TY - JOUR KW - Cybersecurity KW - education and training KW - exercises KW - human factors KW - organizational learning AU - Kirsi Aaltola AU - Petteri Taitto AB -

Development of information technology and the globalization require constant investment in people. New and emerging technologies such as autonomous systems, machine learning and AI radically re-contextualize the human dimension of the organization. Strategic changes have revealed new critical vulnerabilities such as social media-based election meddling and disinformation campaigning with impact on the human aspects at state, societal, organizational and individual levels. Education and training raise the level of expertise, skills and competences and ensure better performance in complex cyber situations. Researchers have addressed assumptions, models, concepts and cognitive aspects of human performance in the cyber domain. However, the theories and approaches of human learning in training and exercises are only partly touched. New techniques for enhancing organizational cyber resilience to cyber-attacks are needed and they still lack sound theoretical foundations.

This article aims to advance the discussion suggesting viewpoints on training and exercises in the cyber domain, taking into consideration specifics of skills in cyber security. It provides overview of theories of learning to better support human performance. Our critical interpretation enhances the comprehensive understanding of decision-making, learning theories, and design of cyber security training and exercises. Furthermore, our intention is to constructively promote discussion on current issues about human learning in cyber training and education and thus boost multidisciplinary studies to enhance cyber awareness.

BT - Information & Security: An International Journal DO - https://doi.org/10.11610/isij.4311 IS - 2 LA - eng N2 -

Development of information technology and the globalization require constant investment in people. New and emerging technologies such as autonomous systems, machine learning and AI radically re-contextualize the human dimension of the organization. Strategic changes have revealed new critical vulnerabilities such as social media-based election meddling and disinformation campaigning with impact on the human aspects at state, societal, organizational and individual levels. Education and training raise the level of expertise, skills and competences and ensure better performance in complex cyber situations. Researchers have addressed assumptions, models, concepts and cognitive aspects of human performance in the cyber domain. However, the theories and approaches of human learning in training and exercises are only partly touched. New techniques for enhancing organizational cyber resilience to cyber-attacks are needed and they still lack sound theoretical foundations.

This article aims to advance the discussion suggesting viewpoints on training and exercises in the cyber domain, taking into consideration specifics of skills in cyber security. It provides overview of theories of learning to better support human performance. Our critical interpretation enhances the comprehensive understanding of decision-making, learning theories, and design of cyber security training and exercises. Furthermore, our intention is to constructively promote discussion on current issues about human learning in cyber training and education and thus boost multidisciplinary studies to enhance cyber awareness.

PY - 2019 SE - 123 SP - 123 EP - 133 T2 - Information & Security: An International Journal TI - Utilising Experiential and Organizational Learning Theories to Improve Human Performance in Cyber Training VL - 43 ER -