2012; pp. 47–54. [Google Scholar] [CrossRef]
- Linkov, I.; Eisenberg, D.A.; Bates, M.E.; Chang, D.; Convertino, M.; Allen, J.H.; Flynn, S.E.; Seager, T.P. Measurable resilience for actionable policy. Environ. Sci. Technol. 2013, 47, 10108–10110. [Google Scholar] [CrossRef] [PubMed]
- Alberts, D.S.; Hayes, R.E. Power to the Edge: Command…Control…in the Information Age; Office of the Assistant Secretary of Defense Washington DC Command and Control Research Program (CCRP): Washington, DC, USA, 2003.
- Linkov, I.; Eisenberg, D.A.; Plourde, K.; Seager, T.P.; Allen, J.; Kott, A. Resilience metrics for cyber systems. Environ. Syst. Decis. 2013, 33, 471–476. [Google Scholar] [CrossRef]
- Collier, Z.A.; Dimase, D.; Walters, S.; Tehranipoor, M.M.; Lambert, J.H.; Linkov, I. Cybersecurity standards: Managing risk and creating resilience. Computer (Long. Beach. Calif.) 2014, 47, 70–76. [Google Scholar] [CrossRef]
- Ferdinand, J. Building organisational cyber resilience: A strategic knowledge-based view of cyber security management. J. Bus. Contin. Emerg. Plan. 2015, 9, 185–195. [Google Scholar]
- Jensen, L. Challenges in Maritime Cyber-Resilience. Technol. Innov. Manag. Rev. 2015, 5, 35–39. [Google Scholar] [CrossRef]
- Di Mase, D.; Collier, Z.A.; Heffner, K.; Linkov, I. Systems engineering framework for cyber physical security and resilience. Environ. Syst. Decis. 2015, 35, 291–300. [Google Scholar] [CrossRef]
- Boyes, H. Cybersecurity and Cyber-Resilient Supply Chains. Technol. Innov. Manag. Rev. 2015, 5, 28–34. [Google Scholar] [CrossRef]
- Björck, F.; Henkel, M.; Stirna, J.; Zdravkovic, J. Cyber Resilience—Fundamentals for a Definition. In Advances in Intelligent Systems and Computing; Springer: New York, NY, USA, 2015; Volume 353, pp. 311–316. [Google Scholar]
- Tran, H.; Campos-Nanez, E.; Fomin, P.; Wasek, J. Cyber resilience recovery model to combat zero-day malware attacks. Comput. Secur. 2016, 61, 19–31. [Google Scholar] [CrossRef]
- Estay, D.A.S.; Sahay, R.; Barfod, M.B.; Jensen, C.D. A systematic review of cyber-resilience assessment frameworks. Comput. Secur. 2020, 97, 101996. [Google Scholar] [CrossRef]
- Annarelli, A.; Clemente, S.; Nonino, F.; Palombi, G. Effectiveness and Adoption of NIST Managerial Practices for Cyber Resilience in Italy; Springer: Berlin/Heidelberg, Germany, 2021; pp. 818–832. [Google Scholar]
- Carayannis, E.G.; Grigoroudis, E.; Rehman, S.S.; Samarakoon, N. Ambidextrous Cybersecurity: The Seven Pillars (7Ps) of Cyber Resilience. IEEE Trans. Eng. Manag. 2021, 68, 223–234. [Google Scholar] [CrossRef]
- Kott, A.; Linkov, I. To improve cyber resilience, measure it. IEEE Comp. 2021, 54, 80–85. [Google Scholar] [CrossRef]
- Colabianchi, S.; Costantino, F.; di Gravio, G.; Nonino, F.; Patriarca, R. Discussing resilience in the context of cyber physical systems. Comput. Ind. Eng. 2021, 160, 107534. [Google Scholar] [CrossRef]
- Tukker, A. Product services for a resource-efficient and circular economy—A review. J. Clean. Prod. 2015, 97, 76–91. [Google Scholar] [CrossRef]
- Rai, A.; Patnayakuni, R.; Seth, N. This content downloaded from 216.227.221.251 on Tue. Manag. MIS Q. 2006, 30, 226–246. [Google Scholar]
- Selander, L.; Henfridsson, O.; Svahn, F. Capability search and redeem across digital ecosystems. J. Inf. Technol. 2013, 28, 183–197. [Google Scholar] [CrossRef]
- McAfee, A.; Brynjolfsson, E. Investing in the IT That Makes a Competitive Difference. Harv. Bus. Rev. 2008, 86, 98–107. [Google Scholar]
- Mishra, A.N.; Konana, P.; Barua, A. Antecedents and consequences of Internet use in procurement: An empirical investigation of U.S. manufacturing firms. Inf. Syst. Res. 2007, 18, 103–120. [Google Scholar] [CrossRef]
- Drnevich, P.L.; Croson, D.C. Information T Echnology and B Usiness -L Evel S Trategy: T Oward an I Ntegrated T Heoretical P Erspective 1. MIS Q. 2013, 37, 483–509. [Google Scholar] [CrossRef]
- Tripsas, M.; Gavetti, G. Capabilities, Cognition, and Inertia: Evidence from Digital Imaging. Strateg. Manag. J. 2000, 21, 1147–1161. [Google Scholar] [CrossRef]
- Wheeler, B.C. NEBIC: A dynamic capabilities theory for assessing net-enablement. Inf. Syst. Res. 2002, 13, 125–146. [Google Scholar] [CrossRef] [Green Version]
- Pavlou, P.A.; Sawy, O.A.E. The ‘third hand’: IT-enabled competitive advantage in turbulence through improvisational capabilities. Inf. Syst. Res. 2010, 21, 443–471. [Google Scholar] [CrossRef]
- El Sawy, O.A.; Malhotra, A.; Park, Y.K.; Pavlou, P.A. Seeking the configurations of digital ecodynamics: It takes three to tango. Inf. Syst. Res. 2010, 21, 835–848. [Google Scholar] [CrossRef]
- Kannan, P.K. Digital marketing: A framework, review and research agenda. Int. J. Res. Mark. 2017, 34, 22–45. [Google Scholar] [CrossRef]
- Yang, M.; Fu, M.; Zhang, Z. The adoption of digital technologies in supply chains: Drivers, process and impact. Technol. Forecast. Soc. Chang. 2021, 169, 120795. [Google Scholar] [CrossRef]
- Barua, A.; Konana, P.; Whinston, A.B.; Yin, F. An empirical investigation of net-enabled business value. MIS Q. 2004, 28, 585–620. [Google Scholar] [CrossRef] [Green Version]
- Sambamurthy, V.; Bharadwaj, A.; Grover, V. Shaping Agility through Digital Options: Reconceptualizing the Role of Information. MIS Q. 2003, 27, 237–263. [Google Scholar] [CrossRef] [Green Version]
- Tøndel, I.A.; Line, M.B.; Jaatun, M.G. Information security incident management: Current practice as reported in the literature. Comput. Secur. 2014, 45, 42–57. [Google Scholar] [CrossRef]
- Mendonça, D.; Wallace, W.A. Studying Organizationally-situated Improvisation in Response to Extreme Events. Int. J. Mass Emerg. Disasters 2004, 22, 5–29. [Google Scholar]
- Kachra, A.; White, R.E. Know-how transfer: The role of social, economic/ competitive, and firm boundary factors. Strateg. Manag. J. 2008, 29, 425–445. [Google Scholar] [CrossRef]
- Ganin, A.A.; Quach, P.; Panwar, M.; Collier, Z.A.; Keisler, J.M.; Marchese, D.; Linkov, I. Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management. Risk Anal. 2020, 40, 183–199. [Google Scholar] [CrossRef]
- Teece, D. Explicating Dynamic Capabilities: The nature and microfoundations of (sustainable) enterprise performance. Strateg. Manag. J. 2007, 28, 1319–1350. [Google Scholar] [CrossRef] [Green Version]
Digitalization Capabilities | Cyber Resilience Practice | Cyber Resilience Phase | |
---|---|---|---|
Employing heterogeneous resources | Employing heterogeneous distributed resources to use digital solutions to different extents and in different stages of the business processes. There can be a distinction between digital capabilities to exchange and process information and digital capabilities to automate tasks [30] | Prevention; Training | Plan/Prepare |
Improvisational capabilities | Ability to spontaneously reconfigure existing resources to build new operational capabilities to address urgent, unpredictable, and novel environmental situations, through IT-enabled capability, i.e., the effective use of digital IT systems [34] | Update | Adapt |
Capabilities that enable spontaneous change, are best suited for extremely turbulent environments, characterized by sudden changes in demand and unexpected technological breakthroughs [35] | |||
Online informational capabilities | The ability of a firm to exchange strategic and tactical information through the integration of IT resources and processes [27,38] | Prevention; Review | Plan/Prepare; Adapt |
Promoting continuous learning | Firms should promote continuous learning of the unique properties of digital technologies, by acquiring new skills both internally and externally while establishing new digital roles [3] | Training | Plan/Prepare |
Scanning evolution of digital environment | To identify opportunities, firms need to scan their digital environment to foresee and understand key changes [3] | Context | Adapt |
Timely reconfiguration of resources | Net enablement capability as a dynamic capability to turn timely the business innovations enabled by digital networks into customer value [33] | Context | Adapt |
Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. |
© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Annarelli, A.; Palombi, G. Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework. Sustainability 2021, 13, 13065. https://doi.org/10.3390/su132313065
Annarelli A, Palombi G. Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework. Sustainability. 2021; 13(23):13065. https://doi.org/10.3390/su132313065
Chicago/Turabian StyleAnnarelli, Alessandro, and Giulia Palombi. 2021. "Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework" Sustainability 13, no. 23: 13065. https://doi.org/10.3390/su132313065
APA StyleAnnarelli, A., & Palombi, G. (2021). Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework. Sustainability, 13(23), 13065. https://doi.org/10.3390/su132313065