{"id":"https://openalex.org/W2896921551","doi":"https://doi.org/10.1093/cybsec/tyy006","title":"A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate","display_name":"A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate","publication_year":2018,"publication_date":"2018-01-01","ids":{"openalex":"https://openalex.org/W2896921551","doi":"https://doi.org/10.1093/cybsec/tyy006","mag":"2896921551"},"language":"en","primary_location":{"id":"doi:10.1093/cybsec/tyy006","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyy006","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/4/1/tyy006/27126934/tyy006.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://academic.oup.com/cybersecurity/article-pdf/4/1/tyy006/27126934/tyy006.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061046049","display_name":"Ioannis Agrafiotis","orcid":"https://orcid.org/0000-0003-3747-339X"},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Ioannis Agrafiotis","raw_affiliation_strings":["Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075453550","display_name":"Jason R. C. Nurse","orcid":"https://orcid.org/0000-0003-4118-1680"},"institutions":[{"id":"https://openalex.org/I20581793","display_name":"University of Kent","ror":"https://ror.org/00xkeyj56","country_code":"GB","type":"education","lineage":["https://openalex.org/I20581793"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Jason R C Nurse","raw_affiliation_strings":["School of Computing, University of Kent, Canterbury, CT2 7NF, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computing, University of Kent, Canterbury, CT2 7NF, UK","institution_ids":["https://openalex.org/I20581793"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063148097","display_name":"Michael Goldsmith","orcid":"https://orcid.org/0000-0001-7808-0600"},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Michael Goldsmith","raw_affiliation_strings":["Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004437304","display_name":"Sadie Creese","orcid":"https://orcid.org/0000-0002-2414-9657"},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Sadie Creese","raw_affiliation_strings":["Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Oxford, Oxford, OX1 3QD, UK","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5083514169","display_name":"David M. Upton","orcid":null},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"David Upton","raw_affiliation_strings":["Sa\u00efd Business School, University of Oxford, Oxford, OX1 1HP, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sa\u00efd Business School, University of Oxford, Oxford, OX1 1HP, UK","institution_ids":["https://openalex.org/I40120149"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5061046049"],"corresponding_institution_ids":["https://openalex.org/I40120149"],"apc_list":{"value":1864,"currency":"USD","value_usd":1864},"apc_paid":{"value":1864,"currency":"USD","value_usd":1864},"fwci":29.2023,"has_fulltext":true,"cited_by_count":361,"citation_normalized_percentile":{"value":0.99564501,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"4","issue":"1","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9944000244140625,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12221","display_name":"Cybersecurity and Cyber Warfare Studies","score":0.9799000024795532,"subfield":{"id":"https://openalex.org/subfields/3320","display_name":"Political Science and International Relations"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/harm","display_name":"Harm","score":0.9187310934066772},{"id":"https://openalex.org/keywords/taxonomy","display_name":"Taxonomy (biology)","score":0.4483564496040344},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4324760138988495},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.4263323247432709},{"id":"https://openalex.org/keywords/public-relations","display_name":"Public relations","score":0.3899827301502228},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37788522243499756},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.3165254592895508},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.26775991916656494},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.2431156039237976},{"id":"https://openalex.org/keywords/social-psychology","display_name":"Social psychology","score":0.22628599405288696}],"concepts":[{"id":"https://openalex.org/C2777363581","wikidata":"https://www.wikidata.org/wiki/Q15098235","display_name":"Harm","level":2,"score":0.9187310934066772},{"id":"https://openalex.org/C58642233","wikidata":"https://www.wikidata.org/wiki/Q8269924","display_name":"Taxonomy (biology)","level":2,"score":0.4483564496040344},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4324760138988495},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.4263323247432709},{"id":"https://openalex.org/C39549134","wikidata":"https://www.wikidata.org/wiki/Q133080","display_name":"Public relations","level":1,"score":0.3899827301502228},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37788522243499756},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.3165254592895508},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.26775991916656494},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.2431156039237976},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.22628599405288696},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1093/cybsec/tyy006","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyy006","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/4/1/tyy006/27126934/tyy006.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},{"id":"pmh:oai:kar.kent.ac.uk:69076","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec%2Ftyy006>)","pdf_url":"https://kar.kent.ac.uk/69076/1/Taxonomy_of_Cyber-Harms-author-final.pdf","source":{"id":"https://openalex.org/S4377196264","display_name":"Kent Academic Repository (University of Kent)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I20581793","host_organization_name":"University of Kent","host_organization_lineage":["https://openalex.org/I20581793"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"},{"id":"pmh:oai:ora.ox.ac.uk:uuid:7e86c83a-a7fc-4703-9916-1363302eb55b","is_oa":true,"landing_page_url":"https://ora.ox.ac.uk/objects/uuid:7e86c83a-a7fc-4703-9916-1363302eb55b","pdf_url":null,"source":{"id":"https://openalex.org/S4306402636","display_name":"Oxford University Research Archive (ORA) (University of Oxford)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I40120149","host_organization_name":"University of Oxford","host_organization_lineage":["https://openalex.org/I40120149"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Journal article"}],"best_oa_location":{"id":"doi:10.1093/cybsec/tyy006","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyy006","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/4/1/tyy006/27126934/tyy006.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.75}],"awards":[{"id":"https://openalex.org/G8527692473","display_name":null,"funder_award_id":"EP/S018964/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2896921551.pdf","grobid_xml":"https://content.openalex.org/works/W2896921551.grobid-xml"},"referenced_works_count":45,"referenced_works":["https://openalex.org/W601080578","https://openalex.org/W640989674","https://openalex.org/W1412796528","https://openalex.org/W1499966149","https://openalex.org/W1501321335","https://openalex.org/W1525509791","https://openalex.org/W1541515907","https://openalex.org/W1776087634","https://openalex.org/W1863670505","https://openalex.org/W1980798317","https://openalex.org/W2018085556","https://openalex.org/W2032561088","https://openalex.org/W2042136832","https://openalex.org/W2045757891","https://openalex.org/W2062199894","https://openalex.org/W2062493711","https://openalex.org/W2066212565","https://openalex.org/W2067404301","https://openalex.org/W2068750252","https://openalex.org/W2069396279","https://openalex.org/W2096274199","https://openalex.org/W2110485449","https://openalex.org/W2118243999","https://openalex.org/W2136015481","https://openalex.org/W2136884029","https://openalex.org/W2142225512","https://openalex.org/W2158894011","https://openalex.org/W2406849559","https://openalex.org/W2489576359","https://openalex.org/W2493432324","https://openalex.org/W2516703736","https://openalex.org/W2565682512","https://openalex.org/W2567607894","https://openalex.org/W2588205325","https://openalex.org/W2734999728","https://openalex.org/W2916518443","https://openalex.org/W3130374753","https://openalex.org/W6630017550","https://openalex.org/W6638008848","https://openalex.org/W6655161477","https://openalex.org/W6662236310","https://openalex.org/W6667697102","https://openalex.org/W6682976791","https://openalex.org/W6725881023","https://openalex.org/W6791086374"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W3203175338","https://openalex.org/W2356901839","https://openalex.org/W3209501579","https://openalex.org/W2969547062","https://openalex.org/W2497114785","https://openalex.org/W4283162910","https://openalex.org/W2803806723","https://openalex.org/W4245578471","https://openalex.org/W4293140739"],"abstract_inverted_index":{"Technological":[0],"advances":[1],"have":[2],"resulted":[3],"in":[4,66,172],"organizations":[5,46,227],"digitalizing":[6],"many":[7],"parts":[8],"of":[9,15,24,34,110,116,144,165,237,252],"their":[10],"operations.":[11],"The":[12],"threat":[13],"landscape":[14],"cyberattacks":[16],"is":[17,27,31],"rapidly":[18],"changing":[19],"and":[20,38,42,60,71,73,81,92,97,103,112,137,139,169,180,191,194],"the":[21,44,56,202,219,245,250],"potential":[22],"impact":[23,82],"such":[25,68,78,217],"attacks":[26],"uncertain,":[28],"because":[29],"there":[30],"a":[32,114,215],"lack":[33],"effective":[35],"metrics,":[36],"tools":[37,206],"frameworks":[39],"to":[40,84,228,234],"understand":[41],"assess":[43],"harm":[45,111,166],"face":[47],"from":[48,154,183],"cyber-attacks.":[49,155],"In":[50,142],"this":[51,176],"article,":[52],"we":[53,106,147,221],"reflect":[54],"on":[55,58,87,93,214],"literature":[57,90],"harm,":[59],"how":[61,75,161,170],"it":[62],"has":[63],"been":[64],"conceptualized":[65],"disciplines":[67],"as":[69,79,218],"criminology":[70],"economics,":[72],"investigate":[74],"other":[76,104],"notions":[77],"risk":[80],"relate":[83],"harm.":[85,141,253],"Based":[86],"an":[88],"extensive":[89],"survey":[91],"reviewing":[94],"news":[95],"articles":[96],"databases":[98],"reporting":[99],"cyber-incidents,":[100],"cybercrimes,":[101],"hacks":[102],"attacks,":[105],"identify":[107,229],"various":[108],"types":[109,164,236],"create":[113],"taxonomy":[115,122,216],"cyber-harms":[117,150],"encountered":[118],"by":[119,199],"organizations.":[120],"This":[121],"comprises":[123],"five":[124],"broad":[125],"themes:":[126],"physical":[127],"or":[128],"digital":[129],"harm;":[130,132,134,136],"economic":[131],"psychological":[133],"reputational":[135],"social":[138],"societal":[140],"each":[143],"these":[145,162,233],"themes,":[146],"present":[148],"several":[149],"that":[151],"can":[152,211],"result":[153],"To":[156],"provide":[157],"initial":[158],"indications":[159],"about":[160],"different":[163,235],"are":[167],"connected":[168],"cyber-harm":[171],"general":[173],"may":[174],"propagate,":[175],"article":[177],"also":[178],"analyses":[179],"draws":[181],"insight":[182],"four":[184],"real-world":[185],"case":[186],"studies,":[187],"involving":[188],"Sony":[189],"(2011":[190],"2014),":[192],"JPMorgan":[193],"Ashley":[195],"Madison.":[196],"We":[197],"conclude":[198],"arguing":[200],"for":[201,204,207,249],"need":[203],"analytical":[205],"organizational":[208],"cyber-harm,":[209,238],"which":[210],"be":[212],"based":[213],"one":[220],"propose":[222],"here.":[223],"These":[224],"would":[225],"allow":[226],"corporate":[230],"assets,":[231],"link":[232],"measure":[239],"those":[240],"harms":[241],"and,":[242],"finally,":[243],"consider":[244],"security":[246],"controls":[247],"needed":[248],"treatment":[251]},"counts_by_year":[{"year":2026,"cited_by_count":19},{"year":2025,"cited_by_count":67},{"year":2024,"cited_by_count":56},{"year":2023,"cited_by_count":92},{"year":2022,"cited_by_count":56},{"year":2021,"cited_by_count":37},{"year":2020,"cited_by_count":25},{"year":2019,"cited_by_count":9}],"updated_date":"2026-06-16T09:24:06.705377","created_date":"2025-10-10T00:00:00"}
