@inproceedings{65583,
  abstract     = {{As digital products become increasingly embedded in organisational operations, cyber resilience – the ability to anticipate, withstand, recover from and adapt to cyber disruptions – has become essential. This paper investigates how professionals in German organisations interpret cyber resilience within the software development lifecycle and how socio-technical factors influence its implementation. Drawing on the MITRE Cyber Resiliency Engineering Framework for data collection and coding on Socio-Technical Systems as an interpretive lens, the study adopts a qualitative approach based on semi-structured interviews with 14 professionals across five organisations. The findings reveal a pronounced socio-technical imbalance: while technical measures centred on anticipate and withstand are comparatively established, the corresponding social factors – shared understanding, dedicated responsibility structures, and systematic learning – remain underdeveloped. These conditions are compounded by resource constraints and the absence of strategic prioritisation. Six exploratory hypotheses capture these patterns and offer empirically grounded starting points for future research on product-level cyber resilience.}},
  author       = {{Taaibi, Samira and Kahraman, Emanuel and Berg, Kevin and Dziwok, Stefan}},
  booktitle    = {{ECIS 2026 Proceedings}},
  keywords     = {{Cyber Resilience, Software Development Lifecycle, Qualitative Study, Cyber Resiliency Engineering Framework}},
  location     = {{Milan, Italy}},
  title        = {{{Beyond Security: A Qualitative Study of Cyber Resilience Across the Software Development Lifecycle in German Organisations}}},
  year         = {{2026}},
}

@inproceedings{53811,
  abstract     = {{Persistent security challenges plague DevOps teams due to a deficiency in expertise regarding security tools and methods, as evidenced by frequent security incidents. Existing maturity models fail to adequately address the specific needs of DevOps teams. In response, this paper proposes "Security Belts," a novel maturity model inspired by martial arts ranking systems. This model aims to assist DevOps teams in enhancing their security capabilities by providing a structured approach, starting with fundamental activities and progressing to more advanced techniques. Drawing from the experiences of monitoring 21 teams, the paper presents lessons learned and offers actionable advice for refining maturity models tailored to software quality improvement.}},
  author       = {{Taaibi, Samira and Dziwok, Stefan and Hermerschmidt, Lars and Koch, Thorsten and Merschjohann, Sven and Vollmary, Mark}},
  booktitle    = {{AMCIS 2024 Proceedings. 13.}},
  keywords     = {{Software security, maturity model}},
  location     = {{Salt Lake City}},
  title        = {{{Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report}}},
  year         = {{2024}},
}

