Journal article
A structuration approach to theorizing cybersecurity practice: The STARC model
M Aktaruzzaman, A Ahmad, SB Maynard
Computers and Security | Elsevier BV | Published : 2027
Abstract
The problem: Cybersecurity practice runs simultaneously across analysts, teams, organizations, sectors, and regulators, co-evolves with adversaries, and increasingly blends human and algorithmic decision-making. The theories applied to it operate at single organizational levels and offer limited insight into why organizations with broadly similar controls differ sharply in resilience. This paper: We develop STARC (Structuration Theory Adaptation for Resilient Cybersecurity), a framework for locating where cybersecurity practice succeeds or fails structurally. It extends Giddens' Structuration Theory with three innovations, Multi-Level Adversarial Agency, Threat-Adaptive Structuration, and Ma..
View full abstract