From cyber security incident management to cyber security crisis management in the European Union

dc.contributor.authorRuohonen, Jukka
dc.contributor.authorRindell, Kalle
dc.contributor.authorBusetti, Simone
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.converis.publication-id505082848
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/505082848
dc.date.accessioned2026-01-21T15:00:36Z
dc.date.available2026-01-21T15:00:36Z
dc.description.abstract<p>Incident management is a classical topic in cyber security. Recently, the European Union (EU) has started to consider also the relation between cyber security incidents and cyber security crises. These considerations and preparations, including those specified in the EU’s new cyber security laws, constitute the paper’s topic. According to an analysis of the laws and associated policy documents, (i) cyber security crises are equated in the EU to large-scale cyber security incidents that either exceed a handling capacity of a single member state or affect at least two member states. For this and other purposes, (ii) the new laws substantially increase mandatory reporting about cyber security incidents, including but not limited to the large-scale incidents. Despite the laws and new governance bodies established by them, however, (iii) the working of actual cyber security crisis management remains unclear particularly at the EU-level. With these policy research results, the paper advances the domain of cyber security incident management research by elaborating how European law perceives cyber security crises and their relation to cyber security incidents, paving the way for many relevant further research topics with practical relevance, whether theoretical, conceptual, or empirical.<br></p>
dc.identifier.eissn1872-6208
dc.identifier.jour-issn0167-4048
dc.identifier.olddbid213990
dc.identifier.oldhandle10024/197008
dc.identifier.urihttps://www.utupub.fi/handle/11111/56188
dc.identifier.urlhttps://doi.org/10.1016/j.cose.2025.104689
dc.identifier.urnURN:NBN:fi-fe202601216389
dc.language.isoen
dc.okm.affiliatedauthorRindell, Kalle
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationinternational co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA1 ScientificArticle
dc.publisherElsevier
dc.publisher.countryNetherlandsen_GB
dc.publisher.countryAlankomaatfi_FI
dc.publisher.country-codeNL
dc.relation.articlenumber104689
dc.relation.doi10.1016/j.cose.2025.104689
dc.relation.ispartofjournalComputers and Security
dc.relation.volume159
dc.source.identifierhttps://www.utupub.fi/handle/10024/197008
dc.titleFrom cyber security incident management to cyber security crisis management in the European Union
dc.year.issued2025

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
1-s2.0-S0167404825003785-main.pdf
Size:
1.44 MB
Format:
Adobe Portable Document Format