article · Asian Journal of Current Research
Background: Cybersecurity incident response is commonly described as a sequence of technical activities, yet major incidents are managed by people working across organisational boundaries, under uncertainty and time pressure. Evidence about the human, organisational, procedural and technological conditions that shape response performance has not been consolidated across sectors. Objective: To determine which factors shape organisational cybersecurity incident-response performance and what evidence exists that training, structured processes, collaboration or decision support improve operational outcomes. Methods: An openly accessible evidence search was completed on 6 July 2026 for English-language primary empirical reports published from 1 January 2000 to 30 June 2026. Six reproducible web searches were supplemented by backward citation checking. One reviewer screened records, assessed full texts, extracted data and applied the Mixed Methods Appraisal Tool 2018. Because designs, settings, outcomes and estimands were incompatible, findings were synthesised thematically without statistical pooling. Results: Eighty-five records were identified, 11 duplicates were removed, 74 records were screened, 30 full-text reports were assessed and 26 reports representing 25 unique studies were included. Evidence was predominantly qualitative and spanned security operations centres, computer security incident response teams, critical infrastructure, finance, public administration and healthcare. Recurrent determinants were shared situation awareness, communication across tiers and shifts, role clarity, trusted informal networks, workload and staffing, realistic cross-functional training, usable tools and data, and learning that extends beyond immediate technical restoration. Healthcare studies showed that manual alternatives and local adaptation can preserve care, but may transfer substantial safety and wellbeing burdens to staff. Automation was perceived as useful, but respondents expressed limited willingness to delegate decisions without human oversight. Conclusions: Cybersecurity incident response is a socio-technical capability rather than a discrete technical procedure. Moderate-confidence evidence supports investment in shared situation awareness, explicit coordination, sustainable staffing and deliberate learning. Evidence for particular training formats, automation strategies and objective improvements in detection, containment or recovery time remains limited. Prospective multi-site evaluations using common operational and human-factors outcomes are needed.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.56557/ajocr/2026/v11i411074
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.