Hacking Humans? Social Engineering and the Construction of the "Deficient User" in Cybersecurity Discourses
Bibliographic Data
| ID | 5337367 |
|---|---|
| Authors | Nina Klimburg-Witjes (0000-0003-0583-8788, University of Vienna, corresponding author), Alexander Wentland (0000-0003-3080-8599, Technical University of Munich) |
| Year | 2021 |
| Volume | 46 |
| Issue | 6 |
| Pages | 1316-1339 |
| Publication date | 2021-11-01 |
| Peer Reviewed | Yes |
| Open Access | Yes |
| Type | ARTICLE |
| Venue | Science Technology & Human Values (JOURNAL) |
| Journal identifiers | ISSN: 0162-2439 • E-ISSN: 1552-8251 |
| Publisher | SAGE Publications Inc (PUBLISHER) |
| DOI | 10.1177/0162243921992844 |
| OpenAlex | W3133399946 |
| Language | EN |
| Citations received | 8 |
| References cited | 45 |
Today, social engineering techniques are the most common way of committing cybercrimes through the intrusion and infection of computer systems. Cybersecurity experts use the term "social engineering" to highlight the "human factor" in digitized systems, as social engineering attacks aim at manipulating people to reveal sensitive information. In this paper, we explore how discursive framings of individual versus collective security by cybersecurity experts redefine roles and responsibilities at the digitalized workplace. We will first show how the rhetorical figure of the deficient user is constructed vis-à-vis notions of (in)security in social engineering discourses. Second, we will investigate the normative tensions that these practices create. To do so, we link work in science and technology studies on the politics of deficit construction to recent work in critical security studies on securitization and resilience. Empirically, our analysis builds on a multi-sited conference ethnography during three cybersecurity conferences as well as an extensive document analysis. Our findings suggest a redistribution of institutional responsibility to the individual user through three distinct social engineering story lines-"the oblivious employee," "speaking code and social," and "fixing human flaws." Finally, we propose to open up the discourse on social engineering and its inscribed politics of deficit construction and securitization and advocate for companies and policy makers to establish and foster a culture of collective cyber in/security and corporate responsibility
Business · Computer security · Critical security studies · Cyberwarfare · Hacker · Information security · Malware · Network security policy · Political science · Politics · Public relations · Rhetorical question · Securitization · Security service · Social media · Sociology · Computer Science · COVID-19 Digital Contact Tracing · Cybersecurity and Cyber Warfare Studies · Global Security and Public Health · Law
Diabolus in Machina? Complex Digital Systems Interpreted through Early Modern Demonology
Anticipatory Governance in Biobanking
Engaging with cybercriminals
From Criminal to Crucial Participation
The fabrication of a necessary policy fiction
Collateral transitions. Reassembling societies, data centres and the twin transition
When the future meets the past
The Security-Innovation Nexus in (Geo-)Political Imagination
Vulnerability in Technological Cultures
Resilience
The Closed World
Challenging the “deficit model” of innovation
Public Engagement as a Means of Restoring Public Trust in Science – Hitting the Notes, but Missing the Music?
Critical Security Studies and World Politics
Research to improve public understanding programmes
From deficit to democracy (re-visited)
Risk and the War on Terror
Ethnographies of Conferences and Trade Fairs
Authoritative Governance
Cybersecurity Research Meets Science and Technology Studies
Cyber Security Assemblages
Enacting Expertise
A theory of actor-network for cyber-security
Securing Virtual Space
Exercising emergencies
What’s in an act? On security speech acts and little security nothings
Genealogies of resilience
Critical Approaches to Security in Europe
Resilience and (in)security
From ‘fearing’ to ‘empowering’ climate refugees
Technosecurity Cultures
An overview of social engineering malware
Machineries for Making Publics
Studying Global Environmental Meetings to Understand Global Environmental Governance
Cybersecurity, Bureaucratic Vitalism and European Emergency
An introduction to science and technology studies
Digital Disaster, Cyber Security, and the Copenhagen School
The Three Faces of Securitization
Securitization and the Construction of Security
The (in)securitization practices of the three universes of EU border control
Misunderstood misunderstanding
Opening Up" and "Closing Down
Securitization' revisited
Governing insecurity
| Unique citing works | 8 |
|---|---|
| Citations per year | 1,6 |
| Citation span | 2021 - 2026 (6) |
| Citation velocity | current |
| Highly cited | No |
| Citation types | Neutral: 7 |