<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>An exploration into organizational practice to address insider risk: A socio-technical perspective</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Robert Kennedy</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Portsmouth, School of Criminology and Criminal Justice</institution>
          ,
          <addr-line>Portsmouth</addr-line>
          ,
          <country country="UK">United Kingdom</country>
        </aff>
      </contrib-group>
      <fpage>132</fpage>
      <lpage>139</lpage>
      <abstract>
        <p>Insiders can inadvertently or purposefully pose serious threats to organizations by facilitating access to or misuse of proprietary sensitive data. However, technological-centric security solutions have rather limited scope to tackle this problem, with a holistic approach to security potentially providing a better means to address the challenge of preventing and responding to insider threats. In this paper, we explore organizational practices when it comes to security convergence to prevent and address insider risk. The empirical inquiry will involve 12-16 security professionals using semi-structured interviews and conducted from an interpretive stance.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Insider threat</kwd>
        <kwd>socio-technical</kwd>
        <kwd>converged security</kwd>
        <kwd>work practice</kwd>
        <kwd>security professionals 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The harm that the insider threat can potentially provide to organizations is widely recognized
[
        <xref ref-type="bibr" rid="ref25">27</xref>
        ], however, insider risk is often managed with a technological-centric approach [
        <xref ref-type="bibr" rid="ref18">19</xref>
        ]. The
current approach to insider risk mitigation would arguably benefit from a socio-technical
approach supporting security convergence [
        <xref ref-type="bibr" rid="ref27">29</xref>
        ]. Research into insider risk management suggests
that in general, organizational approaches lack maturity, often operate within a silo and fail to
utilize interdependent business functions efficiently [
        <xref ref-type="bibr" rid="ref18">19</xref>
        ].
      </p>
      <p>This short paper aims to present early ideas and receive feedback on research-in-progress
designed to emphasize the importance of a better understanding of how security governance and
risk management can potentially be enhanced by utilizing a socio-technical system. This will
inform practice to enable a converged security approach with the interdependent disciplines of
protective security and wider business functions.</p>
      <p>The remainder of this paper is organized as follows: the next section presents the background
research. Section three summarizes the research method and design and provides details about data
collection process and data analysis method. As this is research in progress, key findings,
discussion and conclusion are not yet available, however, potential implications in practice have been
reviewed.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <p>
        Organizations cannot attain a reasonable level of assurance against security risk unless it
considers all of its security risk when developing security strategy and risk mitigation [
        <xref ref-type="bibr" rid="ref34">36</xref>
        ]. This
holistic approach to protective security is known as security convergence [
        <xref ref-type="bibr" rid="ref1 ref29">1, 31</xref>
        ] and requires
organizations to employ a ‘systems thinking’ approach to manage security [
        <xref ref-type="bibr" rid="ref18">19</xref>
        ]. Security
convergence is therefore the formal, collaborative and strategic integration of the combined
organizational security resources to deliver organizational wide benefits through effective risk
mitigation, enhanced operational effectiveness, increased efficiency and financial savings [
        <xref ref-type="bibr" rid="ref34">36</xref>
        ]. The
converged approach to protective security is viewed by many to provide organizations with a better
security risk management approach to enable senior risk owners to make informed decisions whilst
also streamlining security teams to enable organizational efficiency [20]. Security convergence is
perceived as a contemporary subject amongst both academia and those working within the
protective security sector. The risk posed by human activity can be especially dangerous to organizations
[
        <xref ref-type="bibr" rid="ref37">39</xref>
        ] with insider threat and risk requiring organizations to undertake assessments, risk
prioritization and action as opposed to reaction [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Insider risk mitigation requires personnel security to
mitigate, personnel security being defined by Martin [
        <xref ref-type="bibr" rid="ref18">19</xref>
        ] as “the system of protective security
measures by which an organization understands and manages insider risk” (2023, p. 12).
      </p>
      <sec id="sec-2-1">
        <title>2.1 Insider Threat Actors</title>
        <p>
          Whilst three of the four security disciplines; cyber, physical and technical security [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ] can be
employed by an organization with a combination of security risk management and commercially
available products, the same cannot be said for personnel security. Insiders have the potential to
inflict harm with a variety of methods [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ] and can potentially provide a substantial threat as they
possess the knowledge of an organizations vulnerabilities and have the ability to bypass security
mitigations due to their legitimate access to organizational assets [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Insiders can provide a major
threat to organizations [
          <xref ref-type="bibr" rid="ref32">34</xref>
          ] with deviant behavior capable of harming an organization via several
pathways [
          <xref ref-type="bibr" rid="ref11 ref36">38, 11</xref>
          ]. A host of factors including malevolent creativity; the deliberate intent to cause
harm [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ] and unintentional actions have contributed to enabling unauthorized disclosure of
sensitive information, process corruption, physical or IT sabotage, the facilitation of third-party access
[
          <xref ref-type="bibr" rid="ref35">37</xref>
          ] and violent assault [
          <xref ref-type="bibr" rid="ref30">32</xref>
          ] including murder. An insider intent on causing harm to an
organization can potentially be far more effective than an external threat actor due to insiders having
legitimate, sometimes even privileged access to organizational facilities and information, combined with
the knowledge they possess regarding organizational vulnerabilities and assets [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. This is
supported by research conducted on security failure identifying that insiders can provide a credible threat
to organizations, either intentionally or unintentionally, by enabling third party access or the
misuse of sensitive data [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ]. As the average cost of an insider event has been estimated to be $11.45
million [
          <xref ref-type="bibr" rid="ref25">27</xref>
          ], this should be a concern to organizations. However, examples of insider events
continue to surface across the globe and include; the former head of the Swiss bank Raiffeisen profiting
from illicit deals, a former Chinese based employee of a Dutch semiconductor manufacturer
stealing confidential information regarding chip-making machinery, an Arctic University of Norway
researcher arrested for being a Russian spy [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ], and a disgruntled EnerVest employee sabotaging
infrastructure [
          <xref ref-type="bibr" rid="ref25">27</xref>
          ]. Such breaches amplify the risk to organizations due to the lack of, or even
absence of detection, a slow response to insider activity if detected, and inconsistent remediation
measures [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. Early detection requires vigilance by organizations to identify when signs of
potential disgruntlement arise within individuals to act early and prevent the said individual from
progressing down a critical pathway to become an insider [
          <xref ref-type="bibr" rid="ref30">32</xref>
          ].
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2 Security Risk Exposure</title>
        <p>
          The importance of managing risk exposure is critical to enabling organizational security,
business continuity and resilience [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] with security risk being both dynamic and adaptive [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ].
The disparity between the volume of threat information regarding external actors, currently
outweighs the available data regarding insider events [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ], which could conceivably hinder
commensurate security risk management. Many organizations focus on external threats and
overlook the threat posed by the insider [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ] which could potentially impact their exposure to risk.
The use of quantitative risk methodology developed and used for managing project or insurance
risks is often misapplied to manage security risk. Security risks differ significantly from other
risks, as security risk is a combination of threat, vulnerability and impact, quantitative tools used to
manage risk in other contexts may not always work for security [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ]. Risk is also often perceived
subjectively and shaped by the individual’s experience and political, social, and cultural factors [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]
with insider risk mitigation, often relying on protection provided by potential threats, the insiders
themselves [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. Ideally, the risk assessment process should be undertaken with a systematical
approach involving multiple stakeholders from each business unit within an organization [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]. This is
supported by the doctrine that protective security should be managed holistically as opposed to
individually, with a converged approach recognizing the interdependencies within the security
disciplines [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ] of cyber, personnel, physical and technical security. Such interdependencies would
also include wider business functions, for example Human Resources (HR). Wright and Roy [
          <xref ref-type="bibr" rid="ref39">41</xref>
          ]
argue that with regards to industrial espionage, the key to the problem is people, i.e. insiders, and
therefore the HR manager has a significant role to play with regards to insider risk management
and should ideally understand the security requirements of the organization to enable appropriate
security messaging etc.
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3 Security Governance</title>
        <p>
          Security governance is the combined efforts of multiple stakeholders to ensure the delivery of
effective security through organizational hierarchies and networks [
          <xref ref-type="bibr" rid="ref35">37</xref>
          ]. Leadership is required to
provide executive commitment and oversight [
          <xref ref-type="bibr" rid="ref21">23</xref>
          ] to support and underpin the governance process.
However, a governance structure that has each security discipline reporting to a Chief Security
Officer (CSO) would not necessarily provide a converged security governance function. Without an
understanding of the interdependence of different business risks, an organization is conceivably
operating an inefficient governance model [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ] which may not provide an accurate single overview of
risk [
          <xref ref-type="bibr" rid="ref29">31</xref>
          ]. Whilst the CSO should ensure that executive leadership, governance groups and senior
management contribute towards protective security discussion and define responsibilities to
discharge actions [
          <xref ref-type="bibr" rid="ref21">23</xref>
          ], this should ideally be part of a wider enterprise risk management approach
[
          <xref ref-type="bibr" rid="ref29">31</xref>
          ]. Sadok et al [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ] argue that a top-down approach to managerial instruction, and the
development of policy and process without the integration of all security functions and active engagement
with stakeholders, may encourage employees to work around security compliance and potentially
circumvent security measures altogether. The design of security should therefore not only consider
the integration of the interdependent security functions [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ], but also consider the context of the
work role from each employee and stakeholder when designing security [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ], which would include
policy and process to mitigate the insider risk in practice.
        </p>
      </sec>
      <sec id="sec-2-4">
        <title>2.4 The socio-technical approach to mitigate insider risk.</title>
        <p>
          Criticism of insider risk mitigation methods has included that this tends to be
technologicalcentric [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ], with Steinmetz [
          <xref ref-type="bibr" rid="ref33">35</xref>
          ] arguing that a technological approach alone is not effective.
Sadok et al. [
          <xref ref-type="bibr" rid="ref27">29</xref>
          ] argue that a socio-technical approach is required as technology-centered
solutions, without the inclusion of people and processes, induces flaws within potential security
solutions. The United Kingdom National Protective Security Authority (NPSA) encourage the
combination of social, physical and technical mitigations within their Insider Risk Mitigation
Framework [
          <xref ref-type="bibr" rid="ref22">24</xref>
          ], with NPSA advocating the use of ‘the critical path’ approach. The critical-path
approach identifies four factors that contribute to insider risk, those being personal
predispositions, stressors, concerning behaviors and problematic organizational response [
          <xref ref-type="bibr" rid="ref30">32</xref>
          ]. The
critical-path elements have been applied by NPSA to the case study involving David Smith, who
was imprisoned for spying on behalf of a hostile state [
          <xref ref-type="bibr" rid="ref23">25</xref>
          ]. The four elements of the critical-path
approach employing a combination of social, physical and technical security measures would
potentially benefit from employing ‘Work Systems Theory’ to develop a system employing a
sociotechnical approach [
          <xref ref-type="bibr" rid="ref27">29</xref>
          ] The development and use of a socio-technical system is supported by
Fischer and Herrmann [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] who argue that technology alone does not impact social
structures or human behavior positively. As a socio-technical system would enable a security
design incorporating human, social, organizational and technical factors [
          <xref ref-type="bibr" rid="ref10 ref3">3, 10</xref>
          ] this could
potentially bridge the security disciplines by identifying, acknowledging and capitalizing on the
interdependencies between each security function, it could conceivably be argued that a converged
security approach would better support the management of insider risk [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ]. Of course, any
security design is challenging to embed within an organization as the balance between security and
usability needs to be contextualized to the organization’s everyday practices [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ]. This would require
democracy, which is a fundamental socio-technical value, with employees encouraged to
collaborate in security design [
          <xref ref-type="bibr" rid="ref20">22</xref>
          ] to better support usability.
        </p>
        <p>
          Good personnel security requires organizations to move forwards towards being a high trust
organization with a healthy security culture [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ]. Organizations that can create a sense of confidence
within their workforce, rather than individuals being on-guard and suspecting potential
mistreatment, with employees confident that the management and organization are honorable, often
perform better that those that do not [
          <xref ref-type="bibr" rid="ref38">40</xref>
          ]. High levels of mutual trust within organizations and their
stakeholders are generally successful organizations in many ways and they also tend to
demonstrate less insider risk [
          <xref ref-type="bibr" rid="ref18">19</xref>
          ]. This is possibly because engaged and motivated staff that demonstrate
ownership of their organization’s objectives are also more likely to support the protection of
organizational interests through commensurate security measures [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ]. The benefits of a socio-technical
systems design can support organizations to become highperforming [
          <xref ref-type="bibr" rid="ref19">21</xref>
          ], with a high performing
work system defined as an organization operating at levels of excellence far beyond other
comparable organizations [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Research design</title>
      <p>The study undertaken is an exploratory study, conducted from an interpretive stance. This
means that it aims to shed light on actual, experienced practices within a sample of public and
private sector organizations. This study will therefore not uncover any statistically significant, or
indeed generalizable conclusions.</p>
      <p>The purpose of this qualitative study is to understand the barriers and enablers to embed
personnel security to manage the insider risk within organizations. Using semi-structured
interviews involving security professionals to gather qualitative data, this study will explore the
challenges organizations face to embed effective personnel security and explore the potential
contribution that converged security could provide to mitigate risk.</p>
      <p>
        Noaks &amp; Wincup [
        <xref ref-type="bibr" rid="ref24">26</xref>
        ] argue that some aspects of criminological enquiry are challenging to
investigate using quantitative methods citing insider activity in the form of ‘white-collar’ crime
as one such relevant example. To enable the concept of Max Weber’s ‘Verstehen’, the ontological
approach of constructionism and the epistemological interpretivist stance will be used to gain such
understanding [
        <xref ref-type="bibr" rid="ref2 ref7">7, 2</xref>
        ]. Qualitative research is therefore appropriate and is underpinned by
philosophy to inform the research questions, research objectives and hypothesis developed. This will be
conducted using semi-structured interviewing to collect data. The interviews will be scheduled at
convenience, last no longer than one hour and be conducted online with the aim to encourage
spontaneous interactions between the interviewer and participants [17]. This study therefore aims
to use semi-structured interviews to discover through dialogue, discussion and interactions the tacit
knowledge that security professionals possess to support the production of Mode 2 knowledge [
        <xref ref-type="bibr" rid="ref13 ref15 ref28">15,
30, 13</xref>
        ].
      </p>
      <p>The study aims to research the below questions:
RQ1 – To explore to what extent organizations are aware of insider threat.</p>
      <p>RQ2- To explore organizations’ practices when it comes to assessing and addressing insider risk.
RQ3- To explore the potential contribution of security convergence to prevent and address
insider risk.
This study also aims to explore the below hypotheses:
H1- Insider risk is not well-considered or widely integrated into security risk management.
H2- Security convergence can support the prevention of insider activity.</p>
      <p>H3- A disjoint between policy, process and usability hinders effective security mitigations.
H4Current insider activity detection is reactive not pro-active.</p>
      <p>H5- Technological-centric solutions to manage insider risk are limited.</p>
      <p>H6- Effective leadership and governance are necessary to mitigate insider risk.</p>
      <p>H7- Organizational culture has a direct impact on personnel security.</p>
      <p>The semi-structured interview themes detailed below will be used during the interviews:
1) In your experience how well do organizations in general manage the risk posed by
insiders?
2) What do you think the barriers are to embedding effective personnel security into
organizations?
3) How does leadership and governance contribute to effective personnel security?
4) How can other non-security functions of a business impact personnel security?
5) How effective are technological-centric only risk mitigations?
6) What do you believe is required for organizations to become a high-trust organization? 7)</p>
      <p>
        What blocks organizations from becoming a high-trust organization?
8) What do you envisage to be the future challenges organizations will face regarding
personnel security?
9) How will emerging technology such as artificial intelligence impact personnel security?
10) How would you envisage security convergence supporting personnel security?
A snowball sampling technique will be used to recruit interview participants. Initial
recruitment will involve contacting individuals within the researcher’s professional network;
however, this will not include individuals from the researcher’s own organization. Participants from
government agencies that require organizational permissions, e.g. law enforcement, will not be
approached. Individuals from both public and private organizations will be invited to participate in
this study. This qualitative research study will require interaction with individuals as it is the
perspective of the participant regarding the topic of research that the researcher will endeavor to
research [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Participants will be included in the research should they work within the security sector
to include those within interdependent business functions regarding the management of insider
risk, such as Human Resources. Participants will be excluded if they do not work within the
security sector or within an interdependent business function. The researcher’s ability to be flexible with
the sample size may be appropriate should; the semistructured interviews identify new factors
which are deemed to require further data collection, the researcher initially focuses on a small
sample then use the wider sample to test emerging generalizations, or alternatively, unexpected
generalizations identified during the data analysis phase leads the researcher to seek out new
participants [
        <xref ref-type="bibr" rid="ref31">33</xref>
        ].
      </p>
      <p>The initial identification of research participants includes a number of UK security
professionals that span both the public and private sectors. This includes security leaders and
consultants specializing in personnel security that support multiple clients, along with a personnel
security leader working in the private sector managing insider risk within a critical infrastructure
sector. The participants are relevant to this research as they have a vast amount of experience
regarding the mitigation of insider risk across the national security arena and both the public and
private sectors. The combined tacit knowledge and experience from the participants is expected to
provide high-value qualitative data to inform this study.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Potential Implications in Practice</title>
      <p>The researcher’s motivation for undertaking a Professional Doctorate has been borne out of
frustration with the current culture of addressing protective security with a siloed approach. This
siloed approach enables threat actors to exploit the vulnerabilities provided within the gaps that
exist between cyber, personnel, physical and technical security and also fails to provide a single
overview of security risk to enable organizational senior risk owners to effectively manage risk.
Without a converged approach to protective security organizations cannot expect to effectively
mitigate converged threat vectors. Personnel security is arguably the most difficult of the protective
security disciplines to embed within organizations, and therefore provides the biggest challenge for
organizations to adopt a converged approach. At a time when contributing factors within society
have provided a perfect storm for insider events, with some high-profile cases reported within the
UK media, and potentially many more that go undetected, organizations need to consider the risk
posed by insiders as part of any security strategy.</p>
      <p>This study aims to raise awareness and understanding of this problem with a view to
identifying a potential strategy to enable organizations to work towards a converged security
approach incorporating the four disciplines of protective security within an interdependent
model. The participants within this study will provide a wealth of data gained from their
combined knowledge amassed throughout their careers working within the protective security
sector. The findings from this study will hopefully contribute to the creation of new knowledge to
drive change to encourage organizations to review their current security strategy and consider
moving from a siloed approach to a converged approach. This study will also support the
researcher’s ambition to contribute to the body of knowledge to support and shape the future of
protective security strategies.</p>
      <p>
        The researcher is currently developing a ‘Protective Security Adviser’ qualification [
        <xref ref-type="bibr" rid="ref17">18</xref>
        ] with
UK stakeholders that includes academia, public and private sector organizations. This training
qualification aims to; educate delegates to the benefits of security convergence, provide delegates with a
base level of competence across the four disciplines of security, provide a pathway for delegates to
progress onto academic qualifications, and standardize the approach to protective security within
the UK. This qualification also aims to boost social mobility, and as such, provide a positive impact
to equality, diversity and inclusion to enable organizations to recruit and retain a workforce
providing diversity of thought to enhance organizational capability to mitigate risk. The qualification is
very much a ‘ground-up’ approach to influence the sector and provide future leaders within the
security sector that are equipped with the appropriate knowledge, skills and behaviors to support a
converged approach to protective security. The identified ‘ground-up’ approach will be supported
by this academic study and the future research conducted as part of the researchers Professional
Doctorate to enable a ‘top-down’ approach to drive change moving forwards towards security
convergence underpinned by academic evidence.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Aleem</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wakefield</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Button</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Addressing the weakest link: Implementing converged security</article-title>
          .
          <source>Security Journal</source>
          ,
          <volume>26</volume>
          ,
          <fpage>236</fpage>
          -
          <lpage>248</lpage>
          . https://doi.org/10.1057/sj.
          <year>2013</year>
          .14
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Aspers</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Corte</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>What is qualitative in qualitative research</article-title>
          .
          <source>Qualitative sociology</source>
          ,
          <volume>42</volume>
          ,
          <fpage>139</fpage>
          -
          <lpage>160</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Baxter</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          &amp;
          <string-name>
            <surname>Sommerville</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          (
          <year>2011</year>
          ),
          <article-title>Socio-technical systems: From design methods to systems engineering</article-title>
          . Interacting with computers,
          <volume>23</volume>
          (
          <issue>1</issue>
          ),
          <fpage>4</fpage>
          -17 https://doi.org/10.1016/j.intcom.
          <year>2010</year>
          .
          <volume>07</volume>
          .003
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Bazeley</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Qualitative Data Analysis: Practical Strategies</article-title>
          , Sage.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Buchanan</surname>
            ,
            <given-names>D.A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Huczynski</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2019</year>
          ). Organizational Behaviour. Pearson UK
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Cappelli</surname>
            ,
            <given-names>D. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Moore</surname>
            ,
            <given-names>A. P.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Trzeciak</surname>
            ,
            <given-names>R. F.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>The CERT guide to insider threats: how to prevent, detect, and respond to information technology crimes (Theft, Sabotage</article-title>
          , Fraud).
          <source>Addison-Wesley.</source>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Clark</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Foster</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bryman</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sloan</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2021</year>
          ).
          <article-title>Bryman's social research methods</article-title>
          . Oxford University Press.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Colwill</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>Human factors in information security: The insider threat-Who can you trust these days?</article-title>
          .
          <source>Information security technical report</source>
          ,
          <volume>14</volume>
          (
          <issue>4</issue>
          ),
          <fpage>186</fpage>
          -
          <lpage>196</lpage>
          . https://doi.org/10.1016/j.istr.
          <year>2010</year>
          .
          <volume>04</volume>
          .004
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Cropley</surname>
            ,
            <given-names>D.H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Cropley</surname>
            ,
            <given-names>A.J.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>Creativity and malevolence: past, present, and future</article-title>
          .
          <source>The Cambridge Handbook of Creativity</source>
          ,
          <fpage>677</fpage>
          -
          <lpage>690</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Dalpiaz</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paja</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Security requirements engineering: designing secure socio-technical systems</article-title>
          . MIT Press.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Di</given-names>
            <surname>Stefano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            ,
            <surname>Scrima</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            , &amp;
            <surname>Parry</surname>
          </string-name>
          ,
          <string-name>
            <surname>E.</surname>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>The effect of organizational culture on deviant behaviors in the workplace</article-title>
          .
          <source>The International Journal of Human Resource Management</source>
          ,
          <volume>30</volume>
          (
          <issue>17</issue>
          ),
          <fpage>2482</fpage>
          -
          <lpage>2503</lpage>
          . https://doi.org/10.1080/09585192.
          <year>2017</year>
          .1326393
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Fischer</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Herrmann</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Socio-technical systems: a meta-design perspective</article-title>
          .
          <source>International Journal of Sociotechnology and Knowledge Development (IJSKD)</source>
          ,
          <volume>3</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>33</lpage>
          . DOI:
          <volume>10</volume>
          .4018/jskd.2011010101
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Fulton</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuit</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sanders</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Smith</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>The role of the professional doctorate in developing professional practice</article-title>
          .
          <source>Journal of nursing management</source>
          ,
          <volume>20</volume>
          (
          <issue>1</issue>
          ),
          <fpage>130</fpage>
          -
          <lpage>139</lpage>
          . https://doi.org/10.1111/j.1365-
          <fpage>2834</fpage>
          .
          <year>2011</year>
          .
          <volume>01345</volume>
          .x
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Georgiadou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mouzakitis</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Askounis</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2022</year>
          ).
          <article-title>Detecting insider threat via a cybersecurity culture framework</article-title>
          .
          <source>Journal of Computer Information Systems</source>
          ,
          <volume>62</volume>
          (
          <issue>4</issue>
          ),
          <fpage>706</fpage>
          -
          <lpage>717</lpage>
          . https:// doi.org/10.1080/08874417.
          <year>2021</year>
          .1903367
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Gibbons</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Limoges</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nowotny</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schwartzman</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scott</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          &amp;
          <string-name>
            <surname>Trow</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>1994</year>
          ).
          <article-title>The New Production of Knowledge, SAGE publications</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Harris</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sadok</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>How do professionals assess security risks in practice? An exploratory study</article-title>
          .
          <source>Security Journal</source>
          ,
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          . https://doi.org/10.1057/s41284-023-00389-y [17]
          <string-name>
            <surname>James</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Busher</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Online Interviewing</article-title>
          . In D. Silverman (Ed).
          <source>Qualitative Research</source>
          (4th ed., pp-
          <volume>245</volume>
          -260). Sage.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Kennedy</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2023</year>
          , September 28).
          <article-title>Level 4 protective security apprenticeship brings a converged approach</article-title>
          . City Security Magazine.
          <article-title>Level 4 protective security apprenticeship brings a converged approach</article-title>
          - City Security Magazine
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Martin</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Insider risk and personnel security: An introduction</article-title>
          . Taylor &amp; Francis. [20]
          <string-name>
            <surname>Mattord</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kotwica</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Whitman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Battaglia</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Organizational perspectives on converged security operations</article-title>
          .
          <source>Information &amp; Computer Security</source>
          ,
          <year>2023</year>
          . Vol.
          <article-title>ahead-of-print No. ahead-of-print</article-title>
          . https://doi.org/10.1108/ICS-03-2023-0029
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Mohr</surname>
            ,
            <given-names>B. J.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Creating High-Performing Organizations: The North American Open Sociotechnical Systems Design Approach</article-title>
          . In B. Mohr &amp;
          <string-name>
            <given-names>P. V.</given-names>
            <surname>Amelsvoort</surname>
          </string-name>
          ,
          <string-name>
            <surname>Co-Creating Humane</surname>
          </string-name>
          and Innovative Organizations,
          <fpage>16</fpage>
          -
          <lpage>33</lpage>
          ,
          <string-name>
            <given-names>Global</given-names>
            <surname>STS-D Network</surname>
          </string-name>
          Press.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Mumford</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          (
          <year>2006</year>
          ).
          <article-title>The story of socio-technical design: Reflections on its successes, failures and potential</article-title>
          .
          <source>Information Systems Journal</source>
          ,
          <volume>16</volume>
          (
          <issue>4</issue>
          ),
          <fpage>317</fpage>
          -
          <lpage>342</lpage>
          . https://doi.org/10.1111/j.1365-
          <fpage>2575</fpage>
          .
          <year>2006</year>
          .
          <volume>00221</volume>
          .x
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>New</given-names>
            <surname>Zealand Government</surname>
          </string-name>
          (
          <year>2022</year>
          ).
          <article-title>Capability Maturity Model for Protective Security</article-title>
          .
          <article-title>Capability Maturity Model 2022 (protectivesecurity</article-title>
          .govt.nz)
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>National</given-names>
            <surname>Protective Security Authority</surname>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Insider Risk Mitigation Framework. Insider Risk Mitigation Framework | NPSA</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>National</given-names>
            <surname>Protective Security Authority</surname>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>If you have people, you have an Insider Risk: A David Smith case study. If you have people, you have an Insider Risk: A David Smith case study | NPSA</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Noaks</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Wincup</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          (
          <year>2004</year>
          ).
          <article-title>Criminological research: Understanding qualitative methods</article-title>
          .
          <source>Sage.</source>
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Renaud</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warkentin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pogrebna</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>van der Schyff</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (
          <year>2024</year>
          ).
          <article-title>VISTA: An inclusive insider threat taxonomy, with mitigation strategies</article-title>
          .
          <source>Information &amp; Management</source>
          ,
          <volume>61</volume>
          (
          <issue>1</issue>
          ), 103877 https://doi.org/10.1016/j.im.
          <year>2023</year>
          .103877
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Sadok</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Welch</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Bednar</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>A socio-technical perspective to counter cyberenabled industrial espionage</article-title>
          .
          <source>Security Journal</source>
          ,
          <volume>33</volume>
          ,
          <fpage>27</fpage>
          -42 https://doi.org/10.1057/s41284-018- 00198-2
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [29]
          <string-name>
            <surname>Sadok</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alter</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Bednar</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>It is not my job: exploring the disconnect between corporate security policies and actual security practices in SMEs</article-title>
          . Information &amp; Computer Security,
          <volume>28</volume>
          (
          <issue>3</issue>
          ),
          <fpage>467</fpage>
          -
          <lpage>483</lpage>
          . https://doi.org/10.1108/ICS-01-2019-0010
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [30] San Miguel,
          <string-name>
            <given-names>C.</given-names>
            , &amp;
            <surname>Nelson</surname>
          </string-name>
          ,
          <string-name>
            <surname>C. D.</surname>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Key writing challenges of practice-based doctorates</article-title>
          .
          <source>Journal of English for Academic Purposes</source>
          ,
          <volume>6</volume>
          (
          <issue>1</issue>
          ),
          <fpage>71</fpage>
          -
          <lpage>86</lpage>
          . https://doi.org/10.1016/j.jeap.
          <year>2006</year>
          .
          <volume>11</volume>
          .007
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Schneller</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Porter</surname>
            ,
            <given-names>C. N.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Wakefield</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Implementing converged security risk management: Drivers, barriers, and facilitators</article-title>
          .
          <source>Security Journal</source>
          ,
          <volume>36</volume>
          (
          <issue>2</issue>
          ),
          <fpage>333</fpage>
          -
          <lpage>349</lpage>
          . https://doi.org/10.1057/s41284-022-00341-6
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Shaw</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sellers</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Application of the critical-path method to evaluate insider risks</article-title>
          .
          <source>Studies in Intelligence</source>
          ,
          <volume>59</volume>
          (
          <issue>2</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Silverman</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Interpreting Qualitative Data (4th ed</article-title>
          .), Sage.
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Soomro</surname>
            ,
            <given-names>Z. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shah</surname>
            ,
            <given-names>M. H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Ahmed</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Information security management needs more holistic approach: A literature review</article-title>
          .
          <source>International Journal of Information Management</source>
          ,
          <volume>36</volume>
          (
          <issue>2</issue>
          ),
          <fpage>215</fpage>
          -
          <lpage>225</lpage>
          . https://doi.org/10.1016/j.ijinfomgt.
          <year>2015</year>
          .
          <volume>11</volume>
          .009
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [35]
          <string-name>
            <surname>Steinmetz</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2021</year>
          ).
          <article-title>The 'Insider Threat' and the 'Insider Advocate'</article-title>
          . In P. Cornish,
          <source>The Oxford Handbook of Cyber Security</source>
          ,
          <fpage>348</fpage>
          -
          <lpage>357</lpage>
          , Oxford University Press.
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [36]
          <string-name>
            <surname>Tyson</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Security convergence: Managing enterprise security risk</article-title>
          .
          <source>Elsevier.</source>
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [37]
          <string-name>
            <surname>Wakefield</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2021</year>
          ).
          <article-title>Security and crime: converging perspectives on a complex world</article-title>
          .
          <source>Sage.</source>
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [38]
          <string-name>
            <surname>Walsh</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Extra-and intra-organizational drivers of workplace deviance</article-title>
          .
          <source>The Service Industries Journal</source>
          ,
          <volume>34</volume>
          (
          <issue>14</issue>
          ),
          <fpage>1134</fpage>
          -
          <lpage>1153</lpage>
          . https://doi.org/10.1080/02642069.
          <year>2014</year>
          .939645
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [39]
          <string-name>
            <surname>Warkentin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Willison</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>Behavioral and policy issues in information systems security: the insider threat</article-title>
          .
          <source>European Journal of Information Systems</source>
          ,
          <volume>18</volume>
          (
          <issue>2</issue>
          ),
          <fpage>101</fpage>
          -
          <lpage>105</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [40]
          <string-name>
            <surname>Whetten</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cameron</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Woods</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2000</year>
          ).
          <article-title>Developing Management Skills for Europe</article-title>
          . Prentice Hall.
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [41]
          <string-name>
            <surname>Wright</surname>
            ,
            <given-names>P.C.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Roy</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          (
          <year>1999</year>
          ).
          <article-title>Industrial espionage and competitive intelligence: one you do; one you do not</article-title>
          .
          <source>Journal of Workplace Learning</source>
          ,
          <volume>11</volume>
          (
          <issue>2</issue>
          ),
          <fpage>53</fpage>
          -
          <lpage>59</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>