{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:12:45Z","timestamp":1783764765340,"version":"3.55.0"},"reference-count":140,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2019,10,11]],"date-time":"2019-10-11T00:00:00Z","timestamp":1570752000000},"content-version":"vor","delay-in-days":283,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/100010412","name":"Global Risk Institute in Financial Services","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100010412","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The growing sophistication, frequency and severity of cyberattacks targeting financial sector institutions highlight their inevitability and the impossibility of completely protecting the integrity of critical computer systems. In this context, cyber-resilience offers an attractive complementary alternative to the existing cybersecurity paradigm. Cyber-resilience is defined in this article as the capacity to withstand, recover from and adapt to the external shocks caused by cyber risks. Resilience has a long and rich history in a number of scientific disciplines, including in engineering and disaster management. One of its main benefits is that it enables complex organizations to prepare for adverse events and to keep operating under very challenging circumstances. This article seeks to explore the significance of this concept and its applicability to the online security of financial institutions. The first section examines the need for cyber-resilience in the financial sector, highlighting the different types of threats that target financial systems and the various measures of their adverse impact. This section concludes that the \u201cprevent and protect\u201d paradigm that has prevailed so far is inadequate, and that a cyber-resilience orientation should be added to the risk managers\u2019 toolbox. The second section briefly traces the scientific history of the concept and outlines the five core dimensions of organizational resilience, which is dynamic, networked, practiced, adaptive, and contested. Finally, the third section analyses three types of institutional approaches that are used to foster cyber-resilience in the financial sector (and beyond): (i) a thriving cybersecurity industry is promoting cyber-resilience as the future of security; (ii) standards bodies are embedding cyber-resilience into some of their cybersecurity standards; and (iii) regulatory agencies have developed a broad range of compliance tools aimed at enhancing cyber-resilience.<\/jats:p>","DOI":"10.1093\/cybsec\/tyz013","type":"journal-article","created":{"date-parts":[[2019,10,11]],"date-time":"2019-10-11T10:24:15Z","timestamp":1570789455000},"source":"Crossref","is-referenced-by-count":98,"title":["The cyber-resilience of financial institutions: significance and applicability"],"prefix":"10.1093","volume":"5","author":[{"given":"Beno\u00eet","family":"Dupont","sequence":"first","affiliation":[{"name":"Professor of Criminology, International Centre for Comparative Criminology, Universit\u00e9 de Montr\u00e9al, Montr\u00e9al QC Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2019,10,11]]},"reference":[{"key":"2019101106184105300_tyz013-B1","author":"Nakashima","year":"2017"},{"key":"2019101106184105300_tyz013-B2","author":"Perlroth","year":"2017"},{"key":"2019101106184105300_tyz013-B3","author":"Gallagher","year":"2018"},{"key":"2019101106184105300_tyz013-B4","volume-title":"Surviving on a Diet of Poisoned Fruit: Reducing the National Security Risks of America\u2019s Cyber Dependencies","author":"Danzig","year":"2014"},{"key":"2019101106184105300_tyz013-B5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1146\/annurev.es.04.110173.000245","article-title":"Resilience and stability of ecological systems","volume":"4","author":"Holling","year":"1973","journal-title":"Annu Rev Ecol Syst"},{"key":"2019101106184105300_tyz013-B6","doi-asserted-by":"crossref","DOI":"10.1057\/9780230583634","volume-title":"Doing Security: Critical Reflections and an Agenda for Change","author":"Button","year":"2008"},{"key":"2019101106184105300_tyz013-B7","first-page":"10108","article-title":"Measurable resilience for actionable policy","volume":"47","author":"Linkov","year":"2013","journal-title":"Envir Sci Tech"},{"key":"2019101106184105300_tyz013-B8","article-title":"Organisational cyber resilience: research opportunities","author":"Bagheri","year":"2017","journal-title":"Australasian Conference on Information Systems"},{"key":"2019101106184105300_tyz013-B9","article-title":"Conference Board of Canada","year":"2018","journal-title":"Building Cyber Resilience. Ottawa: Conference Board of Canada"},{"key":"2019101106184105300_tyz013-B10","volume-title":"Cyber Resiliency Engineering Framework","author":"Bodeau","year":"2011"},{"key":"2019101106184105300_tyz013-B11","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-322-89613-1","volume-title":"The Internet Galaxy: Reflexions on the Internet, Business, and Society","author":"Castells","year":"2001"},{"key":"2019101106184105300_tyz013-B12","first-page":"1","volume-title":"Cyberpower and National Security","author":"Kuehl","year":"2009"},{"key":"2019101106184105300_tyz013-B13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.5751\/ES-08450-210227","article-title":"Interrogating resilience: toward a typology to improve its operationalization","volume":"21","author":"Davidson","year":"2016","journal-title":"Ecol Soc"},{"key":"2019101106184105300_tyz013-B14","doi-asserted-by":"crossref","first-page":"777","DOI":"10.1080\/08941920.2014.901467","article-title":"The end of sustainability","volume":"27","author":"Benson","year":"2014","journal-title":"Soc Natur Resour"},{"key":"2019101106184105300_tyz013-B15","first-page":"362","volume-title":"Disaster Resilience: An Integrated Approach","author":"Tedim","year":"2017"},{"key":"2019101106184105300_tyz013-B16","volume-title":"Enabling and Managing End-to-End Resilience","author":"Gorniak","year":"2011"},{"key":"2019101106184105300_tyz013-B17","volume-title":"Forces Shaping the Cyber Threat Landscape for Financial Institutions","author":"Carter","year":"2017"},{"key":"2019101106184105300_tyz013-B18","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1177\/0894439312452998","article-title":"Examining the forces shaping cybercrime markets online","volume":"31","author":"Holt","year":"2013","journal-title":"Soc Sci Comput Rev"},{"key":"2019101106184105300_tyz013-B19","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1016\/j.ijcip.2013.01.002","article-title":"Crimeware-as-a-service\u2014a survey of commoditized crimeware in the underground market","volume":"6","author":"Sood","year":"2013","journal-title":"Int J Crit Infr Prot"},{"key":"2019101106184105300_tyz013-B20","doi-asserted-by":"crossref","DOI":"10.4159\/9780674989047","volume-title":"Industry of Anonymity: Inside the Business of Cybercrime","author":"Lusthaus","year":"2018"},{"key":"2019101106184105300_tyz013-B21","author":"Brewster","year":"2017"},{"key":"2019101106184105300_tyz013-B22","year":"2017"},{"key":"2019101106184105300_tyz013-B23","volume-title":"London Blue: UK-Based Multinational Gang Runs BEC Scams like a Modern Corporation","year":"2018"},{"key":"2019101106184105300_tyz013-B24","author":"Volkov","year":"2018"},{"key":"2019101106184105300_tyz013-B25"},{"key":"2019101106184105300_tyz013-B26","year":"2018"},{"key":"2019101106184105300_tyz013-B27","year":"2016"},{"key":"2019101106184105300_tyz013-B28","author":"Evans","year":"2018"},{"key":"2019101106184105300_tyz013-B29","volume-title":"Hacker, Hoaxer, Whistleblower, Spy: The Many Faces of Anonymous","author":"Coleman","year":"2014"},{"key":"2019101106184105300_tyz013-B30","author":"Crosman","year":"2016"},{"key":"2019101106184105300_tyz013-B31","year":"2018"},{"key":"2019101106184105300_tyz013-B32","volume-title":"Insider Threat Study: Illicit Cyber Activity in the Banking and Finance Sector","author":"Randazzo","year":"2005"},{"key":"2019101106184105300_tyz013-B33","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1057\/ejis.2009.12","article-title":"Behavioral and policy issues in information systems security: the insider threat","volume":"18","author":"Warkentin","year":"2009","journal-title":"Eur J Inform Syst"},{"key":"2019101106184105300_tyz013-B34","volume-title":"The Financial Industry and the Insider Threat","year":"2015"},{"key":"2019101106184105300_tyz013-B35","author":"Miller","year":"2018"},{"key":"2019101106184105300_tyz013-B36","volume-title":"2018 Data Breach Investigations Report 11th Edition","year":"2018"},{"key":"2019101106184105300_tyz013-B37","volume-title":"Annual Banking Loss Report: Operational Risk Loss Data for Banks Submitted between 2012 and 2017","year":"2018"},{"key":"2019101106184105300_tyz013-B38","year":"2018"},{"key":"2019101106184105300_tyz013-B39","author":"Forrest","year":"2018"},{"key":"2019101106184105300_tyz013-B40","author":"Koenig","year":"2018"},{"key":"2019101106184105300_tyz013-B41","author":"Newman","year":"2018"},{"key":"2019101106184105300_tyz013-B42","volume-title":"2018 Cost of a Data Breach Study: Global Overview","year":"2018"},{"key":"2019101106184105300_tyz013-B43","volume-title":"Impact of Cybercrime on Canadian Businesses, 2017","year":"2018"},{"key":"2019101106184105300_tyz013-B44","author":"Bouveret","year":"2018"},{"key":"2019101106184105300_tyz013-B45","volume-title":"Operational Risk Horizon 2019: Summary","year":"2019"},{"key":"2019101106184105300_tyz013-B46","doi-asserted-by":"crossref","first-page":"433","DOI":"10.1111\/j.0361-3666.2006.00331.x","article-title":"The concept of resilience revisited","volume":"30","author":"Manyena","year":"2006","journal-title":"Disasters"},{"key":"2019101106184105300_tyz013-B47","year":"2018"},{"key":"2019101106184105300_tyz013-B48","first-page":"31","volume-title":"Engineering within Ecological Constraints","author":"Holling","year":"1996"},{"key":"2019101106184105300_tyz013-B49","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1088\/1748-9326\/8\/1\/014041","article-title":"How do we know about resilience? An analysis of empirical research on resilience, and implications for interdisciplinary praxis","volume":"8","author":"Downes","year":"2013","journal-title":"Environ Res Lett"},{"key":"2019101106184105300_tyz013-B50","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1126\/sciadv.1400217","article-title":"Why resilience is unappealing to social science: theoretical and empirical investigations of the scientific use of resilience","volume":"1","author":"Olsson","year":"2015","journal-title":"Sci Adv"},{"key":"2019101106184105300_tyz013-B51","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1111\/jftr.12255","article-title":"Resilience theory and research on children and families: past, present, and promise","volume":"10","author":"Masten","year":"2018","journal-title":"J Fam Theor Rev"},{"key":"2019101106184105300_tyz013-B52","doi-asserted-by":"crossref","first-page":"290","DOI":"10.1037\/0002-9432.71.3.290","article-title":"Resilience in ecosystemic context: evolution of the concept","volume":"71","author":"Waller","year":"2001","journal-title":"Am J Orthopsychiat"},{"key":"2019101106184105300_tyz013-B53","doi-asserted-by":"crossref","first-page":"307","DOI":"10.1002\/jclp.10020","article-title":"The metatheory of resilience and resiliency","volume":"58","author":"Richardson","year":"2002","journal-title":"J Clin Psychol"},{"key":"2019101106184105300_tyz013-B54","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1037\/0003-066X.55.1.5","article-title":"Positive psychology: an introduction","volume":"55","author":"Seligman","year":"2000","journal-title":"Am Psychol"},{"key":"2019101106184105300_tyz013-B55","doi-asserted-by":"crossref","DOI":"10.7591\/9781501711992","volume-title":"Overcoming the Odds: High Risk Children from Birth to Adulthood","author":"Werner","year":"1992"},{"key":"2019101106184105300_tyz013-B56","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1037\/0003-066X.59.1.20","article-title":"Loss, trauma, and human resilience: have we underestimated the human capacity to thrive after extremely aversive events?","volume":"59","author":"Bonanno","year":"2004","journal-title":"Am Psychol"},{"key":"2019101106184105300_tyz013-B57","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1037\/0003-066X.56.3.227","article-title":"Ordinary magic: resilience processes in development","volume":"56","author":"Masten","year":"2001","journal-title":"Am Psychol"},{"key":"2019101106184105300_tyz013-B58","volume-title":"Risk Society: Towards a New Modernity","author":"Beck","year":"1992"},{"key":"2019101106184105300_tyz013-B59","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1111\/1468-2230.00188","article-title":"Risk and responsibility","volume":"62","author":"Giddens","year":"1999","journal-title":"Mod Law Rev"},{"key":"2019101106184105300_tyz013-B60","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/978-94-007-5476-8_3","volume-title":"Resilience Thinking in Urban Planning","author":"Tasan-Kok","year":"2013"},{"key":"2019101106184105300_tyz013-B61","volume-title":"Disaster Resilience: An Integrated Approach","author":"Paton","year":"2017"},{"key":"2019101106184105300_tyz013-B62","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1111\/j.1468-5973.2010.00620.x","article-title":"Managing transboundary crises: identifying the building blocks of an effective response system","volume":"18","author":"Ansell","year":"2010","journal-title":"J Conting Crisis Man"},{"key":"2019101106184105300_tyz013-B63","first-page":"17","volume-title":"Resilience and Development: Positive Life Adaptations","author":"Kaplan","year":"1999"},{"key":"2019101106184105300_tyz013-B64","volume-title":"Sociologie de L\u2019Impr\u00e9visible: Dynamiques de L\u2019Activit\u00e9 et Des Formes Sociales","author":"Grossetti","year":"2004"},{"key":"2019101106184105300_tyz013-B65","doi-asserted-by":"crossref","first-page":"147","DOI":"10.3917\/dec.bessi.2009.01.0147","volume-title":"Bifurcations: Les Sciences Sociales Face Aux Ruptures et \u00e0 L\u2019\u00c9v\u00e9nement","author":"Grossetti","year":"2009"},{"key":"2019101106184105300_tyz013-B66","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1111\/j.1468-5973.2007.00501.x","article-title":"Systems that should have failed: critical infrastructure protection in an institutionally fragmented environment","volume":"15","author":"De Bruijne","year":"2007","journal-title":"J Conting Crisis Man"},{"key":"2019101106184105300_tyz013-B67","volume-title":"Institutions for Cyber Security: International Responses and Data Sharing Initiatives","author":"Choucri","year":"2016"},{"key":"2019101106184105300_tyz013-B68","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/s10611-016-9653-3","article-title":"A typology of cybersecurity and public\u2013private partnerships in the context of the EU","volume":"67","author":"Bossong","year":"2017","journal-title":"Crime Law Social Ch"},{"key":"2019101106184105300_tyz013-B69","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1080\/08850607.2016.1230701","article-title":"S cyber threat intelligence sharing framework","volume":"30","author":"Jasper","year":"2017","journal-title":"Int J Intel Counter Intel"},{"key":"2019101106184105300_tyz013-B70","author":"Sedenberg","year":"2018"},{"key":"2019101106184105300_tyz013-B71","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1111\/1758-5899.12625","article-title":"CSIRTs and global cybersecurity: how technical experts support science diplomacy","volume":"9","author":"Tanczer","year":"2018","journal-title":"Glob Policy"},{"key":"2019101106184105300_tyz013-B72","doi-asserted-by":"crossref","first-page":"733","DOI":"10.1177\/0170840601225001","article-title":"Minimal structures: from jazz improvisation to product innovation","volume":"22","author":"Kamoche","year":"2001","journal-title":"Organ Stud"},{"key":"2019101106184105300_tyz013-B73","doi-asserted-by":"crossref","first-page":"582","DOI":"10.1177\/009365088015005005","article-title":"Jazz as a process of organizational innovation","volume":"15","author":"Bastien","year":"1988","journal-title":"Commun Res"},{"key":"2019101106184105300_tyz013-B74","doi-asserted-by":"crossref","first-page":"543","DOI":"10.1287\/orsc.9.5.543","article-title":"Improvisation as a mindset for organizational analysis","volume":"9","author":"Weick","year":"1998","journal-title":"Organ Sci"},{"key":"2019101106184105300_tyz013-B75","volume-title":"Stress, Cognition and Human Performance: A Literature Review and Conceptual Framework","author":"Staal","year":"2004"},{"key":"2019101106184105300_tyz013-B76","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1080\/10508414.2015.1128293","article-title":"Fear-potentiated startle: a review from an aviation perspective","volume":"25","author":"Martin","year":"2015","journal-title":"Int J Aviat Psychol"},{"key":"2019101106184105300_tyz013-B77","doi-asserted-by":"crossref","first-page":"1161","DOI":"10.1177\/0018720817723428","article-title":"Dealing with unexpected events on the flight deck: a conceptual model of startle and surprise","volume":"59","author":"Landman","year":"2017","journal-title":"Hum Factors"},{"key":"2019101106184105300_tyz013-B78","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1177\/0967010612438432","article-title":"Anticipating emergencies: technologies of preparedness and the matter of security","volume":"43","author":"Adey","year":"2012","journal-title":"Secur Dialogue"},{"key":"2019101106184105300_tyz013-B79","volume-title":"Searching for Safety","author":"Wildavsky","year":"1988"},{"key":"2019101106184105300_tyz013-B80","volume-title":"Disaster Resilience: An Integrated Approach","author":"Paton","year":"2006"},{"key":"2019101106184105300_tyz013-B81","first-page":"79","volume-title":"Disaster Resilience: An Integrated Approach","author":"Paton","year":"2017"},{"key":"2019101106184105300_tyz013-B82","volume-title":"The Third Annual Study on the Cyber Resilient Organization","author":"Institute","year":"2018"},{"key":"2019101106184105300_tyz013-B83","volume-title":"Thinking, Fast and Slow","author":"Kahneman","year":"2011"},{"key":"2019101106184105300_tyz013-B84","doi-asserted-by":"crossref","DOI":"10.2307\/j.ctv2hdrfz6","volume-title":"The Ostrich Paradox: Why we Underprepare for Disasters","author":"Meyer","year":"2017"},{"key":"2019101106184105300_tyz013-B85","volume-title":"Hurricane Attitudes of Coastal Connecticut Residents: A Segmentation Analysis to Support Communication","author":"Marlon","year":"2015"},{"key":"2019101106184105300_tyz013-B86","volume-title":"Cyber Resilience for the C-Suite","year":"2017"},{"key":"2019101106184105300_tyz013-B87","volume-title":"Strengthening Digital Society against Cyber Shocks","year":"2018"},{"key":"2019101106184105300_tyz013-B88","volume-title":"The Cyber Resilience Blueprint: A New Perspective on Security","year":"2015"},{"key":"2019101106184105300_tyz013-B89","volume-title":"Cyber Resilience: Safeguarding the Digital Organization","year":"2016"},{"key":"2019101106184105300_tyz013-B90","volume-title":"Gaining Ground on the Cyber Attacker: 2018 State of Cyber Resilience","year":"2018"},{"key":"2019101106184105300_tyz013-B91","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/8962.001.0001","volume-title":"Standards: Recipes for Reality","author":"Busch","year":"2011"},{"key":"2019101106184105300_tyz013-B92","first-page":"3","volume-title":"Standards and Their Stories","author":"Star","year":"2009"},{"key":"2019101106184105300_tyz013-B93","doi-asserted-by":"crossref","first-page":"132","DOI":"10.1080\/17508487.2012.736871","article-title":"The invisible infrastructure of standards","volume":"54","author":"Gorur","year":"2013","journal-title":"Crit Stud Educ"},{"key":"2019101106184105300_tyz013-B94","volume-title":"A World of Standards","author":"Brunsson","year":"2000"},{"key":"2019101106184105300_tyz013-B95","first-page":"6","article-title":"How to tackle today\u2019s IT security risks","volume":"132","author":"Lewis","year":"2019","journal-title":"ISOfocus"},{"key":"2019101106184105300_tyz013-B96","first-page":"92","article-title":"ISO\/IEC 27000, 27001 and 27002 for information security management","volume":"4","author":"Disterer","year":"2013","journal-title":"J Inf Secur"},{"key":"2019101106184105300_tyz013-B97","author":"Fomin","year":"2008"},{"key":"2019101106184105300_tyz013-B98","volume-title":"ISO\/IEC 27035-1: Information Technology \u2013 Security Techniques \u2013 Information Security Incident Management \u2013 Part 1: Principles of Incident Management","year":"2016"},{"key":"2019101106184105300_tyz013-B99","year":"2019"},{"key":"2019101106184105300_tyz013-B100","volume-title":"Framework for Improving Critical Infrastructure Cybersecurity","year":"2014"},{"key":"2019101106184105300_tyz013-B101","first-page":"16","article-title":"The NIST Cybersecurity Framework: overview and potential impacts","volume":"10","author":"Lei","year":"2014","journal-title":"SciTech Lawyer"},{"key":"2019101106184105300_tyz013-B102","first-page":"305","article-title":"Toward a global cybersecurity standard of care: exploring the implications of the 2014 NIST Cybersecurity Framework on shaping reasonable national and international cybersecurity practices","volume":"50","author":"Schackelford","year":"2015","journal-title":"Tex Int Law J"},{"key":"2019101106184105300_tyz013-B103","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1109\/MC.2013.448","article-title":"Cybersecurity standards: managing risk and creating resilience","volume":"47","author":"Collier","year":"2014","journal-title":"Comput"},{"key":"2019101106184105300_tyz013-B104","volume-title":"Systems Security Engineering: Cyber Resiliency Considerations for the Engineering of Trustworthy Secure Systems","author":"Ross","year":"2018"},{"key":"2019101106184105300_tyz013-B105","volume-title":"CERT Resilience Management Model, Version 1.2","author":"Caralli","year":"2016"},{"key":"2019101106184105300_tyz013-B106","volume-title":"Cyber Resilience Review (CRR): Self-Assessment Package","year":"2016"},{"key":"2019101106184105300_tyz013-B107","first-page":"97","volume-title":"Best Practices in Computer Network Defense: Incident Detection and Response","author":"Purser","year":"2014"},{"key":"2019101106184105300_tyz013-B108","volume-title":"Good Practice Guide on National Exercises: Enhancing the Resilience of Public Communications Networks","year":"2009"},{"key":"2019101106184105300_tyz013-B109","volume-title":"Resilience Metrics and Measurements: Technical Report","year":"2011"},{"key":"2019101106184105300_tyz013-B110","volume-title":"The Global Risks Report 2019, 14th Edition","year":"2019"},{"key":"2019101106184105300_tyz013-B111","volume-title":"Advancing Cyber Resilience: Principles and Tools for Boards","year":"2017"},{"key":"2019101106184105300_tyz013-B112","doi-asserted-by":"crossref","DOI":"10.1002\/9781119175834","volume-title":"Managing the Unexpected Third Edition: Sustained Performance in a Complex World","author":"Weick","year":"2015"},{"key":"2019101106184105300_tyz013-B113","doi-asserted-by":"crossref","DOI":"10.1093\/oso\/9780195070705.001.0001","volume-title":"Responsive Regulation","author":"Ayres","year":"1992"},{"key":"2019101106184105300_tyz013-B114","doi-asserted-by":"crossref","DOI":"10.7208\/chicago\/9780226190174.001.0001","volume-title":"The Culture of Control: Crime and Social Order in Contemporary Society","author":"Garland","year":"2001"},{"key":"2019101106184105300_tyz013-B115","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1177\/1362480603007001198","article-title":"What\u2019s wrong with the sociology of punishment?","volume":"7","author":"Braithwaite","year":"2003","journal-title":"Theor Criminol"},{"key":"2019101106184105300_tyz013-B116","volume-title":"Guidance on Cyber Resilience for Financial Market Infrastructures","year":"2016"},{"key":"2019101106184105300_tyz013-B117","volume-title":"Cyber-Resilience: Range of Practices","year":"2018"},{"key":"2019101106184105300_tyz013-B118","volume-title":"Business Continuity Planning: IT Examination Handbook","year":"2015"},{"key":"2019101106184105300_tyz013-B119","volume-title":"Cyber Resilience: Health Check","year":"2015"},{"key":"2019101106184105300_tyz013-B120","volume-title":"Building the UK Financial Sector\u2019s Operational Resilience","year":"2018"},{"key":"2019101106184105300_tyz013-B121","volume-title":"Cyber Resilience Oversight Expectations for Financial Market Infrastructures","year":"2018"},{"key":"2019101106184105300_tyz013-B122","volume-title":"Response to the Public Consultation on the Cyber Resilience Oversight Expectations","year":"2018"},{"key":"2019101106184105300_tyz013-B123","volume-title":"Cyber Security Self-Assessment Guidance","year":"2013"},{"key":"2019101106184105300_tyz013-B124","volume-title":"Cyber Resilience of Firms in Australia\u2019s Financial Markets","year":"2017"},{"key":"2019101106184105300_tyz013-B125","volume-title":"Financial Stability Report - Issue No. 43","year":"2018"},{"key":"2019101106184105300_tyz013-B126","volume-title":"TIBER-DK General Implementation Guide","year":"2018"},{"key":"2019101106184105300_tyz013-B127","year":"2018"},{"key":"2019101106184105300_tyz013-B128","doi-asserted-by":"crossref","first-page":"268","DOI":"10.1109\/TSMCB.2005.855569","article-title":"Characterizing warfare in red teaming","volume":"36","author":"Yang","year":"2006","journal-title":"IEEE T Syst Man Cy B"},{"key":"2019101106184105300_tyz013-B129","volume-title":"Red Team: How to Succeed by Thinking like the Enemy","author":"Zenko","year":"2015"},{"key":"2019101106184105300_tyz013-B130","volume-title":"TIBER-EU Framework: How to Implement the European Framework for Threat Intelligence Based Ethical Red Teaming","year":"2018"},{"key":"2019101106184105300_tyz013-B131","first-page":"405","article-title":"Cyber Babel: finding the Lingua Franca in cybersecurity regulation","volume":"87","author":"Pierotti","year":"2018","journal-title":"Fordham Law Rev"},{"key":"2019101106184105300_tyz013-B132","doi-asserted-by":"crossref","DOI":"10.1017\/9780521780339","volume-title":"Global Business Regulation","author":"Braithwaite","year":"2000"},{"key":"2019101106184105300_tyz013-B133","year":"2019"},{"key":"2019101106184105300_tyz013-B134","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1111\/rmir.12016","article-title":"Risk management: history, definition, and critique","volume":"16","author":"Dionne","year":"2013","journal-title":"Risk Manag Insur Rev"},{"key":"2019101106184105300_tyz013-B135","volume-title":"Risk, Uncertainty, and Government","author":"O\u2019Malley","year":"2004"},{"key":"2019101106184105300_tyz013-B136","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1057\/gpp.2009.14","article-title":"A global review of insurance industry response to climate change","volume":"34","author":"Mills","year":"2009","journal-title":"Geneva Pap R I-Iss P"},{"key":"2019101106184105300_tyz013-B137","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1038\/476033b","article-title":"Insurers could help address climate risks","volume":"476","author":"Nel","year":"2011","journal-title":"Nature"},{"key":"2019101106184105300_tyz013-B138","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1093\/cybsec\/tyz002","article-title":"Content analysis of cyber insurance policies: how do carriers price cyber risk?","volume":"5","author":"Romanosky","year":"2019","journal-title":"J Cybersecur"},{"key":"2019101106184105300_tyz013-B139","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1111\/j.1468-5973.2009.00558.x","article-title":"Measuring resilience potential: an adaptive strategy for organizational crisis planning","volume":"17","author":"Somers","year":"2009","journal-title":"J Conting Crisis Man"},{"key":"2019101106184105300_tyz013-B140","author":"Kopp","year":"2017"}],"container-title":["Journal of Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/cybersecurity\/article-pdf\/5\/1\/tyz013\/30132313\/tyz013.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"http:\/\/academic.oup.com\/cybersecurity\/article-pdf\/5\/1\/tyz013\/30132313\/tyz013.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,24]],"date-time":"2024-07-24T21:48:09Z","timestamp":1721857689000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/cybersecurity\/article\/doi\/10.1093\/cybsec\/tyz013\/5585673"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,1]]},"references-count":140,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,1,1]]}},"URL":"https:\/\/doi.org\/10.1093\/cybsec\/tyz013","relation":{},"ISSN":["2057-2085","2057-2093"],"issn-type":[{"value":"2057-2085","type":"print"},{"value":"2057-2093","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2019]]},"published":{"date-parts":[[2019,1,1]]},"article-number":"tyz013"}}