Cyber security and the disaster resilience framework

Panda, A and Bower, A (2020) Cyber security and the disaster resilience framework. International Journal of Disaster Resilience in the Built Environment, 11(4), pp. 507-518. ISSN 1759-5916

Abstract

Purpose: The purpose of this paper is to concentrate on the place of cyber security risk in the framework of global commitments adopted in 2015 to reduce disaster risks in an all-hazards approach. It explores the correlations between traditional risks associated with critical infrastructures – as understood by the Sendai framework – cyber security risks and the cascading effects characteristic of today’s complex and interrelated shocks and stresses. It takes a step further, expanding the focus of traditionally understood technological risks to explore cyber security risks, at the heart of our societies' digital transformations,and showcase opportunities from the European context. Design/methodology/approach: By reviewing existing literature on cyber security, disaster resilience and cascading disasters, this paper highlights current challenges and good practices undertaken by various governments. Findings: Understanding disaster risks is a precondition to improving the mitigation of impacts of existing risks and preventing new risks. Effective risk reduction relies on a solid understanding of losses resulting from events to inform future actions, and on the assessment of risks relying on a robust evidence base and state-of-the-art scientific capacity to model and simulate potential hazards. In this context, embedding cyber security risks, and the complexity of cascading impacts in improving the understanding of disaster risks, calls for appropriate methods and tools allowing for a multi-risk and holistic focus to the assessment of risks and the planning of risk management capacities that follow. Research limitations/implications: Globally and in Europe, focus on interconnected risk and their impacts is steadily increasing. Risk assessments are still conservative; incorporation of cyber resilience into national and local level DRR plans is yet not visible. Originality/value: Existing research is restricted to cyber security and disaster resilience, as separated subjects. This paper, for the first time, brings together the interconnection between the two topic options to address them.

Item Type: Article
Uncontrolled Keywords: capability; climate change; cyber security; disaster risk reduction; governance; resilience; Sendai framework
Index terms: commitment, disaster resilience, society, disaster risk, risk reduction, complexity, disaster risk reduction, climate change, mitigation, state of the art, evidence, methodology, transformation, good practice, Europe, governance, cascading effect, option, critical infrastructure, heart, risk management, risk assessment
Subjects: decision analysis, systems engineering, environmental hazards, infrastructure and transport systems, communities and social development, research methods, performance measurement, physical geography and landforms, medical science and clinical practice, financial risk, psychology, business, risk assessment, research dissemination and communication, evaluation and assessment methods, climate science
Topics: Organizational Design, Quality Management, Governance, Sustainability, Stakeholder Management, Risk Management, Geographical Context, Research Practice, Engineering Principles, Business Strategy, Cost Management, Health and Safety
Descriptive scope: 4 PCTA

N.B. Descriptive scope is a count of how many of the five facets of empirical research are indicated by the words used in title, abstract and keywords. It is not intended as a judgement on the research; merely a count of the kind of word we would expect to indicate Phenomenon, Concepts, Theoretical framing, Empirical techniques, Analytical techniques. If all five are present, then a code of “5 PCTEA” will indicate this. If you feel the coding for this record is questionable, we welcome discussion around the terms we matched or the way we categorized them. The facet you would expect may not be coded, or a facet may be coded inappropriately. This can also bear on a larger question, of which facets should be treated as defining in construction management research. Please get in touch, and we will look at it. More details here