Paper Type
Short
Paper Number
PACIS2026-1355
Description
Cybersecurity threats continue to expose weak security controls in information systems. This risk is acute in Information Systems Development (ISD) outsourcing projects, where clients and vendors must exchange complex security knowledge. This study develops a framework to explain how cybersecurity knowledge is transferred from clients to vendors and within vendor organizations. Drawing on knowledge management theory, we conducted four semi structured interviews with experienced ISD professionals and analyzed the data using thematic analysis. Findings show that cybersecurity knowledge operates across application, integration, infrastructure, and physical levels. We identify three transfer mechanisms: expertise transfer, framework and upgrades transfer, and design and functionality transfer. The framework clarifies how secure systems are produced in outsourced contexts. Ongoing research will extend the model through additional interviews and develop propositions to guide future empirical work.
Recommended Citation
Subasinghage, Maduka; Hassandoust, Farkhondeh; and Johnston, Allen, "Cybersecurity Knowledge Transfer in Information Systems Development Outsourcing Projects" (2026). PACIS 2026 Proceedings. 4.
https://aisel.aisnet.org/pacis2026/dig_sec/dig_sec/4
Cybersecurity Knowledge Transfer in Information Systems Development Outsourcing Projects
Cybersecurity threats continue to expose weak security controls in information systems. This risk is acute in Information Systems Development (ISD) outsourcing projects, where clients and vendors must exchange complex security knowledge. This study develops a framework to explain how cybersecurity knowledge is transferred from clients to vendors and within vendor organizations. Drawing on knowledge management theory, we conducted four semi structured interviews with experienced ISD professionals and analyzed the data using thematic analysis. Findings show that cybersecurity knowledge operates across application, integration, infrastructure, and physical levels. We identify three transfer mechanisms: expertise transfer, framework and upgrades transfer, and design and functionality transfer. The framework clarifies how secure systems are produced in outsourced contexts. Ongoing research will extend the model through additional interviews and develop propositions to guide future empirical work.
Comments
08-Security