The Impact of Organizational Structure and Technology Use on Collaborative Practices in Computer Emergency Response Teams: An Empirical Study
Thea Riebe, Marc-André Kaufhold, Christian Reuter
Abstract
Besides the merits of increasing digitization and interconnectedness in private and professional spaces, critical infrastructures and societies are more and more exposed to cyberattacks. In order to enhance the preventative and reactive capabilities against cyberattacks, Computer Emergency Response Teams (CERTs) are deployed in many countries and organizations. In Germany, CERTs in the public sector operate on federal and state level to provide information security services for authorities, citizens, and enterprises. Their tasks of monitoring, analyzing, and communicating threats and incidents is getting more complex due to the increasing amount of information disseminated into public channels. By adopting the perspectives of Computer-Supported Cooperative Work (CSCW) and Crisis Informatics, we contribute to the study of organizational structures, technology use, and the impact on collaborative practices in and between state CERTs with empirical research based on expert interviews with representatives of German state CERTs (N=15) and supplementary document analyses (N=25). We derive design and policy implications from our findings, including the need for interoperable and modular architecture, a shift towards service level agreements, cross-platform monitoring and analysis of incident data, use of deduplication techniques and standardized threat exchange formats, a reduction of resource costs through process automation, and transparent reporting and tool structures for information exchange.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a3c66049-c04c-48d3-9954-5067325b148dCited by top-tier papers3
- 'We Do Not Have the Capacity to Monitor All Media': A Design Case Study on Cyber Situational Awareness in Computer Emergency Response TeamsMarc-André Kaufhold, Thea Riebe, Markus Bayer, Christian ReuterCHI 2024 · 22 citations
- "I needed to solve their overwhelmness": How System Administration Work was Affected by COVID-19Mannat Kaur, Simon Parkin, Marijn Janssen, Tobias FiebigCSCW 2022 · 9 citations
- Cyber Threat Awareness, Protective Measures and Communication Preferences in Germany: Implications from Three Representative Surveys (2021-2024)Marc-André Kaufhold, Julian Bäumler, Marius Bajorski, Christian ReuterCHI 2025 · 4 citations
Related papers
- "Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTsAksel Ethembabaoglu, Natalia I. Kadenko, Yana Angelova, Yury Zhauniarovich et al.CHI 2026 · 1 citation
- Harnessing Inter-Organizational Collaboration and Automation to Combat Online Hate Speech: A Qualitative Study with German Reporting CentersJulian Bäumler, Thea Riebe, Marc-André Kaufhold, Christian ReuterCSCW 2025 · 4 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- Collaborative Work in Malware Analysis: Understanding the Roles and Challenges of Malware AnalystsRei Yamagishi, Shota Fujii, Shingo Yasuda, Takayuki Sato et al.CHI 2025 · 4 citations
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 4 citations
