A Structuration Approach to Theorizing Cybersecurity Practice: The STARC Model

📅 2026-07-28
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of existing theories that focus solely on the organizational level and fail to explain why organizations with similar security controls exhibit markedly different levels of cyber resilience. Drawing on structuration theory, it proposes the STARC framework, which employs five structure–agency dualities to analyze the mechanisms underlying the success or failure of cybersecurity practices across multi-level, adversarial, and human–machine hybrid environments. The work innovatively extends structuration theory through three key contributions: multi-level adversarial agency, threat-adaptive structuration, and material–agentic structural properties, thereby introducing structuration theory into cybersecurity research. Based on in-depth interviews with 20 practitioners from three banks in Australia, Indonesia, and Malaysia, the study uncovers structural sources of organizational resilience shaped by resource endowments and outsourcing arrangements, offers novel conceptual tools for diagnosing cross-level coordination failures, temporal misalignments, and breakdowns in human–machine accountability boundaries, and advances seven testable propositions.
📝 Abstract
The problem: Cybersecurity practice runs simultaneously across analysts, teams, organizations, sectors, and regulators, co-evolves with adversaries, and increasingly blends human and algorithmic decision-making. The theories applied to it operate at single organizational levels and cannot explain why organizations with broadly similar controls differ sharply in resilience. This paper: We develop STARC (Structuration Theory Adaptation for Resilient Cybersecurity), a framework for locating where cybersecurity practice succeeds or fails structurally. It extends Giddens' Structuration Theory with three innovations, Multi-Level Adversarial Agency, Threat-Adaptive Structuration, and Material-Agential Structural Properties, across five structure-agency triads. Evidence base: STARC is illustrated through re-analysis of three financial organizations, an Australian, an Indonesian, and a Malaysian bank, across 20 interviews from SOC analysts to senior executives, selected as diverse insourced and outsourced configurations rather than as a comparison of equivalents. Cybersecurity contribution: STARC offers a structural account of why differently resourced and outsourced organizations differ in resilience, and a vocabulary for diagnosing incident-response breakdown across levels, tempos, and the human-algorithm authority boundary that single-level frameworks leave invisible. Theory and outputs: It extends Structuration Theory to adversarial, multi-level, and hybrid human-algorithmic contexts, and yields seven testable propositions linking structuration to resilience, offered for future testing.
Problem

Research questions and friction points this paper is trying to address.

cybersecurity practice
organizational resilience
multi-level analysis
human-algorithm decision-making
adversarial co-evolution
Innovation

Methods, ideas, or system contributions that make the work stand out.

Structuration Theory
Cybersecurity Resilience
Human-Algorithm Collaboration
Multi-Level Adversarial Agency
Threat-Adaptive Structuration
🔎 Similar Papers