[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83657-en":3,"doc-seo-83657-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83657,3848291630094,"Emma Wilson","https://eur-avatar.wpscdn.com/davatar_085a072bc5b1113ac321206ff7593b45",8,"Research & Report","SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors","Cybersecurity incident response is a critical research and practice area, yet the literature remains scattered without a unified structure to organize accumulated knowledge. This study systematizes organizational preparedness and response factors using a “Cybersecurity Incident Response Influencing Factor Taxonomy” (CIR-IF). A systematic review covers 417 academic papers and 40 non-scientific publications, spanning 1999 to mid-2024. Empirical findings are mapped to the taxonomy and compared with seven frameworks and NIST SP 800-61r3 elements, yielding a richer, more rigorous, and systematically organized view of incident response drivers.","SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors  \nThomas Biege∗ , Marius Brockhoff†‡, Jonas Kaspereit∗‡, Fabian Ising†, Lea Gröber§ , Sebastian Schinzel∗†  \n∗ FH Münster University of Applied Sciences, Steinfurt, Germany  \n{thomas.biege, j.kaspereit, [schinzel}@fh-muenster.de](schinzel}@fh-muenster.de)  \n† Fraunhofer SIT and National Research Center for Applied Cybersecurity ATHENE, Steinfurt, Germany  \n{marius.brockhoff, [fabian.ising}@sit.fraunhofer.de](fabian.ising}@sit.fraunhofer.de)  \n‡ Graduate School for Applied Research in North Rhine-Westphalia (Graduate School NRW), Bochum, Germany  \n§ International Computer Science Institute, UC Berkeley, Berkeley, CA, USA  \n[lgrober@icsi.berkeley.edu](lgrober@icsi.berkeley.edu)  \narXiv :2607 .0245 1v 1 [ cs .CR] 2 Jul 2026  \nAbstract—Cybersecurity incident response has emerged asa critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology, human-computer interaction, organizational theory, and human factors. A comprehensive, integrative perspective on these factors can enable researchers to identify underexplored areas and more effectively target their empirical and theoretical investigations. Our study systematizes the factors that influence organizational preparedness for and response to cybersecurity incidents. Through a systematic review of academic literature (n = 417) and non-scientific publications (n = 40), we derived the \"Cybersecurity Incident Response Influencing Factor Taxonomy\"(CIR-IF Taxonomy). Existing empirical findings were classified within this taxonomy, providing a comprehensive and up-to-date overview of knowledge from the period 1999 to mid-2024. The taxonomy categories were systematically compared with seven established scientific frameworks and with the NIST Cyber Security Framework elements referenced in the NIST Special Publication 800-61r3 incident response profile. The results of this comparison show that the CIRIF Taxonomy delivers a richer, more rigorous, and more systematically organized view of the factors that drive and shape incident response.  \nIndex Terms—Cybersecurity Incident Response, Influencing Factors, Taxonomy, Systematization of Knowledge, Security Operation Center, CERT, Management, Human Factors, Context Factors  \n1. Introduction  \nApproximately a decade after the first Computer Emergency Response Team (CERT) had been established in response to the Morris worm incident in 1988 [1], the first scientific and practitioner-oriented publicationson Computer Emergency Response Teams (CERTs) and Cybersecurity Incident Response (CIR) were published. Early literature mainly provided guidance on how to organize a CERT and what the incident response process could look like. Notable examples are the second edition of the \"Handbook for Computer Security Incident Response  \nTeams (CSIRTs)\" by Moira West-Brown et al. [2] and\"A common process model for incident response and computer forensics\" by Felix C. Freiling and Bastian Schwittay [3] .  \nBody of literature. Around 2014, the number of publications increased significantly; see Fig. 3. Researchers and experts in the field were probably driven by the major cyberattacks that were carried out at this time 1. Since then, both the frequency and complexity of cyberattacks worldwide have increased, reaching a maximum during the COVID-19 pandemic (see [Statista.com](Statista.com2)[2](Statista.com2)) . In parallel with these developments, the corresponding body of literature has undergone continuous and substantial expansion. The interdisciplinary interest in this sociotechnical research domain [4] has grown, encompassing not only technological but also human-centered aspects.  \nFrameworks. Industry standards, such as NIST SP 800-61, and ","cbCaivlEdCAZNfmB","https://ap.wps.com/l/cbCaivlEdCAZNfmB","pdf",1189671,5,1,22,"English","en",105,"# Introduction\n## Research motivation and questions\n# Systematization method\n## Systematic review scope\n# CIR-IF Taxonomy and comparison","[{\"question\":\"What gap does the CIR-IF Taxonomy address?\",\"answer\":\"It addresses the lack of an industry-agnostic, bottom-up scientific systematization of incident response influencing factors, turning fragmented findings into a structured taxonomy.\"},{\"question\":\"How was the taxonomy derived in the study?\",\"answer\":\"Through a systematic review of academic literature (n=417) and non-scientific publications (n=40), identifying and organizing factors affecting organizational preparedness and response.\"},{\"question\":\"How was the taxonomy validated or evaluated?\",\"answer\":\"Existing empirical findings were classified within CIR-IF and then compared against seven established scientific frameworks and incident response elements referenced from NIST SP 800-61r3.\"}]",1784189571,55,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"sok-a-taxonomy-for-cybersecurity-incident-response-influence-factors","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/sok-a-taxonomy-for-cybersecurity-incident-response-influence-factors/83657/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What gap does the CIR-IF Taxonomy address?","Question",{"text":76,"@type":77},"It addresses the lack of an industry-agnostic, bottom-up scientific systematization of incident response influencing factors, turning fragmented findings into a structured taxonomy.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How was the taxonomy derived in the study?",{"text":81,"@type":77},"Through a systematic review of academic literature (n=417) and non-scientific publications (n=40), identifying and organizing factors affecting organizational preparedness and response.",{"name":83,"@type":74,"acceptedAnswer":84},"How was the taxonomy validated or evaluated?",{"text":85,"@type":77},"Existing empirical findings were classified within CIR-IF and then compared against seven established scientific frameworks and incident response elements referenced from NIST SP 800-61r3.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]