Promoting Cybersecurity Culture Change in Healthcare

Branley-Bell, Dawn, Coventry, Lynne and Sillence, Elizabeth (2021) Promoting Cybersecurity Culture Change in Healthcare. In: PETRA 2021: The 14th PErvasive Technologies Related to Assistive Environments Conference. Association for Computing Machinery, New York, pp. 544-549. ISBN 9781450387927

PETRA_Branley-Bell et al (2021).pdf - Accepted Version

Download (466kB) | Preview
Official URL:


Cybersecurity problems have traditionally been addressed through technological solutions and staff training. Whilst technology can reduce or remove some weaknesses some attacks specifically target human users. Whilst training can educate staff on how to behave more securely, this is often not sufficient to promote actual secure behaviours . Knowing what to do is necessary but not sufficient. It is also necessary to remove barriers to the required behaviour and to intervene in a way that affords behaviour change. This is particularly true in healthcare, where environmental factors including time pressure, and staff fatigue can create barriers for cybersecurity behaviour change. Technology and training are only a partial solution. Only by taking a more holistic approach which encompasses technology, people and processes and addressing the culture change needed to facilitate more secure behaviours will any progress be made in the workplace. We conducted a series of in-depth interviews and workshops with staff across 3 healthcare organisations in Italy, Crete and Ireland. This paper reflects on our main findings, including key requirements for future cybersecurity interventions. We used this reflection to develop a secure behaviour toolkit to help healthcare organisations identify problematic behaviours, co-create interventions to increase secure staff behaviour being mindful that sometimes culture change is necessary to enable the required security behaviours. The toolkit also provides a means to evaluate the interventions identified and the final implementation of the intervention.

Item Type: Book Section
Additional Information: Funding information: This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 826293.
Uncontrolled Keywords: behaviour change, culture, cybersecurity, healthcare, toolkit
Subjects: C800 Psychology
G900 Others in Mathematical and Computing Sciences
Department: Faculties > Health and Life Sciences > Psychology
Depositing User: Elena Carlaw
Date Deposited: 02 Aug 2021 14:57
Last Modified: 02 Aug 2021 15:00

Actions (login required)

View Item View Item


Downloads per month over past year

View more statistics