<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Is cyber-security the new lifeboat? An exploration of the employee's perspective of cyber-security within the cruise ship industry</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Victoria Knight</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Moufida Sadok</string-name>
          <email>moufida.sadok@port.ac.uk</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <addr-line>Street, Portsmouth</addr-line>
          ,
          <country country="UK">United Kingdom</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Portsmouth</institution>
          ,
          <addr-line>Park Building, King Henry</addr-line>
        </aff>
      </contrib-group>
      <fpage>216</fpage>
      <lpage>231</lpage>
      <abstract>
        <p>After the International Maritime Organisation introduced the Maritime Cyber Risk Management in Safety Management Systems Resolution in 2017, with the compliance date set for January 2021, the Maritime industry has displayed an increased focus on its cyber-security. This quantitative research, supported by the socio-technical perspective, explores the employee perceptions of cyber-security onboard cruise ships. The results show that the cruise industry has made an attempt to increase its cyber-security by introducing a formal policy and training their employees. Employees, as a consequence, perceive cyber-security to be important. However, employee perceptions are not reflective of their behaviours onboard. This is because there are various technical and organizational obstacles to their cyber-security practices which have been overlooked. As a result, the cruise industry could do more to prioritise cyber-security on a day-to-day level in order to make sure that the employee experience is in alignment with cyber-security policies.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Maritime</kwd>
        <kwd>cruise ship</kwd>
        <kwd>cyber-security</kwd>
        <kwd>socio-technical</kwd>
        <kwd>employee perspective</kwd>
        <kwd>quantitative</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The research shows that the maritime industry could benefit from applying the
sociotechnical perspective to its cyber-security strategy. Currently, the day-to-day level
cybersecurity is being ignored by the cruise ship sector. As a result, employees are aware of the
threat of a cyber-attack at sea, they perceive cyber-security to be important, they are receiving
training and are aware of cyber-security policies. However, there is a disparity between their
intentions and their practices which is a result of daily obstacles and challenges preventing
them from following cyber-security policies.</p>
      <p>This paper will be comprised of three parts. The first, will explain the background and
situate this research amongst other relevant literature. Next, an overview of the research
methodology will be outlined and its limitations presented. Lastly, the paper will discuss the
results, offering recommendations and suggestions for future research.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <p>
        In 2017, the maritime industry was awakened to the importance of cyber-security when
Maersk Shipping Solutions was hit with what the White House said to be, ‘the most destructive
and costly cyber-attack in history’ [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Since then, the number of cyber-attacks on the maritime
industry has risen, exacerbated by the dramatic impact of the COVID-19 outbreak, meaning
that the majority of seafarers are working remotely with increased connectivity between
devices [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Alarmingly, even the International Maritime Organisation (IMO) faced a
cyberattack in October 2020 which disrupted its website and networks [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Consequently, such
attacks have highlighted the importance of maritime cyber-security and therefore should be
highly prioritised [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        Within the maritime industry, the approach to cyber-security, often focuses on highlighting
the various ways that a vessel could be exploited [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], paying frequent attention to
the navigational system vulnerabilities due to its reliance on multiple sensory digital
technologies to operate [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Attention is also often paid to considering
the protection of supply chains and ports as a critical infrastructure [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ].
      </p>
      <p>
        However, so far, the cruise ship industry has escaped focus, despite there being evidence
of cyber-exploitation within the sector [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. This needs addressing because any weak link
within the maritime industry could be the means for exploitation of critical operations at sea
[
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. Therefore it is important that the cruise sector’s cyber-security is efficient for the safety
of both its crew and passengers as well as its contribution to the maritime industry in general
[
        <xref ref-type="bibr" rid="ref24">24</xref>
        ].
      </p>
      <p>
        Furthermore, despite the IMO guidelines highlighting the importance of the adoption of a
holistic approach to cyber-security [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], the maritime industry has relied heavily on a technical
approach [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Although a technological approach to cyber-security is
necessary, overly technocentric approaches do not provide effective protection [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ].
This is because, as highlighted by the socio-technical perspective, there are many other factors,
aside from the technical which influence the cyber-security of an organisation [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ].
      </p>
      <p>
        Currently, there is extremely limited discussion of cyber-security from humanistic
approach. However, the human factor is a vital contribution and is in need of attention [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ].
      </p>
      <p>
        The literature provided from the socio-technical perspective adopts an employee
perspective in order to try to understand user behaviour. Oftentimes, users are aware of their
role in cyber-security, but their intentions do not match their practices [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. Therefore, it is
important to consider how to maximise the efficacy of training in order to alter their behaviours
for the long term. For instance, Bada et al. explains that, ‘people must be able to understand
and apply the advice, and secondly, they must be motivated and willing to do so’ [
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. It is
therefore vital to explain why cyber-security practices are important in order for them to be
adopted [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. Furthermore, all humans have different processes of understanding information
and decision making regarding cyber-security behaviour, therefore training should reflect this
and should be uniquely delivered and matched with the learning style of the individual in order
to be most effective [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ] [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ].
      </p>
      <p>
        Similarly, it is not sufficient to just train employees because workplace cyber-security
practices degrade overtime [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ].Therefore, it is important that cyber-security awareness is
maintained, most effectively through actively involving users with training and awareness as
opposed to passive forms of maintenance [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ].
      </p>
      <p>
        Aside from understanding and changing user behaviour, the socio-technical perspective
highlights that there are other factors which influence employee’s practices. Oftentimes there
are many social and organisational factors acting as an obstacle to employee’s cyber-security
which are overlooked. For instance, the needs of the designers, compared to the needs of the
users are not in alignment [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ]. Similarly, managerial expectations, and organisational policies
are frequently out of touch with workplace routines [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ]. Employees, as a result, are not able
to balance the needs of the organisation with the demands of cyber-security policies, meaning
that they do not highly prioritise cyber-security practices or workaround them [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ] [
        <xref ref-type="bibr" rid="ref38">38</xref>
        ]. By
adopting a socio-technical approach, a shift can be made from humans as a problem, to humans
as a solution [
        <xref ref-type="bibr" rid="ref39">39</xref>
        ]. Therefore, in order to be successful, cyber-security practices must be
influenced by the employees who are affected by security controls [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ].
      </p>
      <p>It is also important that the organisational culture is in alignment with the cyber-security
policies in order to encourage good cyber-security practices. This helps to communicate the
importance of cyber-security to employees and promote compliance with cyber-security
policies [40].</p>
      <p>There is evidence that the maritime industry could greatly improve its cyber-security by
considering the socio-technical in its strategy. Interestingly, after the Maersk attack, the U.S.
Coast Guard discovered that crew members were aware that computers onboard had been
compromised, they avoided using them for personal tasks out of fear of being compromised
but disregarded the threat when conducting professional tasks. It was therefore said that
“simple cyber hygiene would have prevented this issue… it’s in the day-to-day that these things
happen” [41]. This evidence highlights the dangers of relying heavily on a technical approach
to cyber-security and ignoring the humanistic elements of cyber-security. Consequently, the
maritime industry should adopt a holistic approach to cyber-security, considering people,
processes and technology combined [42].</p>
      <p>This research therefore seeks to apply the socio-technical perspective to the maritime
industry to see if this environment could also gain the benefits of adopting the perspective to
its cyber-security strategy. The research assumption is that staff members onboard are
conducting common practices which could be putting cruise ships at risk of a cyber-attack.
These behaviours are the result of daily challenges which are acting as an obstacle for staff
members. This research therefore aims to gain an employee perspective of cyber-security
onboard cruise ships and apply the socio-technical perspective in order to understand the
reasons behind their behaviour.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology</title>
      <p>Using a quantitative method, this research was conducted via the use of a computerised
self-administered questionnaire design [43] which was formed mostly of closed-ended
questions [44]. The justification for the appropriateness of this method, is that cyber-security
is generally something that not everyone is particularly knowledgeable about. Many people
consider it to be an expert subject and are intimidated about discussing the topic. Additionally,
given that cruise ship employees come from all over the world and speak many different
languages, using qualitative research to explore the perceptions of someone whose first
language is not English would potentially discourage participants from taking part. Instead,
asking participants to simply select a number as a response, rather than requiring them to
attempt to express their answer about an expert subject in their second language, was
considered more appropriate. Consequently, in order to gain responses which were useful, a
quantitative design was adopted to give structure and support to the participants’ responses. To
provide explanation for the selected responses, an interpretivist epistemology [45] was used
with inductive reasoning.</p>
      <p>The questions were answered on a five-point Likert Scale [46] in order to assess the level
of agreement with the statement proposed [47] ranging from ‘Strongly agree’ to ‘Strongly
disagree’. Open-ended questions, producing qualitative data, were also used in the
questionnaire, giving participants the chance to offer a subjective response based on their own
experience and support the inductive reasoning.</p>
      <p>The sample of cruise ship employees was obtained through a nonprobability purposive
sampling method [48] obtained through Facebook ‘Crew Only’ groups and LinkedIn. The
researcher was already a member of many of these closed groups on Facebook but selected
specific groups based on the diversity of the members, ensuring it was comprised of employees
in differing job roles and varying cruise ship companies. This enabled a wider exploration of
the perceptions and also was an attempt to avoid reputational damage to any one company in
particular. Once permission was obtained from the group administrators, the researcher posted
a message in the groups, informing members of the research, containing a link to the
questionnaire if the participant wanted to participate.</p>
      <p>Those who were in a job role that had access to an IT system between 2018-2020 were
invited to take part. The IMO guidelines were released in 2017, so the time frame selected
enabled companies the chance to respond, and ensured that the exploration of the perceptions
of employees was from the time which there was cyber-security awareness within the maritime
industry.</p>
      <p>According to the Facebook group descriptions, there was approximately 50,000 group
members combined. However, it is difficult to determine how many of these members were
actively engaging in the group at the time. It is also important to highlight that these groups are
for social purposes and so, many members are no longer employed, nor have been in a long
time. As a result, they may not have been working for a cruise company when cyber-security
was a priority and therefore not eligible to partake in the research.</p>
      <p>A total of 155 participants completed the questionnaire. The responses from the
closedended questions were analysed using descriptive statistics [49]. IBM SPSS software was used
to facilitate this to avoid human error. Confidence intervals of the proportion were also
calculated using the modified Wald method [50].
3.1.</p>
    </sec>
    <sec id="sec-4">
      <title>Limitations</title>
      <p>The researcher will now briefly outline the limitations of this research so that the results
within their given context. Due to the quantitative method adopted and questionnaire design,
the exploration of employee perceptions was limited in scope. Therefore inductive reasoning,
supported by the answers from the qualitative questions, was used to give further explanation
to results. This therefore means that the research is not completely objective and has an element
of researcher influence.</p>
      <p>The questionnaire was also conducted in English by many participants who are not
fluent speakers. Given that cyber-security is considered a complex subject, there is a chance
that some participant’s comprehension of the questions may have been reduced. Some staff
members who were not entirely comfortable with partaking in the research due to it being
conducted in English may have even been put off taking part.</p>
      <p>Embracing the use of the internet to conduct the research was a useful aid during a
pandemic. Without such a tool, it would have been extremely challenging to obtain the
perceptions of employees who were scattered around the globe. However, not all employees
are connected to the internet, nor are necessarily on social media, or a part of Crew Groups on
Facebook. Therefore, by embracing this method of sampling, the generalisability of the results
to the entire population is reduced.</p>
      <p>Furthermore, the sample obtained was a size which enabled an exploration to be
obtained into the perceptions of employees. However, the results represent a snap-shot of the
number of staff members employed in total across the entire industry.</p>
      <p>The researcher would also like to highlight that the cruise industry has paused its operations
for over a year. Therefore this research required employees to recall their experiences. This
means that their responses may have been influenced by lack of memory. Furthermore, in the
year that has passed, the cruise industry may have taken more steps to improve its
cybersecurity which has yet to be rolled out to employees.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Findings</title>
      <sec id="sec-5-1">
        <title>The key findings of the research are:</title>
        <p>1. The cruise ship industry is raising cyber-security awareness amongst employees
This explains the employee awareness of cyber-security policies, their experience of
training onboard and the maintenance of their awareness.</p>
      </sec>
      <sec id="sec-5-2">
        <title>2. Employee cyber-security intentions do not match their behaviour</title>
        <p>This explains employee perceptions of a cyber-attack/the importance of cyber-security.</p>
        <p>It then proceeds to discuss employee’s onboard behaviour.</p>
      </sec>
      <sec id="sec-5-3">
        <title>3. Day-to-day level cyber-security is being ignored</title>
        <p>This explains the various obstacles which are influencing employee’s cyber-security
practices onboard.</p>
        <p>This section will be comprised of three parts, presenting a discussion of each of these
key findings.
4.1.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>Key Finding One: Cyber-security awareness amongst employees</title>
      <p>This finding will be discussed in three parts. The first part will present the findings from
the exploration of the employee’s experience of training. The second part will focus on the
maintenance of their training and awareness. The third part will discuss the impact of the
current approach to training and awareness maintenance.</p>
      <p>The results show that the cruise industry appears to be attempting to improve its
cybersecurity in accordance with the IMO guidelines. A formal cyber-security policy has been
introduced, which 68.4% of employees confirmed had already been established (90% CI
[0.6197, 0.7418]). Alongside this, 67.7% of employees received cyber-security training (90%
CI [0.6130, 0.7358]). which was given to employees occupying the full range of job roles
onboard. However, there are limitations to the cruise ship industry’s efforts which will be
outlined below.</p>
      <p>The training was not always conducted prior to the employee using an IT system
onboard, due to employees being left to ‘settle in’ before being given cyber-security training.
Employees also explained that the cyber-security training was ‘not taken seriously’.</p>
      <p>Furthermore, not all employees who are using an IT system are being trained; those in
job roles that are more centred around IT are more likely to receive training at 71.4% (90% CI
[0.5471, 0.6748]), compared to those who said that they used an IT system as part of their role
but not centrally, with only 45.5% receiving training (90% CI [0.0381, 0.1058]).</p>
      <p>Furthermore, although the training was given to those in varying levels of authority,
those with increased authority were more likely to receive cyber-security training, as displayed
in the bar graph below.</p>
      <p>100
80
60
40
20
0</p>
      <sec id="sec-6-1">
        <title>Cyber-security training amongst authority levels</title>
        <p>78.4%
70.5%</p>
        <p>51.6%
Senior Management
Departmental Management
Team Member Management</p>
        <p>Employees also explained that oftentimes the training was not job specific and ‘quite
generic’. An employee explained:
‘each position has different levels of access (a media manager has open access to the
internet - entertainment hosts is an intranet so closed access) the risks for these 2 roles
for example would be different’.</p>
        <p>This meant that only 45.8% (90% CI [0.7212, 0.8305]) of employees strongly agreed
that cyber-security was important for their job role. Therefore, the standardised training given
to employees in varying job roles, meant that they disregard it and considered it irrelevant to
their role onboard.</p>
        <p>Similarly, given that cyber-security is considered a complex subject for most, and that
the cruise ship environment is made up of employees speaking many different languages, it
was also suggested that the training not only be more job specific, but also employee specific.
For instance, an employee explained:
‘Have important training like cyber security be offered in multiple languages for easier
understanding. Cyber security training uses specific vocabulary that may be difficult
for crew members who speak English as an additional language’.</p>
        <p>Therefore, the exploration of the employee experience of training, shows that there is
more work to be done to make it as efficient as it could be.</p>
        <p>Next, the researcher will discuss the maintenance of training and awareness. The results
show that only 16.1% of participants received any further additional training to maintain their
knowledge (90% CI [0.1182, 0.2160]). Instead, passive forms of cyber-awareness, such as
publications were the main source of maintenance. The bar graph below presents the various
methods that were used to keep employees up-to-date with cyber-security.</p>
        <p>50
40
30
20
10
0</p>
      </sec>
      <sec id="sec-6-2">
        <title>Ways in which employee cyber-security awareness was maintained</title>
        <p>42.6%
21.3%
18.15%</p>
        <p>16.1%
Publications Departmental I was not kept Additional
meetings up-to-date training
1.9%
Other</p>
        <p>Lastly, this section will discuss the impact of the current approach to training and
awareness maintenance. The implications of the sporadic training, conducted with a
standardised, generic session, suggests to the employees that cyber-security is, at present, not
something which is considered as everyone’s responsibility onboard. As a result, employees
perceived cyber-security as an IT department responsibility only. When asked how they would
respond to a suspicious threat, participants most commonly selected that they would contact
the IT department. This resulted, in some instances, with the IT department becoming
overburdened. For instance, an employee explained:
‘…IT was prompt with fixing the issue when reported but it was hard to get a hold of
them via either phone or email. Typically I did not come across security problems but
if I had, not much was promoted in terms of equipping managers with the tools they’d
need to combat or prepare against’.</p>
        <p>Furthermore, the lack of maintenance of cyber-security awareness is implying that
cyber-security training is a tick box exercise. As a result, employees are disregarding their
training on a practical day-to-day level, and putting the trust in the IT department to mitigate
threats.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>4.2. Key Finding Two: Employee’s cyber-security perceptions compared to cyber-practices</title>
      <p>This finding will discuss the perceptions of the employee and their practices onboard.
Employee perceptions surrounding cyber-security and cyber threats appear to be reflective of
the increased concerns of the maritime industry in general. 76.1% of employees strongly agreed
or agreed that a cyber-attack on a cruise ship is a threat (90% CI [0.7006, 0.8130]) and 92.9%
of the employees believed that cyber-security onboard is important (90% CI [0.8865 to
0.9569]).</p>
      <p>The employee’s perceptions surrounding cyber-security appear to be influenced by the
training that they received, as demonstrated in the table below.</p>
      <sec id="sec-7-1">
        <title>Perceptions of cyber-security compared to training</title>
        <p>
          However, when examined more closely, the results show that the employees seem to
be more concerned about cyber-security than is evident from their practices. Despite these
perceptions, 81.8% of employees conducted practices onboard that could result in a
cyberattack (99% CI [0.5485, 0.7423]), therefore showing that there is a disparity between the
intentions of the employees and their conduct onboard, which supports the findings of
Albrechsten [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ]. The graph below shows the type of behaviours and the level of commonality.
        </p>
      </sec>
      <sec id="sec-7-2">
        <title>Employee behaviour onboard</title>
        <p>Connected a personal device to a professional IT</p>
        <p>system
Used a personal device to conduct professional tasks</p>
        <p>It was found that the training did have some level of impact on the employee’s conduct.
Of the participants who received training, 78.6% selected behaviours (90% CI [0.3190,
0.4464]), compared to 87.5% of participants selecting behaviours who did not receive training
(90% CI [0.8380, 0.9601]). However, due to the limitations of the training which were
discussed above, the influence of training on the employee’s practices is limited.
4.3.</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>Key Finding Three: Day-to-day level cyber-security</title>
      <p>The results show that despite the indication of an attempt to increase cyber-security
onboard, cyber-security on a day-to-day level is not being prioritised. This is resulting in many
organisational obstacles for the employees. This section will present a deeper understanding of
the factors which are influencing their practices.</p>
      <p>
        Firstly, there is a misalignment between cyber-security practices, and the needs of the
employees in executing their job role. This is consistent with the work of Hooper &amp; McKissask
[
        <xref ref-type="bibr" rid="ref36">36</xref>
        ]. Only 41.3% of employees strongly agreed that the cyber-security rules were easy to
follow when carrying out their daily tasks (90% CI [0.3499, 0.4789]), and only 31% of
employees strongly agreed that cyber-security rules were useful within their job role (99% CI
[0.2232, 0.4118]). As a result, in support of Koppel et al. [
        <xref ref-type="bibr" rid="ref38">38</xref>
        ], employees would often
workaround cyber-security practices, opting for efficiency and convenience over security.
      </p>
      <p>Similarly, a lack of connectivity onboard meant that employees were left with no choice
but to work around cyber-security policies. For instance, an employee explained:
24%
‘I was also required to take company electronics off of the ship into insecure internet
connections in order to complete program updates as the ship internet was not strong
enough to do so’.</p>
      <p>This suggests that the cruise ship companies are not prioritising cyber-security on a
practical level. This is supported by the fact that another significant reason for employee
workarounds onboard was simply, a lack of resources. Employees were left with no choice but
to use their own, potentially insecure devices, to conduct professional tasks because they did
not have the resources needed.</p>
      <p>Lastly, a cruise ship is an environment which encompasses employees living and
working in the same space whilst being detached from the outside world. This presents
obstacles to employees which need to be considered when forming cyber-security policies. For
instance, a lack of connectivity both in port and onboard, as well as the high cost of Wi-Fi for
crew, meant that employees commonly explained that they used onboard, professional devices
and networks to conduct their personal correspondence. For instance, a participant explained:
‘I was in the middle of a house purchase and needed to scan and send documents
overthere is often no time or appropriate place in ports we visit to do this.’</p>
      <p>Therefore, it is not just the professional tasks of employees which are encouraging
workarounds, but also personal factors, that have not been considered as part of the
cybersecurity strategy, which are forcing them to disregard cyber-security policies.</p>
      <p>
        There is also a misalignment between the corporate policies and the workplace routines,
consistent with the findings of Sadok et al. [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ]. For instance, oftentimes, employees explained
that their behaviours onboard were at the request of shoreside management who had assigned
them tasks that were not achievable unless they ignored cyber-security rules.
      </p>
      <p>Furthermore, although employees knew that their practices were jeopardising the
cyber-security of the vessel, they explained commonly that they were ‘normal’. For instance,
an employee explained:
‘I can't say I have ever really thought twice about the security risk factor in doing so
and everybody does it so it seems like the normal thing to do.’</p>
      <p>In some instances, these behaviours were even encouraged, or considered a benefit to
the position onboard. For instance, an employee explained:
‘I also used my office computer to do personal things, yet was never told not to do so
on it. I was actually advised by head office that it was one of the “perks” of my job.’
Consequently, the misalignment between the organisational cyber-security policies and
the culture onboard, implies to employees that on a day-to-day basis, breaking cyber-security
rules is normal and acceptable.
4.4.</p>
    </sec>
    <sec id="sec-9">
      <title>Recommendations</title>
      <p>Overall, although the results outlined above indicate that the cruise ship industry has
attempted to improve its cyber-security strategy with increased training and awareness amongst
employees, there is still progress to be made. The researcher recommends that training is given
more thoroughly across departments to every employee, and is more job specific, to
communicate the relevancy of cyber-security to each crew member. IT is also strongly
recommended, that the training sessions are delivered in various languages for those who do
not speak English as their first.</p>
      <p>
        It is also the recommendation of the researcher that the training sessions and awareness
of employees onboard is maintained. As per Albrechsten &amp; Hovden, this should be most
beneficially conducted through the use of interactive methods of cyber-security awareness [
        <xref ref-type="bibr" rid="ref35">35</xref>
        ],
such as refresher training sessions or drills (which will be discussed below). This would
encourage employees to continually be aware of cyber-security and enhance the change in
behaviour over a longer period of time.
      </p>
      <p>The researcher also recommends that the cyber-security culture onboard also needs to
be addressed. As per Alshaikha, this has been seen to improve cyber-security for a sustained
amount of time. There are various ways that the culture could be achieved [40]. Firstly, it must
be communicated to employees that cyber-security is everyone’s responsibility and not just the
role of the IT department. Ultimately, at sea, every crew member’s supreme priority is safety.
For instance, an employee explained:
‘Safety is our number one priority it is very important that we see different aspect on
how we can deal on such incidents. This training should be considered as very
important as this is a safety issue.’</p>
      <p>Currently onboard, employees often experience safety drills to maintain their
knowledge of safety procedures, as well as keep safety as a forefront priority. The cruise
industry should seek to treat cyber-security as just as important, by consistently reinforcing
employee’s awareness that vessels are made up of complex, interlinking cyber-physical
systems [51] and adopting good cyber-security practices is vital to protect the overall safety of
the vessel. It should also be communicated often to employees that adopting good
cybersecurity practices is a necessity of every crew member onboard to prevent harm coming to all
those onboard. Employees should also be informed often of what could be suspicious and how
they should act if they see such occurrences. This could be done on a large scale with a drill in
order to reinforce not only the importance, but also the notion that it is everyone’s responsibility
onboard.</p>
      <p>As suggested by Alshaikha another way that the cyber-security culture onboard could
be improved could be through the use of incentives, similar to ‘employee of the month’ which
would reward individuals who have raised awareness of a threat or conducted good
cybersecurity onboard [40]. This would ignite a collective call to action, acting as a reminder to be
cyber-security mindful, and alter the perceptions that poor cyber-security practices are ‘normal’
and acceptable onboard.</p>
      <p>
        The researcher also recommends that the organisational approach to cyber-security
adopts a more employee centric approach in order to mitigate some of the challenges that they
face which are ultimately impacting their cyber-security practices. As per Sadok et al., it is
vital that cyber-security practices are influenced by the employees who are affected by security
controls [
        <xref ref-type="bibr" rid="ref37">37</xref>
        ].
      </p>
      <p>Time and time again, employees blamed a lack of resources, and inconvenience as a
reason for their behaviours onboard. This could be mitigated by increasing the number of
secure portable devices which are available to employees so that they do not opt to use their
personal device.</p>
      <p>Lastly, it is important not just to mitigate the misalignments in the employees professional
experience, but also their personal conduct also. The cost of crew Wi-Fi, and poor connectivity,
is deterring employees from using the correctly assigned network. Employee’s must have the
ability to contact home and carry out personal tasks onboard, easily and affordably. If this is
not the case, their personal needs will take priority over cyber-security measures.</p>
    </sec>
    <sec id="sec-10">
      <title>5. Conclusion</title>
      <p>To conclude, employees are aware of the importance of cyber-security onboard, yet they
are conducting practices onboard which are putting cruise ships at risk of exploitation.
Although employees appear to be the weak link in the cyber-security onboard, their behaviours
are influenced by many, humanistic and organisational factors. Their practices are therefore
the product of organisational weaknesses which have arisen because the employee perspective,
and the practical day-to-day level cyber-security, have not been considered. Therefore, the
cruise ship industry could take cyber-security more seriously.</p>
      <p>Although employees are receiving training, it is rolled out amongst employees sporadically,
delivered through sessions which are standard and generic across many different job roles. This
means that employees consider cyber-security as irrelevant to them. Furthermore, after the
training has been conducted, it is not maintained, meaning that there has been little
consideration about how to actually change the behaviour of employees in the long term. This
means that employees are trusting the cruise ship companies and IT departments to maintain
the cyber-security of the vessel, without fully considering their role, and the potential impacts
of their behaviours.</p>
      <p>There are also misalignments between the corporate cyber-security policies, the manager’s
expectations and the experience of employees when trying to balance their tasks and the
cybersecurity practices. This means that employees are working around them or disregarding them.
Furthermore, the organisational cyber-security culture does not mirror the culture onboard.
This communicates to employees that cyber-security does not really matter.</p>
      <p>This research highlights the dangers of relying heavily on a technical approach to
cybersecurity within the maritime industry. Applying the socio-technical perspective to the maritime
environment produces results which are consistent with the perspective’s previous research.
Therefore, this research shows that there are many benefits, discussed throughout, which could
be gained from applying the socio-technical perspective to the cyber-security of the cruise ship
sector, and the maritime industry more generally. By adopting a socio-technical perspective
within the maritime industry, a more holistic cyber-security strategy will be formed, which will
ultimately provide more efficient protection.</p>
      <p>The findings of this research were mostly as expected, particularly surrounding the level of
common behaviours that are conducted onboard, potentially putting cruise ships at risk.
However, particularly surprising was the perceptions of employees. The researcher assumed
that employees were unaware of the threat of a cyber-attack/did not perceive cyber-security to
be important, which would explain why frequent common bad practices were being conducted
onboard. This research suggests the opposite, which although, initially was alarming to
discover, upon reflection, was actually reassuring. This therefore means that it is the obstacles
which are impacting employee behaviour, which ultimately can be addressed more easily than
altering people’s perceptions.</p>
      <p>This research hopes to encourage the application of the socio-technical approach within the
maritime industry more so in the future. There are many areas to pursue, the avenues of which
can vary depending on the corporate level. For instance, on a higher level, the researcher would
suggest that an exploration of the designer perspective would be useful. Are they aware of the
lives of crew members onboard and do they take it into account when they are designing the
policies?</p>
      <p>Similarly, an exploration into the efficiency of the corporate approach to training and
awareness could be conducted. For instance, given that the cruise ship industry, and the
maritime industry in general is made up of employees from all over the globe, future research
could consider cyber-security perceptions across varying nationalities. This research suggests
that employees speaking different languages may find it more difficult to comprehend the
training. Therefore, the researcher would recommend future exploration surrounding the
efficacy of conducting cyber-security training in various different languages for the employees
who do not speak English as their first language. If cyber-security awareness and training was
not only more job specific, but more tailored to the employee’s learning needs, would their
practices improve?</p>
      <p>Alternatively, on a more managerial level, it would also be useful to explore the perceptions
of the shoreside employees. As mentioned, oftentimes the employee behaviours onboard are
the result of a request at shoreside. Future research could investigate whether the perceptions
of the two sides are similar, the challenges that shoreside face and how these two elements of
the organisation come together in order to reduce the conflict which is currently occurring.</p>
      <p>Lastly, this exploration encompasses employees from various cruise lines. However, future
research could focus on one single cruise ship and explore the perceptions and experience of
employees in greater depth. This would allow a deeper understanding of the cyber-security
practices on a more specific level rather than generically across the entire industry.</p>
      <p>Ultimately, this research aims to encourage the adoption of a more holistic approach to
cyber-security within the maritime industry, particularly with the support of the socio-technical
perspective, to not only understand, but also alter user behaviour. Now is the time to take an
employee centric approach to understand how to secure vessels. The researcher hopes that this
is the start of employees onboard being seen as a solution to cyber-security, rather than part of
the problem.</p>
    </sec>
    <sec id="sec-11">
      <title>6. References</title>
      <p>[40] M. Alshaikha, Developing cybersecurity culture to influence employee behaviour: A practice
perspective, Computers &amp; Security, 98 (2020). https://doi.org/10.1016/j.cose.2020.102003
[41] I. Bramson, Cyber Risk Series – United States Coast Guard, 2020. URL:
https://open.spotify.com/episode/2hqSRYPsLHo0a2r5D5FUk5?si=PQN0UmIHThCb531DFgJ7k
w&amp;nd=1
[42] A. Garcia-Perez, M. Thurlbeck, E. How, Towards cyber security readiness in the Maritime
industry: A knowledge-based approach (2017).
https://pure.coventry.ac.uk/ws/portalfiles/portal/12219284/Towards_Cyber_Security_Readiness_
In_The_Maritime_Industry.pdf
[43] V. Vehovar, K. Manfreda, Overview: online surveys, in: N. Fielding, R. Lee, G. Blank. (Ed.),
The Sage Handbook of online research methods. 2nd. ed., Sage Publications Ltd, London, UK,
2017, pp. 143-161. https://www.doi.org/10.4135/9781473957992
[44] C. Leddy-Owen, Questionnaire Design, in: N. Gilbert, P. Stoneman (Ed.), Researching Social</p>
      <p>Life, 4th ed., Sage Publications, London, UK, 2016., pp. 245-257. ISBN: 9781412946629
[45] V. D. Alexander, H. Thomas, A. Cronin, J. Feilding, J. Moran-Ellis, Mixed Methods, in: N.</p>
      <p>Gilbert, P. Stoneman (Ed.), Researching Social Life, 4th ed., Sage Publications, London, UK,
2016., pp. 119-139. ISBN: 9781412946629
[46] R. Likert, A technique for the measurements of attitudes, Archives of Psychology 22 (1932)
556.
[47] A. Bryman, Social Research Methods, 5th ed., Oxford University Press, New York, NY, 2016.
[48] E. Ruel, W. Wagner |||, B. Gillespie, Nonprobability sampling and sampling hard-to-find
populations, in: E. Ruel, W. Wagner |||, B. Gillespie (Ed.), The practice of survey research, Sage
Publications, London, UK, 2016, pp. 149-159. https://www.doi.org/10.4135/9781483391700
[49] P. Stoneman, Analysis Survey Data, in: N. Gilbert, P. Stoneman (Ed.), Researching Social Life,
4th ed., Sage Publications, London, UK, 2016., pp. 389-411. ISBN: 9781412946629
[50] A. Agresti, B. Coull, Approximate Is Better than "Exact" for Interval Estimation of Binomial</p>
      <p>Proportions, The American Statistician 52 (1998) https://doi.org/10.2307/2685469
[51] V. Bolbot, G. Theotokatos, L. Bujorianu, E. Boulougouris, D. Vassalos, Vulnerabilities and safety
assurance methods in Cyber-Physical Systems: A comprehensive review, Reliability Engineering
&amp; System Safety, 182 (2019). https://doi.org/10.1016/j.ress.2018.09.004</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>G.A.</given-names>
            <surname>Res</surname>
          </string-name>
          . A.
          <volume>741</volume>
          (
          <issue>18</issue>
          ).
          <source>(Nov. 4</source>
          ,
          <year>1993</year>
          ). https://www.palaureg.com/product/resolution-a-74118
          <string-name>
            <surname>-</surname>
          </string-name>
          international
          <article-title>-management-code-for-the-safe-operation-of-ships-and-for-pollution-preventioninternational-safety-management-ism-code/ [</article-title>
          <source>Accessed July 28</source>
          ,
          <year>2021</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>International</given-names>
            <surname>Maritime</surname>
          </string-name>
          <string-name>
            <given-names>Organisation</given-names>
            , The International Safety
            <surname>Management (ISM) Code</surname>
          </string-name>
          ,
          <year>2019</year>
          . URL: https://www.imo.org/en/OurWork/HumanElement/Pages/ISMCode.aspx
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>G.A.</given-names>
            <surname>Res</surname>
          </string-name>
          .
          <volume>428</volume>
          (
          <issue>98</issue>
          ).
          <source>(June</source>
          . 16,
          <year>2017</year>
          ). https://wwwcdn.imo.org/localresources/en/KnowledgeCentre/IndexofIMOResolutions/MSCReso lutions/MSC.
          <volume>428</volume>
          (
          <issue>98</issue>
          ).
          <source>pdf [Accessed July 28</source>
          ,
          <year>2021</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>G.A.</given-names>
            <surname>Res</surname>
          </string-name>
          . 1/Circ.3.
          <issue>(</issue>
          <year>July</year>
          . 5,
          <year>2019</year>
          ). http://www.gard.no/Content/23896593/MSC-FAL.
          <fpage>1</fpage>
          - Circ.3.pdf [
          <issue>Accessed July 28</issue>
          ,
          <year>2021</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>International</given-names>
            <surname>Maritime</surname>
          </string-name>
          <string-name>
            <surname>Organisation</surname>
          </string-name>
          ,
          <source>Maritime Cyber Risk</source>
          ,
          <year>2019</year>
          . URL: https://www.imo.org/en/OurWork/Security/Pages/Cyber-security.aspx
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>White</given-names>
            <surname>House</surname>
          </string-name>
          , Statement from the Press Secretary,
          <year>2018</year>
          . URL: https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25
          <source>/ [Accessed July 28</source>
          ,
          <year>2021</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>B.</given-names>
            <surname>Shajari</surname>
          </string-name>
          ,
          <source>Cyber Risk Series - Emergency Response and Facility Security Perspectives</source>
          ,
          <year>2020</year>
          . URL: https://open.spotify.com/episode/5yU5Da1V2lc1431gx2AtPb?si=bOg74vydSWSpHM321SZpC A
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>CSIS</surname>
          </string-name>
          , Significant Cyber Incidents,
          <year>2021</year>
          . URL: https://www.csis.org/programs/strategictechnologies-program/significant-cyber-incidents
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>United</given-names>
            <surname>States Coast Guard</surname>
          </string-name>
          ,
          <source>Cyber Incident Exposes Potential Vulnerabilities Onboard Commercial Vessels</source>
          ,
          <year>2019</year>
          . URL: https://www.dco.uscg.mil/Portals/9/DCO%20Documents/5p/CG-5PC/INV/Alerts/0619.pdf
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>D.</given-names>
            <surname>Sepulveda</surname>
          </string-name>
          <string-name>
            <surname>Estay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Sahay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Meng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Jensen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Barfod</surname>
          </string-name>
          ,
          <article-title>Exploring Cybership Vulnerabilities Through a Systems Theoretic Process Approach</article-title>
          , Ocean Engineering Journal (
          <year>2020</year>
          ). http://dx.doi.org/10.2139/ssrn.3753663
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>K.</given-names>
            <surname>Tam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Jones</surname>
          </string-name>
          ,
          <article-title>Maritime cyber security policy: the scope and impact of evolving technology on international shipping</article-title>
          ,
          <source>Journal of Cyber Policy</source>
          <volume>3</volume>
          (
          <year>2018</year>
          ). doi:
          <volume>10</volume>
          .1080/23738871.
          <year>2018</year>
          .
          <volume>1513053</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>K.</given-names>
            <surname>Tam</surname>
          </string-name>
          , K. Jones,
          <article-title>MaCRA: a model-based framework for maritime cyber-risk assessment</article-title>
          ,
          <source>World Maritime University Journal of Maritime Affairs</source>
          <volume>18</volume>
          (
          <year>2019</year>
          ). https://doi.org/10.1007/s13437-019-00162-2
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Government</surname>
            <given-names>Office for Science.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>Future of the Sea: Cyber security</article-title>
          . URL: https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file /671824/Future_of_the_Sea_-_
          <string-name>
            <surname>Cyber</surname>
          </string-name>
          _Security_Final.pdf
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>M.</given-names>
            <surname>Lund</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O. Sveinung</given-names>
            <surname>Hareide</surname>
          </string-name>
          ,
          <source>Ø. Jøsok, An Attack on an Integrated Navigation System, Necesse</source>
          <volume>3</volume>
          (
          <year>2018</year>
          ).
          <source>doi: 10.21339/2464-353x.3.2</source>
          .149.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>B.</given-names>
            <surname>Svilicic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Rudan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Frančić</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Doričić</surname>
          </string-name>
          ,
          <article-title>Shipboard ECDIS cyber security: third-party component threats</article-title>
          ,
          <source>Scientific Journal of Maritime Research</source>
          <volume>33</volume>
          (
          <year>2019</year>
          ). https://doi.org/10.31217/p.
          <fpage>33</fpage>
          .
          <issue>2</issue>
          .7.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>B.</given-names>
            <surname>Svilicic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Brčić</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Žuškin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kalebić</surname>
          </string-name>
          ,
          <article-title>Raising awareness on cyber security of ECDIS</article-title>
          , TransNav: The
          <source>International Journal of Maritime Navigation and Safety of Sea Transportation</source>
          <volume>13</volume>
          (
          <year>2019</year>
          ).
          <source>doi: 0.12716/1001.13.01</source>
          .24.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>B.</given-names>
            <surname>Svilicic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kristić</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Žuškin</surname>
          </string-name>
          ,
          <article-title>Paperless ship navigation: cyber security weaknesses</article-title>
          ,
          <source>Journal of Transport Security</source>
          <volume>13</volume>
          (
          <year>2020</year>
          ). https://doi.org/10.1007/s12198-020-00222-2
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>B.</given-names>
            <surname>Svilicic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Rudan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Frančić</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mohović</surname>
          </string-name>
          ,
          <article-title>Towards a Cyber Secure Shipboard Radar</article-title>
          ,
          <source>Journal of Navigation</source>
          <volume>73</volume>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1017/S0373463319000808.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>S.</given-names>
            <surname>Carnovale</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Yeniyurt</surname>
          </string-name>
          ,
          <string-name>
            <surname>S.</surname>
          </string-name>
          (Ed.),
          <source>Cyber Security and Supply Chain Management: Risks</source>
          , Challenges, and Solutions, World Scientific,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>N.</given-names>
            <surname>Polemi</surname>
          </string-name>
          , Port Cybersecurity, Elsevier, Amsterdam, NL,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <article-title>National Institute of Standards and Technology, Framework for improving critical infrastructure</article-title>
          <source>Cybersecurity</source>
          ,
          <year>2018</year>
          . URL: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.
          <volume>04162018</volume>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>S.</given-names>
            <surname>Schauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Polemi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Mouratidis</surname>
          </string-name>
          ,
          <article-title>MITIGATE: a dynamic supply chain cyber risk assessment methodology</article-title>
          ,
          <source>Journal of Transportation Security</source>
          <volume>12</volume>
          (
          <year>2019</year>
          ). https://doi.org/10.1007/s12198-018-0195-z
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>S.</given-names>
            <surname>Cobel</surname>
          </string-name>
          ,
          <source>Carnival Confirms Passenger Data Comprimised</source>
          ,
          <year>2020</year>
          . URL: https://www.infosecurity
          <article-title>-magazine.com/news/carnival-confirms-passenger-data/</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>Emergency</given-names>
            <surname>Risk</surname>
          </string-name>
          <string-name>
            <surname>Brief</surname>
          </string-name>
          ,
          <source>Maritime Cyber Threat Intelligence and Vulnerability Landscape</source>
          ,
          <year>2021</year>
          . URL: https://fortressinfosec.com/blog/maritime-cyber
          <article-title>-threat-intelligence-report-currentvulnerability-landscape</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>J.</given-names>
            <surname>Jeong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. G.</given-names>
            <surname>Mihelcic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Oliver</surname>
          </string-name>
          , Rudolph,
          <article-title>Towards an Improved Understanding of Human Factors in Cybersecurity</article-title>
          ,
          <source>in: 5th International Conference on Collaboration and Internet Computing (CIC)</source>
          , IEEE, Los Angeles, CA,
          <year>2019</year>
          , pp.
          <fpage>338</fpage>
          -
          <lpage>345</lpage>
          doi: 10.1109/CIC48465.
          <year>2019</year>
          .
          <volume>00047</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>M.</given-names>
            <surname>Malatjia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Marnewicka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Solmsb</surname>
          </string-name>
          ,
          <article-title>Validation of a socio-technical management process for optimizing cyber security practices</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>95</volume>
          (
          <year>2020</year>
          ). https://doi.org/10.1016/j.cose.
          <year>2020</year>
          .101846
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>A.</given-names>
            <surname>Totade</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Godbole</surname>
          </string-name>
          , Culture and Human Factors, in: D.
          <string-name>
            <surname>Antonucci</surname>
          </string-name>
          (Ed.),
          <article-title>The cyber risk handbook: Creating and measuring effective cybersecurity capabilities</article-title>
          , 1st. ed., John Wiley and Sons Incorporated, Hoboken, NJ,
          <year>2017</year>
          , pp.
          <fpage>243</fpage>
          -
          <lpage>255</lpage>
          . ISBN:
          <volume>111930972</volume>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>E.</given-names>
            <surname>Albrechtsen</surname>
          </string-name>
          ,
          <article-title>A qualitative study of users' view on information security</article-title>
          ,
          <source>Computers &amp; Security</source>
          ,
          <volume>26</volume>
          (
          <year>2007</year>
          ). doi:
          <volume>10</volume>
          .1016/j.cose.
          <year>2006</year>
          .
          <volume>11</volume>
          .004.
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>T.</given-names>
            <surname>Pseftelis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Chondrokoukis</surname>
          </string-name>
          .
          <article-title>A Study about the Role of the Human Factor in Maritime Cybersecurity</article-title>
          ,
          <source>Journal of Economics and Business</source>
          <volume>71</volume>
          (
          <year>2021</year>
          ). https://spoudai.unipi.gr/index.php/spoudai/article/download/2887/2724
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>M.</given-names>
            <surname>Bada</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sasse</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Nurse</surname>
          </string-name>
          . Cyber Security Awareness Campaigns:
          <article-title>Why do they fail to change behaviour?</article-title>
          , arXiv https://arxiv.org/pdf/
          <year>1901</year>
          .02672.pdf
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>K.</given-names>
            <surname>Parsons</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>McCormac</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Butavicius</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Pattinson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Jerram</surname>
          </string-name>
          ,
          <article-title>Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q)</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>42</volume>
          (
          <year>2014</year>
          ). https://doi.org/10.1016/j.cose.
          <year>2013</year>
          .
          <volume>12</volume>
          .003
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>R.</given-names>
            <surname>Protcor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <article-title>The Role of Human Factors/Ergonomics in the Science of Security: Decision Making and Action Selection in Cyberspace, Human Factors 57 (</article-title>
          <year>2015</year>
          ). doi:
          <volume>10</volume>
          .1177/0018720815585906.
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>M.</given-names>
            <surname>Pattinson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Butavicius</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lillie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ciccarello</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Parsons</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Calic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>McCormac</surname>
          </string-name>
          ,
          <article-title>Matching training to individual learning styles improves information security awareness</article-title>
          ,
          <source>Information and Computer Security</source>
          <volume>28</volume>
          (
          <year>2020</year>
          ). https://doi.org/10.1108/ICS-01-2019-0022
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>R.</given-names>
            <surname>McEvoy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kowalski</surname>
          </string-name>
          ,
          <article-title>Deriving Cyber Security Risks from Human and Organizational Factors -</article-title>
          A
          <string-name>
            <surname>Socio-technical</surname>
            <given-names>Approach</given-names>
          </string-name>
          ,
          <source>Complex Systems Informatics and Modeling Quarterly (CSIMQ) 105</source>
          (
          <year>2019</year>
          ). doi:
          <volume>10</volume>
          .7250/csimq.2019-
          <volume>18</volume>
          .
          <fpage>03</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>E.</given-names>
            <surname>Albrechtsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hovden</surname>
          </string-name>
          ,
          <article-title>Improving information security awareness and behaviour through dialogue, participation and collective reflection. An intervention study</article-title>
          ,
          <source>Computers &amp; Security</source>
          ,
          <volume>29</volume>
          (
          <year>2010</year>
          ). doi:
          <volume>10</volume>
          .1016/j.cose.
          <year>2009</year>
          .
          <volume>12</volume>
          .005.
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>V.</given-names>
            <surname>Hooper</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. McKissask</surname>
          </string-name>
          ,
          <article-title>The Emerging Role of the CISO</article-title>
          ,
          <source>Business Horizons</source>
          <volume>59</volume>
          (
          <year>2016</year>
          ). https://doi.org/10.1016/j.bushor.
          <year>2016</year>
          .
          <volume>07</volume>
          .004
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>M.</given-names>
            <surname>Sadok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Alter</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Bednar</surname>
          </string-name>
          ,
          <article-title>It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs, Information</article-title>
          and Computer Security,
          <volume>28</volume>
          (
          <year>2020</year>
          ). https://doi.org/10.1108/ICS-01-2019-0010
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>R. S.</given-names>
            <surname>Koppel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Smith</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Blythe</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kothari</surname>
          </string-name>
          ,
          <article-title>Workarounds to computer access in healthcare organizations: You want my password or a dead patient?</article-title>
          <source>Studies in Health and Technology Informatics</source>
          <volume>208</volume>
          (
          <year>2015</year>
          )
          <fpage>220</fpage>
          -
          <lpage>251</lpage>
          . doi:
          <volume>10</volume>
          .3233/978-1-
          <fpage>61499</fpage>
          -488-6-215.
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>V.</given-names>
            <surname>Zimmermann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Renaud</surname>
          </string-name>
          ,
          <article-title>Moving from a 'human-as-problem” to a 'human-as-solution” cyber security mindset</article-title>
          ,
          <source>International Journal of Human-Computer Studies</source>
          <volume>131</volume>
          (
          <year>2019</year>
          ). https://doi.org/10.1016/j.ijhcs.
          <year>2019</year>
          .
          <volume>05</volume>
          .005
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>