Organizational cybersecurity depends on countless employee cybersecurity behaviours (ECBs), such as proper handling of phishing threats or safe browsing . Hence, improving cybersecurity demands behaviour change towards security-enhancing ECBs, which itself – for effectiveness and efficiency – requires an in-depth understanding of target behaviours and their underlying characteristics. However, in the current literature, various notions of ECBs are used, and a consistent classification thereof is lacking, resulting in diverging research efforts. To overcome this gap, we transferred findings from behavioural science to cybersecurity and unifyingly define ECBs as “ actions taken by individuals in organisations that influence the protection of information and information systems within the organisation ”. Further, based on existing literature, we synthesized a new Taxonomy of Employee Cybersecurity Behaviour in Organisations (TECBO) that groups behaviours in five domains: 1) Using IT-Systems, 2) Communicating & Exchanging Data, 3) Authenticating, Authorizing & Controlling Access, 4) Maintaining & Safeguarding IT-Systems, 5) Incident Reporting & Handling. TECBO is the first taxonomy that is based on a foundational definition of ECBs and uses underlying similarities of ECBs (e.g., behavioural characteristics on molecular level following Action Identification Theory) as classification criterion. When we used TECBO to categorize existing real-life examples of human cybersecurity behaviours from the security behaviour database (SebDB) and items of existing questionnaires, we found fair to substantial agreement amongst eight raters and acceptable inter-rater reliability. Consequently, these results are of high ecological validity and demonstrate relevance for academia and industry alike, how TECBO provides a fundamentally new conceptualization and a unifying classification structure to accelerate convergence in behavioural cybersecurity. • ECBs are “ actions taken by employees that influence the protection of information and information systems within the organisation ”. • TECBO groups ECBs in five domains. • TECBO uses the underlying behavioural characteristics of ECBs as classification criterion. • TECBO was applied with substantial inter-rater reliability to categorize behaviours of SebDB.
Ambuehl et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: