{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,29]],"date-time":"2025-12-29T22:12:46Z","timestamp":1767046366290,"version":"3.41.2"},"reference-count":37,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2019,7,8]],"date-time":"2019-07-08T00:00:00Z","timestamp":1562544000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2019,7,8]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>This paper aims to provide an understanding of the proportions of incidents that relate to human error. The information security field experiences a continuous stream of information security incidents and breaches, which are publicised by the media, public bodies and regulators. Despite the need for information security practices being recognised and in existence for some time, the underlying general information security affecting tasks and causes of these incidents and breaches are not consistently understood, particularly with regard to human error.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>This paper analyses recent published incidents and breaches to establish the proportions of human error and where possible subsequently uses the HEART (human error assessment and reduction technique) human reliability analysis technique, which is established within the safety field.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>This analysis provides an understanding of the proportions of incidents and breaches that relate to human error, as well as the common types of tasks that result in these incidents and breaches through adoption of methods applied within the safety field.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>This research provides original contribution to knowledge through the analysis of recent public sector information security incidents and breaches to understand the proportions that relate to human error.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-12-2018-0147","type":"journal-article","created":{"date-parts":[[2019,6,3]],"date-time":"2019-06-03T06:19:17Z","timestamp":1559542757000},"page":"343-357","source":"Crossref","is-referenced-by-count":9,"title":["Published incidents and their proportions of human error"],"prefix":"10.1108","volume":"27","author":[{"given":"Mark Glenn","family":"Evans","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ying","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Iryna","family":"Yevseyeva","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"issue":"2","key":"key2020052710223889700_ref001","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1108\/ICS-01-2016-0006","article-title":"An information security risk-driven investment model for analysing human factors","volume":"24","year":"2016","journal-title":"Information and Computer Security"},{"issue":"5","key":"key2020052710223889700_ref002","doi-asserted-by":"crossref","first-page":"328","DOI":"10.1108\/09685221011095245","article-title":"Human\u2010related problems of information security in East African cross\u2010cultural environments","volume":"18","year":"2010","journal-title":"Information Management and Computer Security"},{"issue":"1","key":"key2020052710223889700_ref003","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/09617353.2016.1148920","article-title":"Probability and security \u2013 pitfalls and chances","volume":"36","year":"2016","journal-title":"Safety and Reliability"},{"issue":"4","key":"key2020052710223889700_ref004","doi-asserted-by":"crossref","first-page":"e1","DOI":"10.1016\/j.ijmedinf.2008.10.005","article-title":"Human factors engineering in healthcare systems: the problem of human error and accident management","volume":"79","year":"2010","journal-title":"International Journal of Medical Informatics"},{"key":"key2020052710223889700_ref005","unstructured":"Chandler, T., Chang, J., Mosleb, A.J.M., Boring, R. and Gertman, D. (2006), \u201cHuman reliability analysis methods selection guidance for NASA\u201d, National Aeronautics and Space Administration, July, p. 175, available at: www.hq.nasa.gov\/office\/codeq\/rm\/docs\/HRA_Report.pdf"},{"key":"key2020052710223889700_ref006","doi-asserted-by":"publisher","DOI":"10.1177\/0165551517748288","article-title":"Information security: listening to the perspective of organisational insiders","year":"2018","journal-title":"Journal of Information Science"},{"issue":"17","key":"key2020052710223889700_ref007","doi-asserted-by":"publisher","first-page":"4667","DOI":"10.1002\/sec.1657","article-title":"Human behaviour as an aspect of cybersecurity assurance","volume":"9","year":"2016","journal-title":"Security and Communication Networks"},{"key":"key2020052710223889700_ref008","first-page":"74","article-title":"HEART-IS: a novel technique for evaluating human error-related information security incidents","volume-title":"Computers & Security","year":"2019"},{"journal-title":"International Journal of Medical Informatics","article-title":"Core human error causes (IS-CHEC) technique in public sector and comparison with the private sector","year":"2018","key":"key2020052710223889700_ref009"},{"first-page":"911","article-title":"Analysis of published public sector information security incidents and breaches to establish the proportions of human error","year":"2018","key":"key2020052710223889700_ref010"},{"key":"key2020052710223889700_ref011","unstructured":"Frangopoulos, E.D., Eloff, M.M. and Venter, L.M. (2014), \u201cHuman aspects of information assurance: a questionnaire-based quantitative approach to assessment\u201d, available at: https:\/\/pdfs.semanticscholar.org\/8d43\/bcc32ddaa0bfd067d822997018154e435a4f.pdf (accessed: 26 May 2018)."},{"key":"key2020052710223889700_ref012","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2018.01.016","article-title":"Enhancing security behaviour by supporting the user","volume":"75","year":"2018","journal-title":"Computers & Security"},{"key":"key2020052710223889700_ref013a","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1016\/j.cose.2018.10.006","article-title":"Exploring the role of work identity and work locus of control in information security awareness","volume":"81","year":"2019","journal-title":"Computers & Security"},{"issue":"1\/2","key":"key2020052710223889700_ref013","first-page":"43","article-title":"Cultural and psychological factors in cyber-security","volume":"13","year":"2017","journal-title":"Rinton Press"},{"issue":"11","key":"key2020052710223889700_ref014","doi-asserted-by":"crossref","first-page":"941","DOI":"10.1016\/j.ijmedinf.2015.08.010","article-title":"Improving the redistribution of the security lessons in healthcare: an evaluation of the generic security template","volume":"84","year":"2015","journal-title":"International Journal of Medical Informatics"},{"issue":"2","key":"key2020052710223889700_ref015","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1093\/intqhc\/mzx181","article-title":"Are root cause analyses recommendations effective and sustainable? An observational study","volume":"30","year":"2018","journal-title":"International Journal for Quality in Health Care"},{"issue":"1","key":"key2020052710223889700_ref016","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1108\/OIR-11-2015-0358","article-title":"Why not comply with information security? An empirical approach for the causes of non-compliance","volume":"41","year":"2017","journal-title":"Online Information Review"},{"key":"key2020052710223889700_ref017","unstructured":"Information Commissioner\u2019s Office (2018), \u201cData security incident trends\u201d, available at: https:\/\/ico.org.uk\/action-weve-taken\/data-security-incident-trends\/."},{"issue":"1","key":"key2020052710223889700_ref018","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1108\/09685221311314383","article-title":"Human aspects of information security","volume":"21","year":"2013","journal-title":"Information Management and Computer Security"},{"key":"key2020052710223889700_ref019","doi-asserted-by":"publisher","first-page":"202","DOI":"10.1016\/J.SSCI.2017.07.008","article-title":"Understanding human performance in sociotechnical systems \u2013 steps towards a generic framework","volume":"107","year":"2018","journal-title":"Safety Science"},{"issue":"1","key":"key2020052710223889700_ref020","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1108\/09685221011035223","article-title":"Understanding and transforming organizational security culture","volume":"18","year":"2010","journal-title":"Information Management and Computer Security"},{"key":"key2020052710223889700_ref021","first-page":"223","article-title":"Human reliability analysis in healthcare: a review of techniques","volume":"16","year":"2004","journal-title":"International Journal of Risk and Safety in Medicine"},{"key":"key2020052710223889700_ref024","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1016\/J.DSS.2018.02.007","article-title":"Cyber-analytics: modeling factors associated with healthcare data breaches","volume":"108","year":"2018","journal-title":"Decision Support Systems"},{"key":"key2020052710223889700_ref022","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ICRIIS.2017.8002442","article-title":"A systematic literature review: information security culture","volume-title":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","year":"2017"},{"key":"key2020052710223889700_ref023","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3098954.3098986","article-title":"Reliable behavioural factors in the information security context","volume-title":"Proceedings of the 12th International Conference on Availability, Reliability and Security \u2013 ARES \u201817","year":"2017"},{"key":"key2020052710223889700_ref025","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1016\/J.SBSPRO.2014.07.133","article-title":"The human factor of information security: unintentional damage perspective","volume":"147","year":"2014","journal-title":"Procedia \u2013 Social and Behavioral Sciences"},{"key":"key2020052710223889700_ref026","unstructured":"National Patient Safety Foundation (2015), \u201cRCA improving root cause analyses and actions to prevent harm\u201d, www.Npsf.Org, (January), p. 51, available at: https:\/\/scholar.google.co.uk\/scholar?hl=en&as_sdt=0%2C5&q=RCA2+Improving+Root+cause+Analyses+and+Actions+to+prevent+harm&btnG= (accessed 11 November 2018)."},{"key":"key2020052710223889700_ref027","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TVCG.2018.2859969","article-title":"Understanding user behaviour through action sequences: from the usual to the unusual","year":"2018","journal-title":"IEEE Transactions on Visualization and Computer Graphics"},{"key":"key2020052710223889700_ref028","unstructured":"NHS Digital (2018), \u201cInformation governance incidents closed\u201d, available at: www.igt.hscic.gov.uk\/resources\/IGIncidentsPublicationStatement.pdf. (accessed 14 December 2018)."},{"key":"key2020052710223889700_ref029","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1016\/j.cose.2017.01.004","article-title":"The human aspects of information security questionnaire (HAIS-Q): two further validation studies","volume":"66","year":"2017","journal-title":"Computers & Security"},{"key":"key2020052710223889700_ref030","doi-asserted-by":"crossref","first-page":"S205","DOI":"10.1016\/j.ijmedinf.2006.05.019","article-title":"Incident reporting schemes and the need for a good story","volume":"76","year":"2007","journal-title":"International Journal of Medical Informatics"},{"issue":"5","key":"key2020052710223889700_ref031","doi-asserted-by":"crossref","first-page":"494","DOI":"10.1108\/ICS-07-2016-0054","article-title":"Information security management and the human aspect in organizations","volume":"25","year":"2017","journal-title":"Information and Computer Security"},{"key":"key2020052710223889700_ref032","unstructured":"The British Standards Institution (2013), \u201cISO\/IEC 27001 \u2013 Information security management systems \u2014 requirements\u201d, BSI. available at: https:\/\/shop.bsigroup.com\/ProductDetail?pid=000000000030347472&utm_source=google&utm_medium=cpc&utm_campaign=SM-STAN-PRM-CSR-iso27001-1810&c1reative=307410444133&keyword=%2Biso%2B27001&matchtype=b&network=g&device=c&gclid=EAIaIQobChMI1ovTo7_A3wIVLrvtCh0xi (accessed 27 December 2018)."},{"key":"key2020052710223889700_ref033","unstructured":"Wangen, G.B., Hellesen, N., Wangen, G., Torres, H. and Braekken, E. (2017), \u201cAn empirical study of root-cause analysis in information security management implementation of information security management system and risk management view project an empirical study of root-cause analysis in information security management\u201d, available at: www.researchgate.net\/publication\/319753715 (accessed 11 November 2018)."},{"issue":"1","key":"key2020052710223889700_ref034","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1108\/09685220910944722","article-title":"An integrated view of human, organizational, and technological challenges of IT security management","volume":"17","year":"2009","journal-title":"Information Management and Computer Security"},{"volume-title":"\u2018A User Manual for the HEART Human Reliability Assessment Method","year":"1992","key":"key2020052710223889700_ref035"},{"issue":"3","key":"key2020052710223889700_ref036","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1080\/09617353.2015.11691046","article-title":"Heart\u2013a proposed method for achieving high reliability in process operation by means of human factors engineering technology","volume":"35","year":"2015","journal-title":"Safety and Reliability"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-12-2018-0147\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-12-2018-0147\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:26Z","timestamp":1753406606000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/27\/3\/343-357\/106048"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,8]]},"references-count":37,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2019,7,8]]}},"alternative-id":["10.1108\/ICS-12-2018-0147"],"URL":"https:\/\/doi.org\/10.1108\/ics-12-2018-0147","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"type":"print","value":"2056-4961"},{"type":"print","value":"2056-4961"}],"subject":[],"published":{"date-parts":[[2019,7,8]]}}}