Search papers, labs, and topics across Lattice.
This paper introduces the STARC model, a novel framework that adapts Giddens' Structuration Theory to analyze cybersecurity practices across multiple organizational levels and contexts. By incorporating innovations such as Multi-Level Adversarial Agency and Threat-Adaptive Structuration, the model explains the structural factors contributing to varying resilience among organizations with similar cybersecurity controls. The findings, drawn from interviews with analysts and executives across three banks in different countries, reveal critical insights into the interplay between human and algorithmic decision-making in incident response and resilience diagnostics.
Organizations with similar cybersecurity controls can exhibit vastly different resilience due to structural factors that traditional theories overlook.
The problem: Cybersecurity practice runs simultaneously across analysts, teams, organizations, sectors, and regulators, co-evolves with adversaries, and increasingly blends human and algorithmic decision-making. The theories applied to it operate at single organizational levels and cannot explain why organizations with broadly similar controls differ sharply in resilience. This paper: We develop STARC (Structuration Theory Adaptation for Resilient Cybersecurity), a framework for locating where cybersecurity practice succeeds or fails structurally. It extends Giddens'Structuration Theory with three innovations, Multi-Level Adversarial Agency, Threat-Adaptive Structuration, and Material-Agential Structural Properties, across five structure-agency triads. Evidence base: STARC is illustrated through re-analysis of three financial organizations, an Australian, an Indonesian, and a Malaysian bank, across 20 interviews from SOC analysts to senior executives, selected as diverse insourced and outsourced configurations rather than as a comparison of equivalents. Cybersecurity contribution: STARC offers a structural account of why differently resourced and outsourced organizations differ in resilience, and a vocabulary for diagnosing incident-response breakdown across levels, tempos, and the human-algorithm authority boundary that single-level frameworks leave invisible. Theory and outputs: It extends Structuration Theory to adversarial, multi-level, and hybrid human-algorithmic contexts, and yields seven testable propositions linking structuration to resilience, offered for future testing.