Atif Ahmad

dblp:09/6570 · DBLP profile ↗
← Back
24ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0002-8862-5755ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 6 first-author · 9 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
abstract
1. AbstractThis socio-technical case study examines how organizations operationalize cyber-threat intelligence in complex business environments. Cyber-threat intelligence (CTI) is increasingly recognized as a critical decision-support function for organizations given an increasingly militarized cyber-threat environment. CTI promises to transform cyber defense from reactive and undirected responses to proactive, anticipatory and directed capabilities. Hence CTI enables organizations to anticipate the intent and capability of threat actors, thereby facilitating the development of defensive strategies to counter expected attack patterns.Yet despite cybersecurity being consistently ranked among top enterprise risks and the substantial organizational investment driven by strategic risk concerns, there is very little empirical evidence about how organizations actually implement and operationalize intelligence-led approaches in complex socio-technical environments. To understand how CTI can be operationalized in organizations, we draw on intelligence doctrine situated in the military context as theoretical underpinning, as this represents the most established approach to intelligence-led decision-making. Using the intelligence cycle as our theoretical lens we examine a mature CTI practice in a leading Australian financial organization. The empirical evidence we collect is framed as a stakeholder-activity process model that explains how CTI is practiced across Leadership, Business, and Technology Groups.Our findings reveal a fundamental inversion of established intelligence doctrine - rather than strategic requirements flowing downward from leadership to drive intelligence operations, our case organization generates requirements within technology operations silos, pushing intelligence outward and upward to operational, tactical, and strategic levels. This constitutes a reversal of intelligence norms established over seventy years of organizational practice in the military, revealing the unique challenges modern civilian organizations face in operationalizing CTI within complex business environments.Our study reveals a paradox where organizations invest heavily in CTI to address cyber-threats as a strategic priority yet simultaneously create barriers that prevent CTI from delivering strategic value. The root cause of this paradox is found in the positioning of the CTI function in the lowest level of the organizational structure, the profound knowledge gap between Business and IT Groups, and the prevalence of analytical products that lack the strategic relevance and analytical rigor that create decision value.Our stakeholder activity process model contributes to theory by providing the first systematic empirical explanation of CTI practice in organizations and by applying intelligence doctrine to the cyber context. From a practice perspective, the model serves as a diagnostic tool for understanding bottom-up operationalization of CTI practice. It enables organizations to map intelligence flows arising from key stakeholders, processes, and technology systems, and to redesign these flows to improve strategic coherence and relevance. Our findings challenge fundamental assumptions about intelligence-led security in civilian contexts and have significant implications for the organizations implementing CTI programs in the modern business environment.
Scott Ainslie, Atif Ahmad, Dean Thompson, Sean B. Maynard
Comput. Secur.2
2025 Shadow information security practices in organizations: The role of information security transparency, overload, and psychological empowerment
abstract
Employees are both the first line of defense in organizations and a significant source of vulnerability. Behavioral research in information security (InfoSec) has predominantly studied the compliance of employees with organizational directives. Less understood are ‘shadow security practices’ – a related category of behavior where employees adopt InfoSec workarounds, albeit to still comply with organizational security needs. We develop a model of the antecedents of employees’ intentions to engage in shadow security practices and empirically test our model through a sample of 433 office workers. Results of our structural equation modeling analysis reveal that both InfoSec overload and psychological empowerment increase intentions to adopt shadow security measures, whereas perceived transparency of organizational InfoSec (through InfoSec communication) reduces this intention. Furthermore, we find that these constructs are interrelated and that InfoSec overload can be increased by both psychological empowerment and InfoSec transparency . Our study develops the theoretical understanding of the important yet under-researched concept of shadow security and presents practical recommendations to effectively manage organizational InfoSec through these factors.
Duy Dang-Pham, Nik Thompson, Atif Ahmad, Sean B. Maynard
Comput. Secur.3
2024 Enabling cybersecurity incident response agility through dynamic capabilities: the role of real-time analytics
abstract
We explore how organisations enable agility in their cybersecurity incident response (IR) process by developing dynamic capabilities using real-time analytics (RTA). Drawing on RTA practices in the IR process at three large financial organisations, we develop a framework to explain how IR teams respond to the rapidly evolving cyber threat environment by developing RTA-based microfoundations that underpin the building of sensing, seizing, and transforming dynamic IR capabilities. These dynamic IR capabilities in turn help organisations to enable agility in their IR processes by leveraging swift, flexible, and innovative IR strategies, including active threat reconnaissance, active threat defence, and pervasive learning. Our findings have implications for the discourse on cybersecurity because we demystify the black box of IR agility, for our understanding of the use of RTA to enable agility in IR, and for the discourse on dynamic capabilities.
Humza Naseer, Kevin C. Desouza, Sean B. Maynard, Atif Ahmad
Eur. J. Inf. Syst.4
2024 Case-based learning for cybersecurity leaders: A systematic review and research agenda
abstract
Increasingly, large organisations are turning to cybersecurity leaders to protect their information resources against attack. However, because cybersecurity leadership roles are new, educational literature and practice targeting this role are nascent. In this systematic review, we assess the value of case-based learning (CBL) in educating cybersecurity leaders. We also aim to discover what gaps, if any, exist in this body of research. We find that cybersecurity leaders’ attitudes and metacognitive abilities are important but overlooked elements of their competence, and that CBL has potential to develop these competencies. The article concludes with a competency matrix and agenda for further research.
Ashley Baines Anderson, Atif Ahmad, Shanton Chang
Inf. Manag.2
2023 Cyber-threat intelligence for security decision-making: A review and research agenda for practice
abstract
The increasing militarization of the cyber-threat environment has driven considerable interest in understanding the role of cyber-threat intelligence (CTI) in supporting the enterprise. Despite CTI's value proposition to organizations, the rate of industry adoption has been low and localized within IT Operations. Our review of the research and practice literature on CTI shows that the discourse is heavily dominated by the technology perspective, leaving significant gaps in the knowledge of CTI. We begin with a background study that reinforces the traditional origins of CTI as a process derived from the Intelligence Cycle that is referenced and practiced in military intelligence studies. We describe the Intelligence Cycle and its phases and reinforce the characteristics and attributes of intelligence, asserting the critical importance of synthesizing information into intelligence. We subsequently develop a research agenda for practice researchers addressing the critical research question: “How can cyber-threat intelligence be operationalized in organizations?” We begin by exploring research questions to develop the theoretical foundations of CTI. Towards this objective, we present a useful template for process theory that generates practice outcomes. We then discuss methods suited to practice research in CTI before moving on to inquiries concerning the role and purpose of CTI in practice. We delve into questions on the broad aspects of practice at both the macro-level, focusing on the examination of CTI programs in organizations with different strategic risks, and the micro-level, exploring the distinctions between practice, praxis, and practitioners. Additionally, we explore questions on the role of artifacts, objects, and information systems that support CTI practice, including spaces and the role of practitioners and non-practitioners. After exploring various practice-related topics, we examine potential research opportunities pertaining to the prevailing narratives surrounding technology and information sharing, as identified in our literature review.
Scott Ainslie, Dean Thompson, Sean B. Maynard, Atif Ahmad
Comput. Secur.4
2023 Moving towards agile cybersecurity incident response: A case study exploring the enabling role of big data analytics-embedded dynamic capabilities
abstract
Organizations are at risk of cyber-attacks more than ever before due to the ongoing digitalization of business operations. Industry reports indicate that it is not a matter of if but when organizations become victims of cyber-attacks or breaches. In this research, we argue that organizations must enable agility in their incident response (IR) to quickly respond to diverse cybersecurity threats, and big data analytics (BDA) plays a pivotal role in enabling agility in the IR. Drawing from dynamic capabilities theory, we conducted a field study using a case study approach to examine the following research question: What dimensions of big data analytics-embedded dynamic capabilities enable agility in cybersecurity incident response? We develop a framework that presents five key dimensions of BDA-embedded dynamic capabilities (data consolidation, threat intelligence, incident investigation, analytical skillset, and cybersecurity analytics warehouse) in IR at four specific stages, that is, manual analysis, basic analytics, advanced analytics, and pervasive analytics. The detail of the framework explains how BDA-embedded dynamic capabilities at the pervasive analytics stage enable agility in IR by infusing agile characteristics of flexibility, speed, and learning in IR. This study contributes to the knowledge of IT-embedded dynamic capabilities and cybersecurity IR agility. Detailed recommendations are also provided for potential practitioners.
Ayesha Naseer, Humza Naseer, Atif Ahmad, Sean B. Maynard, Adil Masood Siddiqui
Comput. Secur.3
2023 Adopting and integrating cyber-threat intelligence in a commercial organisation
abstract
Cyber-attacks are increasingly perpetrated by organised, sophisticated and persistent entities such as crime syndicates and paramilitary forces. Even commercial firms that fully comply with industry “best practice” cyber security standards cannot cope with military-style cyber-attacks. We posit that the primary reason is the increasing asymmetry between the cyber-offensive capability of attackers and the cyber-defensive capability of commercial organisations. A key avenue to resolve this asymmetry is for organisations to leverage cyber-threat intelligence (CTI) to direct their cyber-defence. How can commercial organisations adopt and integrate CTI to routinely defend their information systems and resources from increasingly advanced cyber-attacks? There is limited know-how on how to package CTI to inform the practices of enterprise-wide stakeholders. This clinical research describes a practitioner-researcher’s experiences in directing a large multinational finance corporation to adopt and integrate CTI to transform cybersecurity-related practice and behaviour. The research contributes practical know-how on the organisational adoption and integration of CTI, enacted through the transformation of cybersecurity practice, and enterprise-wide implementation of a novel solution to package CTI for commercial contexts. The study illustrates the inputs, processes, and outputs in clinical research as a genre of action research.
James Kotsias, Atif Ahmad, Rens Scheepers
Eur. J. Inf. Syst.2
2022 Editorial
Atif Ahmad, Sean B. Maynard, Richard L. Baskerville
Comput. Secur.1
2022 Barriers and enablers to adoption of cyber insurance in developing countries: An exploratory study of Malaysian organizations
Nor Hasnul Azirah Abdul Hamid, Normalina Ibrahim @ Mat Nor, Fazlin Marini Hussain, Rajeswari Raju, Humza Naseer, Atif Ahmad
Comput. Secur.6
2021 How can organizations develop situation awareness for incident response: A case study of management practice
Atif Ahmad, Sean B. Maynard, Kevin C. Desouza, James Kotsias, Monica T. Whitty, Richard L. Baskerville
Comput. Secur.1
2021 Applying social marketing to evaluate current security education training and awareness programs in organisations
Moneer Alshaikh, Sean B. Maynard, Atif Ahmad
Comput. Secur.3
2021 Do privacy concerns determine online information disclosure? The case of internet addiction
abstract
Purpose It is a widely held belief that users make a rational cost-benefit decision when choosing whether to disclose information online. Yet, in the privacy context, the evidence is far from conclusive suggesting that strong and as-yet unmeasured influences on behaviour may exist. This paper aims to demonstrate one such link – the effect of internet addiction on information disclosure. Design/methodology/approach Data from 216 Web users was collected regarding their perceptions on privacy and information disclosure intentions as well as avoidance behaviour, an element of internet addiction. Using a research model based on the Privacy Calculus theory, structural equation modelling was applied to quantify the determinants of online disclosure under various conditions. Findings The authors show that not all aspects of privacy (a multi-dimensional construct) influence information disclosure. While concerns about data collection influence self-disclosure behaviour, the level of awareness about privacy does not. They next examine the impact of internet addiction on these relationships, finding that internet addiction weakens the influence of privacy concerns to the point of non-significance. Originality/value The authors highlight some of the influences of self-disclosure behaviour, showing that some but not all aspects of privacy are influential. They also demonstrate that there are powerful influences on user behaviour that have not been accounted for in prior work; internet addiction is one of these factors. This provides some of the first evidence of the potentially deleterious effect of internet addiction on the privacy calculus.
Nik Thompson, Atif Ahmad, Sean B. Maynard
Inf. Comput. Secur.2
2021 Case-based learning in the management practice of information security: an innovative pedagogical instrument
Atif Ahmad, Sean B. Maynard, Sameen Motahhir, Ashley Baines Anderson
Pers. Ubiquitous Comput.1
2020 Weaponizing information systems for political disruption: The Actor, Lever, Effects, and Response Taxonomy (ALERT)
Kevin C. Desouza, Atif Ahmad, Humza Naseer, Munish Sharma
Comput. Secur.2
2020 How integration of cyber security management and incident response enables organizational learning
abstract
Abstract Digital assets of organizations are under constant threat from a wide assortment of nefarious actors. When threats materialize, the consequences can be significant. Most large organizations invest in a dedicated information security management (ISM) function to ensure that digital assets are protected. The ISM function conducts risk assessments, develops strategy, provides policies and training to define roles and guide behavior, and implements technological controls such as firewalls, antivirus, and encryption to restrict unauthorized access. Despite these protective measures, incidents (security breaches) will occur. Alongside the security management function, many organizations also retain an incident response (IR) function to mitigate damage from an attack and promptly restore digital services. However, few organizations integrate and learn from experiences of these functions in an optimal manner that enables them to not only respond to security incidents, but also proactively maneuver the threat environment. In this article we draw on organizational learning theory to develop a conceptual framework that explains how the ISM and IR functions can be better integrated. The strong integration of ISM and IR functions, in turn, creates learning opportunities that lead to organizational security benefits including: increased awareness of security risks, compilation of threat intelligence, removal of flaws in security defenses, evaluation of security defensive logic, and enhanced security response.
Atif Ahmad, Kevin C. Desouza, Sean B. Maynard, Humza Naseer, Richard L. Baskerville
J. Assoc. Inf. Sci. Technol.1
2019 Strategically-motivated advanced persistent threat: Definition, process, tactics and a disinformation model of counterattack
Atif Ahmad, Jeb Webb, Kevin C. Desouza, James Boorman
Comput. Secur.1
2016 The Internet of Things (IoT) and its impact on individual privacy: An Australian perspective
Xavier Caron, Rachelle Bosua, Sean B. Maynard, Atif Ahmad
Comput. Law Secur. Rev.4
2015 Digital forensic readiness: Expert perspectives on a theoretical framework
Mohamed Elyas, Atif Ahmad, Sean B. Maynard, Andrew Lonie
Comput. Secur.2
2014 Protecting organizational competitive advantage: A knowledge leakage perspective
Atif Ahmad, Rachelle Bosua, Rens Scheepers
Comput. Secur.1
2014 A situation awareness model for information security risk management
Jeb Webb, Atif Ahmad, Sean B. Maynard, Graeme G. Shanks
Comput. Secur.2
2014 Teaching information security management: reflections and experiences
abstract
Purpose – The purpose of this paper is to describe the development, design, delivery and evaluation of a postgraduate information security subject that focuses on a managerial, rather than the more frequently reported technical perspective. The authors aimed to create an atmosphere of intellectual excitement and discovery so that students felt empowered by new ideas, tools and techniques and realized the potential value of what they were learning in the industry. Design/methodology/approach – The paper develops fundamental principles and arguments that inform the design and development of the teaching curriculum. The curriculum is aimed at security management professionals in general and consultants in particular. The paper explains the teaching method in detail including the specific topics of lectures, representative reading material, assessment tasks and feedback mechanisms. Finally, lessons learned by the authors and their conclusions are presented as a form of reflection. Findings – The instructors recognized four key factors that played a role in the atmosphere of intellectual excitement and motivation. These were new concepts and ideas, an increased level of engagement, opportunities for students to make their own discoveries and knowledge presented in a practical context. Maintaining a high quality of teaching resources, catering for diverse student needs and incorporating learning cycles of assessment in a short period of time were additional challenges. Originality/value – Most “information security” curricula described in research literature take a technology-oriented perspective. This paper presents a much-needed management point of view. The teaching curriculum (including assessment tasks) and experiences will be useful to existing and future teaching and research academics in “information security management”. Those interested in developing their own teaching material will benefit from the discussion on potential topic areas, choice of assessment tasks and selection of recommended reading material.
Atif Ahmad, Sean B. Maynard
Inf. Manag. Comput. Secur.1
2014 Towards A Systemic Framework for Digital Forensic Readiness
abstract
Although digital forensics has traditionally been associated with law enforcement, the impact of new regulations, industry standards and cyber-attacks, combined with a heavy reliance on digital assets, has resulted in a more prominent role for digital forensics in organizations. Modern organizations, therefore, need to be forensically ready in order to maximize their potential to respond to forensic events and demonstrate compliance with laws and regulations. However, little research exists on the assessment of organizational digital forensic readiness. This paper describes a comprehensive approach to identifying the factors that contribute to digital forensic readiness and how these factors work together to achieve forensic readiness in an organization. We develop a conceptual framework for organizational forensic readiness and define future work towards the empirical validation and refinement of the framework.
Mohamed Elyas, Sean B. Maynard, Atif Ahmad, Andrew Lonie
J. Comput. Inf. Syst.3
2012 Incident response teams - Challenges in supporting the organisational security function
Atif Ahmad, Justin Hadgkiss, Anthonie B. Ruighaver
Comput. Secur.1
2010 Information Security Governance: When Compliance Becomes More Important than Security
C. C. Terence Tan, Anthonie B. Ruighaver, Atif Ahmad
SEC3