An Empirical Study of Challenges for Developing Global Cybersecurity Culture
Context: Cyberspace insecurity presents global challenges that require coordinated action among governments, industry, academia, and civil society. Although the United Nations adopted Resolution 57/239 in 2003 to promote a global cybersecurity culture, implementation remains uneven due to differences in national capabilities, priorities, and geopolitical interests. From a software engineering perspective, these challenges influence software security practices and highlight the need to integrate cybersecurity culture into the Software Development Life Cycle (SDLC). Objective: This study aims to empirically identify and validate the key challenges that hinder the development of a global cybersecurity culture and to position cybersecurity culture as a software engineering concern rather than solely as a policy or awareness issue. Method: Following Multivocal Literature Review (MLR) guidelines in software engineering, initial challenges were identified through literature analysis and subsequently validated via a questionnaire survey of 51 cybersecurity professionals across Asia (61%), Europe (24%), and other regions (15%). Participants included junior, intermediate, and senior professionals. Descriptive statistical analysis was used to determine consensus levels, with ≥86% agreement used as the threshold for identifying critical challenges. Results: Seven critical challenges were identified with strong expert consensus: lack of public awareness and education, absence of a coordinated global cybersecurity strategy, rapidly evolving cyber threats, uneven national capabilities, insufficient public-private sector partnerships, disputes over digital human rights integration, and limited international cooperation. These challenges significantly affect secure software development practices and globally distributed systems. Conclusion: The findings indicate that achieving a unified global cybersecurity culture requires addressing not only the identified challenges but also the differing perspectives underlying proposed solutions. The study provides empirical evidence for policymakers and technical stakeholders and recommends treating cybersecurity culture as a non-functional requirement within the SDLC. This research reframes global cybersecurity culture as a software engineering issue and outlines a new direction for integrating cultural dimensions into secure system design and development.
Fri 12 JunDisplayed time zone: London change
09:00 - 17:00 | Software Security Engineering WorkshopSSE-26 Workshop on Software Security Engineering at JMS 707 Chair(s): Mohammad Alshayeb King Fahd University of Petroleum & Minerals, Mahmood Niazi King Fahd University of Petroleum and Minerals | ||
09:00 15mDay opening | Welcome by the Organizers SSE-26 Workshop on Software Security Engineering | ||
09:15 15mTalk | A Multi-Agentic AI Pipeline for Iterative Vulnerability Detection and Auto-Remediation in Python SSE-26 Workshop on Software Security Engineering | ||
09:30 15mTalk | An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code SSE-26 Workshop on Software Security Engineering | ||
09:45 15mTalk | Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets SSE-26 Workshop on Software Security Engineering | ||
10:00 15mTalk | Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners SSE-26 Workshop on Software Security Engineering Muhammad Azeem Akbar LUT University, Saima Rafi Edinburgh Napier University, Arif Ali Khan University of Oulu | ||
10:15 15mTalk | An Empirical Study of Challenges for Developing Global Cybersecurity Culture SSE-26 Workshop on Software Security Engineering Nisar Muhammad , Siffat Ullah Khan University of Malakand, Mahmood Niazi King Fahd University of Petroleum and Minerals, Mohammad Shameem | ||
10:30 30mBreak | Coffee Break SSE-26 Workshop on Software Security Engineering | ||
11:00 15mTalk | Pick and Sort for Graphical Authentication SSE-26 Workshop on Software Security Engineering Argianto Rahartomo TU Clausthal, Amirhossein Jamshidipoor , Mohammad Ghafari Tehran Institute for Advanced Studies (TEIAS) | ||
11:15 15mTalk | Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy SSE-26 Workshop on Software Security Engineering Petru-Liviu Bouruc , Ciprian Păduraru University of Bucharest, Alin Stefanescu The Institute for Logic and Data Science (ILDS), and University of Bucharest | ||
11:30 15mTalk | Empirical Evaluation of TLS Communication Overhead in Federated Learning Systems SSE-26 Workshop on Software Security Engineering | ||
11:45 15mTalk | Understanding Security Issues in Open-Source Agentic AI Frameworks: An Empirical Analysis SSE-26 Workshop on Software Security Engineering Muhammad Hamza Lappeenranta-Lahti University of Technology (LUT), Muhammad Azeem Akbar LUT University, Wardah Naeem Awan LUT University, Muhammad Shoaib | ||