Return
A Literature Review of Social Engineering Countermeasures: Temporality as a Harmonizing and Extending Factor
A
E
DOI:10.1093/cybsec/tyag017.png)
Abstract
En 中文
Social engineering (SE) attacks are among the most prevalent and persistent threats to organizations, carrying severe financial and legal consequences. Despite their severity and frequency, academic discourse addressing countermeasures that organizations can apply to minimize their occurrence remains fragmented, often relying on disparate conceptualizations that limit their practical uptake. In addition, widely recognized cybersecurity frameworks, such as NIST or ISO/IEC ones, broadly address diverse types of cyber threats, which may result in underrepresented specific SE countermeasures or limited consideration of the temporal dynamics of an SE attack. Therefore, our study aims to harmonize SE countermeasures identified in academic research by utilizing temporality as an analytical lens. Drawing on a systematic literature review, we first synthesize and categorize dispersed conceptualizations of SE countermeasures into six overarching either primary or cross-cutting themes, supported by knowledge-based tools. Second, we organize these harmonized SE countermeasures within a temporal framework that represents the lifecycle of SE attacks, emphasizing that distinct SE countermeasures serve different aims, such as anticipation, coping, or reflection, over time. Through this research, we contribute to scholarly discourse by demonstrating that temporality offers a unifying structure for reconciling fragmented SE countermeasure concepts and extends defense-in-depth thinking beyond static protection to a more dynamic, lifecycle-based perspective.
Journal
J
IF:
3.2
Papers:
52
Citations:
0
