1.1. Motivation
Currently, the functioning of modern society is increasingly dependent on critical infrastructure (CI). This infrastructure includes systems that support the operation of key sectors of the economy, such as energy, transportation, finance, and communications. This inherent dependence creates significant risks related to cybersecurity.
In recent times, there has been a surge in cyber intrusions and cyberattacks on CI. The growing trend of cyberattacks is driven by several factors:
1. Increasing complexity and interconnectedness of digital systems: Modern systems are becoming more complex, which provides more opportunities for malicious actors.
2. Greater accessibility of cybercrime: Cybercrime has become more accessible with the availability of ready-made tools and services, allowing even inexperienced hackers to launch attacks.
3. Increasing value of data: Data has become a valuable asset, making it an attractive target for cybercriminals.
Cyberattacks on CI pose a serious threat that can lead to significant economic losses, social disruptions, and even threats to national security.
Despite the growing threat of cyberattacks, there remains a significant gap in understanding how companies operating in the CI sector recover from such incidents. The issue is particularly pronounced when comparing the approaches to recovery between internal specialists (investors, reputation management managers, chief information security officers) and external information security auditors.
Existing research on CI cybersecurity primarily focuses on the technical aspects of protection against cyberattacks, paying insufficient attention to recovery after incidents and reputation management. In particular, there is a lack of deep understanding of how different groups of specialists involved in the recovery process perceive and implement recovery strategies, as well as how these differences affect the efficiency and speed of recovery.
Understanding the differences in recovery approaches between internal and external specialists after cyberattacks is crucial for developing more effective cybersecurity strategies and enhancing the resilience of CI.
1.2. State-of-the-Art
As a cybersecurity awareness and education manager, Esther Solomon Edun’s research, based on her Ph.D. in Cyber Security from Cranfield University, highlights the significance of stakeholder interactions in fostering positive cybersecurity behaviour within organizations. The focus is on overcoming the information security barrier between top-level executives, information security experts, and non-IT professionals, with the ultimate aim of aligning security objectives with the broader business goals [
1] In light of these challenges, the research “The Global State of Industrial Cybersecurity 2021: Resilience Amid Disruption” report shows that 80% of critical infrastructure organizations experienced a ransomware cyber-attack. That causes staggering financial and societal repercussions when critical infrastructure is disrupted. The report also found that the combination of the ever-accelerating digital transformation and limited availability of skilled cybersecurity workers has resulted in several high-profile attacks on critical infrastructure. In response, many C-suite executives have become heavily involved in the decision-making and oversight of their organization’s cybersecurity practices. In fact, more than 60% who are centralizing IT governance are under the Chief Information Security Officers (CISOs). In addition, 62% are supportive of government regulators enforcing mandatory and timely reporting of cybersecurity incidents. The report also found that the combination of the ever-accelerating digital transformation and limited availability of skilled cybersecurity workers has resulted in several high-profile attacks on critical infrastructure [
2]. There are cross-country differences in opinion regarding information security processes that could affect assessment of the company’s reputation among individuals in Czech Republic and Belgium: 58% of Czech individuals “agree” with that competing to 48% from Belgium. However, Belgian respondents are more unequivocally convinced of this need which is 32% of the total mass of respondents and is three times higher than the data for the same response of respondents in the Czech Republic. Given the intensity of public concern about information security, reputational issues could not be short term, hoc and defensive but should have strategic view and long-term planning to defend reputation [
3].
Although the implication of cybersecurity stretches across all business regions, the most attention of the cybersecurity in the business world focuses on the PayTech financial sector (or PayTech – technology-driven solutions for electronic payments, transactions, and financial services) because financial information attack leads to a negative stock market reaction [
4]. In connection with that, research shows that external auditors pay more attention to cybersecurity incidents and also can apply more pressure as external auditors are responsible for providing reasonable financial assurance statements that a company is presented fairly and in conformity with information security standards [
5]. Nevertheless, for example, according to an Ernst &
Young survey, only 7 % of Fortune 100 companies disclosed that they perform cyber incident simulations or tabletop exercises; and only 16 percent of companies disclosed the use of an external independent consultant to help management with cybersecurity-related practices [
6].
Consistent with prior studies, in this research within our analyses, we have identified a few current problems: the disparity in approaches to recovering from cyber-attacks between internal company stakeholders and external information security auditors, particularly in the strategy for recovering the company’s reputation that is damaged by cyber incidents. Emphasizing the need for a better understanding between different approaches and prevention of information security and reputation that is damaged by cyber incidents, this study proposes two research questions (RQs): RQ1: Do internal stakeholders (investor relations, reputation management, and Chief Information Security Officers) and external auditors differ in their viewpoints on recovery strategies following cyber-attacks? RQ2: Do internal stakeholders (investor relations, reputation management, and Chief Information Security Officers) and external auditors differ in their viewpoints on reputation defense and role that the European Union (EU) has outside its jurisdiction from cyber-attacks?
To address the above research questions, the current study contributes to existing research in several ways. First, considering the previous researches that focuses on cyber-attacks impact a company’s reputation, which in turn impacts the company’s share price as serious business interruptions after a breach have one of the largest effects on the value of companies because of its impact on cash flow [
7]. According to David Chinn, senior partner at McKinsey: “In most cases, company share prices bounce back from business interruption”. In particular, such damage can be of greater importance and higher impact, if the company is an essential part of critical infrastructures; new risks, vulnerabilities and threats can result in political confrontations; therefore, critical infrastructure must be protected and resilient [
8].
Second, we consider existing frameworks and regulations to enforce several information security frameworks and regulations that information security specialists must follow whenever they are internal or external employees. For instance, the European Central Bank (ECB) imposes specific information security practices that are crucial for ensuring cybersecurity in critical infrastructure companies [
9].
In the EU is the NIS2 directive (proposed by National Institute of Standards and Technology) – that aims to establishes a common level of cybersecurity in the EU, with the aim of ensuring the technological and digital sovereignty of the European Union in the cyber field, as well as managing risk and reputation. It requires the EU Member States to identify and assess the risks to the security of network and information systems, and to take appropriate measures to manage those risks [
10]. This is particularly important for financial markets and company reputation recovery after cyber-attacks [
11]. Furthermore, firms with stronger reputations are more likely to weather market volatility better than those with weaker reputations.
Third, the research examines the view on the boundary conditions for implementing recovery steps after cyber incidents such as project management methodologies and collaboration with EU authorities. This holistic approach ensures that risk-based decision making is integrated into every aspect of the organization, from the strategic to the tactical level. The PM² project management methodology, developed and supported by the European Commission, emphasizes the importance of risk management in recovering from cyberattacks. According to the European Commission the PM² methodology uses a structured risk management process that includes identifying risks, assessing their impact, and developing and implementing mitigation measures to minimize their impact. In addition to the PM² methodology, Lean Six Sigma offers a continuous improvement methodology for managing risks in the cybersecurity context. This methodology begins with quantifying risk and then focuses on prevention, detection, and remediation. Consequently, Lean Six Sigma used to mitigate risks in three ways such preventing incidents from happening, detecting incidents as early as possible, and minimizing the impact of incidents that do occur [
8]. By focusing on these three elements, organizations can minimize the damage caused by cyber-attacks and improve their resilience to future threats.
Finally, our study aims to address the above research questions by examining different viewpoints on different viewpoints on reputation defense and the utilization of reputation management tools, which have the potential to restore the value of a company’s shares following a cyber incident. Such a reputation management tools includes: transparency in admitting cyber-attack incidents within 24 hours, constant communication with key stakeholders through regular channels, maintaining own news channels with higher frequency for communication, conducting trainings for company management and employees on incidents and communication, maintaining security through secure backup systems and system design review, continuous improvement through feedback analysis and addressing concerns, and reporting actions taken before, during, and after incidents.
Dealing with information security attacks requires broad knowledge and include people with knowledge from different fields, including investor relations, reputation relations and information security and each of these areas must have a specialist or single point of contact for these tasks. For example, Investor relations (IR) managers are responsible for effectively communicating an organization’s cybersecurity initiatives and risk management practices to investors, building trust and confidence in the company’s ability to prevent cyberattacks. Reputation managers (RM) play a vital role in protecting the organization’s public image and brand reputation during and after a cyber-attack, implementing strategies to manage the incident and restore trust with stakeholders. Chief information security officers (CISOs) lead the prevention of cyber-attacks by implementing comprehensive security measures, assessing risks, and developing proactive strategies to safeguard critical information and systems from potential threats [
11].
Table 1 above illustrates the relationship between cyber-attacks, the dynamics of company stock, and reputation management. The analysis also demonstrates the impact of the participation of professionals such as investor relations (IR), reputation management (RM) specialists, together with Chief Information Security Officers (CISOs), on the recovery process.