EDBT 2026 Demo / reviewers in the wild / expert
Atif Ahmad
dblp:09/6570
· DBLP profile ↗
5ranked-venue papers in the field
1as first author
3since 2021 · last 2024
0000-0002-8862-5755ORCID · verified
Domains — venue-derived; a paper can count in several
Knowledge Engineering, Semantic Web & Information Systems · 4Information Retrieval & Web Search · 1 (1 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Enabling cybersecurity incident response agility through dynamic capabilities: the role of real-time analyticsabstractWe explore how organisations enable agility in their cybersecurity incident response (IR) process by developing dynamic capabilities using real-time analytics (RTA). Drawing on RTA practices in the IR process at three large financial organisations, we develop a framework to explain how IR teams respond to the rapidly evolving cyber threat environment by developing RTA-based microfoundations that underpin the building of sensing, seizing, and transforming dynamic IR capabilities. These dynamic IR capabilities in turn help organisations to enable agility in their IR processes by leveraging swift, flexible, and innovative IR strategies, including active threat reconnaissance, active threat defence, and pervasive learning. Our findings have implications for the discourse on cybersecurity because we demystify the black box of IR agility, for our understanding of the use of RTA to enable agility in IR, and for the discourse on dynamic capabilities. Humza Naseer, Kevin C. Desouza, Sean B. Maynard, Atif Ahmad |
Eur. J. Inf. Syst. | 4 |
| 2024 | Case-based learning for cybersecurity leaders: A systematic review and research agendaabstractIncreasingly, large organisations are turning to cybersecurity leaders to protect their information resources against attack. However, because cybersecurity leadership roles are new, educational literature and practice targeting this role are nascent. In this systematic review, we assess the value of case-based learning (CBL) in educating cybersecurity leaders. We also aim to discover what gaps, if any, exist in this body of research. We find that cybersecurity leaders’ attitudes and metacognitive abilities are important but overlooked elements of their competence, and that CBL has potential to develop these competencies. The article concludes with a competency matrix and agenda for further research. Ashley Baines Anderson, Atif Ahmad, Shanton Chang |
Inf. Manag. | 2 |
| 2023 | Adopting and integrating cyber-threat intelligence in a commercial organisationabstractCyber-attacks are increasingly perpetrated by organised, sophisticated and persistent entities such as crime syndicates and paramilitary forces. Even commercial firms that fully comply with industry “best practice” cyber security standards cannot cope with military-style cyber-attacks. We posit that the primary reason is the increasing asymmetry between the cyber-offensive capability of attackers and the cyber-defensive capability of commercial organisations. A key avenue to resolve this asymmetry is for organisations to leverage cyber-threat intelligence (CTI) to direct their cyber-defence. How can commercial organisations adopt and integrate CTI to routinely defend their information systems and resources from increasingly advanced cyber-attacks? There is limited know-how on how to package CTI to inform the practices of enterprise-wide stakeholders. This clinical research describes a practitioner-researcher’s experiences in directing a large multinational finance corporation to adopt and integrate CTI to transform cybersecurity-related practice and behaviour. The research contributes practical know-how on the organisational adoption and integration of CTI, enacted through the transformation of cybersecurity practice, and enterprise-wide implementation of a novel solution to package CTI for commercial contexts. The study illustrates the inputs, processes, and outputs in clinical research as a genre of action research. James Kotsias, Atif Ahmad, Rens Scheepers |
Eur. J. Inf. Syst. | 2 |
| 2020 | How integration of cyber security management and incident response enables organizational learningabstractAbstract Digital assets of organizations are under constant threat from a wide assortment of nefarious actors. When threats materialize, the consequences can be significant. Most large organizations invest in a dedicated information security management (ISM) function to ensure that digital assets are protected. The ISM function conducts risk assessments, develops strategy, provides policies and training to define roles and guide behavior, and implements technological controls such as firewalls, antivirus, and encryption to restrict unauthorized access. Despite these protective measures, incidents (security breaches) will occur. Alongside the security management function, many organizations also retain an incident response (IR) function to mitigate damage from an attack and promptly restore digital services. However, few organizations integrate and learn from experiences of these functions in an optimal manner that enables them to not only respond to security incidents, but also proactively maneuver the threat environment. In this article we draw on organizational learning theory to develop a conceptual framework that explains how the ISM and IR functions can be better integrated. The strong integration of ISM and IR functions, in turn, creates learning opportunities that lead to organizational security benefits including: increased awareness of security risks, compilation of threat intelligence, removal of flaws in security defenses, evaluation of security defensive logic, and enhanced security response. Atif Ahmad, Kevin C. Desouza, Sean B. Maynard, Humza Naseer, Richard L. Baskerville |
J. Assoc. Inf. Sci. Technol. | 1 |
| 2014 | Towards A Systemic Framework for Digital Forensic ReadinessabstractAlthough digital forensics has traditionally been associated with law enforcement, the impact of new regulations, industry standards and cyber-attacks, combined with a heavy reliance on digital assets, has resulted in a more prominent role for digital forensics in organizations. Modern organizations, therefore, need to be forensically ready in order to maximize their potential to respond to forensic events and demonstrate compliance with laws and regulations. However, little research exists on the assessment of organizational digital forensic readiness. This paper describes a comprehensive approach to identifying the factors that contribute to digital forensic readiness and how these factors work together to achieve forensic readiness in an organization. We develop a conceptual framework for organizational forensic readiness and define future work towards the empirical validation and refinement of the framework. Mohamed Elyas, Sean B. Maynard, Atif Ahmad, Andrew Lonie |
J. Comput. Inf. Syst. | 3 |