Return
Situational crime prevention for securing business processes: challenges and opportunities
C
H
E
J
R
DOI:10.1093/cybsec/tyag018.png)
Abstract
En 中文
Despite a widespread ‘People–Process–Technology’ (PPT) approach to organizational cybersecurity, research on re-engineering processes for cybercrime prevention remains limited. While business process management (BPM) has been traditionally used to improve process efficiency and effectiveness, there is an opportunity to integrate criminological approaches to address cybercrime risks embedded within organisational processes. The criminological frameworks, crime script analysis (CSA) and situational crime prevention (SCP), promise to offer valuable insights into analysing how crime develops within processes and informing crime-opportunity reduction interventions. However, their application within business process contexts remains underexplored in research and practice. To address this, we systematically reviewed literature focusing on maturing or managing business processes for cybercrime prevention, classifying existing research through a holistic PPT perspective. The review results indicate that the ‘Technology’ aspect is comparatively well developed. However, two gaps were identified: (i) the need for a balanced integration of ‘People-focused’ strategy alongside technical perspective to enhance cybercrime prevention, and (ii) the need for a ‘Process-centric’ cybercrime prevention approach to re-engineer vulnerable processes. To address these gaps, we propose the Cybercrime Prevention for Business Processes (CP4BP) model, which integrates CSA and SCP as a structured approach, preparing for process re-engineering when organizations require necessary process changes in response to cybercrime. By integrating these criminological insights, the model promotes a more holistic, socio-technical cybersecurity practice for organizations and informs security by design at the process level. It incorporates criminological perspectives to improve cybercrime understanding among ‘People’, guide the re-engineering ‘Process’, and complement cybersecurity with additional criminological insights, ensuring a comprehensive enhancement of organisational processes for cybercrime prevention. We demonstrate the model’s application in addressing cybercrime risks through two real-world cases, illustrating how it can strengthen organizations’ internal workflows and processes involving external third parties. These case applications also highlight its flexibility in supporting reactive postincident re-engineering of flawed internal workflows to reduce opportunities for insider exploitation, and proactive re-engineering that enforces clear third-party responsibilities to reduce opportunities for criminal exploitation arising from weaknesses in third-party management. The model further advances research and practice by providing an interdisciplinary foundation for cybercrime-resilient and secure processes.
Journal
J
IF:
3.2
Papers:
52
Citations:
0
