•  
  •  
 

Publication Date

7-27-2026

Abstract

 Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking.  The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from policy and procedural failures, and emergent cybersecurity ecosystem properties. It further defines technocentric mythos bias as a possible blinder causality for cybersecurity and technical security professionals who might otherwise be unable to or improperly trained to attribute incident causality as systemic. It explains why the end-user becomes the most heuristically available failure explanation, simply because of visibility. This attribution fails to account for organizational and systemic conditions which set the stage for end-user blaming, instead using availability bias for causality attribution.  It recommends training considerations to improve the systemic identification of causality in accordance with systems engineering and industry’s best practices.

Share

COinS