# Cybersecurity for Decision Makers

**Authors:** Narasimha Rao Vajjhala (University of New York Tirana, Tirana, Albania) — ORCID 0000-0002-8260-2392; Kenneth David Strang (W3-Research, USA; RMIT University, Australia) — ORCID 0000-0002-4333-4399
**Type:** Edited book
**Source:** CRC Press, 424 pp.
**Published:** 2023-05-25
**DOI:** https://doi.org/10.1201/9781003319887
**Canonical page:** https://www.narasimharao.net/research/cybersecurity-for-decision-makers/
**Indexing:** Edited book · Scopus
**Methodology:** Edited volume of 23 chapters by 46 contributors from 11 countries; chapter methods include case-study analysis, systematic literature review, empirical surveys of psychological factors, comparative regional analysis, and conceptual and policy frameworks.

## Research summary

- **The Problem:** Managers, policymakers and practitioners make cybersecurity decisions with little access to evidence that connects theory to practice.
- **The Approach:** Edited volume of 23 chapters by 46 contributors from 11 countries; chapter methods include case-study analysis, systematic literature review, empirical surveys of psychological factors, comparative regional analysis, and conceptual and policy frameworks.
- **The Core Contribution:** Contributors from 11 countries integrate theory with evidence-based practice on cyberattack causes, human factors, awareness, cybercrime trends, emerging domains such as space and cyber-physical systems, and business continuity, giving decision-makers actionable mitigation strategies.
- **The Citation:** Vajjhala, N. R., & Strang, K. D. (Eds.). (2023). Cybersecurity for Decision Makers. CRC Press. https://doi.org/10.1201/9781003319887

## Summary in detail

**Question.** What do managers, practitioners, policymakers and academics need to understand about cybersecurity risks, and which evidence-based strategies can they use to mitigate future problems?

**Scope.** Twenty-three chapters by 46 scholars from 11 countries integrate theory with evidence-based practice: why cyberattacks disrupt society, cyberbullying, human factors, cybercrime fundamentals, attack case studies, awareness programmes (Malaysia) and social engineering among adolescents, named-entity cybercrime recognition, a decade of cybercrime in India, space systems and cyber-physical systems, AI for financial-crime decisions, measuring the business impact of cyberattacks, ethics, psychological factors in policy compliance, banking breaches and kidnapping in Nigeria, SME misconceptions, informal organisational rules, e-commerce ethics, healthcare, business continuity after attacks, capacity building through education, and awareness prerequisites for strategic decision makers.

**Why it matters.** Cybersecurity literature is often written for technical specialists. This volume is aimed explicitly at decision makers at all levels and at policymakers, combining case evidence, statistics and frameworks that non-technical leaders can act on.

## What the book covers

1. Opens with an analysis of why cyberattacks disrupt society and how to mitigate risk, followed by chapters on cyberbullying, human factors and the fundamentals of cybercrime and cybersecurity.
2. Provides case-based evidence: attack case studies and lessons learned, a decade of cybercrime across Indian zones, banking breaches and kidnap-for-ransom in Nigeria, and business continuity and disaster recovery after cyberattacks.
3. Covers awareness and behaviour: a cybersecurity awareness programme for non-technical audiences in Malaysia, social engineering awareness among adolescents, psychological factors in compliance with security policies, and informal organisational rules.
4. Extends to emerging domains: space systems, regulation of cyber-physical systems, AI for decision making in financial crime, e-commerce ethics and healthcare cybersecurity.
5. Concludes with building capacity through education, awareness and training, and the awareness prerequisites for strategic decision makers.

## Book at a glance

| Item | Detail |
|---|---|
| Type | Edited book, 1st edition, 424 pages, 65 B/W illustrations |
| Editors | Narasimha Rao Vajjhala and Kenneth David Strang |
| Chapters | 23, with foreword, preface and contributor biographies |
| Contributors | 46 scholars from 11 countries (publisher’s description) |
| Editors’ own chapter | Ch. 1, Why Cyberattacks Disrupt Society and How to Mitigate Risk (Strang and Vajjhala) |
| Audience | Managerial decision makers, practitioners, government policymakers, academics and students |

## Publisher’s description

This book is aimed at managerial decision makers, practitioners in any field, and the academic community. The chapter authors have integrated theory with evidence-based practice to go beyond merely explaining cybersecurity topics. To accomplish this, the editors drew upon the combined cognitive intelligence of 46 scholars from 11 countries to present the state of the art in cybersecurity. Managers and leaders at all levels in organizations around the globe will find the explanations and suggestions useful for understanding cybersecurity risks as well as formulating strategies to mitigate future problems. Employees will find the examples and caveats both interesting as well as practical for everyday activities at the workplace and in their personal lives. Cybersecurity practitioners in computer science, programming, or espionage will find the literature and statistics fascinating and more than likely a confirmation of their own findings and assumptions. Government policymakers will find the book valuable to inform their new agenda of protecting citizens and infrastructure in any country around the world. Academic scholars, professors, instructors, and students will find the theories, models, frameworks, and discussions relevant and supportive to teaching as well as research.

## Contents

- Why Cyberattacks Disrupt Society and How to Mitigate Risk — Kenneth David Strang and Narasimha Rao Vajjhala
- Nature, Forms, and Remedies of Cyberbullying on Social Media Platforms: A Brief Philosophical Perspective — Sooraj Kumar Maurya
- Cybersecurity and Human Factors: A Literature Review — Natasha Cecilia Edeh
- An Introduction to Cybercrime and Cybersecurity: The Whys and Whos of Cybersecurity — Riddhita Parikh
- Cybersecurity Attack Case Studies: Lessons Learned — D. V. Manjula, Aisshwarya Nallamilli, and Dulkarnine Raseeda
- Towards a Cybersecurity Awareness Program for Non-Technical Audiences in Malaysia — Shafiq Ul Rehman and Selvakumar Manickam
- Raising Awareness of Social Engineering among Adolescents: Psychological and Cybersecurity Perspective — Ruchi Joshi and Shafiq Ul Rehman
- Intelligent Named Entity-Based Cybercrime Recognition System for Social Media Network Platforms — Kathiravan Pannerselvam, Saranya Rajiakodi, and Shanmugavadivu Pichai
- A Case Study on Zonal Analysis of Cybercrimes Over a Decade in India — Diya C. R., Umme Salma M., and Chaitra R. Beerannavar
- Taming the Confluence of Space Systems and Cybersecurity — Syed Shahzad, Keith Joiner, and Felicity Deane
- Regulating Cyber-Physical Systems for Safety Consequences — Mark van Zomeren, Keith Joiner, Elena Sitnikova, and Lily Qiao
- Mapping the State of the Art: Artificial Intelligence for Decision Making in Financial Crime — Borja Álvarez Martínez, Richard Allmendinger, Hadi Akbarzadeh Khorshidi, Theodore Papamarkou, Andre Freitas, Johanne Trippas, Markos Zachariadis, Nicholas Lord, and Katie Benson
- Understanding and Measuring the Impact of Cyberattacks on Businesses: A Systematic Literature Review — Xiuqin Li, Richard Allmendinger, Elvira Uyarra, and James Mercer
- Problems and Ethical Issues in Cybersecurity Today: Some Critical Readings — Maximiliano E. Korstanje
- An Empirical Investigation of Psychological Factors Affecting Compliance with Information Security Organizational Policies — Tatyana Ryutov
- Nexus between Banking Cybersecurity Breaches, Cyber Vulnerabilities, and Kidnap for Ransom in Nigeria: A Comparative Analysis of Kaduna and Abuja Metropolis, Nigeria — Hassan Abdulazeez and Sule Magaji
- SME Cybersecurity Misconceptions: A Guide for Decision Makers — Martin Wilson and Sharon McDonald
- Rethinking the Impact of Informal Organizational Rules on Organizational Cybersecurity — Maharazu Kasim
- Ethical Aspects of Cybersecurity in E-Commerce — Tanya Kumar and Satveer Kaur
- Cybersecurity in Healthcare — Arijita Banerjee and Sumit Kumar
- Business Continuity and Disaster Recovery Strategies as Resilience Tools after Cyberattacks in Toxic Entrepreneurship Ecosystems — Lukman Raimi
- Building Cybersecurity Capacity Through Education, Awareness, and Training — Ruth Shillair, Patricia Esteve-González, William H. Dutton, Sadie Creese, and Basie Von Solms
- Cybersecurity Awareness: Prerequisites for Strategic Decision Makers — Sadiq Nasir

## When this research may be relevant

This book may be relevant to researchers and practitioners seeking management-level treatments of cyber risk, cybersecurity awareness and human factors, regional cybercrime evidence (India, Nigeria, Malaysia), cybersecurity governance for SMEs, healthcare and critical systems, and cybersecurity education and capacity building.

## Limitations

- An edited collection whose chapters draw on different methods, regions and evidence; conclusions are chapter-specific.

## How to cite

Vajjhala, N. R., & Strang, K. D. (Eds.). (2023). Cybersecurity for Decision Makers. CRC Press. https://doi.org/10.1201/9781003319887

```bibtex
@book{vajjhala2023cybersecurity,
  title = {Cybersecurity for Decision Makers},
  editor = {Vajjhala, Narasimha Rao and Strang, Kenneth David},
  isbn = {9781003319887},
  edition = {1st},
  year = {2023},
  publisher = {CRC Press},
  doi = {10.1201/9781003319887},
  url = {https://doi.org/10.1201/9781003319887}
}
```
